Concern about PLY dependency being quarantined due to vulnerabilities – blocking Airflow installation #61714
Replies: 1 comment 1 reply
-
|
You can definitely propose a PR removing it. As far as I could check, howver, The base reference image: The slim image (this one has only preinstalled providers): After some quick check with There are a number of things you can do yourself however to help with that - and it would be great if your company can contribute back by contributing your time (or somoene else to help with it) - since you are interested in removing So if you would like to spend time and see how to fix it - that would be a welcome contribution - and I am sure the amazon team will be happy to help reviewing and merging it. For now I see you have several options to proceed:
There is also a workaround if you are not using amazon provider: If you are using airflow reference image, you can instead use airflow slim image and extend it and build your own without So - you are absolutely not blocked, contributions are welcome and it seems that there are some viable paths for you to improve things - so it's only on you now to execute one of those paths @jskalasariya |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
We are currently facing an issue related to the PLY Python package, which is a dependency of Apache Airflow.
Recently, several PyPI packages have been quarantined in our Nexus repository due to known security vulnerabilities. While most of these packages could be resolved by upgrading to a newer minor or patch version, PLY appears to be an exception.
Key points:
Because of this, we are currently unable to install Airflow in environments with strict security policies
Wanted to ask the community:
Any guidance or direction would be greatly appreciated.
Thanks in advance!
Beta Was this translation helpful? Give feedback.
All reactions