Repository navigation
Changes
This release includes security hardening requested by Microsoft. It incorporates #2339 and #2340.
馃敀 Security and reliability
- Restrict loading of executable recorder artifacts. Data-only reads and new in-memory training remain available without an opt-in; loading artifacts from verified, trusted storage now requires explicit
trusted=True. See the artifact loading migration guide. - Keep high-frequency cache paths inside the configured artifact root and replace the bundled HIST example artifact with a data-only format.
- Replace evaluation of feature expressions with a restricted parser, and use explicit mappings for built-in TRA backbones and model-performance graph names.
- Require explicit
trusted: truefor configuration-driven local.pyimports. Package imports and class objects are unchanged. See the configuration migration guide.
鈿狅笍 Upgrade notes
These security changes may require configuration updates when loading older trusted recorder artifacts, local Python modules, or custom expression and model extensions. Review both migration guides before upgrading production workflows. Trust must be granted only for sources you have verified.
This GitHub release provides source archives. Check PyPI separately for package availability.