chore(deps): cherry-pick CVE bumps from lightspeed/release-1.10 - #5017
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-1.10/lightspeed #5017 +/- ##
==========================================================
Coverage ? 60.96%
==========================================================
Files ? 2098
Lines ? 65167
Branches ? 16940
==========================================================
Hits ? 39726
Misses ? 25219
Partials ? 222
*This pull request uses carry forward flags. Click here to find out more. Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
…middleware (#4705) * bump nanoid to 3.3.19 * bump webpack-dev-middleware to 7.4.6 * partial bump dompurify to 3.4.15 * partially bump qs to 6.16.0 * bump undici to 7.29.1 * bump urllib to 4.9.1 * run yarn dedupe
* bump js-yaml to 4.3.2 and 3.15.2 using yarn up * bump multer to 2.4.0 using yarn up * bump compression to 1.8.2 using yarn up * bump swagger-ui-react to 5.33.0 which will bring js-yaml to 4.3.2 - using yarn up * run yarn dedupe
a637c90 to
931b37c
Compare
|
JessicaJHee
left a comment
There was a problem hiding this comment.
/lgtm
✅ Verified target branch
- Base is
release-1.10/lightspeed(active naming; not deprecatedlightspeed/release-1.10)
✅ Verified packages have been updated to the patched versions or beyond
- Claimed full fixes in lightspeed match advisories for published plugin paths (
yarn why/ lockfile inworkspaces/lightspeed/)
✅ Verified lockfile (workspaces/lightspeed/yarn.lock):
- Cherry-picked CVE bumps from the deprecated twin; no unexpected
@backstage/*bumps - No dependency version downgrades
- Leftovers are local-dev only (plugins-package-impact):
isomorphic-git@1.27.1= RUNNER (packages/backend→ scaffolder);js-yaml@4.1.1=@microsoft/api-documentertooling while PLUGIN_PROD resolves4.3.2



This PR aims to bring the CVE bumps accidentally made against a deprecated branch
lightspeed/release-1.10I used the following commands:
$ git cherry-pick bbe97a43ae4fd85ff33a1b8066b5ecb39ca90092 $ git cherry-pick 67cf4143a3218ea75900a1e4e468d34808707621 # conflicts, accepted the incoming $ yarn install $ git add workspaces/lightspeed/yarn.lock $ git cherry-pick --continue $ git cherry-pick ae481a8c64889778178212b11fc0d78a5e824aca $ git cherry-pick 52e38136a5342747649ffae216acd12945bf6173