Skip to content

chore(deps): bump vm2 to 3.12.2 - #4886

Open
alizard0 wants to merge 1 commit into
orchestrator/release-1.10from
r1105-vm2-orchestrator
Open

alizard0 wants to merge 1 commit into
orchestrator/release-1.10from
r1105-vm2-orchestrator

Conversation

@alizard0

Copy link
Copy Markdown
Member

Description

Bumps transitive dependencies to address CVEs for RHDH 1.10.5.

Package Version CVEs Scope
vm2 3.11.5 → 3.12.2 CVE-2026-92942, CVE-2026-92958, CVE-2026-92959, CVE-2026-92961, CVE-2026-47683 dependency

Fixed with yarn up vm2 in workspaces/orchestrator (vm2@npm:^3.10.0 now resolves to 3.12.2).

Which issue(s) does this PR fix

vm2:

  • Fixes RHIDP-17012
  • Fixes RHIDP-17009
  • Fixes RHIDP-17004
  • Fixes RHIDP-17002
  • Fixes RHIDP-17021
  • Fixes RHIDP-17018

How to test changes / Special notes to the reviewer

vm2 (3.12.2) is fully patched on every installed path.

The published plugin production path is orchestrator-backend dependencies@backstage/backend-defaults@0.16.0@backstage/config-loader@1.10.9typescript-json-schema@0.67.1 (^3.10.0) → vm2@3.12.2. CLI / test paths (@backstage/cli, @janus-idp/cli, @backstage/repo-tools, @backstage/backend-test-utils) are toolchain only. Scope is dependency because a prod path exists.

In rhdh-plugins, app, app-legacy, and backend are SBOM-excluded.

@codecov

codecov Bot commented Sep 20, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (orchestrator/release-1.10@ba03a1a). Learn more about missing BASE report.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@                     Coverage Diff                      @@
##             orchestrator/release-1.10    #4886   +/-   ##
============================================================
  Coverage                             ?   59.57%           
============================================================
  Files                                ?     2097           
  Lines                                ?    65234           
  Branches                             ?    17001           
============================================================
  Hits                                 ?    38862           
  Misses                               ?    25977           
  Partials                             ?      395           
Flag Coverage Δ *Carryforward flag
adoption-insights 83.58% <ø> (?) Carriedforward from 0f6f9df
ai-integrations 70.03% <ø> (?) Carriedforward from 0f6f9df
app-defaults 69.60% <ø> (?) Carriedforward from 0f6f9df
augment 69.36% <ø> (?) Carriedforward from 0f6f9df
bulk-import 72.86% <ø> (?) Carriedforward from 0f6f9df
cost-management 16.49% <ø> (?) Carriedforward from 0f6f9df
dcm 32.85% <ø> (?) Carriedforward from 0f6f9df
extensions 61.79% <ø> (?) Carriedforward from 0f6f9df
global-floating-action-button 74.30% <ø> (?) Carriedforward from 0f6f9df
global-header 61.68% <ø> (?) Carriedforward from 0f6f9df
homepage 50.95% <ø> (?) Carriedforward from 0f6f9df
konflux 91.01% <ø> (?) Carriedforward from 0f6f9df
lightspeed 68.34% <ø> (?) Carriedforward from 0f6f9df
mcp-integrations 81.59% <ø> (?) Carriedforward from 0f6f9df
orchestrator 37.54% <ø> (?)
quickstart 62.64% <ø> (?) Carriedforward from 0f6f9df
sandbox 79.56% <ø> (?) Carriedforward from 0f6f9df
scorecard 83.58% <ø> (?) Carriedforward from 0f6f9df
theme 64.54% <ø> (?) Carriedforward from 0f6f9df
translations 8.49% <ø> (?) Carriedforward from 0f6f9df
x2a 57.33% <ø> (?) Carriedforward from 0f6f9df

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update ba03a1a...d06ff02. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant