aws / aws/sagemaker-python-sdk

sagemaker-train should depend on mlflow-skinny, following sagemaker-mlflow 0.5.0

Open Beginner friendly
#6,152 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
2.3k
Forks
1.3k
Avg merge
1d 22h
Merged PRs (30d)
35

Description

## Describe the feature you'd like

`sagemaker-train` (and `sagemaker-serve`) declare an unconditional dependency on the full `mlflow` distribution:

```
sagemaker-train 1.18.0: mlflow<4.0.0,>=3.0.0
```

The training integration uses MLflow purely as a tracking client (logging runs and metrics to a configured tracking server), which `mlflow-skinny` implements completely. The full distribution additionally drags in the tracking server stack and its dependency constraints.

`sagemaker-mlflow` already made exactly this change in 0.5.0: `mlflow-skinny>=2.8` as the base requirement, with full mlflow relegated to an optional `full` extra. Applying the same pattern to `sagemaker-train` and `sagemaker-serve` would make the SDK family consistent.

## Why it matters

Full mlflow currently caps `cryptography<50`. Snyk advisories SNYK-PYTHON-CRYPTOGRAPHY-18516620/21/22 (two high severity) are fixed only in cryptography 50.0.0, so any project consuming sagemaker-train transitively cannot reach the fixed version and must either waive the findings or remove sagemaker-train. Since the mlflow usage is client-only, the cap buys nothing for these packages.

## Suggested change

Mirror sagemaker-mlflow 0.5.0: depend on `mlflow-skinny`, offer full mlflow behind an extra for anyone who genuinely needs the server components.

Contributor guide

Open the contributing guide

Research direction

Inspect the dependency metadata for sagemaker-train and sagemaker-serve, then compare it with the sagemaker-mlflow 0.5.0 pattern described in the issue. Verify that mlflow-skinny is the base requirement, full mlflow is available through an optional extra, and dependency resolution no longer imposes the reported cryptography cap.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
build-system, machine-learning
Issue type
Feature
Difficulty
2/5
Estimated time
Half a day
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.