Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

airflow-3: update advisories#24328

Merged
catmsred merged 1 commit intowolfi-dev:mainfrom
dnegreira:airflow-3-adv-vulns
Oct 23, 2025
Merged

airflow-3: update advisories#24328
catmsred merged 1 commit intowolfi-dev:mainfrom
dnegreira:airflow-3-adv-vulns

Conversation

@dnegreira
Copy link
Member

Update advisories for GHSA-hrfv-mqp8-q5rw, GHSA-f9vj-2wh5-fj8j,
GHSA-2g68-c3qc-8985 and GHSA-q34m-jh98-gwm2

We are currently unable to bump the Werkzeug dependency as there are
some hard constraints on the connnexion dependency for the FAB auth
manager APIs.

More information can be found in a comment by upstream maintainers here:
https://github.com/apache/airflow/pull/51681\#issuecomment-3411116656

We also had to re-work our airflow-3 package to ensure that we are
respecting the constraints so that we don't bump package versions to an
unsupported version.
More information here:
wolfi-dev/os#69508

Signed-off-by: David Negreira [email protected]

Update advisories for GHSA-hrfv-mqp8-q5rw, GHSA-f9vj-2wh5-fj8j,
GHSA-2g68-c3qc-8985 and GHSA-q34m-jh98-gwm2

We are currently unable to bump the Werkzeug dependency as there are
some hard constraints on the connnexion dependency for the FAB auth
manager APIs.

More information can be found in a comment by upstream maintainers here:
https://github.com/apache/airflow/pull/51681\#issuecomment-3411116656

We also had to re-work our airflow-3 package to ensure that we are
respecting the constraints so that we don't bump package versions to an
unsupported version.
More information here:
wolfi-dev/os#69508

Signed-off-by: David Negreira <[email protected]>
@dnegreira dnegreira requested a review from a team October 23, 2025 12:13
@catmsred
Copy link
Member

Fixed link for upstream discussion: apache/airflow#51681 (comment)

@catmsred catmsred added this pull request to the merge queue Oct 23, 2025
Merged via the queue into wolfi-dev:main with commit a3d6099 Oct 23, 2025
4 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants