NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #1876 most downloaded on crates.io
Provides functions to read and write safetensors which aim to be safer than their PyTorch counterpart. The format is 8 bytes which is an unsized int, being the size of a JSON header, the JSON header refers the `dtype` the `shape` and `data_offsets` which are the offsets for the values in the rest of the file.
Last release 4 months ago
09 Jun 2026
Ships fairly regularly
a new release about every 3 months
Rarely documented
notes for 5 of 22 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
22 releases · first in 2022
…more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-le…
safetensors joins the PyTorch foundation!
Read more on that: https://huggingface.co/blog/safetensors-joins-pytorch-foundation
Safetensors 0.8.0 brings direct to Metal loading on Apple Silicon, GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.
The serialize and serialize_file functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a TensorSpec class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-level wrappers (safetensors.torch, safetensors.numpy, safetensors.paddle) are updated internally and their public API is unchanged.
The minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.
TensorIndexer::Narrow now carries a step: NonZeroUsize parameter, so a slice is now start:stop:step. This is a fix as this silent error was hidden behind the Storage::Torch variant which offloaded slicing logic to torch directly.
On the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.
Also dropped the anaconda CI we had as there's already an automatic tracker via conda-forge.
MTLBuffer and handed to the frameworks that support it (only torch atm) via DLPack, skipping needless copies.backend parameter introduced, for the addition of the pread backend. We now support loading files via pread(2) syscall instead of just mmap. Useful for specific archs/platforms.get_slice now handles ellipsis [...] and strided slices [:, ::8] wherever safetensors does the slicing itself (pread for any framework, MPS, and mmap outside torch/paddle), which silently dropped the step or rejected ... before.float8_e4m3fnuz and float8_e5m2fnuz (AMD FNUZ FP8 formats).F_NOCACHE for direct I/O, yielding roughly 30% faster save_file on Apple Silicon.[torch] extra, replaced by a simple hasattr probe for efficiency.2.4 by @McPatate in #710packaging for Torch 2.3.0+ datatype support by @akx in #705__version__ as str in the stub by @tarekziade in #730TensorSpec param to serialize* fns by @McPatate in #7380.8.0-dev.0 by @McPatate in #7403.9 in conda release by @McPatate in #741convert.py script by @McPatate in #746backend with pread file by @McPatate in #760_host_alias_storage w/ MTLBuffer by @McPatate in #7670.9.0-dev.0 by @McPatate in #777Full Changelog: v0.7.0...v0.8.0
One column per quarter.
This release adds support for storing complex64 tensors.
complex64 supportThis release adds support for storing complex64 tensors.
packaging as a dependency for the torch extra by @danieldk in #666Full Changelog: v0.6.2...v0.7.0
Fixing clippy in 1.89 by @Narsil in #644
Full Changelog: v0.6.1...v0.6.2
Rust release upgrade (cache v1 is discontinued). by @Narsil in #627
Full Changelog: v0.6.0...v0.6.1
Bumping version because of breaking changes. by @Narsil in #619
Added support for FP4/FP6 https://www.opencompute.org/documents/ocp-microscaling-formats-mx-v1-0-spec-final-pdf
Support is still nascent in most frameworks (will require torch 2.8 which isn't released yet, and that will only support fp4 with caveats), however being an openspec supported by hardware manufacturers (and therefore hardware support most likely), it fits the bill of implementing it in safetensors (rather than all custom quantized formats existing in the wild in various frameworks.
What FP4/FP6 mean, is that now a element of a tensor may have a non byte-aligned size/access. If you store a single fp4, then there is 4 bit on that byte that is outside of the spec. For now, safetensors library will simply raise MisalignedByte exception whenever an operation leads to unused/unaligned bits within a byte. Since most tensors are larger power of 2s, this shouldn't come up too often in practice. Raising an exception now means we have freedom later to actually implement a behavior which could align with tensor libraries.
In that regard Dtype.size() is now deprecated, as it returns the size of the dtype in bytes, and we now favor bitsize() and it's up to users for now to handle something like len * bitsize() / 8 (and verifying the division is acceptable)
On that note, and for Pytorch users specifically, torch doesn't actually implement fp4, it has a dtype called float4_e2m1fn_x2 which actually represents 2 fp4. This is why torch shouldn't have any alignement problems for now (but cannot implement fp6). But that also means that the shape of a [2, 2] tensor for floa4, contains actually 8 values. safetensors will actuallly silently cast a tensor of shape, [x, y, ...z] into [x, y, ..., z/2], using the last dimension to "swallow" , the x2 contained within the types. Again, there is no definite behavior just yet, so this might be subject to change.
Display and Error impls by @H2CO3 in #616&Option<T> in public API; use Option<&T> instead by @H2CO3 in #617Full Changelog: v0.5.3...v0.6.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →