Version Packages (cost-management)#3134
Open
rhdh-bot wants to merge 1 commit into
Open
Conversation
da42c59 to
e74d081
Compare
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3134 +/- ##
=======================================
Coverage 60.97% 60.97%
=======================================
Files 2081 2081
Lines 64283 64283
Branches 16680 16680
=======================================
Hits 39196 39196
Misses 24880 24880
Partials 207 207
*This pull request uses carry forward flags. Click here to find out more. Continue to review full report in Codecov by Sentry.
🚀 New features to boost your workflow:
|
PreetiW
approved these changes
May 13, 2026
bab97db to
237a458
Compare
Contributor
|
/rebase |
237a458 to
9acddf9
Compare
Contributor
|
/rebase |
9acddf9 to
8d7721d
Compare
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Releases
@red-hat-developer-hub/plugin-cost-management@2.2.1
Patch Changes
558b7c3: fix: patch transitive dependency CVEs via yarn resolutions
Pins vulnerable transitive dependencies to patched versions to address open Dependabot alerts:
815580b: fix: additional CVE patches and dependency updates for 2.2.1
Covers the following changes merged after the initial CVE patch (558b7c3):
chore(deps): update rhdh cost management dependencies (patch) (chore(deps): update rhdh cost management dependencies (patch) #3000) — bumps
@aws-sdk/core/fast-xml-parserto 4.5.6,request/form-datato 2.5.5,request/tough-cookieto 4.1.4,typeormto 0.3.29, andfile-typeto 21.3.4via yarn resolutions
fix: resolve lodash CVEs via workspace resolution (fix(cost-management): resolve lodash CVEs via workspace resolution #3135) — pins lodash to 4.18.1
to address GHSA-r5fr-rjxr-66jc (Code Injection via _.template, CVSS 8.1) and
GHSA-f23m-r3pf-42rh (Prototype Pollution via _.unset/_.omit, CVSS 6.5)
fix: update lodash direct deps to 4.18.1 to close Dependabot alerts (fix(cost-management): update lodash direct deps to 4.18.1 #3142) —
updates pinned lodash versions in individual plugin package.json files so
Dependabot can detect the fix for GHSA-r5fr-rjxr-66jc and GHSA-f23m-r3pf-42rh
fix: CVE patches for casbin/minimatch and fast-xml-parser (Fix CVEs #3143) — adds
casbin/minimatchresolution to 7.4.8 and bumpsfast-xml-parserto 5.7.3fix: upgrade @backstage-community/plugin-rbac-backend to ^7.12.4 (Upgrade Backstage Backend CVE #3161) —
upgrades rbac-backend and rbac-common to address a Backstage backend CVE
chore(deps): update linkifyjs to v4.3.3 (Update RHDH Cost Management Dependencies (patch) #3155) — patch version bump
Updated dependencies [558b7c3]
Updated dependencies [815580b]
@red-hat-developer-hub/plugin-cost-management-backend@2.2.1
Patch Changes
558b7c3: fix: patch transitive dependency CVEs via yarn resolutions
Pins vulnerable transitive dependencies to patched versions to address open Dependabot alerts:
815580b: fix: additional CVE patches and dependency updates for 2.2.1
Covers the following changes merged after the initial CVE patch (558b7c3):
chore(deps): update rhdh cost management dependencies (patch) (chore(deps): update rhdh cost management dependencies (patch) #3000) — bumps
@aws-sdk/core/fast-xml-parserto 4.5.6,request/form-datato 2.5.5,request/tough-cookieto 4.1.4,typeormto 0.3.29, andfile-typeto 21.3.4via yarn resolutions
fix: resolve lodash CVEs via workspace resolution (fix(cost-management): resolve lodash CVEs via workspace resolution #3135) — pins lodash to 4.18.1
to address GHSA-r5fr-rjxr-66jc (Code Injection via _.template, CVSS 8.1) and
GHSA-f23m-r3pf-42rh (Prototype Pollution via _.unset/_.omit, CVSS 6.5)
fix: update lodash direct deps to 4.18.1 to close Dependabot alerts (fix(cost-management): update lodash direct deps to 4.18.1 #3142) —
updates pinned lodash versions in individual plugin package.json files so
Dependabot can detect the fix for GHSA-r5fr-rjxr-66jc and GHSA-f23m-r3pf-42rh
fix: CVE patches for casbin/minimatch and fast-xml-parser (Fix CVEs #3143) — adds
casbin/minimatchresolution to 7.4.8 and bumpsfast-xml-parserto 5.7.3fix: upgrade @backstage-community/plugin-rbac-backend to ^7.12.4 (Upgrade Backstage Backend CVE #3161) —
upgrades rbac-backend and rbac-common to address a Backstage backend CVE
chore(deps): update linkifyjs to v4.3.3 (Update RHDH Cost Management Dependencies (patch) #3155) — patch version bump
Updated dependencies [558b7c3]
Updated dependencies [815580b]
@red-hat-developer-hub/plugin-cost-management-common@2.2.1
Patch Changes
558b7c3: fix: patch transitive dependency CVEs via yarn resolutions
Pins vulnerable transitive dependencies to patched versions to address open Dependabot alerts:
815580b: fix: additional CVE patches and dependency updates for 2.2.1
Covers the following changes merged after the initial CVE patch (558b7c3):
chore(deps): update rhdh cost management dependencies (patch) (chore(deps): update rhdh cost management dependencies (patch) #3000) — bumps
@aws-sdk/core/fast-xml-parserto 4.5.6,request/form-datato 2.5.5,request/tough-cookieto 4.1.4,typeormto 0.3.29, andfile-typeto 21.3.4via yarn resolutions
fix: resolve lodash CVEs via workspace resolution (fix(cost-management): resolve lodash CVEs via workspace resolution #3135) — pins lodash to 4.18.1
to address GHSA-r5fr-rjxr-66jc (Code Injection via _.template, CVSS 8.1) and
GHSA-f23m-r3pf-42rh (Prototype Pollution via _.unset/_.omit, CVSS 6.5)
fix: update lodash direct deps to 4.18.1 to close Dependabot alerts (fix(cost-management): update lodash direct deps to 4.18.1 #3142) —
updates pinned lodash versions in individual plugin package.json files so
Dependabot can detect the fix for GHSA-r5fr-rjxr-66jc and GHSA-f23m-r3pf-42rh
fix: CVE patches for casbin/minimatch and fast-xml-parser (Fix CVEs #3143) — adds
casbin/minimatchresolution to 7.4.8 and bumpsfast-xml-parserto 5.7.3fix: upgrade @backstage-community/plugin-rbac-backend to ^7.12.4 (Upgrade Backstage Backend CVE #3161) —
upgrades rbac-backend and rbac-common to address a Backstage backend CVE
chore(deps): update linkifyjs to v4.3.3 (Update RHDH Cost Management Dependencies (patch) #3155) — patch version bump