Skip to content

chore(deps): Reverts 4ba9992, cherry-picks CVE bumps from orchestrator/release-1.10 and bumps multer, js-yaml and compression - #5021

Open
alizard0 wants to merge 7 commits into
release-1.10/orchestratorfrom
axios-1181
Open

alizard0 wants to merge 7 commits into
release-1.10/orchestratorfrom
axios-1181

Conversation

@alizard0

@alizard0 alizard0 commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

This PR aims to bring the CVE bumps accidentally made against a deprecated branch orchestrator/release-1.10

I used the following commands:

$ git revert 4ba99928dcebefcda9b8234466dbd7eaa6b23e0b
$ git cherry-pick e3fc9663fac1963c51b157bd8d905572d0db58a4   
$ yarn up -R multer
$ yarn up -R js-yaml
$ yarn up -R compression
$ git cherry-pick ba03a1ad7ddb8a59861375fcbf424e9ee0cc08cd 
$ git cherry-pick cb2cbe5d06c5cda9142fc8ef265c63eba272c06e 

For more details about multer, js-yaml and compression -- #4848
swagger-ui-react was not bumped because the js-yaml under it was part of app-legacy (devDependency) -- Quick summary of #4848

Package Version CVEs
multer 2.2.0 → 2.4.0 CVE-2026-88932
compression 1.8.1 → 1.8.2 CVE-2026-87776
js-yaml 3.15.0 → 3.15.2, 4.3.0 → 4.3.2 CVE-2026-84375

Which issue(s) does this PR fix

multer:

compression:

js-yaml:

How to test changes / Special notes to the reviewer

multer (2.4.0), compression (1.8.2), urllib (4.9.1), isomorphic-git (1.42.0), undici (7.29.1), and vm2 (3.12.2) are fully patched on every installed path.

js-yaml is patched on published plugin production trees (4.3.2). The 3.15.0 → 3.15.2 bump is toolchain-only (@backstage/cli, @backstage/repo-tools, @changesets/cli, jest). qs (6.16.0) is patched on published plugin production trees. express@4.22.3 and body-parser@1.20.8 pin qs@~6.16.0. Prod paths include orchestrator-backend dependencies → express@4.22.3 → qs, and orchestrator / orchestrator-form-react dependencies → @backstage/core-components@0.18.8 → qs@6.16.0. webpack-dev-middleware@7.4.6 is patched on the 7.x line; every path is CLI toolchain (@backstage/cli or @janus-idp/cli).

yarn why -R js-yaml still shows leftover versions; they are dismissible:

  • 4.1.1 — workspace devDependencies @backstage/repo-tools@0.17.0 → @microsoft/api-documenter@7.28.8 (~4.1.0). Every api-documenter in ^7.28.1 declares ~4.1.0. DEV / dismissible.
  • 3.0.2 — orchestrator-common devDependencies js-yaml-cli@0.6.0 (~ 3.0.1). No newer js-yaml-cli exists. The runtime js-yaml on that package is ^4.1.0 → 4.3.2. DEV / dismissible.
  • 4.3.0 — app-legacy dependencies → @backstage/plugin-api-docs@0.13.5 → swagger-ui-react@5.32.11 (=4.3.0). swagger-ui-react@5.33.0 is inside ^5.27.1 and pins js-yaml@=4.3.2. A yarn up -R swagger-ui-react would clear it. SBOM-excluded (app-legacy) / dismissible. That bump is already on release-1.10/orchestrator via chore(deps): cherry-pick CVE bumps from orchestrator/release-1.10 #5016; this branch reverts it.

yarn why -R qs still shows a leftover version; it is dismissible:

  • 6.5.5 — still inside >= 2.2.5, < 6.16.0. app-legacy dependencies → @backstage-community/plugin-rbac@1.33.2 → @janus-idp/shared-react@2.14.0 → @kubernetes/client-node → request@2.88.2 (qs@~6.5.2). Every request in ^2.88.0 declares ~6.5.2, which cannot include 6.16.0. SBOM-excluded (app-legacy) / dismissible.

yarn why -R webpack-dev-middleware still shows a leftover version; it is dismissible:

  • 5.3.4 — NVD lists 5.3.4 as affected; 7.4.6 is the patched 7.x release, and no 5.x newer than 5.3.4 is published. orchestrator-backend devDependencies → @janus-idp/cli@3.7.0 → webpack-dev-server@4.15.2 (webpack-dev-middleware@^5.3.4). That range cannot include 7.4.6. DEV / dismissible.

vm2 (3.12.2) prod path: orchestrator-backend dependencies → @backstage/backend-defaults@0.16.0 → @backstage/config-loader@1.10.9 → typescript-json-schema@0.67.1 (^3.10.0) → vm2. CLI and @backstage/repo-tools paths are toolchain only.

Plugin dependencies of axios@^1.15.0 (orchestrator-common, orchestrator, scaffolder-backend-module-orchestrator) resolve to 1.18.1.

In rhdh-plugins, app, app-legacy, and backend are SBOM-excluded.

…-middleware (#4704)

* partially bump webpack-dev-middleware to 7.4.6

* partially bump qs to 6.16.0

* bump undici to 7.29.1

* bump isomorphic-git to 1.42.0

* bump urllib to 4.9.1

* run yarn dedupe
…r to bring qs to v6.16.0 (#4883)

* bump express and body-parser to bring qs to v6.16.0

* run yarn dedupe
@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 2 lines in your changes missing coverage. Please review.
⚠️ Please upload report for BASE (release-1.10/orchestrator@95fe7d5). Learn more about missing BASE report.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@                     Coverage Diff                      @@
##             release-1.10/orchestrator    #5021   +/-   ##
============================================================
  Coverage                             ?   59.57%           
============================================================
  Files                                ?     2097           
  Lines                                ?    65234           
  Branches                             ?    16986           
============================================================
  Hits                                 ?    38862           
  Misses                               ?    25977           
  Partials                             ?      395           
Flag Coverage Δ *Carryforward flag
adoption-insights 83.58% <ø> (?) Carriedforward from 18023a1
ai-integrations 70.03% <ø> (?) Carriedforward from 18023a1
app-defaults 69.60% <ø> (?) Carriedforward from 18023a1
augment 69.36% <ø> (?) Carriedforward from 18023a1
bulk-import 72.86% <ø> (?) Carriedforward from 18023a1
cost-management 16.49% <ø> (?) Carriedforward from 18023a1
dcm 32.85% <ø> (?) Carriedforward from 18023a1
extensions 61.79% <ø> (?) Carriedforward from 18023a1
global-floating-action-button 74.30% <ø> (?) Carriedforward from 18023a1
global-header 61.68% <ø> (?) Carriedforward from 18023a1
homepage 50.95% <ø> (?) Carriedforward from 18023a1
konflux 91.01% <ø> (?) Carriedforward from 18023a1
lightspeed 68.34% <ø> (?) Carriedforward from 18023a1
mcp-integrations 81.59% <ø> (?) Carriedforward from 18023a1
orchestrator 37.54% <0.00%> (?)
quickstart 62.64% <ø> (?) Carriedforward from 18023a1
sandbox 79.56% <ø> (?) Carriedforward from 18023a1
scorecard 83.58% <ø> (?) Carriedforward from 18023a1
theme 64.54% <ø> (?) Carriedforward from 18023a1
translations 8.49% <ø> (?) Carriedforward from 18023a1
x2a 57.33% <ø> (?) Carriedforward from 18023a1

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 95fe7d5...e81e7c6. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant