Skip to content

Commit 6d1ace8

Browse files
authored
chore: main: update protobufjs to fix CVE-2026-41242 (#4745)
* update protobufjs to 7.5.6 and pin @protobufjs/inquire to 1.1.0 Signed-off-by: Kim Tsao <ktsao@redhat.com> * add resolutions to dynamic plugins Signed-off-by: Kim Tsao <ktsao@redhat.com> --------- Signed-off-by: Kim Tsao <ktsao@redhat.com>
1 parent e4e3797 commit 6d1ace8

6 files changed

Lines changed: 40 additions & 32 deletions

File tree

dynamic-plugins/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,8 @@
3636
"@types/react": "18.3.28",
3737
"@types/react-dom": "18.3.7",
3838
"refractor@npm:3.6.0/prismjs": "^1.30.0",
39-
"infinispan": "0.13.0"
39+
"infinispan": "0.13.0",
40+
"@protobufjs/inquire": "1.1.0"
4041
},
4142
"packageManager": "yarn@4.12.0"
4243
}

dynamic-plugins/wrappers/backstage-plugin-kubernetes-backend-dynamic/package.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,9 @@
4747
"@janus-idp/cli": "3.7.0",
4848
"typescript": "5.9.3"
4949
},
50+
"resolutions": {
51+
"@protobufjs/inquire": "1.1.0"
52+
},
5053
"files": [
5154
"dist",
5255
"dist-dynamic/*.*",

dynamic-plugins/wrappers/backstage-plugin-techdocs-backend-dynamic/package.json

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,9 @@
4949
"@janus-idp/cli": "3.7.0",
5050
"typescript": "5.9.3"
5151
},
52+
"resolutions": {
53+
"@protobufjs/inquire": "1.1.0"
54+
},
5255
"files": [
5356
"dist",
5457
"dist-dynamic/*.*",

dynamic-plugins/yarn.lock

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -10990,10 +10990,10 @@ __metadata:
1099010990
languageName: node
1099110991
linkType: hard
1099210992

10993-
"@protobufjs/codegen@npm:^2.0.4":
10994-
version: 2.0.4
10995-
resolution: "@protobufjs/codegen@npm:2.0.4"
10996-
checksum: 10c0/26ae337c5659e41f091606d16465bbcc1df1f37cc1ed462438b1f67be0c1e28dfb2ca9f294f39100c52161aef82edf758c95d6d75650a1ddf31f7ddee1440b43
10993+
"@protobufjs/codegen@npm:^2.0.5":
10994+
version: 2.0.5
10995+
resolution: "@protobufjs/codegen@npm:2.0.5"
10996+
checksum: 10c0/1b8a2ae56ee60a56e9d205cd4b6072a1503c5069b8ebb905710f974ff0098a0d0700641c137e0a8d98dedf14423156a106a9433695cbf52574810f55000fdcab
1099710997
languageName: node
1099810998
linkType: hard
1099910999

@@ -11021,7 +11021,7 @@ __metadata:
1102111021
languageName: node
1102211022
linkType: hard
1102311023

11024-
"@protobufjs/inquire@npm:^1.1.0":
11024+
"@protobufjs/inquire@npm:1.1.0":
1102511025
version: 1.1.0
1102611026
resolution: "@protobufjs/inquire@npm:1.1.0"
1102711027
checksum: 10c0/64372482efcba1fb4d166a2664a6395fa978b557803857c9c03500e0ac1013eb4b1aacc9ed851dd5fc22f81583670b4f4431bae186f3373fedcfde863ef5921a
@@ -11042,10 +11042,10 @@ __metadata:
1104211042
languageName: node
1104311043
linkType: hard
1104411044

11045-
"@protobufjs/utf8@npm:^1.1.0":
11046-
version: 1.1.0
11047-
resolution: "@protobufjs/utf8@npm:1.1.0"
11048-
checksum: 10c0/a3fe31fe3fa29aa3349e2e04ee13dc170cc6af7c23d92ad49e3eeaf79b9766264544d3da824dba93b7855bd6a2982fb40032ef40693da98a136d835752beb487
11045+
"@protobufjs/utf8@npm:^1.1.1":
11046+
version: 1.1.1
11047+
resolution: "@protobufjs/utf8@npm:1.1.1"
11048+
checksum: 10c0/641fc145f00626405e8984b6e90b9edcbcc072ffc82d0647ca3176e09c730b2d022f988e65f011a7a17e2e4d77cde7733643aa10d8ac2bfa30f134dbcad553fd
1104911049
languageName: node
1105011050
linkType: hard
1105111051

@@ -28485,22 +28485,22 @@ __metadata:
2848528485
linkType: hard
2848628486

2848728487
"protobufjs@npm:^7.0.0, protobufjs@npm:^7.2.5, protobufjs@npm:^7.3.2, protobufjs@npm:^7.5.3":
28488-
version: 7.5.4
28489-
resolution: "protobufjs@npm:7.5.4"
28488+
version: 7.5.6
28489+
resolution: "protobufjs@npm:7.5.6"
2849028490
dependencies:
2849128491
"@protobufjs/aspromise": "npm:^1.1.2"
2849228492
"@protobufjs/base64": "npm:^1.1.2"
28493-
"@protobufjs/codegen": "npm:^2.0.4"
28493+
"@protobufjs/codegen": "npm:^2.0.5"
2849428494
"@protobufjs/eventemitter": "npm:^1.1.0"
2849528495
"@protobufjs/fetch": "npm:^1.1.0"
2849628496
"@protobufjs/float": "npm:^1.0.2"
28497-
"@protobufjs/inquire": "npm:^1.1.0"
28497+
"@protobufjs/inquire": "npm:^1.1.1"
2849828498
"@protobufjs/path": "npm:^1.1.2"
2849928499
"@protobufjs/pool": "npm:^1.1.0"
28500-
"@protobufjs/utf8": "npm:^1.1.0"
28500+
"@protobufjs/utf8": "npm:^1.1.1"
2850128501
"@types/node": "npm:>=13.7.0"
2850228502
long: "npm:^5.0.0"
28503-
checksum: 10c0/913b676109ffb3c05d3d31e03a684e569be91f3bba8613da4a683d69d9dba948daa2afd7d2e7944d1aa6c417890c35d9d9a8883c1160affafb0f9670d59ef722
28503+
checksum: 10c0/220df6c3cf6d2346748639a9b0b688fecc994bff9fee7018a93167e8cd45ab0ee3b4270d9eaa6be33a11adb46514ef9dce7e8217fd578c36726a9e70b96327cd
2850428504
languageName: node
2850528505
linkType: hard
2850628506

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,8 @@
7171
"zod@^3.25.76": "3.25.76",
7272
"zod@^3.25.76 || ^4.0.0": "3.25.76",
7373
"zod@^3.25 || ^4.0": "3.25.76",
74-
"infinispan": "0.13.0"
74+
"infinispan": "0.13.0",
75+
"@protobufjs/inquire": "1.1.0"
7576
},
7677
"jest": {
7778
"testTimeout": 20000

yarn.lock

Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -11577,10 +11577,10 @@ __metadata:
1157711577
languageName: node
1157811578
linkType: hard
1157911579

11580-
"@protobufjs/codegen@npm:^2.0.4":
11581-
version: 2.0.4
11582-
resolution: "@protobufjs/codegen@npm:2.0.4"
11583-
checksum: 10c0/26ae337c5659e41f091606d16465bbcc1df1f37cc1ed462438b1f67be0c1e28dfb2ca9f294f39100c52161aef82edf758c95d6d75650a1ddf31f7ddee1440b43
11580+
"@protobufjs/codegen@npm:^2.0.5":
11581+
version: 2.0.5
11582+
resolution: "@protobufjs/codegen@npm:2.0.5"
11583+
checksum: 10c0/1b8a2ae56ee60a56e9d205cd4b6072a1503c5069b8ebb905710f974ff0098a0d0700641c137e0a8d98dedf14423156a106a9433695cbf52574810f55000fdcab
1158411584
languageName: node
1158511585
linkType: hard
1158611586

@@ -11608,7 +11608,7 @@ __metadata:
1160811608
languageName: node
1160911609
linkType: hard
1161011610

11611-
"@protobufjs/inquire@npm:^1.1.0":
11611+
"@protobufjs/inquire@npm:1.1.0":
1161211612
version: 1.1.0
1161311613
resolution: "@protobufjs/inquire@npm:1.1.0"
1161411614
checksum: 10c0/64372482efcba1fb4d166a2664a6395fa978b557803857c9c03500e0ac1013eb4b1aacc9ed851dd5fc22f81583670b4f4431bae186f3373fedcfde863ef5921a
@@ -11629,10 +11629,10 @@ __metadata:
1162911629
languageName: node
1163011630
linkType: hard
1163111631

11632-
"@protobufjs/utf8@npm:^1.1.0":
11633-
version: 1.1.0
11634-
resolution: "@protobufjs/utf8@npm:1.1.0"
11635-
checksum: 10c0/a3fe31fe3fa29aa3349e2e04ee13dc170cc6af7c23d92ad49e3eeaf79b9766264544d3da824dba93b7855bd6a2982fb40032ef40693da98a136d835752beb487
11632+
"@protobufjs/utf8@npm:^1.1.1":
11633+
version: 1.1.1
11634+
resolution: "@protobufjs/utf8@npm:1.1.1"
11635+
checksum: 10c0/641fc145f00626405e8984b6e90b9edcbcc072ffc82d0647ca3176e09c730b2d022f988e65f011a7a17e2e4d77cde7733643aa10d8ac2bfa30f134dbcad553fd
1163611636
languageName: node
1163711637
linkType: hard
1163811638

@@ -33445,22 +33445,22 @@ __metadata:
3344533445
linkType: hard
3344633446

3344733447
"protobufjs@npm:^7.0.0, protobufjs@npm:^7.2.5, protobufjs@npm:^7.2.6, protobufjs@npm:^7.3.0, protobufjs@npm:^7.3.2, protobufjs@npm:^7.4.0, protobufjs@npm:^7.5.3":
33448-
version: 7.5.4
33449-
resolution: "protobufjs@npm:7.5.4"
33448+
version: 7.5.6
33449+
resolution: "protobufjs@npm:7.5.6"
3345033450
dependencies:
3345133451
"@protobufjs/aspromise": "npm:^1.1.2"
3345233452
"@protobufjs/base64": "npm:^1.1.2"
33453-
"@protobufjs/codegen": "npm:^2.0.4"
33453+
"@protobufjs/codegen": "npm:^2.0.5"
3345433454
"@protobufjs/eventemitter": "npm:^1.1.0"
3345533455
"@protobufjs/fetch": "npm:^1.1.0"
3345633456
"@protobufjs/float": "npm:^1.0.2"
33457-
"@protobufjs/inquire": "npm:^1.1.0"
33457+
"@protobufjs/inquire": "npm:^1.1.1"
3345833458
"@protobufjs/path": "npm:^1.1.2"
3345933459
"@protobufjs/pool": "npm:^1.1.0"
33460-
"@protobufjs/utf8": "npm:^1.1.0"
33460+
"@protobufjs/utf8": "npm:^1.1.1"
3346133461
"@types/node": "npm:>=13.7.0"
3346233462
long: "npm:^5.0.0"
33463-
checksum: 10c0/913b676109ffb3c05d3d31e03a684e569be91f3bba8613da4a683d69d9dba948daa2afd7d2e7944d1aa6c417890c35d9d9a8883c1160affafb0f9670d59ef722
33463+
checksum: 10c0/220df6c3cf6d2346748639a9b0b688fecc994bff9fee7018a93167e8cd45ab0ee3b4270d9eaa6be33a11adb46514ef9dce7e8217fd578c36726a9e70b96327cd
3346433464
languageName: node
3346533465
linkType: hard
3346633466

0 commit comments

Comments
 (0)