Skip to content

chore: bump Backstage to 1.55.1 and refresh vulnerable dependencies - #67

Merged
tembleking merged 2 commits into
mainfrom
chore/bump-backstage-1.55
Sep 24, 2026
Merged

tembleking merged 2 commits into
mainfrom
chore/bump-backstage-1.55

Conversation

@tembleking

Copy link
Copy Markdown
Member

The lockfile had drifted: yarn audit reported 8 critical and 85 high advisories, including runtime deps like fast-xml-parser, fast-uri, js-yaml, lodash and react-router. Bumping Backstage to 1.55.1 and refreshing transitives brings that to 0 critical / 2 high. The remaining two are adm-zip (dev-only, via module-federation in the Backstage CLI) and js-cookie via react-use (no fix in range).

http-proxy-middleware stays on 3.x (^3.0.7) since v4 is a major. @backstage/cli-defaults is added now because the CLI warns its built-in fallback is going away.

Also fixes two small bugs found while testing the dev app: a trailing semicolon in marginLeft made React drop the link icon margin, and the dev proxy used v2-style onProxyRes/onError hooks that v3 ignores, so it never logged.

Bumps version to 1.5.1, so merging triggers a release. Supersedes the open Dependabot PRs.

Clears most audit findings (8 critical/85 high down to 0 critical/2 high),
including runtime ones in fast-xml-parser, fast-uri, js-yaml, lodash and
react-router. Adds @backstage/cli-defaults ahead of the CLI fallback removal.
The trailing semicolon in marginLeft made React drop the style, and the
dev proxy still used v2-style onProxyRes/onError, which http-proxy-middleware
v3 silently ignores.
@tembleking
tembleking enabled auto-merge (squash) September 24, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants