Skip to content

Resolve dependencies while keeping vulns out#5093

Open
sharvin2187 wants to merge 4 commits into
mainfrom
shjondhale/automl-newer-envs
Open

Resolve dependencies while keeping vulns out#5093
sharvin2187 wants to merge 4 commits into
mainfrom
shjondhale/automl-newer-envs

Conversation

@sharvin2187
Copy link
Copy Markdown
Contributor

@sharvin2187 sharvin2187 commented May 29, 2026

resolve deps

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 29, 2026

Test Results for assets-test

1 tests   1 ✅  7m 16s ⏱️
1 suites  0 💤
1 files    0 ❌

Results for commit 5d94d8e.

♻️ This comment has been updated with latest results.

@sharvin2187 sharvin2187 changed the title Override pmdarima in AutoML environment Resolve dependencies while keeping vulns out May 29, 2026
SamGos93
SamGos93 previously approved these changes May 29, 2026
Comment thread assets/training/automl/environments/ai-ml-automl/context/Dockerfile
Comment thread assets/training/automl/environments/ai-ml-automl/context/Dockerfile Outdated
Sharvin Jondhale and others added 3 commits May 30, 2026 07:36
Force reinstall pmdarima 2.0.4 in the ai-ml-automl image so newer Python environments do not fail on pmdarima's deprecated pkg_resources import path.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pin the package versions needed by the newer ai-ml-automl image: keep pkg_resources available, align the ONNX conversion stack with ONNX 1.21, and move pandas to the lowest version compatible with the Dask security update.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants