Text Generation
Transformers
Safetensors
PEFT
securecoder
lora
adapter
code
tool-calling
security
cybersecurity
qwen3
qwen3_moe
unsloth
known-issue
Instructions to use Taimwe/securecoder-30b-pro-v2 with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use Taimwe/securecoder-30b-pro-v2 with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("text-generation", model="Taimwe/securecoder-30b-pro-v2")# pip install -U transformers accelerate # Load model directly from transformers import AutoModel model = AutoModel.from_pretrained("Taimwe/securecoder-30b-pro-v2", device_map="auto") - PEFT
How to use Taimwe/securecoder-30b-pro-v2 with PEFT:
Task type is invalid.
- Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- vLLM
How to use Taimwe/securecoder-30b-pro-v2 with vLLM:
Install from pip and serve model
# Install vLLM from pip: pip install vllm # Start the vLLM server: vllm serve "Taimwe/securecoder-30b-pro-v2" # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:8000/v1/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "Taimwe/securecoder-30b-pro-v2", "prompt": "Once upon a time,", "max_tokens": 512, "temperature": 0.5 }'Use Docker
docker model run hf.co/Taimwe/securecoder-30b-pro-v2
- SGLang
How to use Taimwe/securecoder-30b-pro-v2 with SGLang:
Install from pip and serve model
# Install SGLang from pip: pip install sglang # Start the SGLang server: python3 -m sglang.launch_server \ --model-path "Taimwe/securecoder-30b-pro-v2" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "Taimwe/securecoder-30b-pro-v2", "prompt": "Once upon a time,", "max_tokens": 512, "temperature": 0.5 }'Use Docker images
docker run --gpus all \ --shm-size 32g \ -p 30000:30000 \ -v ~/.cache/huggingface:/root/.cache/huggingface \ --env "HF_TOKEN=<secret>" \ --ipc=host \ lmsysorg/sglang:latest \ python3 -m sglang.launch_server \ --model-path "Taimwe/securecoder-30b-pro-v2" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "Taimwe/securecoder-30b-pro-v2", "prompt": "Once upon a time,", "max_tokens": 512, "temperature": 0.5 }' - Unsloth Desktop
- Docker Model Runner
How to use Taimwe/securecoder-30b-pro-v2 with Docker Model Runner:
docker model run hf.co/Taimwe/securecoder-30b-pro-v2
File size: 2,780 Bytes
b124f4a b3d9ae9 b124f4a 681957c b124f4a 681957c b124f4a 681957c b124f4a 681957c b124f4a 681957c b124f4a 681957c b124f4a 681957c b124f4a 681957c b124f4a 681957c b124f4a | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 | ---
license: apache-2.0
pipeline_tag: text-generation
library_name: transformers
base_model: unsloth/Qwen3-Coder-30B-A3B-Instruct
tags:
- securecoder
- peft
- lora
- adapter
- code
- tool-calling
- security
- cybersecurity
- qwen3
- qwen3_moe
- unsloth
- known-issue
---
# SecureCoder 30B Pro v2 — LoRA adapter (known defect, read first)
> [!CAUTION]
> **This adapter produces code that does not parse. Do not use it for code generation.**
>
> Measured on the same prompts through the same harness:
>
> | Model | valid Python |
> |---|---:|
> | `unsloth/Qwen3-Coder-30B-A3B-Instruct` (base) | **93.3%** |
> | this adapter / `securecoder-30b-pro-v2-merged` | **0.0%** |
>
> **Symptom:** the model emits the literal two-character sequence `\n` instead of real
> newlines, so Python blocks fail `ast.parse` at line 1. Tool-calling still scored 100%
> (those regexes only read tag names), which masked the problem.
>
> **Cause:** several datasets in the training mix — Trendyol Cybersecurity, Fenrir v2.1,
> OWASP-sft, Heimdall v1.1, CTF-Instruct — store message text **JSON-escaped**.
> 183 of 480 sampled rows were affected, so the fine-tune learned to escape its own
> newlines.
>
> **Fixed** in [`Taimwe/securecoder-scripts`](https://huggingface.co/Taimwe/securecoder-scripts)
> (`_unescape_if_needed()`, commit `51a4d639`). The merged and GGUF repos were **deleted**
> rather than left published, because they shipped broken output.
## What is here, and why
Only the **LoRA adapter** (102 MB) is kept, for reproducibility and to re-merge after the
data fix is retrained. Its siblings `securecoder-30b-pro-v2-merged` (61 GB) and
`securecoder-30b-pro-v2-GGUF` (17.3 GB) were removed.
For a working code model today use the base
[`unsloth/Qwen3-Coder-30B-A3B-Instruct`](https://huggingface.co/unsloth/Qwen3-Coder-30B-A3B-Instruct)
— 93.3% valid Python on the same test.
## Adapter config
| | |
|---|---|
| Type | LoRA (`peft 0.21.0`) |
| Rank `r` / alpha | 32 / 32 |
| Target modules | `q_proj`, `k_proj`, `v_proj`, `o_proj` (attention only) |
| Base | `Qwen3MoeForCausalLM` |
| Task type | `CAUSAL_LM` |
Attention-only keeps the adapter small and cheap to merge, but it cannot teach new
knowledge — it changes behaviour (style, output format, tool-call shape), not capability.
## Evidence
- [`securecoder-eval-v2`](https://huggingface.co/Taimwe/securecoder-eval-v2) — 0.0% ast_rate
- [`securecoder-eval-base`](https://huggingface.co/Taimwe/securecoder-eval-base) — 93.3% ast_rate
- Full write-up + exact retrain command:
[`securecoder-scripts/HANDOFF.md`](https://huggingface.co/Taimwe/securecoder-scripts/blob/main/HANDOFF.md)
## License
Apache-2.0, following the base model. |