jason810496 opened a new pull request, #71401: URL: https://github.com/apache/airflow/pull/71401
## Why Java SDK dependency changes are not currently blocked when they introduce known vulnerabilities, and the resolved transitive graph is not submitted explicitly for continuous analysis. ## How - Reject pull requests that introduce high or critical vulnerabilities across runtime, development, or unknown scopes. - Submit resolved dependencies from the main SDK build and both standalone example builds. - Validate the Gradle wrapper and keep workflow permissions scoped to each job. - Configure grouped Gradle Dependabot updates for the Java SDK. --- ##### Was generative AI tooling used to co-author this PR? - [x] Yes, with help of Codex GPT-5.6 following [the guidelines](https://github.com/apache/airflow/blob/main/contributing-docs/05_pull_requests.rst#gen-ai-assisted-contributions) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
