-
Notifications
You must be signed in to change notification settings - Fork 4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Unblock PIP package hashes when logging models #5058
Merged
harupy
merged 5 commits into
mlflow:master
from
maitre-matt:users/mmaitre/supply-chain-security
Nov 19, 2021
Merged
Unblock PIP package hashes when logging models #5058
harupy
merged 5 commits into
mlflow:master
from
maitre-matt:users/mmaitre/supply-chain-security
Nov 19, 2021
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
…e to handle PIP requirements including package hashes - Add example show how to manage package hashes within ML projects Signed-off-by: Matthieu Maitre <mmaitre@microsoft.com>
Signed-off-by: Matthieu Maitre <mmaitre@microsoft.com>
dbczumar
reviewed
Nov 18, 2021
dbczumar
approved these changes
Nov 18, 2021
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM! This is fantastic! Thank you for your contribution, @maitre-matt !
harupy
reviewed
Nov 18, 2021
harupy
reviewed
Nov 18, 2021
harupy
reviewed
Nov 18, 2021
Signed-off-by: Matthieu Maitre <mmaitre@microsoft.com>
Signed-off-by: Matthieu Maitre <mmaitre@microsoft.com>
harupy
reviewed
Nov 19, 2021
Signed-off-by: Matthieu Maitre <mmaitre@microsoft.com>
harupy
approved these changes
Nov 19, 2021
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@maitre-matt Thanks, this is a nice enhancement!
23 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
area/artifacts
Artifact stores and artifact logging
area/docs
Documentation issues
area/examples
Example code
rn/bug-fix
Mention under Bug Fixes in Changelogs.
rn/documentation
Mention under Documentation Changes in Changelogs.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Signed-off-by: Matthieu Maitre mmaitre@microsoft.com
What changes are proposed in this pull request?
This addresses #4886.
_is_mlflow_requirement()
was not able to detect thatmlflow
had already been listed in PIP requirements when requirements include package hashes. Per pypa/packaging#488,Requirement
does not handle package hashes because this is a PIP-specific extension. The caller is responsible for removing, which is what this change does.The change also adds an example showing how to manage package hashes using
pip-tools
.How is this patch tested?
Expanded existing unit test
Does this PR change the documentation?
ci/circleci: build_doc
check. If it's successful, proceed to thenext step, otherwise fix it.
Details
on the right to open the job page of CircleCI.Artifacts
tab.docs/build/html/index.html
.Release Notes
Is this a user-facing change?
This adds support for the PIP hash-checking mode in ML projects.
What component(s), interfaces, languages, and integrations does this PR affect?
Components
area/artifacts
: Artifact stores and artifact loggingarea/build
: Build and test infrastructure for MLflowarea/docs
: MLflow documentation pagesarea/examples
: Example codearea/model-registry
: Model Registry service, APIs, and the fluent client calls for Model Registryarea/models
: MLmodel format, model serialization/deserialization, flavorsarea/projects
: MLproject format, project running backendsarea/scoring
: MLflow Model server, model deployment tools, Spark UDFsarea/server-infra
: MLflow Tracking server backendarea/tracking
: Tracking Service, tracking client APIs, autologgingInterface
area/uiux
: Front-end, user experience, plotting, JavaScript, JavaScript dev serverarea/docker
: Docker use across MLflow's components, such as MLflow Projects and MLflow Modelsarea/sqlalchemy
: Use of SQLAlchemy in the Tracking Service or Model Registryarea/windows
: Windows supportLanguage
language/r
: R APIs and clientslanguage/java
: Java APIs and clientslanguage/new
: Proposals for new client languagesIntegrations
integrations/azure
: Azure and Azure ML integrationsintegrations/sagemaker
: SageMaker integrationsintegrations/databricks
: Databricks integrationsHow should the PR be classified in the release notes? Choose one:
rn/breaking-change
- The PR will be mentioned in the "Breaking Changes" sectionrn/none
- No description will be included. The PR will be mentioned only by the PR number in the "Small Bugfixes and Documentation Updates" sectionrn/feature
- A new user-facing feature worth mentioning in the release notesrn/bug-fix
- A user-facing bug fix worth mentioning in the release notesrn/documentation
- A user-facing documentation change worth mentioning in the release notes