Skip to main content
No versions of Astronomer Certified (AC) are currently supported by Astronomer. Astronomer stopped releasing new versions of AC with the release of Apache Airflow 2.4. Astronomer recommends creating all new Deployments with Astro Runtime, as well as migrating existing Deployments from AC to Astro Runtime as soon as your organization is ready. See Migrate to Runtime and Runtime image architecture.
This page is the source of truth for any Common Vulnerabilities and Exposures (CVEs) identified within any of our supported Astronomer Certified images for Apache Airflow. You can find information about supported Astronomer Certified images in the following locations: Refer to Upgrade Apache Airflow on Astronomer for detailed guidelines on how to upgrade between Airflow versions on your Software instance.

Reporting Vulnerabilities and Security Concerns

Vulnerability reports for Astronomer Certified should be sent to security@astronomer.io. All security concerns, questions and requests should be directed here. When we receive a request, our dedicated security team will evaluate and validate it. If we confirm a vulnerability, we’ll allocate internal resources towards identifying and publishing a resolution in an updated image. The timeline within which vulnerabilities are addressed will depend on the severity level of the vulnerability and its impact. Once a resolution has been confirmed, we’ll release it in the next major, minor, or patch Astronomer Certified image and publish details to this page in the section below.
All other Airflow and product support requests should be directed to Astronomer’s Support Portal, where our team’s Airflow Engineers are ready to help.

Previously Announced Vulnerabilities

Apache Airflow Core

Astronomer Certified Docker images

This section lists security related updates/mitigations in the Astronomer Certified docker images.