chore(deps): bump jsonata to 2.2.2 using yarn up - #5018
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## release-1.10/orchestrator #5018 +/- ##
============================================================
Coverage ? 59.57%
============================================================
Files ? 2097
Lines ? 65234
Branches ? 17001
============================================================
Hits ? 38862
Misses ? 25980
Partials ? 392
*This pull request uses carry forward flags. Click here to find out more. Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
|
JessicaJHee
left a comment
There was a problem hiding this comment.
/lgtm
✅ Verified target branch
- Base is
release-1.10/orchestrator(active naming; not deprecatedorchestrator/release-1.10)
✅ Verified packages have been updated to the patched versions or beyond
- Claimed full fixes in orchestrator match advisories (
yarn whyinworkspaces/orchestrator/)
✅ Verified lockfile (workspaces/orchestrator/yarn.lock):
- Minimal expected updates only
- Single resolved version of patched packages after dedupe (if a full fix is expected)
- No dependency version downgrades
- No unexpected
@backstage/*bumps



Description
Bumps transitive dependencies to address CVEs for RHDH 1.10.5.
Fixed with
yarn up -R jsonatainworkspaces/orchestrator. The manifest range stays^2.0.6; the lockfile resolution moves to2.2.2.Which issue(s) does this PR fix
jsonata:How to test changes / Special notes to the reviewer
jsonata(2.2.2) is fully patched on every installed path. It is a production dependency ofplugins/orchestrator-form-widgets(dependencies.jsonata^2.0.6).2.2.2is above the GHSA floors (2.2.1for CVE-2026-77414 and CVE-2026-77415,2.2.0for CVE-2026-77413).In rhdh-plugins,
app,app-legacy, andbackendare SBOM-excluded.