Skip to content

chore(deps): [release-1.9] upgrade backstage packages to tar v7#4644

Draft
jonkoops wants to merge 2 commits intoredhat-developer:release-1.9from
jonkoops:tar-v7-1.9
Draft

chore(deps): [release-1.9] upgrade backstage packages to tar v7#4644
jonkoops wants to merge 2 commits intoredhat-developer:release-1.9from
jonkoops:tar-v7-1.9

Conversation

@jonkoops
Copy link
Copy Markdown
Contributor

Upgrades @backstage/backend-defaults (0.13.2 -> 0.13.3) and @backstage/plugin-scaffolder-backend (3.0.2 -> 3.0.3) to replace the deprecated tar v6 with tar v7.

Backports backstage/backstage#32471 via backstage/backstage#33904.

Depends on #4641.

Upgrades @backstage/backend-defaults (0.13.1 -> 0.13.2) and
@backstage/plugin-scaffolder-node (0.12.1 -> 0.12.3) to address
symlink path traversal in Scaffolder actions (GHSA-rq6q-wr2q-7pgp).

Also removes the redundant patch for @backstage/plugin-scaffolder-backend
3.0.2, which is already the official fix version.

Replaces the previous yarn patch-based mitigation with the official
fix versions. Lockfile changes were applied using yarn-lockfile-surgeon
to minimize transitive dependency impact.
Upgrades @backstage/backend-defaults (0.13.2 -> 0.13.3) and
@backstage/plugin-scaffolder-backend (3.0.2 -> 3.0.3) to replace
the deprecated tar v6 with tar v7.

Backports backstage/backstage#32471 via backstage/backstage#33904.
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented Apr 20, 2026

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@sonarqubecloud
Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
1 Security Hotspot
D Reliability Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@github-actions
Copy link
Copy Markdown
Contributor

This PR is stale because it has been open 7 days with no activity. Remove stale label or comment or this will be closed in 21 days.

@github-actions github-actions Bot added the Stale label Apr 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant