Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-WEBPACK-15235959 - https://snyk.io/vuln/SNYK-JS-WEBPACK-15235969
Review or Edit in CodeSandboxOpen the branch in Web Editor • VS Code • Insiders |
⛔ Snyk checks have failed. 1 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
WalkthroughThis PR updates the dependency management strategy for the dev-utils package by replacing workspace protocol references with fixed version numbers for three Backstage dependencies. The changes pin Changes
Sequence DiagramThis diagram shows the interactions between components: sequenceDiagram
participant PM as Package Manager
participant DevUtils as @backstage/dev-utils
participant CoreComp as @backstage/core-components
participant IntReact as @backstage/integration-react
participant CatReact as @backstage/plugin-catalog-react
Note over PM,CatReact: Dependency Resolution Change
PM->>DevUtils: Read package.json
Note over DevUtils: Dependencies changed from<br/>workspace:^ to fixed versions
alt Before Change (workspace:^)
DevUtils->>CoreComp: Link to local workspace version
DevUtils->>IntReact: Link to local workspace version
DevUtils->>CatReact: Link to local workspace version
Note over DevUtils,CatReact: Uses local development versions
else After Change (fixed versions)
PM->>CoreComp: Resolve @backstage/core-components@0.1.0
CoreComp-->>PM: Return published package
PM->>IntReact: Resolve @backstage/integration-react@0.1.1
IntReact-->>PM: Return published package
PM->>CatReact: Resolve @backstage/plugin-catalog-react@0.0.1
CatReact-->>PM: Return published package
Note over PM,CatReact: Uses published registry versions
end
PM->>DevUtils: Install resolved dependencies
DevUtils-->>PM: Dependencies installed
Note over DevUtils: Package ready with<br/>fixed version dependencies
Note for WindsurfPlease change the default marketplace provider to the following in the windsurf settings:Marketplace Extension Gallery Service URL: https://marketplace.visualstudio.com/_apis/public/gallery Marketplace Gallery Item URL: https://marketplace.visualstudio.com/items Entelligence.ai can learn from your feedback. Simply add 👍 / 👎 emojis to teach it your preferences. More shortcuts belowEmoji Descriptions:
Interact with the Bot:
Also you can trigger various commands with the bot by doing The current supported commands are
More commands to be added soon. |
Snyk has created this PR to fix 2 vulnerabilities in the yarn dependencies of this project.
Snyk changed the following file(s):
packages/dev-utils/package.jsonNote for zero-installs users
If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the
.yarn/cache/directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to runyarnto update the contents of the./yarn/cachedirectory.If you are not using zero-install you can ignore this as your flow should likely be unchanged.
Vulnerabilities that will be fixed with an upgrade:
SNYK-JS-WEBPACK-15235959
SNYK-JS-WEBPACK-15235969
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Server-side Request Forgery (SSRF)
EntelligenceAI PR Summary
This PR pins Backstage dependencies in the dev-utils package to specific versions instead of using workspace protocol.
@backstage/core-componentsfrom workspace protocol to fixed version0.1.0@backstage/integration-reactfrom workspace protocol to fixed version0.1.1@backstage/plugin-catalog-reactfrom workspace protocol to fixed version0.0.1packages/dev-utils/package.json