Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

azureml-mlflow 1.62.0.post5 dependency constraints block required mlflow and cryptography security upgrades

Đang mở
#48,745 12 bình luận 1 reaction 1 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@saanikaguptamicrosoft đang làm issue này rồi.

Từ ngày 26/8/2026.

Đánh giá

Issue này chưa được đánh giá.

Mô tả

Client customer-reported Machine Learning needs-team-attention question Service Attention
  • Package Name: azureml-mlflow
  • Package Version: 1.62.0.post5
  • Operating System: Linux (Kubernetes workload)
  • Python Version: 3.11

Describe the bug

We use azureml-mlflow for remote MLflow tracking against an Azure Machine Learning Workspace from a Kubernetes workload.

The latest available version, azureml-mlflow 1.62.0.post5, currently introduces dependency constraints that prevent us from applying required security upgrades:

  • mlflow-skinny <= 3.13.0
  • cryptography < 49.0.0

Our security scanning requires:

  • mlflow >= 3.15.0
  • cryptography >= 50.0.0

Because azureml-mlflow is required for our azureml:// MLflow tracking URI, removing the package is not currently an option without changing the Azure ML tracking architecture.

To Reproduce

  1. Create a Python 3.11 environment.
  2. Install or declare azureml-mlflow==1.62.0.post5.
  3. Attempt to resolve the environment with mlflow>=3.15.0.
  4. Attempt to resolve the environment with cryptography>=50.0.0.
  5. The dependency resolver cannot satisfy these requirements together with the constraints introduced by azureml-mlflow.

Expected behavior

There should be a supported version of azureml-mlflow that is compatible with current secure versions of MLflow and its dependencies, or documented guidance for customers who need to remediate these dependency vulnerabilities while continuing to use an Azure Machine Learning Workspace as the remote MLflow tracking backend.

Screenshots

N/A

Additional context

Our application already uses Azure Machine Learning SDK v2 (azure-ai-ml / MLClient) to access the workspace.

MLflow is used for experiment tracking, metrics, parameters, artifacts, and model registry operations against the Azure ML Workspace.

According to the current Azure ML documentation, azureml-mlflow is still required when configuring remote MLflow tracking against an Azure Machine Learning Workspace from compute outside Azure ML.

Could you please confirm:

  1. Whether a new azureml-mlflow release is planned that relaxes these dependency constraints.
  2. Whether there is a currently supported alternative that allows us to keep Azure ML Workspace as the MLflow tracking backend while upgrading MLflow.
  3. What the recommended remediation path is for customers blocked from security upgrades by these constraints.
Ngôn ngữ chính
Python
Star
5.6k
Fork
3.4k
Merge trung bình
2 ngày 1 giờ
Pull request đã merge (30 ngày)
213

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của Azure/azure-sdk-for-python

Tất cả issue của Azure/azure-sdk-for-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.