© 2025-2026 PySpect
Circular dependencies detected in the dependency tree: apache-airflow-providers-common-compat → apache-airflow, apache-airflow-providers-standard → apache-airflow, apache-airflow-providers-common-sql → apache-airflow, apache-airflow-providers-smtp → apache-airflow, apache-airflow-providers-common-io → apache-airflow, apache-airflow-core → apache-airflow-task-sdk. Hidden from the diagram below to keep it an acyclic graph.
| Package | Optional | Group |
|---|---|---|
| apache-airflow | true | all |
| apache-airflow-providers-amazon | true | ftp |
| openlineage-airflow | true | airflow |
Source: ClickPy
2 known vulnerabilitiesLatest: PYSEC-2026-238 — The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to `3.15.1` or later, which issues `PROT P` to encrypt the data channel. View all →