azureml-mlflow 1.62.0.post5 dependency constraints block required mlflow and cryptography security upgrades
Los mantenedores suelen responder en 1 día
@saanikaguptamicrosoft ya está trabajando en esto.
Desde el 26/8/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
- Package Name: azureml-mlflow
- Package Version: 1.62.0.post5
- Operating System: Linux (Kubernetes workload)
- Python Version: 3.11
Describe the bug
We use azureml-mlflow for remote MLflow tracking against an Azure Machine Learning Workspace from a Kubernetes workload.
The latest available version, azureml-mlflow 1.62.0.post5, currently introduces dependency constraints that prevent us from applying required security upgrades:
mlflow-skinny <= 3.13.0cryptography < 49.0.0
Our security scanning requires:
mlflow >= 3.15.0cryptography >= 50.0.0
Because azureml-mlflow is required for our azureml:// MLflow tracking URI, removing the package is not currently an option without changing the Azure ML tracking architecture.
To Reproduce
- Create a Python 3.11 environment.
- Install or declare
azureml-mlflow==1.62.0.post5. - Attempt to resolve the environment with
mlflow>=3.15.0. - Attempt to resolve the environment with
cryptography>=50.0.0. - The dependency resolver cannot satisfy these requirements together with the constraints introduced by
azureml-mlflow.
Expected behavior
There should be a supported version of azureml-mlflow that is compatible with current secure versions of MLflow and its dependencies, or documented guidance for customers who need to remediate these dependency vulnerabilities while continuing to use an Azure Machine Learning Workspace as the remote MLflow tracking backend.
Screenshots
N/A
Additional context
Our application already uses Azure Machine Learning SDK v2 (azure-ai-ml / MLClient) to access the workspace.
MLflow is used for experiment tracking, metrics, parameters, artifacts, and model registry operations against the Azure ML Workspace.
According to the current Azure ML documentation, azureml-mlflow is still required when configuring remote MLflow tracking against an Azure Machine Learning Workspace from compute outside Azure ML.
Could you please confirm:
- Whether a new
azureml-mlflowrelease is planned that relaxes these dependency constraints. - Whether there is a currently supported alternative that allows us to keep Azure ML Workspace as the MLflow tracking backend while upgrading MLflow.
- What the recommended remediation path is for customers blocked from security upgrades by these constraints.
- Lenguaje dominante
- Python
- Estrellas
- 5.6k
- Forks
- 3.4k
- Merge medio
- 2 d 1 min
- PR fusionados (30 d)
- 218
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de Azure/azure-sdk-for-python
-
Evaluation Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Azure/azure-sdk-for-python#49190 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Update CODEOWNERSAbierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
Azure/azure-sdk-for-python#49183 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Evaluation Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Azure/azure-sdk-for-python#49153 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Search Service Attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
Azure/azure-sdk-for-python#48555 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Azure.Core customer-reported feature-request needs-team-attention
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
Azure/azure-sdk-for-python#47186 ·
Los mantenedores suelen responder en 1 día
Todos los issues de Azure/azure-sdk-for-python
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
kornia/kornia#5263 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Metadata correction for W16-5400Abiertoapproved correction metadata
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
acl-org/acl-anthology#10133 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
BasedHardware/omi#20084 ·
Los mantenedores suelen responder en 1 día
-
bug needs-acceptance wg/evaluation-quality
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
vllm-project/semantic-router#4424 ·
Los mantenedores suelen responder en 1 día