Skip to content

Commit 6fac6d8

Browse files
committed
fix(deps): upgrade backstage packages to fix CVE-2026-24046
Upgrades @backstage/backend-defaults (0.12.0 -> 0.12.2), @backstage/plugin-scaffolder-backend (2.2.0 -> 2.2.2), and @backstage/plugin-scaffolder-node (0.11.0 -> 0.11.2) to address symlink path traversal in Scaffolder actions (GHSA-rq6q-wr2q-7pgp). Replaces the previous yarn patch-based mitigation with the official fix versions. Lockfile changes were applied using yarn-lockfile-surgeon to minimize transitive dependency impact.
1 parent ab9f8df commit 6fac6d8

14 files changed

Lines changed: 563 additions & 699 deletions

.yarn/patches/@backstage-backend-defaults-npm-0.12.0-ef8b4e5984.patch

Lines changed: 0 additions & 67 deletions
This file was deleted.

.yarn/patches/@backstage-plugin-scaffolder-backend-npm-2.2.0-487419bad1.patch

Lines changed: 0 additions & 82 deletions
This file was deleted.

.yarn/patches/@backstage-plugin-scaffolder-node-npm-0.11.0-2e81f51535.patch

Lines changed: 0 additions & 22 deletions
This file was deleted.

0 commit comments

Comments
 (0)