ray
Model Serving & MLOpsA unified framework for scaling AI and Python applications from a laptop to a cluster
Features
- Unified runtime for distributed execution of Python code
- AI‑focused libraries: Data, Train, Tune, RLlib, Serve
- Core abstractions – Tasks (stateless functions), Actors (stateful workers), Objects (immutable values)
- Built‑in monitoring via Ray Dashboard and a Distributed Debugger
Security Response History
1 CVE| CVE | Severity | Disclosed | Patched (this tool) | vs Ecosystem Median |
|---|---|---|---|---|
| CVE-2023-4863 KEV |
high
CVSS 8.8
|
2023-09-13 | 2026-02-18 | 2y 5mo / median 2y 4mo |
Recent releases
View all 6 releases →
No immediate action
ray-2.56.0
Security relevant
Routine maintenance and dependency updates.
patches CVE-2023-4863
Open
ray-2.55.1
Bug fix
Minor fixes and improvements.
Full changelog
- Fixes SSH connectivity issue in the
ray-llmimage (#62625 / #62718). - Upgrade apt packages in slim base (#62666 / #62717).
ray-2.55.0
Breaking risk
Breaking changes
- local_mode support removed
- Legacy BlockList, locality_with_output, and callback API removed
- PyArrow 9.0 compatibility checks removed
Security fixes
- jackson-databind upgraded from 2.16.1 to 2.18.6 (GHSA-72hv-8253-57qq)
Notable features
- DataSourceV2 API with scanner/reader framework and file partitioning
- Kafka datasink with confluent-kafka migration and datetime offset support
- 2-phase commit checkpointing with trie recovery
ray-2.54.1
Bug fix
Hanging issue detector disabled to resolve pipeline performance degradation from blocking API calls.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Install & Platforms
Install via
pip