Long story short, I'd love to try your model and finetune it for my work but I outright can't without compromising company policy (as loading pickle files is unsafe). I believe in the long run there will be many more people with similar problems.
In theory, one could load the file in a sandboxed VM and then export the safetensor file themselves but that's a large hurdle for adoption.
Would you consider uploading safetensor files to huggingface too?
Long story short, I'd love to try your model and finetune it for my work but I outright can't without compromising company policy (as loading pickle files is unsafe). I believe in the long run there will be many more people with similar problems. In theory, one could load the file in a sandboxed VM and then export the safetensor file themselves but that's a large hurdle for adoption. Would you consider uploading safetensor files to huggingface too?