jason810496 opened a new pull request, #71401:
URL: https://github.com/apache/airflow/pull/71401

   ## Why
   
   Java SDK dependency changes are not currently blocked when they introduce 
known vulnerabilities, and the resolved transitive graph is not submitted 
explicitly for continuous analysis.
   
   ## How
   
   - Reject pull requests that introduce high or critical vulnerabilities 
across runtime, development, or unknown scopes.
   - Submit resolved dependencies from the main SDK build and both standalone 
example builds.
   - Validate the Gradle wrapper and keep workflow permissions scoped to each 
job.
   - Configure grouped Gradle Dependabot updates for the Java SDK.
   
   ---
   
   ##### Was generative AI tooling used to co-author this PR?
   
   - [x] Yes, with help of Codex GPT-5.6 following [the 
guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to