fix(deps): update dependency @backstage/plugin-catalog-unprocessed-entities ( 0.2.23 ➔ 0.2.30 ) [security] #84
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/backstage-application!84
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/npm-backstage-plugin-catalog-unprocessed-entities-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
0.2.23→0.2.30🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.
Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Releasedis the upstream publish time.—means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — sominimumReleaseAgecannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type'sminimumReleaseAgetoReleasedto get the eligibility moment.Backstage: Catalog unprocessed read endpoints allow authenticated cross-owner data access without permission checks
CVE-2026-44374 / GHSA-p7g9-rp3g-mgfg
More information
Details
Impact
The unprocessed entities read endpoints in
@backstage/plugin-catalog-backend-module-unprocesseddo not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This isan information disclosure vulnerability affecting Backstage installations using this module.
Patches
This is patched in
@backstage/plugin-catalog-backend-module-unprocessedversion 0.6.11,@backstage/plugin-catalog-unprocessed-entities-commonversion 0.0.15 and@backstage/plugin-catalog-unprocessed-entitiesversion 0.2.30. Users should upgrade all packages.Workarounds
If users cannot upgrade, they can remove the
@backstage/plugin-catalog-backend-module-unprocessedmodule from their backend until the patch is applied. There is no configuration-based workaround to add permission checks to these endpointswithout upgrading.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/plugin-catalog-unprocessed-entities)
v0.2.30Compare Source
Patch Changes
v0.2.29Compare Source
Patch Changes
482ceed: Migrated fromassertErrortotoErrorfor error handling.b6f1fae: The unprocessed entities view is now primarily intended for use as a tab within the DevTools plugin. The standalone page is still available but disabled by default. To re-enable it, add the following to yourapp-config.yaml:Updated dependencies
v0.2.28Compare Source
v0.2.27Compare Source
Patch Changes
538c985: Updated installation documentation to use feature discovery as the default.aa29b50: New frontend system pages now use the default plugin header together withHeaderPageinstead of the legacy core page header pattern.3f36ce1: Updated alpha plugin icons to follow the new frontend icon sizing rules when rendered in plugin and navigation surfaces.f4a1edd: Removed the deprecatedDevToolsContentBlueprintfrom@backstage/plugin-devtools-react. DevTools pages in the new frontend system now useSubPageBlueprinttabs instead, and the catalog unprocessed entities alpha extension now attaches to DevTools as a subpage.v0.2.26Compare Source
Patch Changes
018ca87: Addedtitleandiconto the plugin definition for the new frontend system.a7e0d50: Updatedreact-router-dompeer dependency to^6.30.2and explicitly disabled v7 future flags to suppress deprecation warnings.v0.2.25Compare Source
Patch Changes
be6cef5: Add support for addingunprocessed-entitiesand other tabs todevtoolswhen using the New Frontend systemv0.2.24Compare Source
Patch Changes
d02db50: Remove unnecessary use ofcompatWrapperandconvertLegacyRouteRef(s) for the new frontend system.df4d646: Moved types, API and client to the common package, allowing both frontend andbackend plugins to use the
CatalogUnprocessedEntitiesClient.The following types, clients and interfaces have been deprecated and should be
imported from the
@backstage/plugin-catalog-unprocessed-entities-commoninstead:CatalogUnprocessedEntitiesApi,CatalogUnprocessedEntitiesApiResponse,UnprocessedEntity,UnprocessedEntityCache,UnprocessedEntityError,CatalogUnprocessedEntitiesClient.All those types, clients and interfaces are re-exported temporarily in the
@backstage/plugin-catalog-unprocessed-entitiespackage until cleaned up.Updated dependencies
Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.