Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): [1.2.x] Bump Express to v4.21.0 to fix a number of CVEs #1735

Merged
merged 5 commits into from
Nov 14, 2024

Conversation

kim-tsao
Copy link
Member

@kim-tsao kim-tsao commented Oct 7, 2024

Description

A backport of #1619 to 1.2.5

CVE-2024-45296
CVE-2024-43799
CVE-2024-45590
CVE-2024-47764
CVE-2024-43800

Please explain the changes you made here.

Which issue(s) does this PR fix

PR acceptance criteria

Please make sure that the following steps are complete:

  • GitHub Actions are completed and successful
  • Unit Tests are updated and passing
  • E2E Tests are updated and passing
  • Documentation is updated if necessary (requirement for new features)
  • Add a screenshot if the change is UX/UI related

How to test changes / Special notes to the reviewer

@kim-tsao kim-tsao requested a review from a team as a code owner October 7, 2024 15:55
@openshift-ci openshift-ci bot requested review from josephca and rnapoles-rh October 7, 2024 15:55
Copy link
Contributor

github-actions bot commented Oct 7, 2024

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

Copy link
Contributor

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

Copy link
Contributor

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

Copy link
Contributor

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

@kim-tsao
Copy link
Member Author

/test e2e-tests

Copy link
Contributor

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

@Fortune-Ndlovu
Copy link
Contributor

/test e2e-tests

1 similar comment
@subhashkhileri
Copy link
Member

/test e2e-tests

@kim-tsao
Copy link
Member Author

/retest

2 similar comments
@kim-tsao
Copy link
Member Author

/retest

@kim-tsao
Copy link
Member Author

/retest

@kim-tsao
Copy link
Member Author

/test e2e-tests

@kim-tsao
Copy link
Member Author

ocm-backend 4.0.10 has not been published which is why the e2e tests are failing

@nickboldt
Copy link
Member

nickboldt commented Oct 18, 2024

If we figure out the cause of the e2e test failues is unrelated to the -dynamic packages being pushed to npmjs (since these exist inside the rhdh-hub-rhel9 container already) we can likely close https://issues.redhat.com/browse/RHIDP-4556 as a "won't do".

@josephca
Copy link
Collaborator

/test e2e-tests

Copy link
Contributor

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

Copy link
Contributor

@Fortune-Ndlovu Fortune-Ndlovu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/approve

Copy link

openshift-ci bot commented Oct 21, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Fortune-Ndlovu, nickboldt

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@Fortune-Ndlovu
Copy link
Contributor

/retest

Copy link

openshift-ci bot commented Oct 23, 2024

New changes are detected. LGTM label has been removed.

@kim-tsao
Copy link
Member Author

ocm-backend v4.0.10 had a mismatched v4.5.0 version in its dist-dynamic/alpha/package.json which resulted in an error when therootHttpRouter module (a dependency in v4.5.0) could not be found. The versions are now consistent in 4.0.12, so it should fix the e2e tests

Copy link
Contributor

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

@kim-tsao
Copy link
Member Author

/retest

2 similar comments
@kim-tsao
Copy link
Member Author

kim-tsao commented Nov 5, 2024

/retest

@kim-tsao
Copy link
Member Author

kim-tsao commented Nov 7, 2024

/retest

@kim-tsao
Copy link
Member Author

kim-tsao commented Nov 8, 2024

blocked by openshift/release#58412

@kim-tsao
Copy link
Member Author

/test e2e-tests

@kim-tsao
Copy link
Member Author

/retest

Copy link
Contributor

The image is available at: quay.io/janus-idp/backstage-showcase:pr-1735!

Copy link

openshift-ci bot commented Nov 14, 2024

@kim-tsao: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-tests da3f27d link true /test e2e-tests

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@kim-tsao kim-tsao merged commit 6254668 into redhat-developer:1.2.x Nov 14, 2024
6 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants