eladkal commented on PR #64402: URL: https://github.com/apache/airflow/pull/64402#issuecomment-4149979482
> I'm not sure we want to do this change, since there are other projects that might be depended on starlette<1, If you have a way to relax `starlette>=0.45.0` feel free to suggest. Regardless, we do not bump min version just because upstream released a CVE unless risk affect airflow directly. We try to be as relaxed as possible with dependencies as long as they don't conflict with what we need. Users may use whatever version is good for them. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
