Skip to content

Multi-AutoML Interface v5.0.2

Choose a tag to compare

@github-actions github-actions released this 28 Sep 21:18
· 58 commits to main since this release

5.0.2 - 2026-09-28

Fixed

  • The desktop "Abrir MLflow" menu opened a port nothing was listening on. The desktop
    app records runs in the local ./mlruns file store, so http://localhost:5000 only
    works when the MLflow container is running. The menu now opens MLFLOW_TRACKING_URI
    when it points at an http(s) server, and otherwise explains where the runs are and how
    to start the UI.

Fixed

  • FLAML training crashed with the app's own default settings. estimator_list
    defaults to ['lgbm', 'rf']: LightGBM is not in requirements.txt, so the search died
    inside FLAML with TypeError: 'NoneType' object is not callable, and the telemetry
    callback FLAML forwards to every learner took six arguments while LightGBM calls it with
    one CallbackEnv - with mixed lists sklearn then raised
    BaseForest.fit() got an unexpected keyword argument 'callbacks'. LightGBM is now a
    declared dependency, the callback matches the CallbackEnv contract, it is registered
    only for learners that accept it, and a missing learner package is named before the
    search instead of failing deep inside cross-validation. Verified end to end in a clean
    environment: train -> MLflow run -> pickle -> trusted reload -> predictions -> notebook.
  • Three more vulnerable pins, found by the pip-audit gate added in 5.0.1: anyio
    4.14.1 -> 4.14.2, pyasn1 0.6.3 -> 0.6.4, sqlparse 0.5.5 -> 0.6.0. pip-audit --strict over requirements.txt now reports no known vulnerabilities, and it is that
    gate - not the earlier spot check behind the 5.0.1 note - that found them.

Corrected

  • The 5.0.1 entry claimed OSV reported no applicable vulnerability for any pin in
    requirements.txt. That was checked against a subset of ~40 packages; the full
    resolved audit found the three above. The published 5.0.1 release notes were edited to
    drop the overstatement.

Prerequisites

The desktop installers bundle the Electron shell and the Streamlit UI, not the Python runtime. Install Python 3.11/3.12 and the app dependencies first:

pip install -r requirements.txt

Installers are not code-signed or notarized, so SmartScreen and Gatekeeper will warn on first launch.