Skip to content

chore(deps): cherry-pick CVE bumps from lightspeed/release-1.10 - #5017

Merged
alizard0 merged 4 commits into
release-1.10/lightspeedfrom
r11005-lightspeed-migrate
Sep 28, 2026
Merged

alizard0 merged 4 commits into
release-1.10/lightspeedfrom
r11005-lightspeed-migrate

Conversation

@alizard0

@alizard0 alizard0 commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

This PR aims to bring the CVE bumps accidentally made against a deprecated branch lightspeed/release-1.10

I used the following commands:

$ git cherry-pick bbe97a43ae4fd85ff33a1b8066b5ecb39ca90092   
$ git cherry-pick 67cf4143a3218ea75900a1e4e468d34808707621  
# conflicts, accepted the incoming
$ yarn install
$ git add workspaces/lightspeed/yarn.lock
$ git cherry-pick --continue
$ git cherry-pick ae481a8c64889778178212b11fc0d78a5e824aca 
$ git cherry-pick 52e38136a5342747649ffae216acd12945bf6173 

@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (release-1.10/lightspeed@57c2d79). Learn more about missing BASE report.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@                    Coverage Diff                     @@
##             release-1.10/lightspeed    #5017   +/-   ##
==========================================================
  Coverage                           ?   60.96%           
==========================================================
  Files                              ?     2098           
  Lines                              ?    65167           
  Branches                           ?    16940           
==========================================================
  Hits                               ?    39726           
  Misses                             ?    25219           
  Partials                           ?      222           
Flag Coverage Δ *Carryforward flag
adoption-insights 83.58% <ø> (?) Carriedforward from 230b90c
ai-integrations 70.03% <ø> (?) Carriedforward from 230b90c
app-defaults 69.60% <ø> (?) Carriedforward from 230b90c
augment 69.36% <ø> (?) Carriedforward from 230b90c
bulk-import 72.86% <ø> (?) Carriedforward from 230b90c
cost-management 16.49% <ø> (?) Carriedforward from 230b90c
dcm 32.85% <ø> (?) Carriedforward from 230b90c
extensions 61.79% <ø> (?) Carriedforward from 230b90c
global-floating-action-button 74.30% <ø> (?) Carriedforward from 230b90c
global-header 61.68% <ø> (?) Carriedforward from 230b90c
homepage 50.95% <ø> (?) Carriedforward from 230b90c
konflux 91.01% <ø> (?) Carriedforward from 230b90c
lightspeed 68.13% <ø> (?)
mcp-integrations 81.59% <ø> (?) Carriedforward from 230b90c
orchestrator 36.36% <ø> (?) Carriedforward from 230b90c
quickstart 62.88% <ø> (?) Carriedforward from 230b90c
sandbox 79.56% <ø> (?) Carriedforward from 230b90c
scorecard 83.58% <ø> (?) Carriedforward from 230b90c
theme 64.54% <ø> (?) Carriedforward from 230b90c
translations 8.49% <ø> (?) Carriedforward from 230b90c
x2a 78.28% <ø> (?) Carriedforward from 230b90c

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 57c2d79...931b37c. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

…middleware (#4705)

* bump nanoid to 3.3.19

* bump webpack-dev-middleware to 7.4.6

* partial bump dompurify to 3.4.15

* partially bump qs to 6.16.0

* bump undici to 7.29.1

* bump urllib to 4.9.1

* run yarn dedupe
* bump js-yaml to 4.3.2 and 3.15.2 using yarn up

* bump multer to 2.4.0 using yarn up

* bump compression to 1.8.2 using yarn up

* bump swagger-ui-react to 5.33.0 which will bring js-yaml to 4.3.2 - using yarn up

* run yarn dedupe
@alizard0
alizard0 force-pushed the r11005-lightspeed-migrate branch from a637c90 to 931b37c Compare September 28, 2026 14:17
@sonarqubecloud

Copy link
Copy Markdown

@JessicaJHee JessicaJHee left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

✅ Verified target branch

  • Base is release-1.10/lightspeed (active naming; not deprecated lightspeed/release-1.10)

✅ Verified packages have been updated to the patched versions or beyond

  • Claimed full fixes in lightspeed match advisories for published plugin paths (yarn why / lockfile in workspaces/lightspeed/)

✅ Verified lockfile (workspaces/lightspeed/yarn.lock):

  • Cherry-picked CVE bumps from the deprecated twin; no unexpected @backstage/* bumps
  • No dependency version downgrades
  • Leftovers are local-dev only (plugins-package-impact): isomorphic-git@1.27.1 = RUNNER (packages/backend → scaffolder); js-yaml@4.1.1 = @microsoft/api-documenter tooling while PLUGIN_PROD resolves 4.3.2

@JessicaJHee JessicaJHee changed the title chre(deps): cherry-pick CVE bumps from lightspeed/release-1.10 chore(deps): cherry-pick CVE bumps from lightspeed/release-1.10 Sep 28, 2026
@openshift-ci openshift-ci Bot added the lgtm label Sep 28, 2026
@alizard0
alizard0 merged commit d7d7a35 into release-1.10/lightspeed Sep 28, 2026
85 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants