This is an automated email from the ASF dual-hosted git repository.

shahar1 pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/airflow.git


The following commit(s) were added to refs/heads/main by this push:
     new ec5b621a9cc Prepare ad-hoc providers release 2026-10-02 (#74097)
ec5b621a9cc is described below

commit ec5b621a9cc2e6c05332dbf2281665a01bc051e5
Author: Shahar Epstein <[email protected]>
AuthorDate: Fri Oct 2 20:04:55 2026 +0300

    Prepare ad-hoc providers release 2026-10-02 (#74097)
    
    Re-cut of cncf.kubernetes 10.23.0, edge3 5.0.0 and duckdb 0.2.0, which
    were held back from the 2026-09-22 wave. Their changelog sections pick up
    the commits that landed on main since that wave was prepared.
---
 providers/.last_release_date.txt                           |  2 +-
 providers/cncf/kubernetes/docs/changelog.rst               |  5 +++++
 providers/cncf/kubernetes/provider.yaml                    |  2 +-
 providers/duckdb/provider.yaml                             |  2 +-
 providers/edge3/docs/changelog.rst                         |  7 +++++++
 providers/edge3/provider.yaml                              | 14 +++++++-------
 .../edge3/src/airflow/providers/edge3/get_provider_info.py | 12 ++++++------
 7 files changed, 28 insertions(+), 16 deletions(-)

diff --git a/providers/.last_release_date.txt b/providers/.last_release_date.txt
index 89b6def6c46..0af6c8eac74 100644
--- a/providers/.last_release_date.txt
+++ b/providers/.last_release_date.txt
@@ -1 +1 @@
-2026-09-22
+2026-10-02
diff --git a/providers/cncf/kubernetes/docs/changelog.rst 
b/providers/cncf/kubernetes/docs/changelog.rst
index 1a8a1ecac2d..6329c882298 100644
--- a/providers/cncf/kubernetes/docs/changelog.rst
+++ b/providers/cncf/kubernetes/docs/changelog.rst
@@ -38,6 +38,7 @@ Features
 Bug Fixes
 ~~~~~~~~~
 
+* ``Fix KubernetesExecutor not queuing tasks on Airflow 3.0.x (#73764)``
 * ``Prevent KubernetesExecutor from launching stale workloads (#69762)``
 * ``Fix KubernetesPodOperator discarding successful XCom when sidecar kill 
fails (#72068)``
 * ``Fix deferrable Kubernetes 401s with a default exec-based kubeconfig 
(#72300)``
@@ -47,6 +48,7 @@ Bug Fixes
 Misc
 ~~~~
 
+* ``Bump the default XCom sidecar image to alpine 3.24.2 (#73629)``
 * ``Unify executor workload queues (#63491)``
 
 Doc-only
@@ -58,6 +60,9 @@ Doc-only
 
 .. Below changes are excluded from the changelog. Move them to
    appropriate section above if needed. Do not delete the lines(!):
+   * ``Correlate executor task events by attempt UUID (#73916)``
+   * ``Add dedicated tests for cncf.kubernetes secret and k8s_model modules 
(#73751)``
+   * ``Prepare providers release 2026-09-22 (#73506)``
    * ``Revert "[main] Upgrade important CI environment (#73308)" (#73621)``
    * ``[main] Upgrade important CI environment (#73308)``
    * ``Remove real sleeps from slow provider unit tests (#73478)``
diff --git a/providers/cncf/kubernetes/provider.yaml 
b/providers/cncf/kubernetes/provider.yaml
index 71f92b85b09..4d403b38797 100644
--- a/providers/cncf/kubernetes/provider.yaml
+++ b/providers/cncf/kubernetes/provider.yaml
@@ -23,7 +23,7 @@ description: |
 
 state: ready
 lifecycle: production
-source-date-epoch: 1790023613
+source-date-epoch: 1790955848
 # Note that those versions are maintained by release manager - do not update 
them manually
 # with the exception of case where other provider in sources has >= new 
provider version.
 # In such case adding >= NEW_VERSION and bumping to NEW_VERSION in a provider 
have
diff --git a/providers/duckdb/provider.yaml b/providers/duckdb/provider.yaml
index 95284703063..20c40c54758 100644
--- a/providers/duckdb/provider.yaml
+++ b/providers/duckdb/provider.yaml
@@ -21,7 +21,7 @@ name: DuckDB
 
 state: ready
 lifecycle: incubation
-source-date-epoch: 1790023613
+source-date-epoch: 1790955848
 description: |
   `DuckDB <https://duckdb.org/>`__ provider for Apache Airflow. Runs SQL 
against an in-process
   DuckDB database — in memory, backed by a local file, or hosted by MotherDuck 
— and manages
diff --git a/providers/edge3/docs/changelog.rst 
b/providers/edge3/docs/changelog.rst
index 47537d6db60..1741821c983 100644
--- a/providers/edge3/docs/changelog.rst
+++ b/providers/edge3/docs/changelog.rst
@@ -41,6 +41,11 @@ Breaking changes
 
 * ``Make EdgeExecutor respect [core] parallelism (#72048)``
 
+Features
+~~~~~~~~
+
+* ``Add OIDC worker token verification to Edge3 (#72262)``
+
 Bug Fixes
 ~~~~~~~~~
 
@@ -62,6 +67,8 @@ Doc-only
 
 .. Below changes are excluded from the changelog. Move them to
    appropriate section above if needed. Do not delete the lines(!):
+   * ``[main] Upgrade important CI environment (#73629)``
+   * ``Prepare providers release 2026-09-22 (#73506)``
    * ``Revert "[main] Upgrade important CI environment (#73308)" (#73621)``
    * ``[main] Upgrade important CI environment (#73308)``
    * ``Add missing test modules for the edge3 provider (#73111)``
diff --git a/providers/edge3/provider.yaml b/providers/edge3/provider.yaml
index 39334a8315a..b8b809204d4 100644
--- a/providers/edge3/provider.yaml
+++ b/providers/edge3/provider.yaml
@@ -34,7 +34,7 @@ description: |
 
 state: ready
 lifecycle: production
-source-date-epoch: 1790023613
+source-date-epoch: 1790955848
 build-system: hatchling
 
 # Note that those versions are maintained by release manager - do not update 
them manually
@@ -126,7 +126,7 @@ config:
           an edge worker. If the issuer serves other workloads, configure
           ``jwt_issuer`` and a ``jwt_verifier`` to restrict which identities 
are
           accepted; otherwise any validly signed token from the issuer is 
accepted.
-        version_added: 4.4.0
+        version_added: 5.0.0
         type: string
         example: https://idp.example.com/oauth2/v1/keys
         default: ~
@@ -138,7 +138,7 @@ config:
           configured to decide which identities may act as edge workers 
(requests are
           rejected otherwise). Set it to bind tokens to your provider. Ignored 
when
           ``trusted_jwks_url`` is empty.
-        version_added: 4.4.0
+        version_added: 5.0.0
         type: string
         example: https://idp.example.com
         default: ~
@@ -148,7 +148,7 @@ config:
           set. When set, the token must carry a matching ``aud``. When empty, 
only
           tokens that carry no ``aud`` claim are accepted (a token that does 
carry
           an ``aud`` is rejected). Ignored when ``trusted_jwks_url`` is empty.
-        version_added: 4.4.0
+        version_added: 5.0.0
         type: string
         example: api
         default: ~
@@ -157,7 +157,7 @@ config:
           Comma-separated list of JWS signing algorithms accepted for edge 
worker
           tokens when ``trusted_jwks_url`` is set. Set it to match the 
algorithm the
           trusted provider signs with. Ignored when ``trusted_jwks_url`` is 
empty.
-        version_added: 4.4.0
+        version_added: 5.0.0
         type: string
         example: RS256,RS512
         default: RS256
@@ -167,7 +167,7 @@ config:
           claims of edge worker tokens issued by a trusted OIDC provider, to 
account for
           clock skew between the identity provider and the API server. Ignored 
when
           ``trusted_jwks_url`` is empty.
-        version_added: 4.4.0
+        version_added: 5.0.0
         type: integer
         example: ~
         default: "30"
@@ -184,7 +184,7 @@ config:
           issuer verification is then skipped. When empty (and ``jwt_issuer`` 
is set)
           any token that passes signature, issuer and audience verification is
           authorized. Ignored when ``trusted_jwks_url`` is empty.
-        version_added: 4.4.0
+        version_added: 5.0.0
         type: string
         example: my_company.edge_auth.verify_worker_token
         default: ~
diff --git a/providers/edge3/src/airflow/providers/edge3/get_provider_info.py 
b/providers/edge3/src/airflow/providers/edge3/get_provider_info.py
index 58488f5c327..083895585c1 100644
--- a/providers/edge3/src/airflow/providers/edge3/get_provider_info.py
+++ b/providers/edge3/src/airflow/providers/edge3/get_provider_info.py
@@ -55,42 +55,42 @@ def get_provider_info():
                     },
                     "trusted_jwks_url": {
                         "description": "When set, edge worker tokens are 
verified against this JSON Web Key Set\n(JWKS) URL of a trusted OpenID Connect 
provider, using asymmetric\nsignatures, instead of the shared ``[api_auth] 
jwt_secret``. This lets\nedge workers authenticate with tokens minted by an 
external identity\nprovider.\n\nWhen empty (the default) the shared-secret 
(symmetric) verification is\nused, so existing deployments are 
unaffected.\n\nSecurity note: enabling this disable [...]
-                        "version_added": "4.4.0",
+                        "version_added": "5.0.0",
                         "type": "string",
                         "example": "https://idp.example.com/oauth2/v1/keys";,
                         "default": None,
                     },
                     "jwt_issuer": {
                         "description": "Expected ``iss`` claim of edge worker 
tokens when ``trusted_jwks_url`` is\nset. Leaving it empty skips issuer 
verification, so a token from any issuer\nwhose key is in the JWKS is accepted; 
in that case ``jwt_verifier`` must be\nconfigured to decide which identities 
may act as edge workers (requests are\nrejected otherwise). Set it to bind 
tokens to your provider. Ignored when\n``trusted_jwks_url`` is empty.\n",
-                        "version_added": "4.4.0",
+                        "version_added": "5.0.0",
                         "type": "string",
                         "example": "https://idp.example.com";,
                         "default": None,
                     },
                     "jwt_audience": {
                         "description": "Expected ``aud`` claim of edge worker 
tokens when ``trusted_jwks_url`` is\nset. When set, the token must carry a 
matching ``aud``. When empty, only\ntokens that carry no ``aud`` claim are 
accepted (a token that does carry\nan ``aud`` is rejected). Ignored when 
``trusted_jwks_url`` is empty.\n",
-                        "version_added": "4.4.0",
+                        "version_added": "5.0.0",
                         "type": "string",
                         "example": "api",
                         "default": None,
                     },
                     "jwt_algorithm": {
                         "description": "Comma-separated list of JWS signing 
algorithms accepted for edge worker\ntokens when ``trusted_jwks_url`` is set. 
Set it to match the algorithm the\ntrusted provider signs with. Ignored when 
``trusted_jwks_url`` is empty.\n",
-                        "version_added": "4.4.0",
+                        "version_added": "5.0.0",
                         "type": "string",
                         "example": "RS256,RS512",
                         "default": "RS256",
                     },
                     "jwt_leeway": {
                         "description": "Number of seconds of leeway allowed 
when validating the expiry and issued-at\nclaims of edge worker tokens issued 
by a trusted OIDC provider, to account for\nclock skew between the identity 
provider and the API server. Ignored when\n``trusted_jwks_url`` is empty.\n",
-                        "version_added": "4.4.0",
+                        "version_added": "5.0.0",
                         "type": "integer",
                         "example": None,
                         "default": "30",
                     },
                     "jwt_verifier": {
                         "description": 'Import path of a callable that 
authorizes edge worker tokens issued by a\ntrusted OIDC provider, run after 
signature, issuer and audience checks pass.\nIt receives the validated claims 
(``dict``) and a request context object\ncarrying the request ``method``, and 
returns a mapping with an\n``authorized`` boolean (e.g. ``{"authorized": 
True}``); a falsy result or a\nraised exception rejects the request. Use it to 
restrict which identities\n(for examp [...]
-                        "version_added": "4.4.0",
+                        "version_added": "5.0.0",
                         "type": "string",
                         "example": "my_company.edge_auth.verify_worker_token",
                         "default": None,

Reply via email to