feat(deps): update dependency @backstage/plugin-scaffolder-backend ( 3.0.1 ➔ 3.1.4 ) [security] #86

Open
renovate wants to merge 1 commit from renovate/npm-backstage-plugin-scaffolder-backend-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@backstage/plugin-scaffolder-backend (source) 3.0.1 → 3.1.4 age adoption passing confidence

🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.

Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.

Released is the upstream publish time. — means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so minimumReleaseAge cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's minimumReleaseAge to Released to get the eligibility moment.


CVE-2026-24046 / GHSA-rq6q-wr2q-7pgp

More information

Details

Impact

Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:

  1. Read arbitrary files via the debug:log action by creating a symlink pointing to sensitive files (e.g., /etc/passwd, configuration files, secrets)
  2. Delete arbitrary files via the fs:delete action by creating symlinks pointing outside the workspace
  3. Write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks

This affects any Backstage deployment where users can create or execute Scaffolder templates.

Patches

This vulnerability is fixed in the following package versions:

  • @backstage/backend-defaults version 0.12.2, 0.13.2, 0.14.1, 0.15.0
  • @backstage/plugin-scaffolder-backend version 2.2.2, 3.0.2, 3.1.1
  • @backstage/plugin-scaffolder-node version 0.11.2, 0.12.3

Users should upgrade to these versions or later.

Workarounds
  • Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates
  • Restrict who can create and execute Scaffolder templates using the permissions framework
  • Audit existing templates for symlink usage
  • Run Backstage in a containerized environment with limited filesystem access
References

Severity

  • CVSS Score: 7.1 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


@​backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass

CVE-2026-29184 / GHSA-8qp7-fhr9-fw53

More information

Details

Impact

A malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs.

The attack requires:

  • The ability to register a template in the catalog
  • A victim who executes the malicious template
Patches

Patched in @backstage/plugin-scaffolder-backend version 3.1.4

Workarounds
  • Implement a custom permission policy that restricts scaffolder.task.read so users can only read their own task logs
  • Restrict who can register templates in the catalog to trusted users only
Resources

Severity

  • CVSS Score: 2.0 / 10 (Low)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

backstage/backstage (@​backstage/plugin-scaffolder-backend)

v3.1.4

Compare Source

Patch Changes

v3.1.3

Compare Source

Patch Changes

v3.1.2

Compare Source

Patch Changes

v3.1.1

Compare Source

Patch Changes

v3.1.0

Compare Source

Minor Changes
  • a4cd405: Add defaultEnvironment config to scaffolder to enable more flexible and custom templates. Now it's possible enable access to default parameters and secrets in templates, improving security and reducing complexity.
Patch Changes

v3.0.3

Compare Source

v3.0.2

Compare Source


Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Adoption](https://docs.renovatebot.com/merge-confidence/) | [Passing](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [@backstage/plugin-scaffolder-backend](https://backstage.io) ([source](https://github.com/backstage/backstage/tree/HEAD/plugins/scaffolder-backend)) | [`3.0.1` → `3.1.4`](https://renovatebot.com/diffs/npm/@backstage%2fplugin-scaffolder-backend/3.0.1/3.1.4) | ![age](https://developer.mend.io/api/mc/badges/age/npm/@backstage%2fplugin-scaffolder-backend/3.1.4?slim=true) | ![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/@backstage%2fplugin-scaffolder-backend/3.1.4?slim=true) | ![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/@backstage%2fplugin-scaffolder-backend/3.0.1/3.1.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@backstage%2fplugin-scaffolder-backend/3.0.1/3.1.4?slim=true) | 🔒 **Security update**: prioritize review and verify the vulnerable component is actually deployed. Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge. `Released` is the upstream publish time. `—` means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — so `minimumReleaseAge` cannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type's `minimumReleaseAge` to `Released` to get the eligibility moment. --- ### Backstage has a Possible Symlink Path Traversal in Scaffolder Actions [CVE-2026-24046](https://nvd.nist.gov/vuln/detail/CVE-2026-24046) / [GHSA-rq6q-wr2q-7pgp](https://github.com/advisories/GHSA-rq6q-wr2q-7pgp) <details> <summary>More information</summary> #### Details ##### Impact Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to: 1. **Read arbitrary files** via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets) 2. **Delete arbitrary files** via the `fs:delete` action by creating symlinks pointing outside the workspace 3. **Write files outside the workspace** via archive extraction (tar/zip) containing malicious symlinks This affects any Backstage deployment where users can create or execute Scaffolder templates. ##### Patches This vulnerability is fixed in the following package versions: - `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, 0.15.0 - `@backstage/plugin-scaffolder-backend` version 2.2.2, 3.0.2, 3.1.1 - `@backstage/plugin-scaffolder-node` version 0.11.2, 0.12.3 Users should upgrade to these versions or later. ##### Workarounds - Follow the recommendation in the [Backstage Threat Model](https://backstage.io/docs/overview/threat-model#scaffolder) to limit access to creating and updating templates - Restrict who can create and execute Scaffolder templates using the permissions framework - Audit existing templates for symlink usage - Run Backstage in a containerized environment with limited filesystem access ##### References - [CWE-59: Improper Link Resolution Before File Access](https://cwe.mitre.org/data/definitions/59.html) - [OWASP Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal) #### Severity - CVSS Score: 7.1 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-rq6q-wr2q-7pgp](https://github.com/backstage/backstage/security/advisories/GHSA-rq6q-wr2q-7pgp) - [https://nvd.nist.gov/vuln/detail/CVE-2026-24046](https://nvd.nist.gov/vuln/detail/CVE-2026-24046) - [https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d](https://github.com/backstage/backstage/commit/c641c147ab371a9a8a2f5f67fdb7cb9c97ef345d) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-rq6q-wr2q-7pgp) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### @&#8203;backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass [CVE-2026-29184](https://nvd.nist.gov/vuln/detail/CVE-2026-29184) / [GHSA-8qp7-fhr9-fw53](https://github.com/advisories/GHSA-8qp7-fhr9-fw53) <details> <summary>More information</summary> #### Details ##### Impact A malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs. The attack requires: - The ability to register a template in the catalog - A victim who executes the malicious template ##### Patches Patched in `@backstage/plugin-scaffolder-backend` version 3.1.4 ##### Workarounds - Implement a custom permission policy that restricts scaffolder.task.read so users can only read their own task logs - Restrict who can register templates in the catalog to trusted users only ##### Resources - Backstage Scaffolder permissions documentation: https://backstage.io/docs/permissions/plugin-authors/01-setup/ - Backstage Threat Model: https://backstage.io/docs/overview/threat-model/ #### Severity - CVSS Score: 2.0 / 10 (Low) - Vector String: `CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N` #### References - [https://github.com/backstage/backstage/security/advisories/GHSA-8qp7-fhr9-fw53](https://github.com/backstage/backstage/security/advisories/GHSA-8qp7-fhr9-fw53) - [https://nvd.nist.gov/vuln/detail/CVE-2026-29184](https://nvd.nist.gov/vuln/detail/CVE-2026-29184) - [https://backstage.io/docs/overview/threat-model](https://backstage.io/docs/overview/threat-model) - [https://backstage.io/docs/permissions/plugin-authors/01-setup](https://backstage.io/docs/permissions/plugin-authors/01-setup) - [https://github.com/backstage/backstage](https://github.com/backstage/backstage) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-8qp7-fhr9-fw53) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>backstage/backstage (@&#8203;backstage/plugin-scaffolder-backend)</summary> ### [`v3.1.4`](https://github.com/backstage/backstage/blob/HEAD/plugins/scaffolder-backend/CHANGELOG.md#314-next0) [Compare Source](https://github.com/backstage/backstage/compare/c4d19ed1b6953eafbc30edc223c88bea6d5ef76b...96adbec3f93f94ec437026798604f290dc6f155c) ##### Patch Changes - [`4e39e63`](https://github.com/backstage/backstage/commit/4e39e63): Removed unused dependencies - Updated dependencies - [@&#8203;backstage/integration](https://github.com/backstage/integration)@&#8203;1.21.0-next.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.1.0-next.0 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.7.1-next.0 - [@&#8203;backstage/backend-openapi-utils](https://github.com/backstage/backend-openapi-utils)@&#8203;0.6.7-next.0 - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.7.6 - [@&#8203;backstage/config](https://github.com/backstage/config)@&#8203;1.3.6 - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.2.7 - [@&#8203;backstage/types](https://github.com/backstage/types)@&#8203;1.2.2 - [@&#8203;backstage/plugin-events-node](https://github.com/backstage/plugin-events-node)@&#8203;0.4.20-next.0 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.6 - [@&#8203;backstage/plugin-permission-node](https://github.com/backstage/plugin-permission-node)@&#8203;0.10.11-next.0 - [@&#8203;backstage/plugin-scaffolder-common](https://github.com/backstage/plugin-scaffolder-common)@&#8203;1.7.7-next.0 - [@&#8203;backstage/plugin-scaffolder-node](https://github.com/backstage/plugin-scaffolder-node)@&#8203;0.12.6-next.0 ### [`v3.1.3`](https://github.com/backstage/backstage/blob/HEAD/plugins/scaffolder-backend/CHANGELOG.md#313) [Compare Source](https://github.com/backstage/backstage/compare/86c4f358edda2a78a8168fdf48c08aef14882d82...c4d19ed1b6953eafbc30edc223c88bea6d5ef76b) ##### Patch Changes - [`7455dae`](https://github.com/backstage/backstage/commit/7455dae): Use node prefix on native imports - [`4fc7bf0`](https://github.com/backstage/backstage/commit/4fc7bf0): Removed unused dependency - [`0ce78b0`](https://github.com/backstage/backstage/commit/0ce78b0): Support `if` conditions inside `each` loops for scaffolder steps - [`5e3ef57`](https://github.com/backstage/backstage/commit/5e3ef57): Added `peerModules` metadata declaring recommended modules for cross-plugin integrations. - [`8148621`](https://github.com/backstage/backstage/commit/8148621): Moved `@backstage/backend-defaults` from `dependencies` to `devDependencies`. - [`1e669cc`](https://github.com/backstage/backstage/commit/1e669cc): Migrate audit events reference docs to <http://backstage.io/docs>. - [`69d880e`](https://github.com/backstage/backstage/commit/69d880e): Bump to latest zod to ensure it has the latest features - Updated dependencies - [@&#8203;backstage/plugin-scaffolder-backend-module-gitlab](https://github.com/backstage/plugin-scaffolder-backend-module-gitlab)@&#8203;0.11.3 - [@&#8203;backstage/integration](https://github.com/backstage/integration)@&#8203;1.20.0 - @&#8203;backstage/plugin-catalog-backend-module-scaffolder-entity-model\@&#8203;0.2.17 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;2.0.0 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-cloud\@&#8203;0.3.3 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket\@&#8203;0.3.19 - [@&#8203;backstage/plugin-scaffolder-backend-module-gerrit](https://github.com/backstage/plugin-scaffolder-backend-module-gerrit)@&#8203;0.2.18 - [@&#8203;backstage/plugin-scaffolder-backend-module-github](https://github.com/backstage/plugin-scaffolder-backend-module-github)@&#8203;0.9.6 - [@&#8203;backstage/plugin-scaffolder-backend-module-gitea](https://github.com/backstage/plugin-scaffolder-backend-module-gitea)@&#8203;0.2.18 - [@&#8203;backstage/backend-openapi-utils](https://github.com/backstage/backend-openapi-utils)@&#8203;0.6.6 - [@&#8203;backstage/plugin-bitbucket-cloud-common](https://github.com/backstage/plugin-bitbucket-cloud-common)@&#8203;0.3.7 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.7.0 - [@&#8203;backstage/plugin-scaffolder-node](https://github.com/backstage/plugin-scaffolder-node)@&#8203;0.12.5 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.13 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.6 - [@&#8203;backstage/plugin-permission-node](https://github.com/backstage/plugin-permission-node)@&#8203;0.10.10 - [@&#8203;backstage/plugin-events-node](https://github.com/backstage/plugin-events-node)@&#8203;0.4.19 - [@&#8203;backstage/plugin-scaffolder-backend-module-azure](https://github.com/backstage/plugin-scaffolder-backend-module-azure)@&#8203;0.2.18 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-server\@&#8203;0.2.18 - [@&#8203;backstage/plugin-scaffolder-common](https://github.com/backstage/plugin-scaffolder-common)@&#8203;1.7.6 ### [`v3.1.2`](https://github.com/backstage/backstage/blob/HEAD/plugins/scaffolder-backend/CHANGELOG.md#312-next0) [Compare Source](https://github.com/backstage/backstage/compare/e63a312b0c8d3b1e1333caf3eb5f576e9e59ee63...86c4f358edda2a78a8168fdf48c08aef14882d82) ##### Patch Changes - [`7455dae`](https://github.com/backstage/backstage/commit/7455dae): Use node prefix on native imports - [`4fc7bf0`](https://github.com/backstage/backstage/commit/4fc7bf0): Removed unused dependency - [`1e669cc`](https://github.com/backstage/backstage/commit/1e669cc): Migrate audit events reference docs to <http://backstage.io/docs>. - [`69d880e`](https://github.com/backstage/backstage/commit/69d880e): Bump to latest zod to ensure it has the latest features - Updated dependencies - @&#8203;backstage/plugin-catalog-backend-module-scaffolder-entity-model\@&#8203;0.2.17-next.0 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;1.21.0-next.0 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-cloud\@&#8203;0.3.2-next.0 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket\@&#8203;0.3.19-next.0 - [@&#8203;backstage/plugin-scaffolder-backend-module-gerrit](https://github.com/backstage/plugin-scaffolder-backend-module-gerrit)@&#8203;0.2.18-next.0 - [@&#8203;backstage/plugin-scaffolder-backend-module-github](https://github.com/backstage/plugin-scaffolder-backend-module-github)@&#8203;0.9.5-next.0 - [@&#8203;backstage/plugin-scaffolder-backend-module-gitlab](https://github.com/backstage/plugin-scaffolder-backend-module-gitlab)@&#8203;0.11.2-next.0 - [@&#8203;backstage/plugin-scaffolder-backend-module-gitea](https://github.com/backstage/plugin-scaffolder-backend-module-gitea)@&#8203;0.2.18-next.0 - [@&#8203;backstage/backend-openapi-utils](https://github.com/backstage/backend-openapi-utils)@&#8203;0.6.6-next.0 - [@&#8203;backstage/plugin-bitbucket-cloud-common](https://github.com/backstage/plugin-bitbucket-cloud-common)@&#8203;0.3.7-next.0 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.7.0-next.0 - [@&#8203;backstage/backend-defaults](https://github.com/backstage/backend-defaults)@&#8203;0.15.1-next.0 - [@&#8203;backstage/plugin-scaffolder-node](https://github.com/backstage/plugin-scaffolder-node)@&#8203;0.12.4-next.0 - [@&#8203;backstage/integration](https://github.com/backstage/integration)@&#8203;1.19.3-next.0 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.12-next.0 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.5-next.0 - [@&#8203;backstage/plugin-permission-node](https://github.com/backstage/plugin-permission-node)@&#8203;0.10.9-next.0 - [@&#8203;backstage/plugin-events-node](https://github.com/backstage/plugin-events-node)@&#8203;0.4.19-next.0 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-server\@&#8203;0.2.18-next.0 - [@&#8203;backstage/catalog-model](https://github.com/backstage/catalog-model)@&#8203;1.7.6 - [@&#8203;backstage/config](https://github.com/backstage/config)@&#8203;1.3.6 - [@&#8203;backstage/errors](https://github.com/backstage/errors)@&#8203;1.2.7 - [@&#8203;backstage/types](https://github.com/backstage/types)@&#8203;1.2.2 - [@&#8203;backstage/plugin-scaffolder-backend-module-azure](https://github.com/backstage/plugin-scaffolder-backend-module-azure)@&#8203;0.2.18-next.0 - [@&#8203;backstage/plugin-scaffolder-common](https://github.com/backstage/plugin-scaffolder-common)@&#8203;1.7.6-next.0 ### [`v3.1.1`](https://github.com/backstage/backstage/blob/HEAD/plugins/scaffolder-backend/CHANGELOG.md#311) [Compare Source](https://github.com/backstage/backstage/compare/d03fd681a91928c65419df989d9fc4adef3a2dba...e63a312b0c8d3b1e1333caf3eb5f576e9e59ee63) ##### Patch Changes - [`5012852`](https://github.com/backstage/backstage/commit/5012852): Remove unused abort controller in debug:wait action - [`c641c14`](https://github.com/backstage/backstage/commit/c641c14): Wrap some of the action logic with `resolveSafeChildPath` and improve symlink handling when fetching remote and local files - [`27f9061`](https://github.com/backstage/backstage/commit/27f9061): REwrite] - [`872eb91`](https://github.com/backstage/backstage/commit/872eb91): Upgrade `zod-to-json-schema` to latest version - Updated dependencies - [@&#8203;backstage/backend-defaults](https://github.com/backstage/backend-defaults)@&#8203;0.15.0 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.6.1 - [@&#8203;backstage/plugin-scaffolder-node](https://github.com/backstage/plugin-scaffolder-node)@&#8203;0.12.3 - [@&#8203;backstage/integration](https://github.com/backstage/integration)@&#8203;1.19.2 - [@&#8203;backstage/backend-openapi-utils](https://github.com/backstage/backend-openapi-utils)@&#8203;0.6.5 - [@&#8203;backstage/plugin-scaffolder-backend-module-github](https://github.com/backstage/plugin-scaffolder-backend-module-github)@&#8203;0.9.4 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.11 - [@&#8203;backstage/plugin-scaffolder-backend-module-azure](https://github.com/backstage/plugin-scaffolder-backend-module-azure)@&#8203;0.2.17 - [@&#8203;backstage/plugin-permission-common](https://github.com/backstage/plugin-permission-common)@&#8203;0.9.4 - [@&#8203;backstage/plugin-permission-node](https://github.com/backstage/plugin-permission-node)@&#8203;0.10.8 - [@&#8203;backstage/plugin-bitbucket-cloud-common](https://github.com/backstage/plugin-bitbucket-cloud-common)@&#8203;0.3.6 - @&#8203;backstage/plugin-catalog-backend-module-scaffolder-entity-model\@&#8203;0.2.16 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket\@&#8203;0.3.18 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-cloud\@&#8203;0.3.1 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-server\@&#8203;0.2.17 - [@&#8203;backstage/plugin-scaffolder-backend-module-gerrit](https://github.com/backstage/plugin-scaffolder-backend-module-gerrit)@&#8203;0.2.17 - [@&#8203;backstage/plugin-scaffolder-backend-module-gitea](https://github.com/backstage/plugin-scaffolder-backend-module-gitea)@&#8203;0.2.17 - [@&#8203;backstage/plugin-scaffolder-backend-module-gitlab](https://github.com/backstage/plugin-scaffolder-backend-module-gitlab)@&#8203;0.11.1 - [@&#8203;backstage/plugin-scaffolder-common](https://github.com/backstage/plugin-scaffolder-common)@&#8203;1.7.5 ### [`v3.1.0`](https://github.com/backstage/backstage/blob/HEAD/plugins/scaffolder-backend/CHANGELOG.md#310) [Compare Source](https://github.com/backstage/backstage/compare/1445ffd3f6a4084fa7f79e86ad3c32930393461d...d03fd681a91928c65419df989d9fc4adef3a2dba) ##### Minor Changes - [`a4cd405`](https://github.com/backstage/backstage/commit/a4cd405): Add `defaultEnvironment` config to scaffolder to enable more flexible and custom templates. Now it's possible enable access to default parameters and secrets in templates, improving security and reducing complexity. ##### Patch Changes - [`be5972b`](https://github.com/backstage/backstage/commit/be5972b): Fixed a bug where config was not passed to NunjucksWorkflowRunner, causing defaultEnvironment to be undefined - [`de96a60`](https://github.com/backstage/backstage/commit/de96a60): chore(deps): bump `express` from 4.21.2 to 4.22.0 - [`2bae83a`](https://github.com/backstage/backstage/commit/2bae83a): Updated `isolated-vm` to `6.0.1` - [`25b560e`](https://github.com/backstage/backstage/commit/25b560e): Internal change to support new versions of the `logform` library - [`8f4aded`](https://github.com/backstage/backstage/commit/8f4aded): Fixing OpenAPI definition - [`1226647`](https://github.com/backstage/backstage/commit/1226647): Updated dependency `esbuild` to `^0.27.0`. - Updated dependencies - [@&#8203;backstage/plugin-scaffolder-backend-module-gitlab](https://github.com/backstage/plugin-scaffolder-backend-module-gitlab)@&#8203;0.11.0 - [@&#8203;backstage/integration](https://github.com/backstage/integration)@&#8203;1.19.0 - [@&#8203;backstage/plugin-auth-node](https://github.com/backstage/plugin-auth-node)@&#8203;0.6.10 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-cloud\@&#8203;0.3.0 - [@&#8203;backstage/plugin-bitbucket-cloud-common](https://github.com/backstage/plugin-bitbucket-cloud-common)@&#8203;0.3.5 - [@&#8203;backstage/backend-defaults](https://github.com/backstage/backend-defaults)@&#8203;0.14.0 - [@&#8203;backstage/backend-openapi-utils](https://github.com/backstage/backend-openapi-utils)@&#8203;0.6.4 - [@&#8203;backstage/plugin-events-node](https://github.com/backstage/plugin-events-node)@&#8203;0.4.18 - [@&#8203;backstage/plugin-permission-node](https://github.com/backstage/plugin-permission-node)@&#8203;0.10.7 - [@&#8203;backstage/backend-plugin-api](https://github.com/backstage/backend-plugin-api)@&#8203;1.6.0 - [@&#8203;backstage/plugin-scaffolder-backend-module-github](https://github.com/backstage/plugin-scaffolder-backend-module-github)@&#8203;0.9.3 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket-server\@&#8203;0.2.16 - @&#8203;backstage/plugin-scaffolder-backend-module-bitbucket\@&#8203;0.3.17 - @&#8203;backstage/plugin-catalog-backend-module-scaffolder-entity-model\@&#8203;0.2.15 - [@&#8203;backstage/plugin-catalog-node](https://github.com/backstage/plugin-catalog-node)@&#8203;1.20.1 - [@&#8203;backstage/plugin-scaffolder-backend-module-azure](https://github.com/backstage/plugin-scaffolder-backend-module-azure)@&#8203;0.2.16 - [@&#8203;backstage/plugin-scaffolder-backend-module-gerrit](https://github.com/backstage/plugin-scaffolder-backend-module-gerrit)@&#8203;0.2.16 - [@&#8203;backstage/plugin-scaffolder-backend-module-gitea](https://github.com/backstage/plugin-scaffolder-backend-module-gitea)@&#8203;0.2.16 - [@&#8203;backstage/plugin-scaffolder-common](https://github.com/backstage/plugin-scaffolder-common)@&#8203;1.7.4 - [@&#8203;backstage/plugin-scaffolder-node](https://github.com/backstage/plugin-scaffolder-node)@&#8203;0.12.2 ### [`v3.0.3`](https://github.com/backstage/backstage/compare/3a50585da82823ade977eb94a5ff2c799b24239e...1445ffd3f6a4084fa7f79e86ad3c32930393461d) [Compare Source](https://github.com/backstage/backstage/compare/3a50585da82823ade977eb94a5ff2c799b24239e...1445ffd3f6a4084fa7f79e86ad3c32930393461d) ### [`v3.0.2`](https://github.com/backstage/backstage/compare/cd79f31c8ccb6d611bac2cfb13a019a555132011...3a50585da82823ade977eb94a5ff2c799b24239e) [Compare Source](https://github.com/backstage/backstage/compare/cd79f31c8ccb6d611bac2cfb13a019a555132011...3a50585da82823ade977eb94a5ff2c799b24239e) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNzEuMyIsInVwZGF0ZWRJblZlciI6IjQzLjI3MS4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJkZXBlbmRlbmNpZXMiLCJyZW5vdmF0ZSIsInNlY3VyaXR5IiwidHlwZS9taW5vciJdfQ==-->
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-backstage-plugin-scaffolder-backend-vulnerability:renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git switch renovate/npm-backstage-plugin-scaffolder-backend-vulnerability

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git switch renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git rebase main
git switch main
git merge --ff-only renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git switch renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git rebase main
git switch main
git merge --no-ff renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git switch main
git merge --squash renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git switch main
git merge --ff-only renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git switch main
git merge renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
git push origin main
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/backstage-application!86
No description provided.