Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): [release-1.3] Bump path-to-regexp to v0.1.12 to fix CVE-2024-52798 #2611

Merged

Conversation

kim-tsao
Copy link
Member

@kim-tsao kim-tsao commented Jan 9, 2025

Regen the dist-dynamic/yarn.lock files to update to Express v4.21.2 in order to bump path-to-regexp to v0.1.12

Fixes:
CVE-2024-52798
https://issues.redhat.com/browse/RHIDP-5179

@kim-tsao kim-tsao requested review from a team as code owners January 9, 2025 20:42
Copy link

changeset-bot bot commented Jan 9, 2025

🦋 Changeset detected

Latest commit: 1afa62b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 5 packages
Name Type
@janus-idp/backstage-plugin-bulk-import-backend Patch
@janus-idp/backstage-plugin-orchestrator-backend Patch
@janus-idp/backstage-plugin-matomo-backend Patch
@janus-idp/backstage-plugin-kiali-backend Patch
@janus-idp/backstage-plugin-ocm-backend Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@kim-tsao kim-tsao changed the title chore(deps): [release-1.3] Bump path-to-regexp to v0.1.12 to fix CVE-2024-45296 chore(deps): [release-1.3] Bump path-to-regexp to v0.1.12 to fix CVE-2024-52798 Jan 9, 2025
Copy link
Member

@JessicaJHee JessicaJHee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kim-tsao
Copy link
Member Author

I also see [email protected] in these plugins as well, I believe we need to bump them too?

* https://github.com/janus-idp/backstage-plugins/blob/f8615f08272419eac4e6127342a24620856707b1/plugins/bulk-import-backend/dist-dynamic/yarn.lock#L1032

* https://github.com/janus-idp/backstage-plugins/blob/f8615f08272419eac4e6127342a24620856707b1/plugins/feedback-backend/dist-dynamic/yarn.lock#L598

* https://github.com/janus-idp/backstage-plugins/blob/f8615f08272419eac4e6127342a24620856707b1/plugins/rbac-backend-module-test/dist-dynamic/yarn.lock#L4483

Thanks, I missed bulk import. Feedback was deprecated in 1.3. /rbac-backend-module-test is a just a test plugin

Copy link
Member

@yashoswalyo yashoswalyo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@mareklibra
Copy link
Contributor

lgtm (orchestrator)

@PatAKnight
Copy link
Member

lgtm (bulk import, ocm)

@openshift-ci openshift-ci bot added the lgtm label Jan 10, 2025
@openshift-merge-bot openshift-merge-bot bot merged commit e3665ac into janus-idp:release-1.3 Jan 10, 2025
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants