Multi-AutoML Interface v5.0.0
Multi-AutoML Interface 5.0.0
First tagged release. It publishes the tree at the 5.0.0 version bump (2de6d83) plus
the security and correctness fixes listed under Fixed, which is why the release date is
later than that commit.
Added
- White-box notebook generation: every AutoML run now exports a runnable Jupyter
notebook reproducing its preprocessing and model (src/notebook_generator.py),
logged as an artifact on the MLflow run. Ported fromautomlops-studio
(bdd9b7a), with dynamic metric support (d3113f8), notebook structure and MLflow
logging (18176bb) and dataset-path wiring (a36a4c1). - HuggingFace as an experiment backend: transformer fine-tuning for text tasks and
Hub push/pull from the UI (src/huggingface_utils.py,f83c877). - Deep Feature Synthesis as an opt-in preprocessing stage (
d791a21). - Strict cross-validation mode and explicit security warnings on unsafe
deserialization paths (3f1da5c). - Multimodal, clustering, multi-label and anomaly-detection tasks, plus a task
catalog that filters frameworks by compatibility (d15f139,f3f7b2d,19ff39a,
c688618,bed8f0f). - Universal orchestrators: framework dispatch decoupled from the Streamlit layer
(src/orchestrator.py,src/processor.py,src/training_worker.py) (76f260f). - Desktop resilience: Streamlit load retries and an error page in the Electron
shell (e1f913b). - CI: lint/compile/regression gate on every push and PR, nightly full suite
(b42fc84,dbb93bf), and a three-OS Electron build workflow (build-electron.yml). - MIT license (
be9910d).
Changed
- Base runtime moved to Python 3.12 in the container images and CI (
c46b08e). - Training flow gained validation checks, error handling and reworked data processing
(a4324f3). xgboostandnbformatbecame explicit runtime dependencies (f83c877).
Fixed
- H2O prediction was broken for every dataset:
prepare_data_for_h2oindexed the
target column unconditionally whilepredict_with_h2opasses a placeholder target,
so each prediction raisedKeyError(src/h2o_utils.py). - Generated notebooks could not run: they called
AutoMLDataProcessor.fit_transform
and.transformwith the wrong arity, and instantiated the framework name as a model
class. The notebook now uses the real processor API and loads the winning model from
its MLflow run instead of re-fitting it (src/notebook_generator.py,
src/training_worker.py). - Leaderboard cleanup crash in the H2O path when the leaderboard could not be
converted to CSV (src/h2o_utils.py). - Path traversal from user-controlled names: run names and data-lake prefixes/names
are reduced to a single safe path component before being joined into filesystem
paths, and the destructivemodels/<run>cleanup now asserts it stays inside
models/(src/data_utils.py,app.py,src/autogluon_utils.py,
src/autokeras_utils.py). - Zip-slip on CV dataset upload: archive members that would extract outside the
target directory are now rejected (src/data_utils.py). - Electron external-link handling:
setWindowOpenHandlerpassed any URL — including
file://and custom schemes — straight toshell.openExternal, and nothing constrained
top-frame navigation. Both are now restricted tohttp(s)and to the local app origin
(electron/main.js). The obsoletenew-windowhandler (removed from Electron) was
dropped. - Electron About dialog and docs link reported
v1.0.0and a placeholder repository
URL; the version now comes fromapp.getVersion()and the link points at this repo. - Dependency CVEs in the pinned stack (OSV): GitPython
3.1.50 → 3.1.62
(incl. CVE-2026-78676, CRITICAL), mlflow/mlflow-tracing3.14.0 → 3.15.0
(CVE-2026-64849, CRITICAL), pillow12.2.0 → 12.3.0, aiohttp3.14.1 → 3.14.3,
cryptography48.0.1 → 49.0.0(mlflow 3.15 caps cryptography at<50). - Build tooling pinned:
requirements-dev.txtis now tracked (.gitignoreexcluded
every*.txt*), so CI installs the pinned ruff/pytest instead of falling back to
whatever the index serves; the pins were aligned withrequirements.txt.
Known limitations
- Installers are not code-signed or notarized, so Windows SmartScreen and macOS
Gatekeeper warn on first launch. - The Electron shell starts the system Python and expects the app dependencies to be
installed already; it does not bundle an interpreter. - Two advisories remain unpatched by design: CVE-2026-71211 (MLflow AI Gateway SSRF —
no fixed release, and this app does not use the gateway) and CVE-2026-69247
(cryptography PKCS#7 decryption — blocked by mlflow'scryptography<50, and this app
performs no PKCS#7 decryption). .dvc/configships without a DVC remote, sodata_lake/*.dvcpointers only resolve
after each user configures their own storage.electron/renderer.jsand thewindow.electronblock inelectron/preload.jsare
dead code kept for a future native-desktop layer.
Prerequisites
The desktop installers bundle the Electron shell and the Streamlit UI, not the Python
runtime. Install Python 3.11/3.12 and the app dependencies first:
pip install -r requirements.txtAutoML backends (AutoGluon, PyCaret, TPOT, Lale, H2O, AutoKeras, HuggingFace) are optional
and lazy-imported; see the README for what each one needs.
Installers are not code-signed or notarized, so SmartScreen and Gatekeeper will warn
on first launch.