The GitHub Actions job "Tests (AMD)" on 
airflow.git/tighten-dag-sources-per-file-authz has succeeded.
Run started by GitHub user potiuk (triggered by potiuk).

Head commit for run:
bce61c5601a47fa97bdc0d30768a76764d775478 / Jarek Potiuk <[email protected]>
Document per-file authorization boundary for dag-source endpoint

Add a Security Model subsection that describes the per-Dag read scope
the dag-source retrieval endpoint enforces, and the known limitation
around historical-version retrieval: the per-Dag scope is evaluated
against the current file membership, which may differ from the file's
contents at the time the requested version was stored. Deployments
that rely on per-Dag read scoping for source isolation should keep one
Dag per source file, or restrict DagAccessEntity.CODE accordingly.

Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>

Report URL: https://github.com/apache/airflow/actions/runs/26657384333

With regards,
GitHub Actions via GitBox


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to