jason810496 opened a new pull request, #71394: URL: https://github.com/apache/airflow/pull/71394
## Why New or compromised npm releases can execute code during dependency installation before they are detected and removed from the registry. ## What - Delay newly resolved dependency versions for 14 days. - Block exotic transitive dependency sources. - Fail on unapproved lifecycle builds and allow only the required `esbuild` scripts. - Document the dependency security policy and include it in compile-hook triggers. --- ##### Was generative AI tooling used to co-author this PR? - [x] Yes, with help of Codex GPT-5 following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
