The GitHub Actions job "Tests (ARM)" on airflow.git/v3-2-test has failed.
Run started by GitHub user vatsrahul1001 (triggered by vatsrahul1001).

Head commit for run:
eb4964b8c82a2692055916c4feba9fdbb596598c / github-actions[bot] 
<41898282+github-actions[bot]@users.noreply.github.com>
[v3-2-test] docs(security): document supported deployment platforms (#66931) 
(#67017)

* docs(security): document supported deployment platforms

Add an explicit out-of-scope section for non-Linux platforms to the
Security Model. Bugs that only manifest on Windows / macOS / other
non-Linux platforms are not eligible for CVE allocation because Airflow
does not officially support those platforms as deployment targets.

Codifies what was already the security team's practice — most recently
the disposition on a 2026-05-14 IMAP-attachment-path-traversal report
that only manifested on Windows due to backslash path-separator
handling, closed NOT-CVE-WORTHY on this basis. Future Windows-only /
macOS-only reports get the same treatment, and reporters can read the
rule upfront before submitting.

The rule applies symmetrically: a bug that affects Linux is judged on
the Linux behavior regardless of whether it also reaches Windows;
non-Linux-only bugs are out of scope.



* Apply suggestions from code review



---------
(cherry picked from commit ea60a4d6844f39e3c5793468ba75c7e661825aad)

Co-authored-by: Jarek Potiuk <[email protected]>
Co-authored-by: Claude Opus 4.7 (1M context) <[email protected]>

Report URL: https://github.com/apache/airflow/actions/runs/26018408255

With regards,
GitHub Actions via GitBox


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to