NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #325 most downloaded on PyPI
Last release 10 days ago
24 Sep 2026
Ships fairly regularly
a new release about every 2 months
Most releases are documented
notes for 20 of 28 stable releases
1 version withdrawn
withdrawn after publishing
4 years old
52 releases · first in 2022
One column per quarter.
Fast ⚡ prefetch loader for the pread backend and CUDA devices. Load times for big models in the order of ~60x faster (benchmarked on glm5.2 tp=8 B200,
Fast ⚡ prefetch loader for the pread backend and CUDA devices. Load times for big models in the order of ~60x faster (benchmarked on glm5.2 tp=8 B200, went from >60mins to 56s).
3.14t wheels!
cargo audit to separate job by @McPatate in #7950.29 by @McPatate in #796working-directory as step parameter by @McPatate in #799PrefetchLoader handle from Open::prefetch by @McPatate in #859Full Changelog: v0.8.0...v0.9.0-rc.1
Fast ⚡ prefetch loader for the pread backend and CUDA devices. Load times for big models in the order of ~60x faster (benchmarked on glm5.2 tp=8 B200,
Fast ⚡ prefetch loader for the pread backend and CUDA devices. Load times for big models in the order of ~60x faster (benchmarked on glm5.2 tp=8 B200, went from >60mins to 56s).
3.14t wheels!
cargo audit to separate job by @McPatate in #7950.29 by @McPatate in #796working-directory as step parameter by @McPatate in #799Full Changelog: v0.8.0...v0.9.0-rc.0
…more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-le…
safetensors joins the PyTorch foundation!
Read more on that: https://huggingface.co/blog/safetensors-joins-pytorch-foundation
Safetensors 0.8.0 brings direct to Metal loading on Apple Silicon, GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.
The serialize and serialize_file functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a TensorSpec class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-level wrappers (safetensors.torch, safetensors.numpy, safetensors.paddle) are updated internally and their public API is unchanged.
The minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.
TensorIndexer::Narrow now carries a step: NonZeroUsize parameter, so a slice is now start:stop:step. This is a fix as this silent error was hidden behind the Storage::Torch variant which offloaded slicing logic to torch directly.
On the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.
Also dropped the anaconda CI we had as there's already an automatic tracker via conda-forge.
MTLBuffer and handed to the frameworks that support it (only torch atm) via DLPack, skipping needless copies.backend parameter introduced, for the addition of the pread backend. We now support loading files via pread(2) syscall instead of just mmap. Useful for specific archs/platforms.get_slice now handles ellipsis [...] and strided slices [:, ::8] wherever safetensors does the slicing itself (pread for any framework, MPS, and mmap outside torch/paddle), which silently dropped the step or rejected ... before.float8_e4m3fnuz and float8_e5m2fnuz (AMD FNUZ FP8 formats).F_NOCACHE for direct I/O, yielding roughly 30% faster save_file on Apple Silicon.[torch] extra, replaced by a simple hasattr probe for efficiency.2.4 by @McPatate in #710packaging for Torch 2.3.0+ datatype support by @akx in #705__version__ as str in the stub by @tarekziade in #730TensorSpec param to serialize* fns by @McPatate in #7380.8.0-dev.0 by @McPatate in #7403.9 in conda release by @McPatate in #741convert.py script by @McPatate in #746backend with pread file by @McPatate in #760_host_alias_storage w/ MTLBuffer by @McPatate in #7670.9.0-dev.0 by @McPatate in #777Full Changelog: v0.7.0...v0.8.0
…more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-le…
safetensors joins the PyTorch foundation!
Read more on that: https://huggingface.co/blog/safetensors-joins-pytorch-foundation
Safetensors 0.8.0 brings direct to Metal loading on Apple Silicon, GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.
The serialize and serialize_file functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a TensorSpec class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-level wrappers (safetensors.torch, safetensors.numpy, safetensors.paddle) are updated internally and their public API is unchanged.
The minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.
TensorIndexer::Narrow now carries a step: NonZeroUsize parameter, so a slice is now start:stop:step. This is a fix as this silent error was hidden behind the Storage::Torch variant which offloaded slicing logic to torch directly.
On the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.
Also dropped the anaconda CI we had as there's already an automatic tracker via conda-forge.
MTLBuffer and handed to the frameworks that support it (only torch atm) via DLPack, skipping needless copies.backend parameter introduced, for the addition of the pread backend. We now support loading files via pread(2) syscall instead of just mmap. Useful for specific archs/platforms.get_slice now handles ellipsis [...] and strided slices [:, ::8] wherever safetensors does the slicing itself (pread for any framework, MPS, and mmap outside torch/paddle), which silently dropped the step or rejected ... before.float8_e4m3fnuz and float8_e5m2fnuz (AMD FNUZ FP8 formats).F_NOCACHE for direct I/O, yielding roughly 30% faster save_file on Apple Silicon.[torch] extra, replaced by a simple hasattr probe for efficiency.2.4 by @McPatate in #710packaging for Torch 2.3.0+ datatype support by @akx in #705__version__ as str in the stub by @tarekziade in #730TensorSpec param to serialize* fns by @McPatate in #7380.8.0-dev.0 by @McPatate in #7403.9 in conda release by @McPatate in #741convert.py script by @McPatate in #746backend with pread file by @McPatate in #760_host_alias_storage w/ MTLBuffer by @McPatate in #7670.9.0-dev.0 by @McPatate in #777Full Changelog: v0.7.0...v0.8.0-rc.1
…more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-le…
safetensors joins the PyTorch foundation!
Read more on that: https://huggingface.co/blog/safetensors-joins-pytorch-foundation
Safetensors 0.8.0 brings GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.
The serialize and serialize_file functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a TensorSpec class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level serialize / serialize_file API directly; the high-level wrappers (safetensors.torch, safetensors.numpy, safetensors.paddle) are updated internally and their public API is unchanged.
The minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.
On the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.
float8_e4m3fnuz and float8_e5m2fnuz (AMD FNUZ FP8 formats).F_NOCACHE for direct I/O, yielding roughly 30% faster save_file on Apple Silicon.[torch] extra, replaced by a simple hasattr probe for efficiency.2.4 by @McPatate in #710packaging for Torch 2.3.0+ datatype support by @akx in #705__version__ as str in the stub by @tarekziade in #730TensorSpec param to serialize* fns by @McPatate in #7380.8.0-dev.0 by @McPatate in #740Full Changelog: v0.7.0...v0.8.0-rc.0
Nothing published for this version
This release adds support for storing complex64 tensors.
complex64 supportThis release adds support for storing complex64 tensors.
packaging as a dependency for the torch extra by @danieldk in #666Full Changelog: v0.6.2...v0.7.0
Set version to 0.7.0-rc.1
Set version to 0.7.0-rc.1
Nothing published for this version
Nothing published for this version
Fixing clippy in 1.89 by @Narsil in #644
Full Changelog: v0.6.1...v0.6.2
Rust release upgrade (cache v1 is discontinued). by @Narsil in #627
Full Changelog: v0.6.0...v0.6.1
Rust release upgrade (cache v1 is discontinued). by @Narsil in #627
Full Changelog: v0.6.0...v0.6.1-rc0
Bumping version because of breaking changes. by @Narsil in https://github.com/huggingface/safetensors/pull/619
Display and Error impls by @H2CO3 in https://github.com/huggingface/safetensors/pull/616&Option<T> in public API; use Option<&T> instead by @H2CO3 in https://github.com/huggingface/safetensors/pull/617Full Changelog: https://github.com/huggingface/safetensors/compare/v0.5.3...v0.6.0-rc0
Nothing published for this version
Updating the dev number. by @Narsil in https://github.com/huggingface/safetensors/pull/558
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.5.2...v0.5.3
support no_std by @ivila in https://github.com/huggingface/safetensors/pull/556
safe_open.__init__ in stub file by @SunghwanShim in https://github.com/huggingface/safetensors/pull/557Full Changelog: https://github.com/huggingface/safetensors/compare/v0.5.1...v0.5.2
Fixed the stubs for type tools.
Fixed the stubs for type tools.
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.5.0...v0.5.1
Update __init__.pyi by @w1gs in https://github.com/huggingface/safetensors/pull/533
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.4.5...v0.5.0
Update __init__.pyi by @w1gs in https://github.com/huggingface/safetensors/pull/533
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.4.5...v0.5.0rc0
Nothing published for this version
Use id rather than modelId by @osanseviero in https://github.com/huggingface/safetensors/pull/517
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.4.4...v0.4.5
Fixed a bug bf16 + big endian + torch https://github.com/huggingface/safetensors/pull/507
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.4.3...v0.4.4
Fixing empty serialization (no tensor) with some metadata. by @Narsil in https://github.com/huggingface/safetensors/pull/472
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.4.3...v0.4.4rc0
Updating minor after release 0.4.2 by @Narsil in https://github.com/huggingface/safetensors/pull/433
[0, :2, -1]. by @Narsil in https://github.com/huggingface/safetensors/pull/440device in safetensors.torch.load_model by @Wauplin in https://github.com/huggingface/safetensors/pull/449Full Changelog: https://github.com/huggingface/safetensors/compare/v0.4.2...v0.4.3
Updating minor after release 0.4.2 by @Narsil in https://github.com/huggingface/safetensors/pull/433
[0, :2, -1]. by @Narsil in https://github.com/huggingface/safetensors/pull/440device in safetensors.torch.load_model by @Wauplin in https://github.com/huggingface/safetensors/pull/449Full Changelog: https://github.com/huggingface/safetensors/compare/v0.4.2...v0.4.3rc0
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329huggingface_hub.get_safetensors_metadata by @Wauplin in https://github.com/huggingface/safetensors/pull/417hfoptions for metadata by @mishig25 in https://github.com/huggingface/safetensors/pull/424Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.4.2
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329huggingface_hub.get_safetensors_metadata by @Wauplin in https://github.com/huggingface/safetensors/pull/417hfoptions for metadata by @mishig25 in https://github.com/huggingface/safetensors/pull/424Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.4.2rc0
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.4.1
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.4.1rc1
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.4.0
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.4.0rc1
Nothing published for this version
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
Mostly fixes for big endian machines.
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.3.3
Temporary revert of the breaking change (keep it for 0.4.0). by @Narsil in https://github.com/huggingface/safetensors/pull/336
View for TensorView by @coreylowman in https://github.com/huggingface/safetensors/pull/329Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.2...v0.3.3.rc1
Remove the breaking change of disallowing zero sized tensors. by @Narsil in https://github.com/huggingface/safetensors/pull/221
save_model and load_model to help with shared tensors with PyTorch. by @Narsil in https://github.com/huggingface/safetensors/pull/236.dev0 while on main by @mishig25 in https://github.com/huggingface/safetensors/pull/246len on SafeTensors by @mfuntowicz in https://github.com/huggingface/safetensors/pull/252safejax in "Featured Projects" by @alvarobartt in https://github.com/huggingface/safetensors/pull/260slice get_dtype() method to get the dtype directly on slices. by @Narsil in https://github.com/huggingface/safetensors/pull/303attacks/README.md by @bliutech in https://github.com/huggingface/safetensors/pull/305Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.0...v0.3.2
Prepare 0.3.2 by @Narsil in https://github.com/huggingface/safetensors/pull/239
.dev0 while on main by @mishig25 in https://github.com/huggingface/safetensors/pull/246len on SafeTensors by @mfuntowicz in https://github.com/huggingface/safetensors/pull/252safejax in "Featured Projects" by @alvarobartt in https://github.com/huggingface/safetensors/pull/260slice get_dtype() method to get the dtype directly on slices. by @Narsil in https://github.com/huggingface/safetensors/pull/303attacks/README.md by @bliutech in https://github.com/huggingface/safetensors/pull/305Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.1rc1...v0.3.2.rc1
Remove the breaking change of disallowing zero sized tensors. by @Narsil in https://github.com/huggingface/safetensors/pull/221
save_model and load_model to help with shared tensors with PyTorch. by @Narsil in https://github.com/huggingface/safetensors/pull/236Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.0...v0.3.1
Remove the breaking change of disallowing zero sized tensors. by @Narsil in https://github.com/huggingface/safetensors/pull/221
save_model and load_model to help with shared tensors with PyTorch. by @Narsil in https://github.com/huggingface/safetensors/pull/236Full Changelog: https://github.com/huggingface/safetensors/compare/v0.3.0...v0.3.1rc1
Everything in this new release should be backward compatible.
Everything in this new release should be backward compatible.
The only thing which might not, is loading a file and saving it again might change it's layout. Content will be the same, but the order and positions of tensors might be changed to improve the alignment of buffers which can enable much faster loads on lower level languages. ( https://github.com/huggingface/safetensors/pull/148)
Full Changelog: https://github.com/huggingface/safetensors/compare/v0.2.8...v0.3.0
Everything in this new release should be backward compatible.
Everything in this new release should be backward compatible.
The only thing which might not, is loading a file and saving it again might change it's layout. Content will be the same, but the order and positions of tensors might be changed to improve the alignment of buffers which can enable much faster loads on lower level languages. ( https://github.com/huggingface/safetensors/pull/148)
Full Changelog: https://github.com/huggingface/safetensors/compare/python-v0.2.8...v0.3.0rc1
Fixing torch version parsing. by @Narsil in https://github.com/huggingface/safetensors/pull/143
np.uint8 and other types for which byte order is not defined. by @Narsil in https://github.com/huggingface/safetensors/pull/160Full Changelog: https://github.com/huggingface/safetensors/compare/v0.2.7...v0.2.8
Fixing SAFETENSORS_FAST_GPU=1 on Windows : https://github.com/huggingface/safetensors/pull/140
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →