NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #5463 most downloaded on PyPI
Provider package apache-airflow-providers-redis for Apache Airflow
Last release 5 days ago
29 Sep 2026
Release timing varies
gaps range from 2 weeks to 3 months
Nearly every release is documented
notes for 41 of 41 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
91 releases · first in 2020
One column per quarter.
- Add redis_conn_id to RedisKeySensor and RedisPubSubSensor template_fields
Release Date: 2026-09-29
Add redis_conn_id to RedisKeySensor and RedisPubSubSensor template_fields (#73018)
Add redis_conn_id to RedisPublishOperator template_fields (#72883)
Keep message queue provider doc markers out of class docstrings (#73588)
Add redis_conn_id to RedisKeySensor and RedisPubSubSensor template_fields (#73018)
Add redis_conn_id to RedisPublishOperator template_fields (#72883)
Keep message queue provider doc markers out of class docstrings (#73588)
Nothing published for this version
- Add Redis cluster mode support to RedisHook
Release Date: 2026-09-14
Add Redis cluster mode support to RedisHook (#71067)
Nothing published for this version
- Add Redis client self-identification for Apache Airflow
Release Date: 2026-06-22
Add Redis client self-identification for Apache Airflow (#61866)
Add Redis client self-identification for Apache Airflow (#61866)
Nothing published for this version
- Add explicit [tool.flit.sdist] sections to flit-based pyproject.tomls
Release Date: 2026-06-07
Add explicit [tool.flit.sdist] sections to flit-based pyproject.tomls (#65861)
Add explicit [tool.flit.sdist] sections to flit-based pyproject.tomls (#65861)
Nothing published for this version
- Load hook metadata from YAML without importing Hook class
Release Date: 2026-04-12
Load hook metadata from YAML without importing Hook class (#63826)
Fix advertising some of the missing provider capabilities via provider info (#64127)
Load hook metadata from YAML without importing Hook class (#63826)
Fix advertising some of the missing provider capabilities via provider info (#64127)
Nothing published for this version
- Migrate redis connection UI metadata to YAML
Release Date: 2026-03-28
Add Python 3.14 Support (#63520)
Migrate redis connection UI metadata to YAML (#62670)
Add RedisTaskHandler configuration example (#63898)
Add Python 3.14 Support (#63520)
Migrate redis connection UI metadata to YAML (#62670)
Add RedisTaskHandler configuration example (#63898)
Nothing published for this version
- New year means updated Copyright notices
Release Date: 2026-01-17
New year means updated Copyright notices (#60344)
Migrate redis provider to use airflow.sdk.configuration.conf (#59983)
New year means updated Copyright notices (#60344)
Migrate redis provider to use airflow.sdk.configuration.conf (#59983)
Nothing published for this version
- Fix the serialization issue of AwaitMessageTrigger with Redis.
Release Date: 2025-12-13
Fix the serialization issue of AwaitMessageTrigger with Redis. (#58746)
Add backcompat for exceptions in providers (#58727)
Fix the serialization issue of AwaitMessageTrigger with Redis. (#58746)
Add backcompat for exceptions in providers (#58727)
Nothing published for this version
This release of provider is only available for Airflow 2.11+ as explained in the Apache Airflow providers support policy < https://github.com/apache/a
Release Date: 2025-11-30
Note
This release of provider is only available for Airflow 2.11+ as explained in the Apache Airflow providers support policy < https://github.com/apache/airflow/blob/main/PROVIDERS.rst#minimum-supported-version-of-airflow-for-community-managed-providers >_.
Bump minimum Airflow version in providers to Airflow 2.11.0 (#58612)
Note
This release of provider is only available for Airflow 2.11+ as explained in the Apache Airflow providers support policy <https://github.com/apache/airflow/blob/main/PROVIDERS.rst#minimum-supported-version-of-airflow-for-community-managed-providers>_.
Bump minimum Airflow version in providers to Airflow 2.11.0 (#58612)
Nothing published for this version
- Convert all airflow distributions to be compliant with ASF requirements
Release Date: 2025-11-17
Convert all airflow distributions to be compliant with ASF requirements (#58138)
Convert all airflow distributions to be compliant with ASF requirements (#58138)
Nothing published for this version
- Migrate redis provider to ''common.compat''
Release Date: 2025-10-26
Migrate redis provider to ''common.compat'' (#57006)
Remove placeholder Release Date in changelog and index files (#56056)
Migrate redis provider to ''common.compat'' (#57006)
Remove placeholder Release Date in changelog and index files (#56056)
Nothing published for this version
- [OSSTaskHandler, CloudwatchTaskHandler, S3TaskHandler, HdfsTaskHandler, ElasticsearchTaskHandler, GCSTaskHandler, OpensearchTaskHandler, RedisTaskHa
Release Date: 2025-09-22
[OSSTaskHandler, CloudwatchTaskHandler, S3TaskHandler, HdfsTaskHandler, ElasticsearchTaskHandler, GCSTaskHandler, OpensearchTaskHandler, RedisTaskHandler, WasbTaskHandler] supports log file size handling (#55455)
[OSSTaskHandler, CloudwatchTaskHandler, S3TaskHandler, HdfsTaskHandler, ElasticsearchTaskHandler, GCSTaskHandler, OpensearchTaskHandler, RedisTaskHandler, WasbTaskHandler] supports log file size handling (#55455)
Nothing published for this version
- AIP-82: Add RedisPubSubMessageQueueProvider
Release Date: 2025-09-09
AIP-82: Add RedisPubSubMessageQueueProvider (#53556)
Refactor Common Queue Interface (#54651)
AIP-82: Add RedisPubSubMessageQueueProvider (#53556)
Refactor Common Queue Interface (#54651)
Nothing published for this version
Nothing published for this version
- Add AwaitMessageTrigger for Redis PubSub
Release Date: 2025-08-02
Add AwaitMessageTrigger for Redis PubSub (#52917)
Resolve OOM When Reading Large Logs in Webserver (#49470)
Add Python 3.13 support for Airflow. (#46891)
Cleanup type ignores in redis provider where possible (#53272)
Remove type ignore across codebase after mypy upgrade (#53243)
Remove upper-binding for "python-requires" (#52980)
Temporarily switch to use >=,< pattern instead of '~=' (#52967)
Imported BaseHook from version_compat in Redis (#52789)
Add AwaitMessageTrigger for Redis PubSub (#52917)
Resolve OOM When Reading Large Logs in Webserver (#49470)
Add Python 3.13 support for Airflow. (#46891)
Cleanup type ignores in redis provider where possible (#53272)
Remove type ignore across codebase after mypy upgrade (#53243)
Remove upper-binding for "python-requires" (#52980)
Temporarily switch to use >=,< pattern instead of '~=' (#52967)
Imported BaseHook from version_compat in Redis (#52789)
Nothing published for this version
- Move 'BaseHook' implementation to task SDK
Release Date: 2025-07-06
Move 'BaseHook' implementation to task SDK (#51873)
Provider Migration: Update Redis for Airflow 3.0 compatibility (#52597)
Drop support for Python 3.9 (#52072)
Use BaseSensorOperator from task sdk in providers (#52296)
Move 'BaseHook' implementation to task SDK (#51873)
Provider Migration: Update Redis for Airflow 3.0 compatibility (#52597)
Drop support for Python 3.9 (#52072)
Use BaseSensorOperator from task sdk in providers (#52296)
Nothing published for this version
This release of provider is only available for Airflow 2.10+ as explained in the Apache Airflow providers support policy < https://github.com/apache/a
Release Date: 2025-05-18
Note
This release of provider is only available for Airflow 2.10+ as explained in the Apache Airflow providers support policy < https://github.com/apache/airflow/blob/main/PROVIDERS.rst#minimum-supported-version-of-airflow-for-community-managed-providers >_.
Fix: SQLExecuteQueryOperator does not pass extra_dejson values to hook_params (#49282)
Remove AIRFLOW_2_10_PLUS conditions (#49877)
Bump min Airflow version in providers to 2.10 (#49843)
Note
This release of provider is only available for Airflow 2.10+ as explained in the Apache Airflow providers support policy <https://github.com/apache/airflow/blob/main/PROVIDERS.rst#minimum-supported-version-of-airflow-for-community-managed-providers>_.
Fix: SQLExecuteQueryOperator does not pass extra_dejson values to hook_params (#49282)
Remove AIRFLOW_2_10_PLUS conditions (#49877)
Bump min Airflow version in providers to 2.10 (#49843)
Nothing published for this version
- Render structured logs in the new UI rather than showing raw JSON
Release Date: 2025-03-13
Render structured logs in the new UI rather than showing raw JSON (#46827)
Upgrade flit to 3.11.0 (#46938)
Render structured logs in the new UI rather than showing raw JSON (#46827)
Upgrade flit to 3.11.0 (#46938)
Nothing published for this version
- Add run_after column to DagRun model
Release Date: 2025-02-26
Add run_after column to DagRun model (#45732)
AIP-72: Support better type-hinting for Context dict in SDK (#45583)
Add run_after column to DagRun model (#45732)
AIP-72: Support better type-hinting for Context dict in SDK (#45583)
Nothing published for this version
All deprecated classes, parameters and features have been removed from the Redis provider package. The following breaking changes were introduced:
Release Date: 2024-12-26
Note
This release of provider is only available for Airflow 2.9+ as explained in the Apache Airflow providers support policy .
Warning
All deprecated classes, parameters and features have been removed from the Redis provider package. The following breaking changes were introduced:
Hooks
Removed ssl_cert_file parameter from RedisHook . Use ssl_certfile instead
Remove Provider Deprecations in Redis (#44633)
Bump minimum Airflow version in providers to Airflow 2.9.0 (#44956)
Update DAG example links in multiple providers documents (#44034)
Note
This release of provider is only available for Airflow 2.9+ as explained in the Apache Airflow providers support policy.
Warning
All deprecated classes, parameters and features have been removed from the Redis provider package. The following breaking changes were introduced:
Hooks
Removed ssl_cert_file parameter from RedisHook. Use ssl_certfile instead
Remove Provider Deprecations in Redis (#44633)
Bump minimum Airflow version in providers to Airflow 2.9.0 (#44956)
Update DAG example links in multiple providers documents (#44034)
Nothing published for this version
Nothing published for this version
This release of provider is only available for Airflow 2.8+ as explained in the Apache Airflow providers support policy .
Release Date: 2024-08-22
Note
This release of provider is only available for Airflow 2.8+ as explained in the Apache Airflow providers support policy .
Bump minimum Airflow version in providers to Airflow 2.8.0 (#41396)
Note
This release of provider is only available for Airflow 2.8+ as explained in the Apache Airflow providers support policy.
Bump minimum Airflow version in providers to Airflow 2.8.0 (#41396)
Nothing published for this version
- Faster 'airflow_version' imports
Release Date: 2024-05-30
Faster 'airflow_version' imports (#39552)
Simplify 'airflow_version' imports (#39497)
Faster 'airflow_version' imports (#39552)
Simplify 'airflow_version' imports (#39497)
Nothing published for this version
This release of provider is only available for Airflow 2.7+ as explained in the Apache Airflow providers support policy .
Release Date: 2024-05-06
Note
This release of provider is only available for Airflow 2.7+ as explained in the Apache Airflow providers support policy .
Bump minimum Airflow version in providers to Airflow 2.7.0 (#39240)
Nothing published for this version
Nothing published for this version
Release Date: 2024-04-13 ### Misc - Allow to use 'redis'>=5
Release Date: 2024-04-13
Allow to use 'redis'>=5 (#38385)
Nothing published for this version
- Add docs and UI form to redis connection
Release Date: 2024-01-10
Add docs and UI form to redis connection (#36581)
Add username authenticating to the Redis hook (#36562)
Fix misconfiguration of redis client with ssl (#36561)
Add docs and UI form to redis connection (#36581)
Add username authenticating to the Redis hook (#36562)
Fix misconfiguration of redis client with ssl (#36561)
Nothing published for this version
This release of provider is only available for Airflow 2.6+ as explained in the Apache Airflow providers support policy .
Release Date: 2023-12-12
Note
This release of provider is only available for Airflow 2.6+ as explained in the Apache Airflow providers support policy .
Bump minimum Airflow version in providers to Airflow 2.6.0 (#36017)
Nothing published for this version
- Add task context logging feature to allow forwarding messages to task logs
Release Date: 2023-11-29
Add task context logging feature to allow forwarding messages to task logs (#32646)
Add task context logging feature to allow forwarding messages to task logs (#32646)
Nothing published for this version
This release of provider is only available for Airflow 2.5+ as explained in the Apache Airflow providers support policy .
Release Date: 2023-10-17
Note
This release of provider is only available for Airflow 2.5+ as explained in the Apache Airflow providers support policy .
Bump min airflow version of providers (#34728)
Note
This release of provider is only available for Airflow 2.5+ as explained in the Apache Airflow providers support policy.
Bump min airflow version of providers (#34728)
Nothing published for this version
Fix resolution of deprecated imports in airflow.utils.helpers
Backfill endpoints no longer disclose which backfill ids exist across Dags
The four routes that name a backfill in their path -- GET /backfills/{backfill_id} and the pause, unpause and cancel routes -- resolved the Dag they authorize against from the dag_id supplied on the request whenever the path's id matched no row. An unknown id and a backfill on a Dag the caller cannot see therefore answered differently, which enumerates backfill ids across Dags.
The backfill named in the path is now the only thing those routes authorize against.
Behaviour changes:
Requesting a backfill on a Dag the caller cannot read now returns 404 (Backfill not found) -- the same response an unknown id gets -- instead of the 403 returned before. A caller who can read the Dag still gets 403 for a write they are not allowed to make.
A backfill_id in the path is never authorized against a dag_id in the request body or query string. GET /backfills, POST /backfills and POST /backfills/dry_run name no backfill in their path and keep authorizing off the request.
All four routes now answer an unknown id with the same detail, Backfill not found. The pause, unpause and cancel routes previously answered Could not find backfill with id {backfill_id}. Clients matching on detail must be updated. (#71113)
An explicit credential now takes precedence over the session cookie
get_user() is written to prefer an explicit bearer token, then OAuth2, then the session cookie, but that precedence was unreachable whenever a cookie was present. JWTRefreshMiddleware runs first, resolves a user from the _token cookie alone and stamps it on request.state, and get_user() returned that cached user before looking at either explicit credential. The effective order on every core-API route was cookie over bearer.
A request carrying both a session cookie and an explicit credential therefore executed, and was recorded in the audit log, as the cookie's principal rather than the identity the client presented. The cached user is now honoured only when the request carries no explicit credential.
Behaviour changes:
A request carrying both a _token cookie and an Authorization: Bearer header is now resolved as the bearer token's principal, where it was previously resolved as the cookie's. The same applies to a cookie combined with an OAuth2 token.
An invalid or expired explicit credential is now rejected with 401/403 even when a valid _token cookie accompanies it. Previously the cookie silently took over and the request succeeded as the cookie's principal; the failure is now loud.
Requests carrying a single credential are unaffected. Cookie-only browser sessions keep the token-refresh behaviour of JWTRefreshMiddleware unchanged.
Clients that relied on the cookie winning -- for example a browser-based tool that sent a service account's bearer token while a user session cookie was present, and expected the user's identity to apply -- will now act as the bearer token's principal. Remove the header, or the cookie, to select the intended identity explicitly. (#72225)
Optimize the previous-task-instance lookup by removing a redundant dag_run join (#72944)
Revoke every credential presented to the logout endpoint, not just the session cookie (#72933)
API: Return HTTP 404 instead of 500 when a task starts against a missing Dag run (#72900)
Fix airflow db clean never purging the callback table (#72899)
Fix the Dag version inflation check not warning about custom DAG subclasses or aliased-module imports (#72898)
Fix DeadlockImminentError when a connection is resolved inside an async task (#72895)
Fix dag processor crash when an orphaned processor is killed (#72888)
Prevent corruption of XCom values that already parse as JSON during the bytea-to-JSONB migration (#72886)
Fix HTTP 500 for non-dict JSON bodies on the Variable and Connection API endpoints (#72878)
Fix resolution of deprecated imports in airflow.utils.helpers (#72868)
Bound single-row lookups with LIMIT 1 to avoid scanning large tables (#72842)
UI: Fix clipping of the Last Run state badge (#72841)
UI: Fix Calendar view computing planned cron runs in UTC instead of the Dag's timezone (#72839)
Fix airflow info --file-io uploading an empty report (#72832)
Preserve custom operator defaults in mapped tasks (#72828)
Gate the asset event partition_key behind the 2026-06-30 Execution API version (#72827)
Improve deadline diagnostics for null DagRun fields (#72812)
Fix missing HTTP access logs when the api-server omits the core app (#72808)
Clarify when the auth manager is_authorized_hitl_task (Human-in-the-loop) hook runs (#72807)
Fix td_format rendering of negative durations (#72798)
UI: Make copied task log text match the on-screen format (#72771)
UI: Fix connection test with a null host and port (#72747)
Allow airflow jobs check --allow-multiple with --limit 0 (#72744)
UI: Keep task log selection stable while dragging (#72743)
UI: Restore counts on the Dag Run and Task Instance lists (#72739)
UI: Fix the Dags list Last Run / Next Run going stale after runs complete (#72735)
UI: Fix the first startup request being sent to an unset API base URL (#72733)
UI: Fix task instance links leading to 404s for tasks outside the run's date range (#72732)
UI: Fix the Human-in-the-loop form crashing on null values (#72731)
UI: Fix copying task logs dropping rows that scrolled out of view (#72729)
UI: Label Dag active runs accurately (#72722)
Bound single-row XCom existence lookups with LIMIT 1 to avoid full scans (#72702)
UI: Fix Firefox multi-line drag selection in the task log view (#72700)
Fix Dag scheduling stall after switching to a coarser cron (#72679)
Fix memray profiling capturing interpreter startup instead of the dag-processor job (#72661)
Prevent Dag-existence disclosure on the partitioned dag runs listing (#72660)
Fix mark-failed KeyError for removed-task task instances (#72620)
UI: Fix hierarchical_alphabetical sort order breaking the graph and grid (#72618)
Clarify @task-decorated callable errors when extra positional arguments are passed (#72616)
Load the correct Dag version when a task starts from a trigger (#72614)
Fix airflow db migrate failing under the PyMySQL driver when a schema migration drops unique constraints (#72613)
Stop airflow providers get --full mutating cached provider metadata (#72601)
Fix airflow connections test returning a success exit code on failure (#72583)
Stop airflow standalone leaking components when one fails to start (#72568)
Fix DAG.cli() crashing on dags pause and dags unpause (#72565)
Prevent Dag CLI subcommands from being silently dropped (#72365)
Respect the limit search param in the task overview duration chart (#72357)
UI: Show duration chart tooltips in the selected timezone (#72339)
Export AIRFLOW_TEST_MODE from airflow tasks test without --env-vars (#72320)
Authenticate only once per task process to external secrets backends (#72237)
Remove the unreachable 404 response from the create Variable API endpoint (#72190)
Speed up bulk updates of Variables and Pools by fixing an N+1 query (#72160)
UI: Fix a React plugin rendering a previously loaded plugin's component (#72136)
Fix Variable write-conflict checks comparing against the wrong team (#72125)
UI: Surface connection test errors instead of failing silently (#71963)
Fix the runtime-varying-value checker skipping tasks defined after a nested with block (#71956)
Speed up marking a Dag run failed when it has many mapped task instances (#71955)
UI: Include the JSON parse-error message in the Variable form warning (#71953)
UI: Allow file downloads from plugin external-view iframes (#71952)
UI: Make the grid run bar tooltip time zone aware (#71951)
Reduce memory used when deleting queued asset events (#71937)
UI: Activate assets materialized from an AssetAlias so they appear in the Assets tab (#71935)
Fix Variable.set rewriting the team_name of existing variables (#71904)
Reduce memory used when deleting a Dag with a large history (#71889)
UI: Show an empty object for object params with no value (#71876)
Fix Dag callbacks silently dropped when the version inflation check blocks parsing (#71865)
Return HTTP 404 from task state store endpoints for unknown task instances (#71860)
Fix deadline never firing after a non-deadline Dag edit (#71859)
Honor the API server Dag cache TTL when no size limit is set (#71845)
Require Dag edit permission to delete asset queued events (#71828)
Bound the scheduler's deserialized Dag cache to prevent unbounded memory growth (#71821)
Stop variables export/import from silently corrupting values (#71791)
UI: Fix datetime pickers unusable on Firefox and Safari (#71788)
Scope /assets/events to the Dags the caller may read (#71785)
Serve logs from the scheduler if any executor is LocalExecutor (#71781)
Fix cleared tasks getting stuck when a Dag run has no version (#71773)
Stop the dag processor warning on every file path normalized for stats (#71764)
UI: Fix the last section on the page not being clickable (#71755)
Fix deadline serialization, repr, and prune edge cases (#71726)
Dispatch the highest-priority tasks first in the executor (#71715)
Keep ZIP-archived Dags active when dag_discovery_safe_mode is False (#71714)
Honor FORWARDED_ALLOW_IPS when the API server runs under gunicorn (#71708)
Fix airflow config lint staying silent on conditional removal rules (#71651)
Avoid exhausting the DB connection pool when rendering the grid structure for large Dags (#71626)
Fix Task SDK IPC short reads crashing the subprocess or hanging the supervisor (#71609)
Fix one bad callback request crashing the Dag processor and dropping the rest (#71608)
Fix clearTaskInstances returning HTTP 500 instead of 422 on an invalid body (#71559)
Mark only a run's most recent asset event as triggering it (#71547)
Fix Variables API handling of non-string JSON values (#71526)
Include server error detail in Task SDK API error tracebacks (#71491)
Show each Dag only once in airflow dags list (#71481)
Keep Dag run Execution API endpoints working for older Task SDK clients (#71438)
UI: Fix Calendar view hanging for Dags with high-frequency cron schedules (#71435)
Require existing-connection read access when testing an existing connection (#71428)
UI: Fix Grid view failing to load large Dags on MySQL (#71370)
Catch general Exception when initializing a Dag bundle (#71363)
Fix deactivation of stale ZIP-packaged Dags (#71326)
Avoid scheduler crash when periodic maintenance actions fail (#71288)
Fix _team_name missing from DagRun passed to some listener calls (#71262)
Add async asset store accessors for async tasks and watcher triggers (#72851)
UI: Add Consuming Tasks, Aliases, and Watchers to the assets pages (#72780)
Improve confirmation output when connections are added via the CLI (#72779)
UI: Sync the browser URL with navigation inside iframe views (#72776)
Reduce Dag-processor log noise by logging a bundle that is not due for refresh at debug instead of info (#72749)
Allow deadline alert UUID references in the serialized Dag schema (#72738)
Add SerializedVariableInterval for deadline alerts (#72244)
Report Dag cache metrics under each component's own namespace (#71925)
Add a password field type to FlexibleForm (#71573)
Add BaseDeadlineReference and deadline_reference to the SDK public interface (#71208)
Update Catalan (ca) UI translations (#73026)
Fix a missing newline in the overview docs that prevented an image from rendering (#73013)
Document durable execution in the core concepts docs (#73012)
Clarify authentication and add an authorization example for plugin FastAPI apps (#72942)
Document that plugin FastAPI apps are not authenticated by Airflow (#72932)
Close German UI translation gaps (#72843)
Fix the Postgres tutorial for psycopg3 (#72837)
Document scope boundaries the security model leaves implicit (#72829)
Make the first tutorial example more explicit about Airflow syntax (#72805)
Add a create_async_metadata_engine example to the docs (#72804)
Add a systemd unit file for the Airflow Dag processor (#72797)
UI: Complete zh-CN Simplified Chinese translations (#72789)
Drop the extraneous "common" tag in i18n (#72781)
Add missing Russian UI translations (#72755)
Complete German UI translations (#72736)
UI: Complete Polish UI translations (#72624)
Record recurring non-issue shapes in the security model (#72617)
Complete Taiwanese Mandarin (zh-TW) UI translations (#72615)
UI: Translate durations and relative times in the selected language (#72334)
Remove the TaskFlow recommendation from the tutorial docs (#72118)
Split the task execution architecture docs into an overview and a dev guide (#71858)
Document service.name and service.instance.id for OpenTelemetry metrics (#71854)
UI: Improve French translation wording (#71846)
Complete French UI translations (#71790)
Improve Arabic UI translations (#71789)
Document HTTP statuses that API routes raise but never declared (#71622)
Recommend dag.test() for testing custom operators in the docs (#71587)
Release Date: 2023-09-12
Improve modules import in Airflow providers by some of them into a type-checking block (#33754)
Limit Redis dependencies to match celery limits (#33773)
Improve modules import in Airflow providers by some of them into a type-checking block (#33754)
Limit Redis dependencies to match celery limits (#33773)
Nothing published for this version
Fix npm vulnerabilities in the simple auth manager
📦 PyPI: https://pypi.org/project/apache-airflow/3.3.1/ 📚 Docs: https://airflow.apache.org/docs/apache-airflow/3.3.1/ 🛠 Release Notes: https://airflow.apache.org/docs/apache-airflow/3.3.1/release_notes.html 🐳 Docker Image: "docker pull apache/airflow:3.3.1" 🚏 Constraints: https://github.com/apache/airflow/tree/constraints-3.3.1
pandas 3 exposes its public classes from the pandas namespace, so a DataFrame is qualified as
pandas.DataFrame instead of pandas.core.frame.DataFrame. XComs record that name alongside the
serialized value, so the name written into the metadata database depends on the pandas version of the
component that pushed the value. Airflow registers both names, and a DataFrame written by either
pandas version can be read by either -- no configuration change is needed, and existing XComs stay
readable.
What you should do:
Roll this Airflow version out to every component before pandas 3 reaches any of them -- workers in particular. A component that predates this change cannot read a DataFrame XCom written under pandas 3, and fails the pull with:
.. code-block:: text
ImportError: pandas.DataFrame was not found in allow list for deserialization imports.
To allow it, add it to allowed_deserialization_classes in the configuration
The message points at configuration, but the allow list is not the cause and changing it does not help. The rows are not corrupt: they become readable again as soon as the reader is upgraded.
Treat a downgrade as a one-way door for those XComs. Rolling back to an Airflow version without this change strands any DataFrame XCom written while on pandas 3, with the same error, until you roll forward again.
Review Dags that inspect the dtypes of a pulled DataFrame. The pandas version of the reader
determines what a pulled DataFrame looks like, not the version that wrote it. Under pandas 3, a
column of strings comes back as str rather than object, and its missing values
come back as nan rather than None. Values are unchanged, but downstream code that branches
on dtype == "object", checks cells with is None, or compares against a reference frame with
DataFrame.equals() can behave differently after the upgrade.
The 0082_3_1_0_make_bundle_name_not_nullable migration assigned every legacy row
bundle_name='dags-folder', so triggering a DagRun raised Requested bundle 'dags-folder' is not configured. on any deployment that uses a bundle other than the default dags-folder.
DagFileProcessorManager now runs a one-shot, best-effort backfill at startup that routes each
affected Dag to the correct bundle based on its file path; unmatched Dags self-heal on the next
successful parse (or run airflow dags reserialize to force it immediately).
Configuration options are registered as sensitive under their base section, so until now only the
base spelling of an option was masked. A team scoped override -- set in a [<team>=<section>]
config file section, or through an AIRFLOW__<TEAM>___<SECTION>__<KEY> environment variable --
was not recognized as the same option and was returned in full.
Sensitivity is now decided after resolving the team scoped spelling back to the base option, so a team scoped value is masked exactly as the base value already was.
Behaviour changes:
AirflowConfigParser.as_dict(display_sensitive=False), GET /config,
GET /config/section/{section}/option/{option} and airflow config list now return
< hidden > for a team scoped value of an option registered as sensitive. Deployments that
read a team's real value through any of these will now receive the mask; use
display_sensitive=True where a real value is required and appropriate._cmd and _secret entries are replaced with < hidden > in place, rather
than being resolved into their value and removed as they are in a base section. Resolving them
is not supported for a team, so the command string or secret path is no longer shown either.display_sensitive=True continues to return real
values.TriggerDagRunOperator gets a 404 (#71083)deadline_reference decorator's no-parentheses form (#70966)bundle_name during upgrade from 2.x to 3.x (#70662)airflow partitions clear (#69547)json_logs is enabled (#70669)none_failed_min_one_success tasks in mapped task groups (#70318)on_failure_callback for heartbeat-timed-out retries (#69824)TaskFailedEvent, instead of always failing terminally (#71163)TaskInstance mark-success downstream default (#70143)update --option/--ignore-option never matching options (#70757)TypeError in airflow db shell when the database name is missing (#70752)-o commands so structured output stays machine-readable (#70747)Variable values stored as JSON lists (#71069)Variable/Connection updates (#71043)KubernetesPodOperator (#70756)structlog>=26.1.0 and croniter>=6.2.2 to fix memory leaks (#70749)dag and note missing from Dag-run state-change listener events (#70245)email_on_failure/email_on_retry task alerts silently ignoring a custom [email] email_backend and always routing through SmtpNotifier; an email_backend that cannot be imported now errors loudly instead of silently falling back to SMTP (#70129)Trigger Again showing empty config for the selected run (#70288)FanOutMapper and wait policies from airflow.partition_mappers (#69513)task.execute OpenTelemetry span around task execution (#69359)run_type tag to the dagrun.duration.failed metric (#70731)he) translations (#70566)ar) translations (#70510)pl) translation (#70507)el) translations (#70471)ResumableJobMixin an abstract base class (subclasses must implement its methods) (#70810)?) and clean up the graph/grid view (#69978)ResumableJobMixin (#70792)jwt_secret/_secret and LocalFilesystemBackend config support (#70730)logging_config_class contract and document REMOTE_TASK_LOG (#70592)AssetAlias usage (#71087)AssetPartitionDagRun provisional-run docstring (#70104)CronDataIntervalTimetable and DeltaDataIntervalTimetable (#70434)FanOutMapper docs (#69511)dev/README.md (#70107)fr) UI translations to 100% coverage (#70387)nl) translations (#70004)zh-CN) UI translations (#70417, #70418, #70419)zh-TW) translation gaps (#70195, #70379, #69707)ko) translations and backport from main (#70807, #70832)Release Date: 2023-08-09
Move redis subscribe to poke() method in Redis Sensor (#32984)
Fix oversubsription of Redis pubsub sensor (#33139)
Move redis subscribe to poke() method in Redis Sensor (#32984)
Fix oversubsription of Redis pubsub sensor (#33139)
Your coding agent can read these notes before it upgrades. Set up the MCP server →