Skip to content

Conversation

@potiuk
Copy link
Member

@potiuk potiuk commented Aug 20, 2025

https://lists.apache.org/thread/d5lx8s5972r69o34zsg9rmjb2mcoyqdc


^ Add meaningful description above
Read the Pull Request Guidelines for more information.
In case of fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
In case of a new dependency, check compliance with the ASF 3rd Party License Policy.
In case of backwards incompatible changes please leave a note in a newsfragment file, named {pr_number}.significant.rst or {issue_number}.significant.rst, in airflow-core/newsfragments.

@potiuk potiuk requested a review from jscheffl August 20, 2025 09:52
@boring-cyborg boring-cyborg bot added area:dev-tools backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch labels Aug 20, 2025
@potiuk potiuk changed the title Add dependabot tests for v3-0-test branch Add dependabot checks for v3-0-test branch Aug 20, 2025
@potiuk potiuk force-pushed the add-dependabot-for-3-0-test-branch branch from b63a0cb to fbc2e87 Compare August 20, 2025 10:41
Copy link
Member

@kaxil kaxil left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Worth adding a link to private discussion as PR description so we know the context when if/when we look back at this PR and wonder why we added this!

@potiuk
Copy link
Member Author

potiuk commented Aug 20, 2025

Worth adding a link to private discussion as PR description so we know the context when if/when we look back at this PR and wonder why we added this!

The discussion is private for now :). I'd hate to link a link that will be unreachable for most ... But I will add a link to the devlist announcement / follow-up after we agree in PMC/Security team about more proactive security process.

@kaxil
Copy link
Member

kaxil commented Aug 20, 2025

Worth adding a link to private discussion as PR description so we know the context when if/when we look back at this PR and wonder why we added this!

The discussion is private for now :). I'd hate to link a link that will be unreachable for most ... But I will add a link to the devlist announcement / follow-up after we agree in PMC/Security team about more proactive security process.

I know but still worth adding. More for future us than anyone else. Private link is still better than empty description :)

You can replace it with the public one when it is added to public devlist

@potiuk
Copy link
Member Author

potiuk commented Aug 20, 2025

@potiuk potiuk merged commit bd5f86a into apache:main Aug 20, 2025
46 checks passed
@potiuk potiuk deleted the add-dependabot-for-3-0-test-branch branch August 20, 2025 11:35
github-actions bot pushed a commit that referenced this pull request Aug 20, 2025
(cherry picked from commit bd5f86a)

Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
@github-actions
Copy link

Backport successfully created: v3-0-test

Status Branch Result
v3-0-test PR Link

potiuk added a commit that referenced this pull request Aug 20, 2025
(cherry picked from commit bd5f86a)

Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
github-actions bot pushed a commit to astronomer/airflow that referenced this pull request Aug 20, 2025
(cherry picked from commit bd5f86a)

Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
@gopidesupavan
Copy link
Member

Nice :) thanks for adding.

@gopidesupavan
Copy link
Member

One main advantage with dependaboat i see always is it checks selected package against any security vulnerabilities in security advisory :)

@potiuk
Copy link
Member Author

potiuk commented Aug 22, 2025

One main advantage with dependaboat i see always is it checks selected package against any security vulnerabilities in security advisory :)

Yep.

mangal-vairalkar pushed a commit to mangal-vairalkar/airflow that referenced this pull request Aug 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:dev-tools backport-to-v3-1-test Mark PR with this label to backport to v3-1-test branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants