--- license: apache-2.0 pipeline_tag: text-generation library_name: transformers base_model: unsloth/Qwen3-Coder-30B-A3B-Instruct tags: - securecoder - peft - lora - adapter - code - tool-calling - security - cybersecurity - qwen3 - qwen3_moe - unsloth - known-issue --- # SecureCoder 30B Pro v2 — LoRA adapter (known defect, read first) > [!CAUTION] > **This adapter produces code that does not parse. Do not use it for code generation.** > > Measured on the same prompts through the same harness: > > | Model | valid Python | > |---|---:| > | `unsloth/Qwen3-Coder-30B-A3B-Instruct` (base) | **93.3%** | > | this adapter / `securecoder-30b-pro-v2-merged` | **0.0%** | > > **Symptom:** the model emits the literal two-character sequence `\n` instead of real > newlines, so Python blocks fail `ast.parse` at line 1. Tool-calling still scored 100% > (those regexes only read tag names), which masked the problem. > > **Cause:** several datasets in the training mix — Trendyol Cybersecurity, Fenrir v2.1, > OWASP-sft, Heimdall v1.1, CTF-Instruct — store message text **JSON-escaped**. > 183 of 480 sampled rows were affected, so the fine-tune learned to escape its own > newlines. > > **Fixed** in [`Taimwe/securecoder-scripts`](https://huggingface.co/Taimwe/securecoder-scripts) > (`_unescape_if_needed()`, commit `51a4d639`). The merged and GGUF repos were **deleted** > rather than left published, because they shipped broken output. ## What is here, and why Only the **LoRA adapter** (102 MB) is kept, for reproducibility and to re-merge after the data fix is retrained. Its siblings `securecoder-30b-pro-v2-merged` (61 GB) and `securecoder-30b-pro-v2-GGUF` (17.3 GB) were removed. For a working code model today use the base [`unsloth/Qwen3-Coder-30B-A3B-Instruct`](https://huggingface.co/unsloth/Qwen3-Coder-30B-A3B-Instruct) — 93.3% valid Python on the same test. ## Adapter config | | | |---|---| | Type | LoRA (`peft 0.21.0`) | | Rank `r` / alpha | 32 / 32 | | Target modules | `q_proj`, `k_proj`, `v_proj`, `o_proj` (attention only) | | Base | `Qwen3MoeForCausalLM` | | Task type | `CAUSAL_LM` | Attention-only keeps the adapter small and cheap to merge, but it cannot teach new knowledge — it changes behaviour (style, output format, tool-call shape), not capability. ## Evidence - [`securecoder-eval-v2`](https://huggingface.co/Taimwe/securecoder-eval-v2) — 0.0% ast_rate - [`securecoder-eval-base`](https://huggingface.co/Taimwe/securecoder-eval-base) — 93.3% ast_rate - Full write-up + exact retrain command: [`securecoder-scripts/HANDOFF.md`](https://huggingface.co/Taimwe/securecoder-scripts/blob/main/HANDOFF.md) ## License Apache-2.0, following the base model.