logoalt Hacker News

tennysontlast Tuesday at 6:27 PM1 replyview on HN

Pickle files are probably still useful saving exploratory work, collaborating inside a company, and use inside a pipeline.

Safetensors is supposed to be the successor for distribution. I believe that it's the "safe" subset of pickle's data format.


Replies

rhdunnlast Tuesday at 8:19 PM

The safetensors file format is a header length, JSON header, and serialized tensor weights. [1]

[1] https://github.com/huggingface/safetensors