Skip to content

Conversation

@loganaden
Copy link

See vulnerability here:
GHSA-6mq8-rvhq-8wgg

Was generative AI tooling used to co-author this PR?

No

@loganaden loganaden requested a review from josh-fell as a code owner January 9, 2026 14:53
@boring-cyborg
Copy link

boring-cyborg bot commented Jan 9, 2026

Congratulations on your first Pull Request and welcome to the Apache Airflow community! If you have any issues or are unsure about any anything please check our Contributors' Guide (https://github.com/apache/airflow/blob/main/contributing-docs/README.rst)
Here are some useful points:

  • Pay attention to the quality of your code (ruff, mypy and type annotations). Our prek-hooks will help you with that.
  • In case of a new feature add useful documentation (in docstrings or in docs/ directory). Adding a new operator? Check this short guide Consider adding an example DAG that shows how users should use it.
  • Consider using Breeze environment for testing locally, it's a heavy docker but it ships with a working Airflow and a lot of integrations.
  • Be patient and persistent. It might take some time to get a review or get the final approval from Committers.
  • Please follow ASF Code of Conduct for all communication including (but not limited to) comments on Pull Requests, Mailing list and Slack.
  • Be sure to read the Airflow Coding style.
  • Always keep your Pull Requests rebased, otherwise your build might fail due to changes not related to your commits.
    Apache Airflow is a community-driven project and together we are making it better 🚀.
    In case of doubts contact the developers at:
    Mailing List: dev@airflow.apache.org
    Slack: https://s.apache.org/airflow-slack

@potiuk potiuk changed the title Fix CVE-2025-69223 Prevent CVE-2025-69223 Jan 9, 2026
@potiuk
Copy link
Member

potiuk commented Jan 9, 2026

It's not a fix, it's at most prevention (and we don't even know if we are vulnerable) - also airflow has constraints mechanisms when releasing that strongly recommends people to install the "latest" versions of the dependencies - you can check in constraints which version is currently recommended.

Copy link
Contributor

@jscheffl jscheffl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In parallel PR #56457 has been merged which also adds another aiohttp reference. Can you rebase and add this in the PR as well?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants