fix(deps): update dependency @backstage/plugin-catalog-unprocessed-entities ( 0.2.23 ➔ 0.2.30 ) [security] #84

Open
renovate wants to merge 1 commit from renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@backstage/plugin-catalog-unprocessed-entities (source) 0.2.23 → 0.2.30 age adoption passing confidence

🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Released is the upstream publish time. — means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so minimumReleaseAge cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's minimumReleaseAge to Released to get the eligibility moment.


Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks

CVE-2026-44374 / GHSA-p7g9-rp3g-mgfg

More information

Details

Impact

The unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is
an information disclosure vulnerability affecting Backstage installations using this module.

Patches

This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30. Users should upgrade all packages.

Workarounds

If users cannot upgrade, they can remove the @backstage/plugin-catalog-backend-module-unprocessed module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints
without upgrading.

Severity

  • CVSS Score: 4.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

backstage/backstage (@​backstage/plugin-catalog-unprocessed-entities)

v0.2.30

Compare Source

Patch Changes

v0.2.29

Compare Source

Patch Changes

v0.2.28

Compare Source

v0.2.27

Compare Source

Patch Changes
  • 538c985: Updated installation documentation to use feature discovery as the default.
  • aa29b50: New frontend system pages now use the default plugin header together with HeaderPage instead of the legacy core page header pattern.
  • 3f36ce1: Updated alpha plugin icons to follow the new frontend icon sizing rules when rendered in plugin and navigation surfaces.
  • f4a1edd: Removed the deprecated DevToolsContentBlueprint from @backstage/plugin-devtools-react. DevTools pages in the new frontend system now use SubPageBlueprint tabs instead, and the catalog unprocessed entities alpha extension now attaches to DevTools as a subpage.
  • Updated dependencies

v0.2.26

Compare Source

Patch Changes

v0.2.25

Compare Source

Patch Changes

v0.2.24

Compare Source

Patch Changes
  • d02db50: Remove unnecessary use of compatWrapper and convertLegacyRouteRef(s) for the new frontend system.

  • df4d646: Moved types, API and client to the common package, allowing both frontend and
    backend plugins to use the CatalogUnprocessedEntitiesClient.

    The following types, clients and interfaces have been deprecated and should be
    imported from the @backstage/plugin-catalog-unprocessed-entities-common instead:
    CatalogUnprocessedEntitiesApi, CatalogUnprocessedEntitiesApiResponse, UnprocessedEntity,
    UnprocessedEntityCache, UnprocessedEntityError, CatalogUnprocessedEntitiesClient.

    All those types, clients and interfaces are re-exported temporarily in the
    @backstage/plugin-catalog-unprocessed-entities package until cleaned up.

  • Updated dependencies


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [@backstage/plugin-catalog-unprocessed-entities](https://backstage.io) ([source](https://github.com/backstage/backstage/tree/HEAD/plugins/catalog-unprocessed-entities)) | [`0.2.23` → `0.2.30`](https://renovatebot.com/diffs/npm/@backstage%2fplugin-catalog-unprocessed-entities/0.2.23/0.2.30) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@backstage%2fplugin-catalog-unprocessed-entities/0.2.30?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@backstage%2fplugin-catalog-unprocessed-entities/0.2.30?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@backstage%2fplugin-catalog-unprocessed-entities/0.2.23/0.2.30?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@backstage%2fplugin-catalog-unprocessed-entities/0.2.23/0.2.30?slim=true) | 🔒 **Security update**: prioritize review and verify the vulnerable component is actually deployed. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. `Released` is the upstream publish time. `—` means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so `minimumReleaseAge` cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's `minimumReleaseAge` to `Released` to get the eligibility moment. --- ### Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks [CVE-2026-44374](https://nvd.nist.gov/vuln/detail/CVE-2026-44374) / [GHSA-p7g9-rp3g-mgfg](https://github.com/advisories/GHSA-p7g9-rp3g-mgfg) <details> <summary>More information</summary> #### Details ##### Impact The unprocessed entities read endpoints in `@backstage/plugin-catalog-backend-module-unprocessed` do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. ### Patches This is patched in `@backstage/plugin-catalog-backend-module-unprocessed` version 0.6.11, `@backstage/plugin-catalog-unprocessed-entities-common` version 0.0.15 and `@backstage/plugin-catalog-unprocessed-entities` version 0.2.30. Users should upgrade all packages. ### Workarounds If users cannot upgrade, they can remove the `@backstage/plugin-catalog-backend-module-unprocessed` module from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpoints without upgrading. #### Severity - CVSS Score: 4.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-p7g9-rp3g-mgfg](https://github.com/backstage/backstage/security/advisories/GHSA-p7g9-rp3g-mgfg) - [https://nvd.nist.gov/vuln/detail/CVE-2026-44374](https://nvd.nist.gov/vuln/detail/CVE-2026-44374) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-p7g9-rp3g-mgfg) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>backstage/backstage (@&#8203;backstage/plugin-catalog-unprocessed-entities)</summary> ### [`v0.2.30`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-unprocessed-entities/CHANGELOG.md#0230-next0) [Compare Source](https://github.com/backstage/backstage/compare/168d7cc9eb2af6902ee21dd37f25b8fc0bc05438...61fbc82cb8dba0fa62e5ac8861e2dbbedb229f32) ##### Patch Changes - Updated dependencies - [@&#8203;backstage/core-components](https://github.com/backstage/core-components)@&#8203;0.18.10-next.0 - [@&#8203;backstage/ui](https://github.com/backstage/ui)@&#8203;0.15.0-next.0 - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.3.1-next.0 - [@&#8203;backstage/core-compat-api](https://github.com/backstage/core-compat-api)@&#8203;0.5.11-next.0 - [@&#8203;backstage/frontend-plugin-api](https://github.com/backstage/frontend-plugin-api)@&#8203;0.17.0-next.0 - [@&#8203;backstage/core-plugin-api](https://github.com/backstage/core-plugin-api)@&#8203;1.12.6-next.0 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.15-next.0 ### [`v0.2.29`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-unprocessed-entities/CHANGELOG.md#0229) [Compare Source](https://github.com/backstage/backstage/compare/caed462d19eac69e18f720c79f500570624c93c2...168d7cc9eb2af6902ee21dd37f25b8fc0bc05438) ##### Patch Changes - [`482ceed`](https://github.com/backstage/backstage/commit/482ceed): Migrated from `assertError` to `toError` for error handling. - [`b6f1fae`](https://github.com/backstage/backstage/commit/b6f1fae): The unprocessed entities view is now primarily intended for use as a tab within the DevTools plugin. The standalone page is still available but disabled by default. To re-enable it, add the following to your `app-config.yaml`: ```yaml app: extensions: - page:catalog-unprocessed-entities ``` - Updated dependencies - [@&#8203;backstage/ui](https://github.com/backstage/ui)@&#8203;0.14.0 - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.3.0 - [@&#8203;backstage/frontend-plugin-api](https://github.com/backstage/frontend-plugin-api)@&#8203;0.16.0 - [@&#8203;backstage/core-components](https://github.com/backstage/core-components)@&#8203;0.18.9 - [@&#8203;backstage/core-compat-api](https://github.com/backstage/core-compat-api)@&#8203;0.5.10 - [@&#8203;backstage/core-plugin-api](https://github.com/backstage/core-plugin-api)@&#8203;1.12.5 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.14 ### [`v0.2.28`](https://github.com/backstage/backstage/compare/7918ae477c7b98b77c79249836898b342e41df29...caed462d19eac69e18f720c79f500570624c93c2) [Compare Source](https://github.com/backstage/backstage/compare/7918ae477c7b98b77c79249836898b342e41df29...caed462d19eac69e18f720c79f500570624c93c2) ### [`v0.2.27`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-unprocessed-entities/CHANGELOG.md#0227) [Compare Source](https://github.com/backstage/backstage/compare/c4d19ed1b6953eafbc30edc223c88bea6d5ef76b...7918ae477c7b98b77c79249836898b342e41df29) ##### Patch Changes - [`538c985`](https://github.com/backstage/backstage/commit/538c985): Updated installation documentation to use feature discovery as the default. - [`aa29b50`](https://github.com/backstage/backstage/commit/aa29b50): New frontend system pages now use the default plugin header together with `HeaderPage` instead of the legacy core page header pattern. - [`3f36ce1`](https://github.com/backstage/backstage/commit/3f36ce1): Updated alpha plugin icons to follow the new frontend icon sizing rules when rendered in plugin and navigation surfaces. - [`f4a1edd`](https://github.com/backstage/backstage/commit/f4a1edd): Removed the deprecated `DevToolsContentBlueprint` from `@backstage/plugin-devtools-react`. DevTools pages in the new frontend system now use `SubPageBlueprint` tabs instead, and the catalog unprocessed entities alpha extension now attaches to DevTools as a subpage. - Updated dependencies - [@&#8203;backstage/ui](https://github.com/backstage/ui)@&#8203;0.13.0 - [@&#8203;backstage/core-compat-api](https://github.com/backstage/core-compat-api)@&#8203;0.5.9 - [@&#8203;backstage/core-plugin-api](https://github.com/backstage/core-plugin-api)@&#8203;1.12.4 - [@&#8203;backstage/core-components](https://github.com/backstage/core-components)@&#8203;0.18.8 - [@&#8203;backstage/frontend-plugin-api](https://github.com/backstage/frontend-plugin-api)@&#8203;0.15.0 ### [`v0.2.26`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-unprocessed-entities/CHANGELOG.md#0226) [Compare Source](https://github.com/backstage/backstage/compare/e63a312b0c8d3b1e1333caf3eb5f576e9e59ee63...c4d19ed1b6953eafbc30edc223c88bea6d5ef76b) ##### Patch Changes - [`018ca87`](https://github.com/backstage/backstage/commit/018ca87): Added `title` and `icon` to the plugin definition for the new frontend system. - [`a7e0d50`](https://github.com/backstage/backstage/commit/a7e0d50): Updated `react-router-dom` peer dependency to `^6.30.2` and explicitly disabled v7 future flags to suppress deprecation warnings. - Updated dependencies - [@&#8203;backstage/core-components](https://github.com/backstage/core-components)@&#8203;0.18.7 - [@&#8203;backstage/core-compat-api](https://github.com/backstage/core-compat-api)@&#8203;0.5.8 - [@&#8203;backstage/frontend-plugin-api](https://github.com/backstage/frontend-plugin-api)@&#8203;0.14.0 - [@&#8203;backstage/plugin-devtools-react](https://github.com/backstage/plugin-devtools-react)@&#8203;0.1.1 - [@&#8203;backstage/core-plugin-api](https://github.com/backstage/core-plugin-api)@&#8203;1.12.3 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.13 ### [`v0.2.25`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-unprocessed-entities/CHANGELOG.md#0225) [Compare Source](https://github.com/backstage/backstage/compare/d03fd681a91928c65419df989d9fc4adef3a2dba...e63a312b0c8d3b1e1333caf3eb5f576e9e59ee63) ##### Patch Changes - [`be6cef5`](https://github.com/backstage/backstage/commit/be6cef5): Add support for adding `unprocessed-entities` and other tabs to `devtools` when using the New Frontend system - Updated dependencies - [@&#8203;backstage/frontend-plugin-api](https://github.com/backstage/frontend-plugin-api)@&#8203;0.13.3 - [@&#8203;backstage/core-components](https://github.com/backstage/core-components)@&#8203;0.18.5 - [@&#8203;backstage/plugin-devtools-react](https://github.com/backstage/plugin-devtools-react)@&#8203;0.1.0 - [@&#8203;backstage/core-compat-api](https://github.com/backstage/core-compat-api)@&#8203;0.5.6 ### [`v0.2.24`](https://github.com/backstage/backstage/blob/HEAD/plugins/catalog-unprocessed-entities/CHANGELOG.md#0224) [Compare Source](https://github.com/backstage/backstage/compare/cd79f31c8ccb6d611bac2cfb13a019a555132011...d03fd681a91928c65419df989d9fc4adef3a2dba) ##### Patch Changes - [`d02db50`](https://github.com/backstage/backstage/commit/d02db50): Remove unnecessary use of `compatWrapper` and `convertLegacyRouteRef`(s) for the new frontend system. - [`df4d646`](https://github.com/backstage/backstage/commit/df4d646): Moved types, API and client to the common package, allowing both frontend and backend plugins to use the `CatalogUnprocessedEntitiesClient`. The following types, clients and interfaces have been deprecated and should be imported from the `@backstage/plugin-catalog-unprocessed-entities-common` instead: `CatalogUnprocessedEntitiesApi`, `CatalogUnprocessedEntitiesApiResponse`, `UnprocessedEntity`, `UnprocessedEntityCache`, `UnprocessedEntityError`, `CatalogUnprocessedEntitiesClient`. All those types, clients and interfaces are re-exported temporarily in the `@backstage/plugin-catalog-unprocessed-entities` package until cleaned up. - Updated dependencies - [@&#8203;backstage/frontend-plugin-api](https://github.com/backstage/frontend-plugin-api)@&#8203;0.13.2 - [@&#8203;backstage/core-components](https://github.com/backstage/core-components)@&#8203;0.18.4 - [@&#8203;backstage/core-plugin-api](https://github.com/backstage/core-plugin-api)@&#8203;1.12.1 - @&#8203;backstage/plugin-catalog-unprocessed-entities-common\@&#8203;0.0.12 </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjI3MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSIsInNlY3VyaXR5IiwidHlwZS9wYXRjaCJdfQ==-->
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability:renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git switch renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git switch renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git rebase main
git switch main
git merge --ff-only renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git switch renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git rebase main
git switch main
git merge --no-ff renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git switch main
git merge --squash renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git switch main
git merge --ff-only renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git switch main
git merge renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability
git push origin main
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/backstage-application!84
No description provided.