Repository navigation
Update dependency @backstage/backend-defaults to ^0.12.0 [SECURITY] - #10
Open
renovate-wibrow[bot] wants to merge 1 commit into
Open
renovate-wibrow[bot] wants to merge 1 commit into
renovate-wibrow[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.3.0→^0.12.0Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
CVE-2026-24046 / GHSA-rq6q-wr2q-7pgp
More information
Details
Impact
Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:
debug:logaction by creating a symlink pointing to sensitive files (e.g.,/etc/passwd, configuration files, secrets)fs:deleteaction by creating symlinks pointing outside the workspaceThis affects any Backstage deployment where users can create or execute Scaffolder templates.
Patches
This vulnerability is fixed in the following package versions:
@backstage/backend-defaultsversion 0.12.2, 0.13.2, 0.14.1, 0.15.0@backstage/plugin-scaffolder-backendversion 2.2.2, 3.0.2, 3.1.1@backstage/plugin-scaffolder-nodeversion 0.11.2, 0.12.3Users should upgrade to these versions or later.
Workarounds
References
Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Backstage has a Possible SSRF when reading from allowed URL's in
backend.reading.allowCVE-2026-24048 / GHSA-q2x5-4xjx-c6p9
More information
Details
Impact
The
FetchUrlReadercomponent, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. This allowed an attacker who controls a host listed inbackend.reading.allowto redirect requests to internal or sensitive URLs that are not on the allowlist, bypassing the URL allowlist security control.This is a Server-Side Request Forgery (SSRF) vulnerability that could allow access to internal resources, but it does not allow attackers to include additional request headers.
Patches
This vulnerability is fixed in
@backstage/backend-defaultsversion 0.12.2, 0.13.2, 0.14.1, and 0.15.0. Users should upgrade to this version or later.Workarounds
backend.reading.allowto only trusted hosts that you control and that do not issue redirectsReferences
Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/backend-defaults)
v0.12.2Compare Source
v0.12.1Compare Source
Patch Changes
33bd4d0: Deduplicate discovered features discovered with discoveryFeatureLoader4eda590: Fixed cache namespace and key prefix separator configuration to properly use configured values instead of hardcoded plugin ID. The cache manager now correctly combines the configured namespace with plugin IDs using the configured separator for Redis and Valkey. Memcache and memory store continue to use plugin ID as namespace.f244e61: Addbackend.loggerconfig options to configure theRootLoggerService.Read more about the new configuration options in the
Root Logger Service
documentation.
Updated dependencies
v0.12.0Compare Source
Minor Changes
133519b: feat: new cache managerInfinispan Data GridPatch Changes
caee2eb: Fixed WinstonLogger throwing when redactions were null or undefineded74af5: Fixed bug in PackageDiscoveryService where packages with "exports" field caused ERR_PACKAGE_PATH_NOT_EXPORTED error during backend startup.3a7dad9: Updatedbetter-sqlite3to v12v0.11.1Compare Source
Patch Changes
ead925a: Add a standardtoStringon credentials objectse0189b8: UrlReader: Fix handling of access tokens for GitLab readURL requestsd1e4a6d: Fixed bug where the GitLab user token and GitLab integration token were being merged togetherv0.11.0Compare Source
Minor Changes
3ccb7fc: Enhanced error handling in the auditor service factory to pass errors as objects. Aligned WinstonRootAuditorService with the default service factory's error handling.Patch Changes
1220cf8: Added new rate limit middleware to allow rate limiting requests to the backendIf you are using the
configurecallback of the root HTTP router service and do NOT callapplyDefaults()inside it, please see the relevant changes that were made, to see if you want to apply them as well to your custom configuration.Rate limiting can be turned on by adding the following configuration to
app-config.yaml:Plugin specific rate limiting can be configured by adding the following configuration to
app-config.yaml:c999c25: Added some default implementations for the experimentalActionsServiceandActionsRegistryServiceunder/alphathat allow registration of actions for a particular plugin.Updated dependencies
v0.10.0Compare Source
Minor Changes
d385854: BREAKING: TheDefaultSchedulerServiceconstructor options now requiresRootLifecycleService,HttpRouterService, andPluginMetadataServicefields.The scheduler will register a REST API for listing and triggering tasks. Please see the scheduler documentation for more details about this API.
Patch Changes
1e06afd:GithubUrlReader's search detects glob-patterns supported byminimatch, instead of just detecting*and?characters.For example, this allows to search for patterns like
{C,c}atalog-info.yaml.acea1d4: update documentation72d019d: Removed various typosc6bc67d: Added Valkey support alongside Redis in backend-defaults cache clients, using the new Keyv Valkey package. Also extended backend-test-utils to support Valkey in tests.36f77e9: Bug fix: Pass user provided token through to gitlab url resolvers0e7a640: TheGithubUrlReaderwill now use the token fromoptionswhen fetching repo detailsUpdated dependencies
v0.9.0Compare Source
Minor Changes
1daedce: Remove Throttle of Bitbucket Server API calls01edf6e: Allow pass through of redis client and cluster options to Cache core servicecf4eb13: Addedactorproperty toBackstageUserPrincipalcontaining the subject of the last service (if any) who performed authentication on behalf of the user.Patch Changes
7c6740e: Implemented SRV lookup support in the defaultHostDiscovery. You can now specify internal URLs on the formhttp+srv://some-srv-name/api/{{pluginId}}and they will be resolved in real time.939116c: Added an optionalbackend.trustProxyapp config value, which sets thecorresponding Express.js
trust proxysetting. This letsyou easily configure proxy trust without making a custom
configurecallbackfor the
rootHttpRouterservice.If you already are using a custom
configurecallback, and if that also does not callapplyDefaults(), you may want to add the following to it:175528c: Addsbackend.auditor.severityLogLevelMappingsto map severity levels to log levels.Updated dependencies
v0.8.2Compare Source
Patch Changes
e293b66: The default auditor service implementation will now log low severity events withdebuglevel instead ofinfo.f422984: Remove unused dependenciesecb9bab: Explicitly stringify extra logger fields withJSON.stringifyto prevent[object Object]errors.12f8e01: Thediscovery.endpointsconfiguration no longer requires bothinternalandexternaltarget when using the object form, instead falling back to the default.89db8b8:GerritUrlReaderis now able tosearchfiles matching a given pattern URL (usingminimatchglob patterns).This allows the Gerrit Discovery to find all Backstage manifests inside a repository using the
**/catalog-info.yamlpattern.Updated dependencies
v0.8.1Compare Source
Release a newer version of
@backstage/techdocs-commonincluding a bug fix #4088.v0.8.0Compare Source
Minor Changes
a4aa244: This change introduces theauditorservice implementation details.Patch Changes
f866b86: Internal refactor to use explicitrequirefor lazy-loading dependency.92a56f6: Internal refactor to stop importing the removedFeatureDiscoveryServicefrom@backstage/backend-plugin-api.a19cb2b: Added default implementation for the newPermissionsRegistryService.0d39029: Do not sendetagorIf-Modified-Sinceheaders for gitlab artifact urlsc7609de: Allow passing IP type to use with cloud-sql-connector3740229: In the differentUrlReadersService, thesearchmethod have been updated to use thereadUrlif the given URL doesn't contain a pattern.For
UrlReadersthat didn't implement thesearchmethod,readUrlis now called internally and throws if the given URL doesn't contain a pattern.72cddf2: UpdatedPermissionsRegistryServiceto usePermissionResourceRefs and added thegetPermissionRulesetmethod.v0.7.0Compare Source
Minor Changes
ec547b8: Ensure that an error handler middleware exists at the end of each pluginhttpRouterhandler chain. This makes it so that exceptions thrown by plugin routes are caught and encoded in the standard error format.If you were using the standard
MiddlewareFactoryjust to put anerrormiddleware in you router, you can now remove that at your earliest convenience since it's redundant. If you have custom error handlers in your plugin router, those will continue to function as previously. If you were relying on thrown errors propagating all the way down to the root HTTP router, you will find that they no longer do that, and may want to hoist your error handling up to the plugin level instead.Patch Changes
575613f: Go back to usingnode-fetchfor gitlabd2b16db: TheGerritUrlReadercan now read content from a commit and not only from the top of a branch. TheGitiles URL must contain the full commit
SHAhash like:https://gerrit.com/gitiles/repo/+/2846e8dc327ae2f60249983b1c3b96f42f205bae/catalog-info.yaml.8ecf8cb: Exclude@backstage/backend-commonfrom schema collection if@backstage/backend-defaultsis present8379bf4: Remove usages ofPluginDatabaseManagerandPluginEndpointDiscoveryand replace with their equivalent service typesv0.6.2Compare Source
v0.6.1Compare Source
v0.6.0Compare Source
Minor Changes
fd5d337: Added a newbackend.health.headersconfiguration that can be used to set additional headers to include in health check responses.BREAKING CONSUMERS: As part of this change the
createHealthRouterfunction exported from@backstage/backend-defaults/rootHttpRouternow requires the root config service to be passed through theconfigoption.3f34ea9: Throttles Bitbucket Server API callsde6f280: BREAKING Upgraded @keyv/redis and keyv packages to resolve a bug related to incorrect resolution of cache keys.This is a breaking change for clients using the
redisstore for cache withuseRedisSetsoption set to false since cache keys will be calculated differently (without the sets:namespace: prefix). For clients with default configuration (or useRedisSets set to false) the cache keys will stay the same, but since @keyv/redis library no longer supports redis sets they won't be utilised anymore.If you were using
useRedisSetsoption in configuration make sure to remove it fromapp-config.yaml:backend: cache: store: redis connection: redis://user:pass@cache.example.com:6379 - useRedisSets: false29180ec: BREAKING PRODUCERS: TheLifecycleMiddlewareOptions.startupRequestPauseTimeouthas been removed. Use thebackend.lifecycle.startupRequestPauseTimeoutsetting in yourapp-config.yamlfile to customize how thecreateLifecycleMiddlewarefunction should behave. Also the root config service is required as an option when calling thecreateLifecycleMiddlewarefunction:277092a: ImplementedAzureBlobStorageUrlReaderto read from the url of committed location from the entity provider18a2c00: All middleware used by the defaultcoreServices.httpis now exported for use by custom implementations.Patch Changes
dfc8b41: Updated dependency@opentelemetry/apito^1.9.0.5b1e68c: Immediately close all connections when shutting down in local development.8863b38: ExportPluginTokenHandlerandpluginTokenHandlerDecoratorServiceRefto allow for custom decoration of the plugin token handler without having to re-implement the entire handler.29180ec: Fix server response time by moving the lifecycle startup hooks back to the plugin lifecycle service.57e0b11: The user and plugin token verification in the defaultAuthServiceimplementation will no longer forward verification errors to the caller, and instead log them as warnings.97c6837: ExportDefaultHttpAuthServiceto allow for custom token extraction logic.e5255f1: Log request and response metadata so it can be used for filtering log messages.The format of the request date was also changed from
clftoutc.57e0b11: The defaultauthServiceFactorynow correctly depends on the plugin scopedLoggerservices rather than the root scoped one.fe87fbf: Add task metrics as two gauges that track the last start and end timestamps as epoch seconds.1ac6b72: Supportconnection.type: cloudsqlin database client for usage with@google-cloud/cloud-sql-connectorandiamauth0e9c9fa: Implements theDefaultRootLifecycleService.addBeforeShutdownHookmethod, and updatesDefaultRootHttpRouterServiceandDefaultRootHealthServiceto listen to that event to stop accepting traffic and close service connections.d0cbd82: Remove use of thestoppablelibrary on theDefaultRootHttpRouterServiceas Node's native http server close method already drains requests.5c9cc05: Use native fetch instead of node-fetchcf627c6: Fixed an issue in the WinstonLogger where Errors thrown and given to logger.error with field values that could not be cast to a string would throw a TypeErrorv0.5.3Compare Source
Patch Changes
bf306cb: Removed dependency@backstage/backend-common.e30bb46: Disabling database migrations now correctly uses thebackend.default.skipMigrationsconfig value.d52d7f9: Support ISO and ms string forms of durations in config toof6eaec2: Link to proper package inrootLoggerServiceFactorydoc string.ecf6b39: Usenode-fetchinstead of native fetch, as per https://backstage.io/docs/architecture-decisions/adrs-adr0134e58bc7: Upgrade to uuid v11 internallyv0.5.2Compare Source
v0.5.1Compare Source
Patch Changes
4b60e0c: Small tweaks to API reports to make them valid321a994: Sensitive internal fields onBackstageCredentialsobjects are now defined as read-only properties in order to minimize risk of leakage.ffd1f4a: Plugin lifecycle shutdown hooks are now performed before root lifecycle shutdown hooks.ffd1f4a: The database manager now attempts to close any database connections in a root lifecycle shutdown hook.e36d12f: The task scheduler now attempts to abort any tasks if it detects that Backstage is being shut down.fd6e6f4: build(deps): bumpcookiefrom 0.6.0 to 0.7.0094eaa3: Remove references to in-repo backend-common720a2f9: Updated dependencygit-url-parseto^15.0.0.920004b: Updating error message for getProjectId when fetching Gitlab project from its url to be more accurated7b44f0: Fix for backend shutdown hanging during local development due to SQLite connection shutdown never resolving.8fd7deb: The default root HTTP service implementation will now pretty-print JSON responses in development.If you are overriding the
rootHttpRouterServiceFactorywith aconfigurefunction that doesn't callapplyDefaults, you can introduce this functionality by adding the following snippet insideconfigure:Updated dependencies
v0.5.0Compare Source
Minor Changes
a4bac3c: BREAKING: You can no longer supply abasePathoption to the host discovery implementation. In the new backend system, the ability to choose this path has been removed anyway at the plugin router level.359fcd7: BREAKING: The backwards compatibility with plugins using legacy auth through the token manager service has been removed. This means that instead of falling back to using the old token manager, requests towards plugins that don't support the new auth system will simply fail. Please make sure that all plugins in your deployment are hosted within a backend instance from the new backend system.baeef13: BREAKING RemovedcreateLifecycleMiddlewareandLifecycleMiddlewareOptionsto clean up API surface. These exports have no external usage and do not provide value in its current form. If you were using these exports, please reach out to the maintainers to discuss your use case.d425fc4: BREAKING: The return values fromcreateBackendPlugin,createBackendModule, andcreateServiceFactoryare now simplyBackendFeatureandServiceFactory, instead of the previously deprecated form of a function that returns them. For this reason,createServiceFactoryalso no longer accepts the callback form where you provide direct options to the service. This also affects allcoreServices.*service refs.This may in particular affect tests; if you were effectively doing
createBackendModule({...})()(note the parentheses), you can now remove those extra parentheses at the end. You may encounter cases of this in yourpackages/backend/src/index.tstoo, where you add plugins, modules, and services. If you were usingcreateServiceFactorywith a function as its argument for the purpose of passing in options, this pattern has been deprecated for a while and is no longer supported. You may want to explore the new multiton patterns to achieve your goals, or moving settings to app-config.As part of this change, the
IdentityFactoryOptionstype was removed, and can no longer be used to tweak that service. The identity service was also deprecated some time ago, and you will want to migrate to the new auth system if you still rely on it.19ff127: BREAKING: The default backend instance no longer provides implementations for the identity and token manager services, which have been removed from@backstage/backend-plugin-api.If you rely on plugins that still require these services, you can add them to your own backend by re-creating the service reference and factory.
The following can be used to implement the identity service:
The following can be used to implement the token manager service:
055b75b: BREAKING: Simplifications and cleanup as part of the Backend System 1.0 work.For the
/databasesubpath exports:dropDatabasefunction has now been removed, without replacement.LegacyRootDatabaseServicetype has now been removed.DatabaseManager.forPluginis now directly aDatabaseService, as arguably expected.DatabaseManager.forPluginnow requires thedepsargument, with the logger and lifecycle services.For the
/cachesubpath exports:PluginCacheManagertype has been removed. You can still import it from@backstage/backend-common, but it's deprecated there, and you should move off of that package by migrating fully to the new backend system.CacheManager.forPluginimmediately returns aCacheServiceinstead of aPluginCacheManager. The outcome of this is that you no longer need to make the extra.getClient()call. The oldCacheManagerwith the old behavior still exists on@backstage/backend-common, but the above recommendations apply.Patch Changes
213664e: Fixed an issue where theuseRedisSetsconfiguration for the cache service would have no effect.6ed9264: chore(deps): bumppath-to-regexpfrom 6.2.2 to 8.0.0622360e: Move down the discovery config to be in the root7f779c7:auth.externalAccessshould be optional in the config schemafe6fd8c: AcceptConfigServiceinstead ofConfigin constructors/factories82539fe: Updated dependencyarchiverto^7.0.0.c2b63ab: Updated dependencysupertestto^7.0.0.5705424: Wrap scheduled tasks from the scheduler core service now in OpenTelemetry spans7a72ec8: Exports thediscoveryFeatureLoaderas a replacement for the deprecatedfeatureDiscoveryService.The
discoveryFeatureLoaderis a new backend system feature loader that discovers backend features from the currentpackage.jsonand its dependencies.Here is an example using the
discoveryFeatureLoaderloader in a new backend instance:b2a329d: Properly indent the config schema66dbf0a: Allow the cache service to accept the human duration format for TTL5a8fcb4: Added the option to skip database migrations by settingskipMigrations: truein config. This can be done globally in the database config or by plugin id.0b2a402: Updates to the config schema to match realityUpdated dependencies
v0.4.4Compare Source
@backstage/backend-common@0.4.2
Patch Changes
5ecd50f: Fix HTTPS certificate generation and add new config switch, enabling it simply by settingbackend.https = true. Also introduces caching of generated certificates in order to avoid having to add a browser override every time the backend is restarted.00042e7: Moving the Git actions to isomorphic-git instead of the node binding version of nodegit0829ff1: Tweaked development log formatter to include extra fields at the end of each log line036a843: Provide support for on-prem azure devopsad5c56f]036a843]@backstage/cli@0.4.5
Patch Changes
37a7d26: Use consistent file extensions for JS output when building packages.818d45e: Fix detection of external package child directories0588be0: Addbackend:bundlecommand for bundling a backend package with dependencies into a deployment archive.b8abdda: Add color to output fromversions:bumpin order to make it easier to spot changes. Also highlight possible breaking changes and link to changelogs.ad5c56f]@backstage/config-loader@0.4.1
Patch Changes
ad5c56f: Deprecate$dataand replace it with$includewhich allows for any type of json value to be read from external files. In addition,$includecan be used without a path, which causes the value at the root of the file to be loaded.Most usages of
$datacan be directly replaced with$include, except if the referenced value is not a string, in which case the value needs to be changed. For example:Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.