Describe the feature you'd like
sagemaker-train (and sagemaker-serve) declare an unconditional dependency on the full mlflow distribution:
sagemaker-train 1.18.0: mlflow<4.0.0,>=3.0.0
The training integration uses MLflow purely as a tracking client (logging runs and metrics to a configured tracking server), which mlflow-skinny implements completely. The full distribution additionally drags in the tracking server stack and its dependency constraints.
sagemaker-mlflow already made exactly this change in 0.5.0: mlflow-skinny>=2.8 as the base requirement, with full mlflow relegated to an optional full extra. Applying the same pattern to sagemaker-train and sagemaker-serve would make the SDK family consistent.
Why it matters
Full mlflow currently caps cryptography<50. Snyk advisories SNYK-PYTHON-CRYPTOGRAPHY-18516620/21/22 (two high severity) are fixed only in cryptography 50.0.0, so any project consuming sagemaker-train transitively cannot reach the fixed version and must either waive the findings or remove sagemaker-train. Since the mlflow usage is client-only, the cap buys nothing for these packages.
Suggested change
Mirror sagemaker-mlflow 0.5.0: depend on mlflow-skinny, offer full mlflow behind an extra for anyone who genuinely needs the server components.
Describe the feature you'd like
sagemaker-train(andsagemaker-serve) declare an unconditional dependency on the fullmlflowdistribution:The training integration uses MLflow purely as a tracking client (logging runs and metrics to a configured tracking server), which
mlflow-skinnyimplements completely. The full distribution additionally drags in the tracking server stack and its dependency constraints.sagemaker-mlflowalready made exactly this change in 0.5.0:mlflow-skinny>=2.8as the base requirement, with full mlflow relegated to an optionalfullextra. Applying the same pattern tosagemaker-trainandsagemaker-servewould make the SDK family consistent.Why it matters
Full mlflow currently caps
cryptography<50. Snyk advisories SNYK-PYTHON-CRYPTOGRAPHY-18516620/21/22 (two high severity) are fixed only in cryptography 50.0.0, so any project consuming sagemaker-train transitively cannot reach the fixed version and must either waive the findings or remove sagemaker-train. Since the mlflow usage is client-only, the cap buys nothing for these packages.Suggested change
Mirror sagemaker-mlflow 0.5.0: depend on
mlflow-skinny, offer full mlflow behind an extra for anyone who genuinely needs the server components.