apache-airflow-core

condav3.1.8

Core packages for Apache Airflow, schedule and API server

License MIT AND BSD-3-Clause AND BSD-2-Clause AND Apache-2.0permissive16 versions1 maintainers0 deps623 weekly dl
apache/airflow
42
/ 100
Health
do not use

apache-airflow-core has critical vulnerabilities — do not use

Update to >= 3.2.0 to fix known vulnerabilities

  • 1 high severity vulnerabilities
  • 1 critical vulnerabilities
Health breakdown0 – 100
20/25
maintenance
3/20
popularity
8/25
security
9/15
maturity
2/15
community
Vulnerabilities
4
1 critical1 high1 medium1 low
Advisories (4)
SeverityIDSummaryFixed in
criticalBIT-airflow-2026-25917Apache Airflow allows code execution through crafted XCom payloads3.2.0
highBIT-airflow-2026-32228Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions3.2.0
mediumBIT-airflow-2026-30912Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false3.2.0
lowBIT-airflow-2026-32690Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries3.2.0

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/conda/apache-airflow-core

First published · 2025-05-14 16:03:35.892000+00:00

Last updated · 2026-03-12 08:28:00.341000+00:00