What mlflow/mlflow shipped
Written by FoxPlug from public releases; not affiliated with Mlflow. An automatic summary of the public release, pull request and commit data of github.com/mlflow/mlflow. Mlflow did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- MLflow 2.11.5 released with opt-in support for routing Unity Catalog model registry artifact uploads and downloads through the Databricks SDK Files API. Release
- SQL daily rollups and optimizations for trace analytics implemented as opt-in feature, with authoritative SQL columns and migration/backfill support. Pull request #25991
- Initial phase of RFC-0002 merged to enable job executor plugins, allowing extensible job execution strategies. Pull request #26119
- Skill Registry now supports secure skill content upload and artifact lifecycle management with audit metadata tracking. Pull request #25958
- Added end-to-end support for
uc_model_servicemodel-serving resource type in Unity Catalog model-version registration. Pull request #26140 - Session metadata now propagates to TypeScript UC root spans, fixing session filtering for Unity Catalog-backed traces. Pull request #26209
- DataFrame indexes are preserved during pyfunc schema enforcement for Array, Object, and Map columns. Pull request #26181
- Fixed metric filter in
search_logged_modelsthat was shrinking result pages by applying subquery joins incorrectly. Pull request #26057 - Spaces around
--trace-idsentries inmlflow traces deleteare now stripped to handle comma-separated lists correctly. Pull request #26204
Why it matters
This week brings infrastructure improvements for trace analytics and job execution extensibility, alongside fixes for common issues in model registration, tracing across multiple LLM providers, and data handling in pandas DataFrames. The SQL optimizations and plugin architecture lay groundwork for scaling production deployments.
Changelog entry
- Added opt-in support for routing Unity Catalog model registry artifact uploads and downloads through the Databricks SDK Files API Release
- Added opt-in SQL daily rollups and optimizations for trace analytics including authoritative SQL columns and migration/backfill support Pull request #25991
- Merged initial phase of RFC-0002 to support job executor plugins for extensible job execution Pull request #26119
- Added secure skill content upload and artifact lifecycle management to Skill Registry with audit metadata tracking Pull request #25958
- Added end-to-end support for
uc_model_serviceresource type in Unity Catalog model-version registration Pull request #26140 - Session metadata now propagates to TypeScript UC root spans for proper session filtering in Unity Catalog traces Pull request #26209
- DataFrame indexes are preserved during pyfunc schema enforcement for Array, Object, and Map columns Pull request #26181
- Fixed metric filter in
search_logged_modelsthat was shrinking pages through incorrect subquery joins Pull request #26057 - Fixed mlflow traces delete --trace-ids to properly strip spaces around comma-separated entries Pull request #26204
MLflow 2.11.5: opt-in UC model registry artifact routing via Databricks SDK Files API, SQL trace analytics optimizations, job executor plugins, and Skill Registry artifact lifecycle support.
Week of September 14, 2026
What shipped
- MLflow 3.16.1 patch release with bug fixes, documentation updates, and security fixes including removal of the default basic-auth admin password. Release
- Fixed security vulnerability that prevented the tracking server from accepting arbitrary artifact location URIs outside the default artifact root. Pull request #25891
- Added validation to reject conflicting protobuf field spellings in request bodies to prevent bypassing security checks. Pull request #25869
- Fixed third-party scorer module matching to use exact module names instead of package prefix matching, closing a potential security gap. Pull request #25906
- Implemented SQL trace analytics daily rollups maintenance with scheduled periodic task execution. Pull request #25489
- Backported Unity Catalog model registry Databricks Files API artifact repository support to version 2.11.4. Pull request #25986
- Backported Unity Catalog model registry Databricks Files API artifact repository support to version 2.13.3. Pull request #25987
- Fixed Unity Catalog trace location resolution in Databricks Model Serving to work without local-store validation. Pull request #25884
- Fixed pandas Series alignment in evaluation results table to use positional indexing instead of label-based indexing. Pull request #25799
Changelog entry
- [Security] Refuse to connect to client-named artifact hosts outside the default artifact root (GHSA-mr9f-g8qf-4w4j). Pull request #25891
- [Security] Reject conflicting protobuf field spellings in request bodies (GHSA-3g8m-hm3x-gh2r). Pull request #25869
- [Security] Bind
trace_idsto authorized experiment on issues/invoke and genai/evaluate/invoke. Pull request #25873 - [Traces] Maintain SQL trace analytics daily rollups with scheduled periodic task execution. Pull request #25489
- [Evaluation] Fix positional Series alignment in
eval_results_tablefor consistent index handling. Pull request #25799 - [Model Serving] Resolve UC trace location without local-store validation in Databricks Model Serving. Pull request #25884
- [Security] Match third-party scorer modules exactly instead of by package prefix (GHSA-26p8-2jq9-3vq9). Pull request #25906
MLflow 3.16.1 is out with bug fixes, security updates, and improvements to gateway model discovery and UC trace handling.