janus-idp / backstage-plugins

Plugins for Backstage
https://janus-idp.io
Apache License 2.0
145 stars 146 forks source link

chore(deps): update yarn.lock to resolve CVE-2024-35255 #1844

Closed kim-tsao closed 2 months ago

kim-tsao commented 3 months ago

update yarn.lock to resolve CVE-2024-35255 Fixes RHIDP-2735

openshift-ci[bot] commented 3 months ago

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Once this PR has been reviewed and has the lgtm label, please ask for approval from kim-tsao. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files: - **[OWNERS](https://github.com/janus-idp/backstage-plugins/blob/main/OWNERS)** Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
kim-tsao commented 3 months ago

Added dependabot rule to filter out findings from root yarn.lock which is not used in RHDH

kim-tsao commented 3 months ago

Re-opening, as discussed with @Zaperex it would be good to keep the root yarn.lock up to date

kim-tsao commented 3 months ago

/retest

kim-tsao commented 3 months ago

/retest

openshift-merge-robot commented 2 months ago

PR needs rebase.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes-sigs/prow](https://github.com/kubernetes-sigs/prow/issues/new?title=Prow%20issue:) repository.
nickboldt commented 2 months ago

Closing as Kim has said:

those were moderate findings. Plugins [update] is not important because it was a root yarn.lock update done to keep dependencies in sync we put a no_backport label and FixVersion=1.3 on it https://issues.redhat.com/browse/RHIDP-2735