backstage / backstage

Backstage is an open framework for building developer portals
https://backstage.io/
Apache License 2.0
26.73k stars 5.52k forks source link

backend-app-api: fix object meta null proto crash #24766

Closed Rugvip closed 2 weeks ago

Rugvip commented 2 weeks ago

Hey, I just made a Pull Request!

This is perhaps not a very likely crash when passing log meta manually, but if passing on log meta from a library this is a bit more likely. Objects with null prototypes are a common way to avoid prototype pollution vulnerabilities.

:heavy_check_mark: Checklist

backstage-goalie[bot] commented 2 weeks ago

Changed Packages

Package Name Package Path Changeset Bump Current Version
@backstage/backend-app-api packages/backend-app-api patch v0.7.3
github-actions[bot] commented 2 weeks ago

Thank you for contributing to Backstage! The changes in this pull request will be part of the 1.28.0 release, scheduled for Tue, 18 Jun 2024.

github-actions[bot] commented 2 weeks ago

Uffizzi Cluster pr-24766 was deleted.