Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency mlflow to v2.5.0 [security] - autoclosed #28

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 28, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
mlflow (source) ==2.3.2 -> ==2.5.0 age adoption passing confidence

⚠ Dependency Lookup Warnings ⚠

Warnings were logged while processing this repo. Please check the Dependency Dashboard for more information.

GitHub Vulnerability Alerts

CVE-2023-3765

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.


Release Notes

mlflow/mlflow (mlflow)

v2.5.0

Compare Source

MLflow 2.5.0 includes several major features and improvements:

Features:

Bug fixes:

  • [Security] Improve robustness to LFI attacks on Windows by enhancing path validation (#​8999, @​serena-ruan)
    • If you are using mlflow server or mlflow ui on Windows, we recommend upgrading to MLflow 2.5.0 as soon as possible.
  • [Scoring] Support nullable array type values as spark_udf return values (#​9014, @​WeichenXu123)
  • [Models] Revert cache deletion of system modules when adding custom model code to the system path (#​8722, @​trungn1)
  • [Models] add micro version to mlflow version pinning (#​8687, @​C-K-Loan)
  • [Artifacts] Prevent manually deleted artifacts from causing artifact garbage collection to fail (#​8498, @​PenHsuanWang)

Documentation updates:

  • [Docs] Update .push_model_to_sagemaker docs (#​8851, @​pdifranc)
  • [Docs] Fix invalid link for Azure ML documentation (#​8800, @​dunnkers)
  • [Artifacts / Docs / Models / Projects] Adds information on the OCI MLflow plugins for seamless integration with Oralce Cloud Infrastructure services. (#​8707, @​mrDzurb)

Deprecation:

  • [Models] Deprecate the gluon model flavor. The mlflow.gluon module will be removed in a future release. (#​8968, @​harupy)

Small bug fixes and documentation updates:

#​9069, #​9056, #​9055, #​9054, #​9048, #​9043, #​9035, #​9034, #​9037, #​9038, #​8993, #​8966, #​8985, @​BenWilson2; #​9039, #​9036, #​8902, #​8924, #​8866, #​8861, #​8810, #​8761, #​8544, @​jerrylian-db; #​8903, @​smurching; #​9080, #​9079, #​9078, #​9076, #​9075, #​9074, #​9071, #​9063, #​9062, #​9032, #​9031, #​9027, #​9023, #​9022, #​9020, #​9005, #​8994, #​8979, #​8983, #​8984, #​8982, #​8970, #​8962, #​8969, #​8968, #​8959, #​8960, #​8958, #​8956, #​8955, #​8954, #​8949, #​8950, #​8952, #​8948, #​8946, #​8947, #​8943, #​8944, #​8916, #​8917, #​8933, #​8929, #​8932, #​8927, #​8930, #​8925, #​8921, #​8873, #​8915, #​8909, #​8908, #​8911, #​8910, #​8907, #​8906, #​8898, #​8893, #​8889, #​8892, #​8891, #​8887, #​8875, #​8876, #​8882, #​8874, #​8868, #​8872, #​8869, #​8828, #​8852, #​8857, #​8853, #​8854, #​8848, #​8850, #​8840, #​8835, #​8832, #​8831, #​8830, #​8829, #​8839, #​8833, #​8838, #​8819, #​8814, #​8825, #​8818, #​8787, #​8775, #​8749, #​8766, #​8756, #​8753, #​8751, #​8748, #​8744, #​8731, #​8717, #​8730, #​8691, #​8720, #​8723, #​8719, #​8688, #​8721, #​8715, #​8716, #​8718, #​8696, #​8698, #​8692, #​8693, #​8690, @​harupy; #​9030, @​AlimurtuzaCodes; #​9029, #​9025, #​9021, #​9013, @​viktoriussuwandi; #​9010, @​Bncer; #​9011, @​Pecunia201; #​9007, #​9003, @​EdAbati; #​9002, @​prithvikannan; #​8991, #​8867, @​AveshCSingh; #​8951, #​8896, #​8888, #​8849, @​gabrielfu; #​8913, #​8885, #​8871, #​8870, #​8788, #​8772, #​8771, @​serena-ruan; #​8879, @​maciejskorski; #​7752, @​arunkumarkota; #​9083, #​9081, #​8765, #​8742, #​8685, #​8682, #​8683, @​dbczumar; #​8791, @​mhattingpete; #​8739, @​yunpark93

v2.4.2

Compare Source

MLflow 2.4.2 is a patch release containing the following bug fixes and changes:

Bug fixes:

Documentation updates:

Small bug fixes and documentation updates:

#​8966, @​BenWilson2; #​8881, @​harupy; #​8846, #​8760, @​smurching

v2.4.1

Compare Source

MLflow 2.4.1 is a patch release containing the following features, bug fixes and changes:

Features:

Bug fixes:

  • [Security] Improve robustness to LFI attacks (#​8648, @​serena-ruan)
    • If you are using mlflow server or mlflow ui, we recommend upgrading to MLflow 2.4.1 as soon as possible.
  • [Models] Fix an issue with transformers serialization for ModelCards that contain invalid characters (#​8652, @​BenWilson2)
  • [Models] Fix connection pooling deadlocks that occurred during large file downloads (#​8682, @​dbczumar; #​8660, @​harupy)

Small bug fixes and documentation updates:

#​8677, #​8674, #​8646, #​8647, @​dbczumar; #​8654, #​8653, #​8660, #​8650, #​8642, #​8636, #​8599, #​8637, #​8608, #​8633, #​8623, #​8628, #​8619, @​harupy; #​8655, #​8609, @​BenWilson2; #​8648, @​serena-ruan; #​8521, @​ka1mar; #​8638, @​smurching; #​8634, @​PenHsuanWang

v2.4.0

Compare Source

MLflow 2.4.0 includes several major features and improvements

Features:

Bug fixes:

  • [Tracking] Terminate Spark callback server when Spark Autologging is disabled or Spark Session is shut down (#​8508, @​WeichenXu123)
  • [Tracking] Fix compatibility of mlflow server with Flask<2.0 (#​8463, @​kevingreer)
  • [Models] Convert mlflow.transformers pyfunc scalar string output to list of strings during batch inference (#​8546, @​BenWilson2)
  • [Models] Fix a bug causing outdated pyenv versions to be installed by mlflow models build-docker (#​8488, @​Hellzed)
  • [Model Registry] Remove aliases from storage when a Model Version is deleted (#​8459, @​arpitjasa-db)

Documentation updates:

Small bug fixes and documentation updates:

#​8611, #​8587, @​dbczumar; #​8617, #​8620, #​8615, #​8603, #​8604, #​8601, #​8596, #​8598, #​8597, #​8589, #​8580, #​8581, #​8575, #​8582, #​8577, #​8576, #​8578, #​8561, #​8568, #​8551, #​8528, #​8550, #​8489, #​8530, #​8534, #​8533, #​8532, #​8524, #​8520, #​8517, #​8516, #​8515, #​8514, #​8506, #​8503, #​8500, #​8504, #​8496, #​8486, #​8485, #​8468, #​8471, #​8473, #​8470, #​8458, #​8447, #​8446, #​8434, @​harupy; #​8607, #​8538, #​8513, #​8452, #​8466, #​8465, @​serena-ruan; #​8586, #​8595, @​prithvikannan; #​8593, #​8541, @​kriscon-db; #​8592, #​8566, @​annzhang-db; #​8588, #​8565, #​8559, #​8537, @​BenWilson2; #​8545, @​apurva-koti; #​8564, @​DavidSpek; #​8436, #​8490, @​jerrylian-db; #​8505, @​eliaskoromilas; #​8483, @​WeichenXu123; #​8472, @​leqiao-1; #​8429, @​jinzhang21; #​8581, #​8548, #​8499, @​gabrielfu;


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title chore(deps): update dependency mlflow to v2.5.0 [security] chore(deps): update dependency mlflow to v2.5.0 [security] - autoclosed Aug 1, 2023
@renovate renovate bot closed this Aug 1, 2023
@renovate renovate bot deleted the renovate/pypi-mlflow-vulnerability branch August 1, 2023 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants