chore(deps): [release-1.8] upgrade backstage packages to tar v7#4642
chore(deps): [release-1.8] upgrade backstage packages to tar v7#4642jonkoops wants to merge 2 commits intoredhat-developer:release-1.8from
Conversation
Upgrades @backstage/backend-defaults (0.12.0 -> 0.12.2), @backstage/plugin-scaffolder-backend (2.2.0 -> 2.2.2), and @backstage/plugin-scaffolder-node (0.11.0 -> 0.11.2) to address symlink path traversal in Scaffolder actions (GHSA-rq6q-wr2q-7pgp). Replaces the previous yarn patch-based mitigation with the official fix versions. Lockfile changes were applied using yarn-lockfile-surgeon to minimize transitive dependency impact.
Upgrades @backstage/backend-defaults (0.12.2 -> 0.12.3), @backstage/plugin-scaffolder-backend (2.2.2 -> 2.2.3), and @backstage/plugin-scaffolder-node (0.11.2 -> 0.11.3) to replace the deprecated tar v6 with tar v7. Backports backstage/backstage#33902.
Code Review by Qodo
1. Dynamic plugins still tar v6
|
|
The container image build workflow finished with status: |
|
Replacing with stacked PR |
Review Summary by QodoUpgrade Backstage packages to tar v7 and fix CVE-2026-24046
WalkthroughsDescription• Upgrade Backstage packages to tar v7 (replacing deprecated tar v6) • Fix CVE-2026-24046 symlink path traversal vulnerability in Scaffolder • Update @backstage/backend-defaults from 0.12.0 to 0.12.3 • Update @backstage/plugin-scaffolder-backend from 2.2.0 to 2.2.3 • Update @backstage/plugin-scaffolder-node from 0.11.0 to 0.11.3 Diagramflowchart LR
A["Backstage Packages v0.12.0/2.2.0"] -- "Upgrade to v0.12.3/2.2.3" --> B["tar v7 Support"]
A -- "Security Fix" --> C["CVE-2026-24046 Patched"]
B --> D["Multiple Package.json Files Updated"]
C --> D
File Changes1. packages/backend/package.json
|
Upgrades
@backstage/backend-defaults(0.12.2 -> 0.12.3),@backstage/plugin-scaffolder-backend(2.2.2 -> 2.2.3), and@backstage/plugin-scaffolder-node(0.11.2 -> 0.11.3) to replace the deprecatedtarv6 withtarv7.Backports backstage/backstage#32471 via backstage/backstage#33902.
Stacked on #4640.