Skip to content

Multi-AutoML Interface v5.0.0

Choose a tag to compare

@github-actions github-actions released this 28 Sep 19:34
· 81 commits to main since this release

Multi-AutoML Interface 5.0.0

First tagged release. It publishes the tree at the 5.0.0 version bump (2de6d83) plus
the security and correctness fixes listed under Fixed, which is why the release date is
later than that commit.

Added

  • White-box notebook generation: every AutoML run now exports a runnable Jupyter
    notebook reproducing its preprocessing and model (src/notebook_generator.py),
    logged as an artifact on the MLflow run. Ported from automlops-studio
    (bdd9b7a), with dynamic metric support (d3113f8), notebook structure and MLflow
    logging (18176bb) and dataset-path wiring (a36a4c1).
  • HuggingFace as an experiment backend: transformer fine-tuning for text tasks and
    Hub push/pull from the UI (src/huggingface_utils.py, f83c877).
  • Deep Feature Synthesis as an opt-in preprocessing stage (d791a21).
  • Strict cross-validation mode and explicit security warnings on unsafe
    deserialization paths (3f1da5c).
  • Multimodal, clustering, multi-label and anomaly-detection tasks, plus a task
    catalog that filters frameworks by compatibility (d15f139, f3f7b2d, 19ff39a,
    c688618, bed8f0f).
  • Universal orchestrators: framework dispatch decoupled from the Streamlit layer
    (src/orchestrator.py, src/processor.py, src/training_worker.py) (76f260f).
  • Desktop resilience: Streamlit load retries and an error page in the Electron
    shell (e1f913b).
  • CI: lint/compile/regression gate on every push and PR, nightly full suite
    (b42fc84, dbb93bf), and a three-OS Electron build workflow (build-electron.yml).
  • MIT license (be9910d).

Changed

  • Base runtime moved to Python 3.12 in the container images and CI (c46b08e).
  • Training flow gained validation checks, error handling and reworked data processing
    (a4324f3).
  • xgboost and nbformat became explicit runtime dependencies (f83c877).

Fixed

  • H2O prediction was broken for every dataset: prepare_data_for_h2o indexed the
    target column unconditionally while predict_with_h2o passes a placeholder target,
    so each prediction raised KeyError (src/h2o_utils.py).
  • Generated notebooks could not run: they called AutoMLDataProcessor.fit_transform
    and .transform with the wrong arity, and instantiated the framework name as a model
    class. The notebook now uses the real processor API and loads the winning model from
    its MLflow run instead of re-fitting it (src/notebook_generator.py,
    src/training_worker.py).
  • Leaderboard cleanup crash in the H2O path when the leaderboard could not be
    converted to CSV (src/h2o_utils.py).
  • Path traversal from user-controlled names: run names and data-lake prefixes/names
    are reduced to a single safe path component before being joined into filesystem
    paths, and the destructive models/<run> cleanup now asserts it stays inside
    models/ (src/data_utils.py, app.py, src/autogluon_utils.py,
    src/autokeras_utils.py).
  • Zip-slip on CV dataset upload: archive members that would extract outside the
    target directory are now rejected (src/data_utils.py).
  • Electron external-link handling: setWindowOpenHandler passed any URL — including
    file:// and custom schemes — straight to shell.openExternal, and nothing constrained
    top-frame navigation. Both are now restricted to http(s) and to the local app origin
    (electron/main.js). The obsolete new-window handler (removed from Electron) was
    dropped.
  • Electron About dialog and docs link reported v1.0.0 and a placeholder repository
    URL; the version now comes from app.getVersion() and the link points at this repo.
  • Dependency CVEs in the pinned stack (OSV): GitPython 3.1.50 → 3.1.62
    (incl. CVE-2026-78676, CRITICAL), mlflow/mlflow-tracing 3.14.0 → 3.15.0
    (CVE-2026-64849, CRITICAL), pillow 12.2.0 → 12.3.0, aiohttp 3.14.1 → 3.14.3,
    cryptography 48.0.1 → 49.0.0 (mlflow 3.15 caps cryptography at <50).
  • Build tooling pinned: requirements-dev.txt is now tracked (.gitignore excluded
    every *.txt*), so CI installs the pinned ruff/pytest instead of falling back to
    whatever the index serves; the pins were aligned with requirements.txt.

Known limitations

  • Installers are not code-signed or notarized, so Windows SmartScreen and macOS
    Gatekeeper warn on first launch.
  • The Electron shell starts the system Python and expects the app dependencies to be
    installed already; it does not bundle an interpreter.
  • Two advisories remain unpatched by design: CVE-2026-71211 (MLflow AI Gateway SSRF —
    no fixed release, and this app does not use the gateway) and CVE-2026-69247
    (cryptography PKCS#7 decryption — blocked by mlflow's cryptography<50, and this app
    performs no PKCS#7 decryption).
  • .dvc/config ships without a DVC remote, so data_lake/*.dvc pointers only resolve
    after each user configures their own storage.
  • electron/renderer.js and the window.electron block in electron/preload.js are
    dead code kept for a future native-desktop layer.

Prerequisites

The desktop installers bundle the Electron shell and the Streamlit UI, not the Python
runtime. Install Python 3.11/3.12 and the app dependencies first:

pip install -r requirements.txt

AutoML backends (AutoGluon, PyCaret, TPOT, Lale, H2O, AutoKeras, HuggingFace) are optional
and lazy-imported; see the README for what each one needs.

Installers are not code-signed or notarized, so SmartScreen and Gatekeeper will warn
on first launch.