This is an automated email from the ASF dual-hosted git repository.
potiuk pushed a commit to branch v3-3-test
in repository https://gitbox.apache.org/repos/asf/airflow.git
The following commit(s) were added to refs/heads/v3-3-test by this push:
new f7378584f91 [v3-3-test] Run the scheduled CI upgrade check on
v3-3-test (#73318) (#73458)
f7378584f91 is described below
commit f7378584f91a2aaf3503a3a2b35b003b9051cf80
Author: github-actions[bot]
<41898282+github-actions[bot]@users.noreply.github.com>
AuthorDate: Tue Sep 22 02:25:13 2026 +0200
[v3-3-test] Run the scheduled CI upgrade check on v3-3-test (#73318)
(#73458)
* [v3-3-test] Clarify that AccessView.JOBS is the Edge worker management
permission (#72627) (#73073)
The Edge UI plugin docs say that "can read on Plugins" and "can read on
Jobs" let you view the UI and manage the workers, but they do not say how
the two permissions differ, and they do not mention what the default
Viewer role already holds.
Both gaps matter, because the endpoints and the navigation are gated
differently:
- The worker management endpoints under /edge_worker/ui/ check only
AccessView.JOBS, and the check is not method-aware -- the same
dependency guards the GET reads and the POST/PATCH/DELETE mutations.
- "can read on Plugins" only controls whether the plugin shows up in the
UI navigation. It is not required in order to call the endpoints.
So "can read on Jobs" alone is enough to shut down, delete, re-queue and
retune Edge workers, whether or not the plugin is visible to that user.
That is intentional -- AccessView.JOBS is the management permission for
the plugin rather than a read-only grant -- but it reads as surprising
from the code alone, where a permission named "can read" guards mutating
routes. It is more surprising in a default Flask AppBuilder setup, where
the Viewer role includes (ACTION_CAN_READ, RESOURCE_JOB) but not the
Plugins read: such a user cannot see the Edge plugin and can still reach
its management endpoints.
Adds a warning to the UI plugin docs stating the intent, the split
between the two permissions, the consequence for the default Viewer role,
and the concrete action for deployments where Viewers must not manage
workers. Points at the existing "fine granular access control" entry in
architecture.rst rather than restating it.
Documentation only; no behaviour change.
(cherry picked from commit 1391b0934240aa70c90d7cad186d71a235bdfdd2)
* [v3-3-test] Keep the Gradle wrapper jar out of the source release
(#69444) (#73108)
ASF policy does not permit compiled binaries in a source release and the
Gradle wrapper is not among the exempted build tools (LEGAL-570), so main
stopped shipping java-sdk/gradle/wrapper/gradle-wrapper.jar in #69444.
Only half of that change reached this branch. The breeze side already
restores gradlew and gradlew.bat after `git archive` drops them, but the
java-sdk/.gitattributes side never followed, so nothing is actually dropped
and the 43 KB jar is still in the 3.3.2rc1 source tarball.
Carrying the rest of the file over also starts shipping
java-sdk/.editorconfig,
which the root .gitattributes strips today even though ktlint reads it at
build time and the build task requires that lint to pass.
gradle-wrapper.properties stays in the tarball on purpose: it carries the
pinned Gradle version and distribution checksum a verifier needs to
regenerate the wrapper.
Generated-by: Claude Opus 5
Claude-Session: https://claude.ai/code/session_01DCUVuZ8CCeER1QLhVEKAaZ
* Authorize POST /assets/events on the asset named in the body (#73007)
(#73139)
The route dependency reads the asset id from the path, but this endpoint
carries it in the request body, so the auth manager was only asked whether
the caller may post to any asset at all. An auth manager that scopes assets
by id, name, or uri could not deny an event for an asset the caller may not
touch, and the response still returned that asset's name and uri.
Co-authored-by: Henry Chen <[email protected]>
* Bump the 3-3-fab-ui-package-updates group across 1 directory with 3
updates (#73208)
Bumps the 3-3-fab-ui-package-updates group with 3 updates in the
/providers/fab/src/airflow/providers/fab/www directory:
[@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core),
[@babel/eslint-parser](https://github.com/babel/babel/tree/HEAD/eslint/babel-eslint-parser)
and
[@babel/preset-env](https://github.com/babel/babel/tree/HEAD/packages/babel-preset-env).
Updates `@babel/core` from 8.0.1 to 8.0.5
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
-
[Commits](https://github.com/babel/babel/commits/v8.0.5/packages/babel-core)
Updates `@babel/eslint-parser` from 8.0.1 to 8.0.5
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
-
[Commits](https://github.com/babel/babel/commits/v8.0.5/eslint/babel-eslint-parser)
Updates `@babel/preset-env` from 8.0.2 to 8.0.5
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
-
[Commits](https://github.com/babel/babel/commits/v8.0.5/packages/babel-preset-env)
---
updated-dependencies:
- dependency-name: "@babel/core"
dependency-version: 8.0.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: 3-3-fab-ui-package-updates
- dependency-name: "@babel/eslint-parser"
dependency-version: 8.0.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: 3-3-fab-ui-package-updates
- dependency-name: "@babel/preset-env"
dependency-version: 8.0.5
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: 3-3-fab-ui-package-updates
...
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
* [v3-3-test] Reject non-numeric --limit values in airflow dags list-jobs
(#72891) (#73214)
The --limit option had no argparse type, so a value such as "abc" or "-1"
was passed straight into the SQLAlchemy query and surfaced as a raw
ValueError traceback instead of a usage error. Validating it at parse
time gives the standard argparse message and exit code 2, while keeping
0 and positive integers working exactly as before.
(cherry picked from commit 022ff83f14563cde9b91e87cd5a18253997384e3)
Co-authored-by: Y-C <[email protected]>
Co-authored-by: Eason09053360
<[email protected]>
* [v3-3-test] Fix DAG.cli() crashing on dags test --show-dagrun (#72810)
(#73216)
* Fix DAG.cli() crashing on dags test --show-dagrun
A Dag file run as a script goes through DAG.cli(), whose parser drops the
dag_id positional and passes the Dag object to the handler instead. dag_test
never needed dag_id from the parsed arguments until it rendered the run: the
task instance query read args.dag_id, so --show-dagrun, --save-dagrun and
--imgcat-dagrun raised AttributeError after the Dag had already run, while
the plain command and the regular airflow dags test path worked.
Filtering on the resolved Dag's id is the same value on the regular path and
the only one available from DAG.cli().
* Update airflow-core/tests/unit/cli/commands/test_dag_command.py
* Update airflow-core/tests/unit/cli/commands/test_dag_command.py
---------
(cherry picked from commit 63fc32fd14bbbb20abfa60301abcd2f33d49726f)
Co-authored-by: Y-C <[email protected]>
Co-authored-by: Eason09053360
<[email protected]>
Co-authored-by: rjgoyln <[email protected]>
Co-authored-by: Henry Chen <[email protected]>
* Split the api_fastapi common parameters module into a package (#73239)
The parameters module had grown to ~1800 lines mixing generic query
helpers with hundreds of domain-specific query-parameter aliases, making
it hard to navigate and maintain. Grouping the machinery (base, search,
filter, sort, range) and the per-domain aliases (dag, dag_run,
task_instance, xcom, asset, misc) into focused submodules keeps each file
readable. The package __init__ re-exports the names consumed elsewhere in
the codebase so existing import paths keep working.
Backport of #72795 to v3-3-test. Because v3-3-test's parameters.py has a
smaller set of query-parameter definitions than main (some PRs were not
backported), this was re-created by running the same mechanical split on
v3-3-test's file rather than cherry-picked: every definition is
byte-identical to the original, and __init__ re-exports only the names
consumed outside the package.
* [v3-3-test] Document that plugin names must be unique (#73197) (#73203)
(cherry picked from commit 49674b776df40562e47b60693958293b734199ce)
Co-authored-by: Aaron Chen <[email protected]>
* [v3-3-test] Decode deadline alert interval and callback without generic
deserialization (#72651) (#73304)
* Decode deadline alert interval and callback without generic
deserialization
decode_deadline_alert passed the Dag-author controlled interval and
callback to
airflow.sdk.serde.deserialize, which imports the class named in the payload
and
instantiates it with the encoded arguments. These decoders run in the
scheduler
and the API server whenever a serialized Dag is loaded, so any class under
the
airflow.* allow list could be constructed there.
The security model says a Dag author reaches those processes only through
registered plugins and providers, and the codebase enforces that at decode
time
for timetables, priority weight strategies and operator extra links.
Deadline
fields had no equivalent gate.
Both fields are now rebuilt from their encoded form directly:
* interval accepts a number, a timedelta payload, or a variable-interval
payload
carrying a key, each reconstructed from primitives.
* callback accepts AsyncCallback or SyncCallback, selected from a fixed map
rather than imported by name, with path as a string, queue/executor as
optional strings, and unexpected fields refused.
Neither reaches serde.deserialize, so the class a Dag author names in either
field is never imported.
Filtering in front of deserialize was tried first and was not sufficient.
serde
normalises the legacy {__type, __var} shape into __classname__ *inside*
deserialize, so a payload inspected beforehand carries no class name to
reject.
Payloads are normalised before inspection here, and that case is tested.
Known residual, deliberately not closed here: callback kwargs are still
passed
through generic deserialization, so a legitimate callback can carry an
arbitrary
allow-listed class under its kwargs. Deferring that decode to the process
that
runs the callback would close it, but the kwargs are consumed through two
paths
using two different encodings, and getting either wrong hands user code an
encoded dict in place of its argument. The residual is not specific to
deadlines -- it is the general property of deserializing Dag-author data,
shared
with every other serde call site. A test asserts the current behaviour so
the
gap stays visible and any change to it has to be deliberate.
Tests assert the class is never constructed rather than that an error is
raised.
Against unpatched sources the callback case reports DID NOT RAISE and the
interval case names the instance that had already been built.
* Accept pre-3.2 callback paths and validate fields per callback class
Review feedback on the deadline decoding gate.
Callbacks moved out of airflow.sdk.definitions.deadline in 3.2, so alerts
serialized by an earlier version name the old module. The allow list only
held
the current path, which would have made those rows undecodable on upgrade --
the same backward-compatibility case the interval allow list already covers.
The permitted callback fields were a hardcoded set covering both subclasses
at
once, so a payload could carry queue on a SyncCallback or executor on an
AsyncCallback. The set is per class, and each class already declares its own
via serialized_fields(), so ask it rather than restating the answer here and
letting the two drift. That also turns a TypeError raised from inside the
rebuild into the intended refusal, and the check now runs before anything is
reconstructed from the payload.
(cherry picked from commit c614c57062a95aade62cd5df774ae3c33bd57003)
Generated-by: Claude Opus 5
Claude-Session: https://claude.ai/code/session_012zrnHJHPchB83FtwrYRf5q
Co-authored-by: Jarek Potiuk <[email protected]>
* Bump swagger-ui-dist (#73332)
Bumps the 3-3-registry-package-updates group with 1 update in the /registry
directory: [swagger-ui-dist](https://github.com/swagger-api/swagger-ui).
Updates `swagger-ui-dist` from 5.32.14 to 5.32.15
- [Release notes](https://github.com/swagger-api/swagger-ui/releases)
-
[Commits](https://github.com/swagger-api/swagger-ui/compare/v5.32.14...v5.32.15)
---
updated-dependencies:
- dependency-name: swagger-ui-dist
dependency-version: 5.32.15
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: 3-3-registry-package-updates
...
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
* Bump webpack (#73333)
Bumps the 3-3-fab-ui-package-updates group with 1 update in the
/providers/fab/src/airflow/providers/fab/www directory:
[webpack](https://github.com/webpack/webpack).
Updates `webpack` from 5.110.3 to 5.111.0
- [Release notes](https://github.com/webpack/webpack/releases)
- [Changelog](https://github.com/webpack/webpack/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webpack/webpack/compare/v5.110.3...v5.111.0)
---
updated-dependencies:
- dependency-name: webpack
dependency-version: 5.111.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: 3-3-fab-ui-package-updates
...
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
* [v3-3-test] Skip provider dependency generation for help command in
breeze cli (#71689) (#73330)
(cherry picked from commit 60633c810c7d78c8575e117a36fbe9fb03180d02)
Co-authored-by: feberbo <[email protected]>
* Bump the github-actions-updates group with 5 updates (#73344)
Bumps the github-actions-updates group with 5 updates:
| Package | From | To |
| --- | --- | --- |
| [actions/setup-java](https://github.com/actions/setup-java) | `6.0.0` |
`6.0.1` |
| [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `10.0.1` |
`10.1.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action) |
`4.37.9` | `4.38.0` |
| [github/codeql-action/autobuild](https://github.com/github/codeql-action)
| `4.37.9` | `4.38.0` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) |
`4.37.9` | `4.38.0` |
Updates `actions/setup-java` from 6.0.0 to 6.0.1
- [Release notes](https://github.com/actions/setup-java/releases)
-
[Commits](https://github.com/actions/setup-java/compare/dd06d9cba3e5552c54d9f8ea23572deb30010f7c...de7274f081f381c8f8158605e0321c36c376e2e6)
Updates `astral-sh/setup-uv` from 10.0.1 to 10.1.0
- [Release notes](https://github.com/astral-sh/setup-uv/releases)
-
[Commits](https://github.com/astral-sh/setup-uv/compare/20cfd1bf945f4377ade1205e4dbc17946fc9a30d...bec219d24cd3e171d82865faccec33120bb574f4)
Updates `github/codeql-action/init` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
-
[Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
-
[Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63)
Updates `github/codeql-action/autobuild` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
-
[Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
-
[Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63)
Updates `github/codeql-action/analyze` from 4.37.9 to 4.38.0
- [Release notes](https://github.com/github/codeql-action/releases)
-
[Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
-
[Commits](https://github.com/github/codeql-action/compare/cdf488f595d80d6e07e03d4674febd5ab45fa938...b96794f015dfd88f77b49b1c93e0fa7110f94c63)
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 6.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: github-actions-updates
- dependency-name: astral-sh/setup-uv
dependency-version: 10.1.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions-updates
- dependency-name: github/codeql-action/init
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions-updates
- dependency-name: github/codeql-action/autobuild
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions-updates
- dependency-name: github/codeql-action/analyze
dependency-version: 4.38.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: github-actions-updates
...
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
* [v3-3-test] Make the constraints check follow the cooldown rules the
constraints use (#73316) (#73385)
After every provider release wave the `Deps *:constraints` jobs doubled for
three or four days and then recovered on their own. The constraints are
resolved under uv's `exclude-newer` cooldown with the per-package overrides
in the root pyproject.toml, where Airflow's own distributions are exempt, so
a fresh provider wave lands in the constraints the same day. The check had
its own 4-day cooldown applied to every package, so for those days the pin
was newer than "latest" and a plain equality check counted it as outdated.
With `--explain-why` every such package then cost a full `uv sync` that
tried to pin it to the *older* version and reported that the pin did not
take effect. On 2026-09-15 that was 37 providers and about 12 extra minutes
per job, with nothing to act on.
The check now reads `[tool.uv.exclude-newer-package]` and applies the same
rules: no cooldown for exempt distributions, a moved cutoff where one is
configured. A pin that is still ahead of "latest" counts as up to date, so
no explanation runs for it either.
(cherry picked from commit 7da73c89cb0133164f65d6189df97e23dc9292dd)
Generated-by: Claude Opus 5
Co-authored-by: Jarek Potiuk <[email protected]>
* Stop shipping broken agent-skill symlinks in the source release (#73107)
(#73448)
Excluding .agents from the source tarball (#68851) left .claude behind.
Everything under .claude/skills is a relay symlink into .agents/skills, so
export-ignore strips the targets while the links themselves still ship:
unpacking the source release yields broken symlinks, and .claude/ arrives
holding nothing but those dead links.
Found while verifying 3.3.2rc1, whose tarball carries five of them. The
released 3.3.1 carries the same ones, so this is long-standing rather than
something a recent change introduced.
.github needs no equivalent entry: its own skills relays are already
covered by the existing .github export-ignore.
(cherry picked from commit 4b0eb8e02060a73a3358ac2778b552a71252c38a)
* [v3-3-test] Run the scheduled CI upgrade check on v3-3-test (#73318)
3.3.x is the release branch under active maintenance, so its pinned uv,
prek and image versions drift the same way main's do — but nothing has
been refreshing them, because the only caller targets main. v3-2-test
carried the same caller until it stopped taking releases.
(cherry picked from commit 39c9a5d6650f3d6f5917f74eb439395274c562a8)
Co-authored-by: Jarek Potiuk <[email protected]>
Generated-by: Claude Code (Opus 5)
---------
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Jarek Potiuk <[email protected]>
Co-authored-by: Vincent <[email protected]>
Co-authored-by: Henry Chen <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Y-C <[email protected]>
Co-authored-by: Eason09053360
<[email protected]>
Co-authored-by: github-actions[bot]
<41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: rjgoyln <[email protected]>
Co-authored-by: Henry Chen <[email protected]>
Co-authored-by: Pierre Jeambrun <[email protected]>
Co-authored-by: Aaron Chen <[email protected]>
Co-authored-by: feberbo <[email protected]>
---
.../scheduled-upgrade-check-v3-3-test.yml | 35 ++++++++++++++++++++++
1 file changed, 35 insertions(+)
diff --git a/.github/workflows/scheduled-upgrade-check-v3-3-test.yml
b/.github/workflows/scheduled-upgrade-check-v3-3-test.yml
new file mode 100644
index 00000000000..379ac7578f9
--- /dev/null
+++ b/.github/workflows/scheduled-upgrade-check-v3-3-test.yml
@@ -0,0 +1,35 @@
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements. See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership. The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied. See the License for the
+# specific language governing permissions and limitations
+# under the License.
+#
+---
+name: "[v3-3-test] Scheduled CI upgrade check"
+on: # yamllint disable-line rule:truthy
+ schedule:
+ # Tue, Thu at 06:00 UTC — the days main does not run, so the two never
overlap.
+ - cron: '0 6 * * 2,4'
+ workflow_dispatch:
+permissions:
+ contents: write
+ pull-requests: write
+jobs:
+ upgrade-v3-3-test:
+ name: "[v3-3-test] Upgrade"
+ uses: ./.github/workflows/upgrade-check.yml
+ with:
+ target-branch: v3-3-test
+ secrets:
+ SLACK_BOT_TOKEN: ${{ secrets.SLACK_BOT_TOKEN }}