Skip to content

chore: release-1.9: update underscore and node-forge to fix CVEs#4634

Merged
openshift-merge-bot[bot] merged 1 commit intoredhat-developer:release-1.9from
kim-tsao:release-1.9-underscore_node-forge
Apr 20, 2026
Merged

chore: release-1.9: update underscore and node-forge to fix CVEs#4634
openshift-merge-bot[bot] merged 1 commit intoredhat-developer:release-1.9from
kim-tsao:release-1.9-underscore_node-forge

Conversation

@kim-tsao
Copy link
Copy Markdown
Member

Description

Please explain the changes you made here.

  • Ran yarn up -R underscore/node-forge to update the packages
  • Could not update the underscore transitive dependency of @backstage/cli but it's ok because the cli is a dev dependency.

Which issue(s) does this PR fix

RHDHBUGS-2973
RHIDP-13184

PR acceptance criteria

Please make sure that the following steps are complete:

  • GitHub Actions are completed and successful
  • Unit Tests are updated and passing
  • E2E Tests are updated and passing
  • Documentation is updated if necessary (requirement for new features)
  • Add a screenshot if the change is UX/UI related

How to test changes / Special notes to the reviewer

Signed-off-by: Kim Tsao <ktsao@redhat.com>
@sonarqubecloud
Copy link
Copy Markdown

@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@kim-tsao
Copy link
Copy Markdown
Member Author

/test e2e-ocp-helm

Copy link
Copy Markdown
Member

@JessicaJHee JessicaJHee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

edit: missed comment above:

Could not update the underscore transitive dependency of @backstage/cli but it's ok because the cli is a dev dependency.

Looks like there's still 1.13.6 present for underscore which is vulnerable

Copy link
Copy Markdown
Member

@JessicaJHee JessicaJHee left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm label Apr 20, 2026
@openshift-merge-bot openshift-merge-bot Bot merged commit d636699 into redhat-developer:release-1.9 Apr 20, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants