Skip to content

Commit 2a5b075

Browse files
committed
Adding upper bound to sm dependency
1 parent e30aaf9 commit 2a5b075

File tree

1 file changed

+2
-4
lines changed

1 file changed

+2
-4
lines changed

src/sagemaker/serve/detector/dependency_manager.py

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -67,12 +67,10 @@ def capture_dependencies(dependencies: dict, work_dir: Path, capture_all: bool =
6767
with open(path, "r") as f:
6868
autodetect_depedencies = f.read().splitlines()
6969
# Pin sagemaker to 2.257.0+ to ensure SHA256 hashing is used for integrity checks
70-
# (version where HMAC vulnerability was fixed). Update this version when 2.257.0 is released.
71-
autodetect_depedencies.append("sagemaker[huggingface]>=2.257.0")
70+
autodetect_depedencies.append("sagemaker[huggingface]>=2.257.0,<3.0.0")
7271
else:
7372
# Pin sagemaker to 2.257.0+ to ensure SHA256 hashing is used for integrity checks
74-
# (version where HMAC vulnerability was fixed). Update this version when 2.257.0 is released.
75-
autodetect_depedencies = ["sagemaker[huggingface]>=2.257.0"]
73+
autodetect_depedencies = ["sagemaker[huggingface]>=2.257.0,<3.0.0"]
7674

7775
module_version_dict = _parse_dependency_list(autodetect_depedencies)
7876

0 commit comments

Comments
 (0)