Update dependency @backstage/plugin-scaffolder-backend [SECURITY] - abandoned - #9491
Closed
backstage-goalie[bot] wants to merge 2 commits into
Closed
Conversation
backstage-goalie
Bot
requested review from
a team,
aljesusg,
deepan10,
deshmukhmayur,
josunect,
riginoommen and
yashoswalyo
as code owners
June 15, 2026 21:15
Contributor
Author
Missing ChangesetsThe following package(s) are changed by this PR but do not have a changeset:
See CONTRIBUTING.md for more information about how to add changesets. Changed Packages
|
backstage-goalie
Bot
deleted the
renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
branch
June 16, 2026 09:54
backstage-goalie
Bot
force-pushed
the
renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
branch
2 times, most recently
from
June 16, 2026 15:52
df1df1e to
d9cf2d4
Compare
backstage-goalie
Bot
force-pushed
the
renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
branch
2 times, most recently
from
June 17, 2026 15:17
d9cf2d4 to
979749c
Compare
backstage-goalie
Bot
force-pushed
the
renovate/npm-backstage-plugin-scaffolder-backend-vulnerability
branch
from
June 23, 2026 16:17
0610eb3 to
def0c1f
Compare
Signed-off-by: Renovate Bot <bot@renovateapp.com>
The updated @backstage/plugin-scaffolder-backend transitively pulls in zod v4 and @backstage/backend-plugin-api@1.9.2, which require TypeScript >=5.4 (NoInfer utility type) and >=5.8 (TS2742 fix). Regenerate kiali API reports to match the new type inference. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Andre Wanlin <awanlin@spotify.com>
awanlin
approved these changes
Jul 3, 2026
awanlin
left a comment
Contributor
There was a problem hiding this comment.
Approving then will merge based on agreement to force merged PRs with that label 👍
| "@backstage/plugin-permission-node": "^0.10.2", | ||
| "@backstage/plugin-proxy-backend": "^0.6.4", | ||
| "@backstage/plugin-scaffolder-backend": "^2.1.0", | ||
| "@backstage/plugin-scaffolder-backend": "^3.0.0", |
Comment on lines
7
to
9
| // @public | ||
| export const config: { | ||
| session: { | ||
| timeOutforWarningUser: number; | ||
| }; | ||
| toolbar: { | ||
| defaultDuration: number; | ||
| defaultRefreshInterval: number; | ||
| defaultTimeRange: { | ||
| rangeDuration: number; | ||
| }; | ||
| refreshInterval: { | ||
| 0: string; | ||
| 10000: string; | ||
| 15000: string; | ||
| 30000: string; | ||
| 60000: string; | ||
| 300000: string; | ||
| 900000: string; | ||
| }; | ||
| graphLayouts: { | ||
| 'kiali-grid': string; | ||
| 'kiali-concentric': string; | ||
| 'kiali-dagre': string; | ||
| }; | ||
| }; | ||
| tracing: { | ||
| configuration: { | ||
| limitResults: { | ||
| 20: number; | ||
| 50: number; | ||
| 100: number; | ||
| 200: number; | ||
| 300: number; | ||
| 400: number; | ||
| 500: number; | ||
| }; | ||
| statusCode: { | ||
| none: string; | ||
| 200: string; | ||
| 400: string; | ||
| 401: string; | ||
| 403: string; | ||
| 404: string; | ||
| 405: string; | ||
| 408: string; | ||
| 500: string; | ||
| 502: string; | ||
| 503: string; | ||
| 504: string; | ||
| }; | ||
| }; | ||
| }; | ||
| about: { | ||
| project: { | ||
| url: string; | ||
| icon: string; | ||
| linkText: string; | ||
| }; | ||
| website: { | ||
| url: string; | ||
| icon: string; | ||
| linkText: string; | ||
| }; | ||
| }; | ||
| documentation: { | ||
| url: string; | ||
| }; | ||
| login: { | ||
| headers: { | ||
| 'X-Auth-Type-Kiali-UI': string; | ||
| }; | ||
| }; | ||
| api: { | ||
| urls: { | ||
| aggregateGraphElements: (namespace: string, aggregate: string, aggregateValue: string) => string; | ||
| aggregateByServiceGraphElements: (namespace: string, aggregate: string, aggregateValue: string, service: string) => string; | ||
| aggregateMetrics: (namespace: string, aggregate: string, aggregateValue: string) => string; | ||
| authenticate: string; | ||
| authInfo: string; | ||
| app: (namespace: string, app: string) => string; | ||
| appGraphElements: (namespace: string, app: string, version?: string) => string; | ||
| appHealth: (namespace: string, app: string) => string; | ||
| appMetrics: (namespace: string, app: string) => string; | ||
| appDashboard: (namespace: string, app: string) => string; | ||
| appSpans: (namespace: string, app: string) => string; | ||
| clusters: string; | ||
| clustersHealth: () => string; | ||
| clustersWorkloads: () => string; | ||
| crippledFeatures: string; | ||
| serviceSpans: (namespace: string, service: string) => string; | ||
| workloadSpans: (namespace: string, workload: string) => string; | ||
| customDashboard: (namespace: string, template: string) => string; | ||
| grafana: string; | ||
| istioConfig: (namespace: string) => string; | ||
| allIstioConfigs: () => string; | ||
| istioConfigCreate: (namespace: string, objectType: string) => string; | ||
| istioConfigDetail: (namespace: string, objectType: string, object: string, apiVersion?: string) => string; | ||
| istioConfigDelete: (namespace: string, objectType: string, object: string) => string; | ||
| istioConfigUpdate: (namespace: string, objectType: string, object: string) => string; | ||
| istioPermissions: string; | ||
| jaeger: string; | ||
| appTraces: (namespace: string, app: string) => string; | ||
| serviceTraces: (namespace: string, svc: string) => string; | ||
| workloadTraces: (namespace: string, wkd: string) => string; | ||
| jaegerErrorTraces: (namespace: string, app: string) => string; | ||
| jaegerTrace: (idTrace: string) => string; | ||
| logout: string; | ||
| metricsStats: string; | ||
| namespaces: string; | ||
| namespace: (namespace: string) => string; | ||
| namespacesGraphElements: string; | ||
| namespaceMetrics: (namespace: string) => string; | ||
| namespaceTls: (namespace: string) => string; | ||
| namespaceValidations: (namespace: string) => string; | ||
| configValidations: () => string; | ||
| meshTls: () => string; | ||
| istioStatus: () => string; | ||
| istioCertsInfo: () => string; | ||
| pod: (namespace: string, pod: string) => string; | ||
| podLogs: (namespace: string, pod: string) => string; | ||
| podEnvoyProxy: (namespace: string, pod: string) => string; | ||
| podEnvoyProxyLogging: (namespace: string, pod: string) => string; | ||
| podEnvoyProxyResourceEntries: (namespace: string, pod: string, resource: string) => string; | ||
| serverConfig: string; | ||
| service: (namespace: string, service: string) => string; | ||
| serviceGraphElements: (namespace: string, service: string) => string; | ||
| serviceHealth: (namespace: string, service: string) => string; | ||
| serviceMetrics: (namespace: string, service: string) => string; | ||
| serviceDashboard: (namespace: string, service: string) => string; | ||
| clustersApps: () => string; | ||
| clustersServices: () => string; | ||
| clustersMetrics: () => string; | ||
| status: string; | ||
| workload: (namespace: string, workload: string) => string; | ||
| workloadGraphElements: (namespace: string, workload: string) => string; | ||
| workloadHealth: (namespace: string, workload: string) => string; | ||
| workloadMetrics: (namespace: string, workload: string) => string; | ||
| workloadDashboard: (namespace: string, workload: string) => string; | ||
| }; | ||
| }; | ||
| graph: { | ||
| maxHosts: number; | ||
| }; | ||
| }; | ||
| export const config: typeof conf; | ||
|
|
| "prettier": "^3.6.2", | ||
| "prettier-plugin-sort-imports": "^1.8.8", | ||
| "typescript": "~5.3.0" | ||
| "typescript": "~5.8.0" |
| "node-gyp": "^9.0.0", | ||
| "prettier": "^2.3.2", | ||
| "typescript": "~5.3.0" | ||
| "typescript": "~5.8.0" |
Contributor
Author
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
Contributor
Author
Autoclosing SkippedThis PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error. |
Contributor
|
Closing due to changes. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^2.1.0→^3.0.03.0.0→3.1.43.1.4→3.1.5Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
CVE-2026-24046 / GHSA-rq6q-wr2q-7pgp
More information
Details
Impact
Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:
debug:logaction by creating a symlink pointing to sensitive files (e.g.,/etc/passwd, configuration files, secrets)fs:deleteaction by creating symlinks pointing outside the workspaceThis affects any Backstage deployment where users can create or execute Scaffolder templates.
Patches
This vulnerability is fixed in the following package versions:
@backstage/backend-defaultsversion 0.12.2, 0.13.2, 0.14.1, 0.15.0@backstage/plugin-scaffolder-backendversion 2.2.2, 3.0.2, 3.1.1@backstage/plugin-scaffolder-nodeversion 0.11.2, 0.12.3Users should upgrade to these versions or later.
Workarounds
References
Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:LReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
@backstage/plugin-scaffolder-backend Vulnerable to Potential Session Token Exfiltration via Log Redaction Bypass
CVE-2026-29184 / GHSA-8qp7-fhr9-fw53
More information
Details
Impact
A malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run through task event logs.
The attack requires:
Patches
Patched in
@backstage/plugin-scaffolder-backendversion 3.1.4Workarounds
Resources
Severity
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
@backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets using dry-run endpoint
CVE-2026-32237 / GHSA-8wq8-6859-qx77
More information
Details
Impact
Authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly
redacted in log output but not in all parts of the response payload.
Deployments that have configured
scaffolder.defaultEnvironment.secretsare affected.Patches
This is patched in
@backstage/plugin-scaffolder-backendversion 3.1.5Workarounds
Remove or empty the
scaffolder.defaultEnvironment.secretsconfiguration fromapp-config.yaml. Alternatively, restrict access to the scaffolder dry-run functionality via thepermissions framework.
References
Severity
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/plugin-scaffolder-backend)
v3.1.4Compare Source
Patch Changes
4e39e63: Removed unused dependenciesv3.1.3Compare Source
Patch Changes
7455dae: Use node prefix on native imports4fc7bf0: Removed unused dependency0ce78b0: Supportifconditions insideeachloops for scaffolder steps5e3ef57: AddedpeerModulesmetadata declaring recommended modules for cross-plugin integrations.8148621: Moved@backstage/backend-defaultsfromdependenciestodevDependencies.1e669cc: Migrate audit events reference docs to http://backstage.io/docs.69d880e: Bump to latest zod to ensure it has the latest featuresv3.1.2Compare Source
Patch Changes
7455dae: Use node prefix on native imports4fc7bf0: Removed unused dependency1e669cc: Migrate audit events reference docs to http://backstage.io/docs.69d880e: Bump to latest zod to ensure it has the latest featuresv3.1.1Compare Source
Patch Changes
5012852: Remove unused abort controller in debug:wait actionc641c14: Wrap some of the action logic withresolveSafeChildPathand improve symlink handling when fetching remote and local files27f9061: REwrite]872eb91: Upgradezod-to-json-schemato latest versionv3.1.0Compare Source
Minor Changes
a4cd405: AdddefaultEnvironmentconfig to scaffolder to enable more flexible and custom templates. Now it's possible enable access to default parameters and secrets in templates, improving security and reducing complexity.Patch Changes
be5972b: Fixed a bug where config was not passed to NunjucksWorkflowRunner, causing defaultEnvironment to be undefinedde96a60: chore(deps): bumpexpressfrom 4.21.2 to 4.22.02bae83a: Updatedisolated-vmto6.0.125b560e: Internal change to support new versions of thelogformlibrary8f4aded: Fixing OpenAPI definition1226647: Updated dependencyesbuildto^0.27.0.v3.0.3Compare Source
v3.0.2Compare Source
v3.0.1Compare Source
Patch Changes
05f60e1: Refactored constructor parameter properties to explicit property declarations for compatibility with TypeScript'serasableSyntaxOnlysetting. This internal refactoring maintains all existing functionality while ensuring TypeScript compilation compatibility.v3.0.0Compare Source
Major Changes
9b81a90: BREAKING - Removing the deprecated types and interfaces, there's no replacement for these types, and hopefully not currently used as they offer no value with the plugin being on the new backend system and no way to consume them.Affected types:
CreateWorkerOptions,CurrentClaimedTask,DatabaseTaskStore,DatabaseTaskStoreOptions,TaskManager,TaskStore,TaskStoreCreateTaskOptions,TaskStoreCreateTaskResult,TaskStoreEmitOptions,TaskStoreListEventsOptions,TaskStoreRecoverTaskOptions,TaskStoreShutDownTaskOptions,TaskWorkerandTemplateActionRegistry.Patch Changes
f222a2e: Fixed distributed actions not being visible in the scaffolder template actions.Depending on the plugin startup order, some of the distributed actions were not being registered correctly,
causing them to be invisible in the scaffolder template actions list.
Updated dependencies
v2.2.3Compare Source
v2.2.2Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.