Skip to content

Commit ad24408

Browse files
committed
feat!: track MLflow in SQLite and harden the canonical gate
BREAKING CHANGE: MlflowService now defaults to `sqlite:///mlflow.db` for both tracking and registry instead of the `./mlruns` file store, and the MLFLOW_ALLOW_FILE_STORE opt-in is gone. Existing local runs are not migrated; point MLFLOW_TRACKING_URI at the old store or start fresh. MLflow 3 put the filesystem store in maintenance mode, so the package now uses the SQLAlchemy backend the model registry is actually designed for. Tests copy a session-scoped, already-migrated database instead of paying Alembic migrations per test (7s -> 0.07s each). Gate changes: - add the canonical `all` task; CI runs `mise run all` and nothing else - add check:actions (actionlint + zizmor) with .github/zizmor.yml - add check:dockerfile (hadolint); pin the uv image and use a numeric uid/gid - fix check:scan: `trivy config .` ignored the committed policy whenever TRIVY_CONFIG was exported and only ran the misconfig scanner - pip-audit skips the editable project and caches under .cache - raise the coverage gate to 100%, which is what the suite actually reaches - lefthook priorities follow the 10/20/30 convention - add a weekly full-history security workflow; harden ci.yml and cd.yml - group Dependabot updates and emit the chore(deps) prefix cliff.toml skips - commit mise.lock so CI installs and caches the pinned toolchain Dependencies are re-locked to latest stable, which clears 25 known vulnerabilities across aiohttp, cryptography, gitpython, and pyasn1. MLflow still declares cryptography<50 while the fix for PYSEC-2026-3552 ships in 50.0.0, so a documented uv override installs the patched library and the test suite plus every MLflow job prove it works. Also: untrack an accidentally committed 790 KB mlflow.db, drop the stale vendored copy of the Agent Skills under .gemini/skills that had drifted back to teaching just and pre-commit, and repoint dead README links.
1 parent cc7ba01 commit ad24408

28 files changed

Lines changed: 880 additions & 1290 deletions

File tree

‎.env.example‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
# Copy to `.env`; `mise.toml` sources it, so every task and hook sees these values.
2+
3+
# MLflow tracking and model registry. SQLite is the local default written by
4+
# `MlflowService`: runs and registered models live in `mlflow.db`, artifact files under
5+
# `./mlruns`. Point these at a real database (PostgreSQL, MySQL) or a tracking server
6+
# (http://127.0.0.1:5000) to share runs across a team — the client code does not change.
7+
MLFLOW_TRACKING_URI=sqlite:///mlflow.db
8+
MLFLOW_REGISTRY_URI=sqlite:///mlflow.db

‎.gemini/skills/MLOps Automation/SKILL.md‎

Lines changed: 0 additions & 80 deletions
This file was deleted.

‎.gemini/skills/MLOps Collaboration/SKILL.md‎

Lines changed: 0 additions & 64 deletions
This file was deleted.

‎.gemini/skills/MLOps Industrialization/SKILL.md‎

Lines changed: 0 additions & 140 deletions
This file was deleted.

0 commit comments

Comments
 (0)