Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.

Conversation

@dnegreira
Copy link
Member

Update advisories for GHSA-hrfv-mqp8-q5rw, GHSA-f9vj-2wh5-fj8j,
GHSA-2g68-c3qc-8985 and GHSA-q34m-jh98-gwm2.

We are currently unable to bump the Werkzeug dependency as there are
some hard constraints on the connnexion dependency for the FAB auth
manager APIs.

More information can be found in a comment by upstream maintainers here:
https://github.com/apache/airflow/pull/51681\#issuecomment-3411116656

Signed-off-by: David Negreira david.negreira@chainguard.dev

Update advisories for GHSA-hrfv-mqp8-q5rw, GHSA-f9vj-2wh5-fj8j,
GHSA-2g68-c3qc-8985 and GHSA-q34m-jh98-gwm2.

We are currently unable to bump the Werkzeug dependency as there are
some hard constraints on the connnexion dependency for the FAB auth
manager APIs.

More information can be found in a comment by upstream maintainers here:
https://github.com/apache/airflow/pull/51681\#issuecomment-3411116656

Signed-off-by: David Negreira <david.negreira@chainguard.dev>
@dnegreira dnegreira closed this Oct 23, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant