Skip to content

chore(deps): bump jsonata to 2.2.2 using yarn up - #5018

Merged
alizard0 merged 2 commits into
release-1.10/orchestratorfrom
r11005-jsonata
Sep 28, 2026
Merged

alizard0 merged 2 commits into
release-1.10/orchestratorfrom
r11005-jsonata

Conversation

@alizard0

Copy link
Copy Markdown
Member

Description

Bumps transitive dependencies to address CVEs for RHDH 1.10.5.

Package Version CVEs Scope
jsonata 2.0.6 → 2.2.2 CVE-2026-77414, CVE-2026-77413, CVE-2026-77415 dependency

Fixed with yarn up -R jsonata in workspaces/orchestrator. The manifest range stays ^2.0.6; the lockfile resolution moves to 2.2.2.

Which issue(s) does this PR fix

jsonata:

  • Fixes RHIDP-17282
  • Fixes RHIDP-17281
  • Fixes RHIDP-17279
  • Fixes RHIDP-17277

How to test changes / Special notes to the reviewer

jsonata (2.2.2) is fully patched on every installed path. It is a production dependency of plugins/orchestrator-form-widgets (dependencies.jsonata ^2.0.6). 2.2.2 is above the GHSA floors (2.2.1 for CVE-2026-77414 and CVE-2026-77415, 2.2.0 for CVE-2026-77413).

In rhdh-plugins, app, app-legacy, and backend are SBOM-excluded.

@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (release-1.10/orchestrator@4ba9992). Learn more about missing BASE report.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@                     Coverage Diff                      @@
##             release-1.10/orchestrator    #5018   +/-   ##
============================================================
  Coverage                             ?   59.57%           
============================================================
  Files                                ?     2097           
  Lines                                ?    65234           
  Branches                             ?    17001           
============================================================
  Hits                                 ?    38862           
  Misses                               ?    25980           
  Partials                             ?      392           
Flag Coverage Δ *Carryforward flag
adoption-insights 83.58% <ø> (?) Carriedforward from 6c374b0
ai-integrations 70.03% <ø> (?) Carriedforward from 6c374b0
app-defaults 69.60% <ø> (?) Carriedforward from 6c374b0
augment 69.36% <ø> (?) Carriedforward from 6c374b0
bulk-import 72.86% <ø> (?) Carriedforward from 6c374b0
cost-management 16.49% <ø> (?) Carriedforward from 6c374b0
dcm 32.85% <ø> (?) Carriedforward from 6c374b0
extensions 61.79% <ø> (?) Carriedforward from 6c374b0
global-floating-action-button 74.30% <ø> (?) Carriedforward from 6c374b0
global-header 61.68% <ø> (?) Carriedforward from 6c374b0
homepage 50.95% <ø> (?) Carriedforward from 6c374b0
konflux 91.01% <ø> (?) Carriedforward from 6c374b0
lightspeed 68.34% <ø> (?) Carriedforward from 6c374b0
mcp-integrations 81.59% <ø> (?) Carriedforward from 6c374b0
orchestrator 37.54% <ø> (?)
quickstart 62.64% <ø> (?) Carriedforward from 6c374b0
sandbox 79.56% <ø> (?) Carriedforward from 6c374b0
scorecard 83.58% <ø> (?) Carriedforward from 6c374b0
theme 64.54% <ø> (?) Carriedforward from 6c374b0
translations 8.49% <ø> (?) Carriedforward from 6c374b0
x2a 57.33% <ø> (?) Carriedforward from 6c374b0

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 4ba9992...8b54a16. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sonarqubecloud

Copy link
Copy Markdown

@JessicaJHee JessicaJHee left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

✅ Verified target branch

  • Base is release-1.10/orchestrator (active naming; not deprecated orchestrator/release-1.10)

✅ Verified packages have been updated to the patched versions or beyond

  • Claimed full fixes in orchestrator match advisories (yarn why in workspaces/orchestrator/)

✅ Verified lockfile (workspaces/orchestrator/yarn.lock):

  • Minimal expected updates only
  • Single resolved version of patched packages after dedupe (if a full fix is expected)
  • No dependency version downgrades
  • No unexpected @backstage/* bumps

@openshift-ci openshift-ci Bot added the lgtm label Sep 28, 2026
@alizard0
alizard0 merged commit 95fe7d5 into release-1.10/orchestrator Sep 28, 2026
85 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants