Conversation
…-middleware (#4704) * partially bump webpack-dev-middleware to 7.4.6 * partially bump qs to 6.16.0 * bump undici to 7.29.1 * bump isomorphic-git to 1.42.0 * bump urllib to 4.9.1 * run yarn dedupe
…r to bring qs to v6.16.0 (#4883) * bump express and body-parser to bring qs to v6.16.0 * run yarn dedupe
alizard0
requested review from
a team,
christoph-jerolimov,
karthikjeeyar,
lholmquist and
lokanandaprabhu
as code owners
September 28, 2026 20:09
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## release-1.10/orchestrator #5021 +/- ##
============================================================
Coverage ? 59.57%
============================================================
Files ? 2097
Lines ? 65234
Branches ? 16986
============================================================
Hits ? 38862
Misses ? 25977
Partials ? 395
*This pull request uses carry forward flags. Click here to find out more. Continue to review full report in Codecov by Harness.
🚀 New features to boost your workflow:
|
|
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR aims to bring the CVE bumps accidentally made against a deprecated branch orchestrator/release-1.10
I used the following commands:
For more details about multer, js-yaml and compression -- #4848
swagger-ui-react was not bumped because the js-yaml under it was part of app-legacy (devDependency) -- Quick summary of #4848
multercompressionjs-yamlWhich issue(s) does this PR fix
multer:compression:js-yaml:How to test changes / Special notes to the reviewer
multer(2.4.0),compression(1.8.2),urllib(4.9.1),isomorphic-git(1.42.0),undici(7.29.1), andvm2(3.12.2) are fully patched on every installed path.js-yamlis patched on published plugin production trees (4.3.2). The3.15.0 → 3.15.2bump is toolchain-only (@backstage/cli,@backstage/repo-tools,@changesets/cli,jest).qs(6.16.0) is patched on published plugin production trees.express@4.22.3andbody-parser@1.20.8pinqs@~6.16.0. Prod paths includeorchestrator-backenddependencies→express@4.22.3→qs, andorchestrator/orchestrator-form-reactdependencies→@backstage/core-components@0.18.8→qs@6.16.0.webpack-dev-middleware@7.4.6is patched on the 7.x line; every path is CLI toolchain (@backstage/clior@janus-idp/cli).yarn why -R js-yamlstill shows leftover versions; they are dismissible:4.1.1— workspacedevDependencies@backstage/repo-tools@0.17.0→@microsoft/api-documenter@7.28.8(~4.1.0). Everyapi-documenterin^7.28.1declares~4.1.0. DEV / dismissible.3.0.2—orchestrator-commondevDependenciesjs-yaml-cli@0.6.0(~ 3.0.1). No newerjs-yaml-cliexists. The runtimejs-yamlon that package is^4.1.0→4.3.2. DEV / dismissible.4.3.0—app-legacydependencies→@backstage/plugin-api-docs@0.13.5→swagger-ui-react@5.32.11(=4.3.0).swagger-ui-react@5.33.0is inside^5.27.1and pinsjs-yaml@=4.3.2. Ayarn up -R swagger-ui-reactwould clear it. SBOM-excluded (app-legacy) / dismissible. That bump is already onrelease-1.10/orchestratorvia chore(deps): cherry-pick CVE bumps from orchestrator/release-1.10 #5016; this branch reverts it.yarn why -R qsstill shows a leftover version; it is dismissible:6.5.5— still inside>= 2.2.5, < 6.16.0.app-legacydependencies→@backstage-community/plugin-rbac@1.33.2→@janus-idp/shared-react@2.14.0→@kubernetes/client-node→request@2.88.2(qs@~6.5.2). Everyrequestin^2.88.0declares~6.5.2, which cannot include6.16.0. SBOM-excluded (app-legacy) / dismissible.yarn why -R webpack-dev-middlewarestill shows a leftover version; it is dismissible:5.3.4— NVD lists5.3.4as affected;7.4.6is the patched 7.x release, and no5.xnewer than5.3.4is published.orchestrator-backenddevDependencies→@janus-idp/cli@3.7.0→webpack-dev-server@4.15.2(webpack-dev-middleware@^5.3.4). That range cannot include7.4.6. DEV / dismissible.vm2(3.12.2) prod path:orchestrator-backenddependencies→@backstage/backend-defaults@0.16.0→@backstage/config-loader@1.10.9→typescript-json-schema@0.67.1(^3.10.0) →vm2. CLI and@backstage/repo-toolspaths are toolchain only.Plugin
dependenciesofaxios@^1.15.0(orchestrator-common,orchestrator,scaffolder-backend-module-orchestrator) resolve to1.18.1.In rhdh-plugins,
app,app-legacy, andbackendare SBOM-excluded.