Skip to content

[v3-1-test] Clarify security model of Airflow (#61754)#61770

Merged
pierrejeambrun merged 1 commit into
v3-1-testfrom
backport-aab557b-v3-1-test
Feb 11, 2026
Merged

[v3-1-test] Clarify security model of Airflow (#61754)#61770
pierrejeambrun merged 1 commit into
v3-1-testfrom
backport-aab557b-v3-1-test

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

  • Clarify security model of Airflow

There are some assumptions that security researchers and our users
might have about security model of Airflow that do not hold true,
but were not clearly spelled out in the model.

This PR updates the security model with more clarity for those.

  • Apply suggestions from code review

Co-authored-by: Amogh Desai amoghrajesh1999@gmail.com


(cherry picked from commit aab557b)

Co-authored-by: Jarek Potiuk jarek@potiuk.com
Co-authored-by: Amogh Desai amoghrajesh1999@gmail.com

* Clarify security model of Airflow

There are some assumptions that security researchers and our users
might have about security model of Airflow that do not hold true,
but were not clearly spelled out in the model.

This PR updates the security model with more clarity for those.

* Apply suggestions from code review

Co-authored-by: Amogh Desai <amoghrajesh1999@gmail.com>

---------
(cherry picked from commit aab557b)

Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
Co-authored-by: Amogh Desai <amoghrajesh1999@gmail.com>
@pierrejeambrun pierrejeambrun marked this pull request as ready for review February 11, 2026 14:52
@pierrejeambrun
Copy link
Copy Markdown
Member

Unrelated CI failure

@pierrejeambrun pierrejeambrun merged commit 2aa7b08 into v3-1-test Feb 11, 2026
56 of 57 checks passed
@pierrejeambrun pierrejeambrun deleted the backport-aab557b-v3-1-test branch February 11, 2026 17:24
@vatsrahul1001 vatsrahul1001 added the type:doc-only Changelog: Doc Only label Mar 2, 2026
@vatsrahul1001 vatsrahul1001 added this to the Airflow 3.1.8 milestone Mar 2, 2026
vatsrahul1001 pushed a commit that referenced this pull request Mar 4, 2026
* Clarify security model of Airflow

There are some assumptions that security researchers and our users
might have about security model of Airflow that do not hold true,
but were not clearly spelled out in the model.

This PR updates the security model with more clarity for those.

* Apply suggestions from code review



---------
(cherry picked from commit aab557b)

Co-authored-by: Jarek Potiuk <jarek@potiuk.com>
Co-authored-by: Amogh Desai <amoghrajesh1999@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants