Skip to content

[release-1.10] chore(orchestrator): upgrade fast-uri in orchestrator to >= 3.1.6 - #4576

Open
JessicaJHee wants to merge 1 commit into
redhat-developer:release-1.10/orchestratorfrom
JessicaJHee:fast-uri-CVE-2026-76172-CVE-2026-75899-CVE-2026-6322-CVE-2026-75931-CVE-2026-84394-CVE-2026-84292-release-1.10-orchestrator
Open

[release-1.10] chore(orchestrator): upgrade fast-uri in orchestrator to >= 3.1.6#4576
JessicaJHee wants to merge 1 commit into
redhat-developer:release-1.10/orchestratorfrom
JessicaJHee:fast-uri-CVE-2026-76172-CVE-2026-75899-CVE-2026-6322-CVE-2026-75931-CVE-2026-84394-CVE-2026-84292-release-1.10-orchestrator

Conversation

@JessicaJHee

@JessicaJHee JessicaJHee commented Sep 3, 2026

Copy link
Copy Markdown
Member

Hey, I just made a Pull Request!

Fixes multiple fast-uri security vulnerabilities in orchestrator by upgrading to version 3.1.7, which patches all six CVEs affecting the package.

Fast-URI Vulnerabilities Fixed:

Version: fast-uri 3.1.3 → 3.1.7

Fixed with simple yarn up -R fast-uri.

✔️ Checklist

  • A changeset describing the change and affected packages. (more info)
  • Added or Updated documentation
  • Tests for new functionality and regression tests for bug fixes
  • Screenshots attached (for UI changes)

@codecov

codecov Bot commented Sep 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (release-1.10/orchestrator@5fdb48f). Learn more about missing BASE report.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@                     Coverage Diff                      @@
##             release-1.10/orchestrator    #4576   +/-   ##
============================================================
  Coverage                             ?   59.57%           
============================================================
  Files                                ?     2097           
  Lines                                ?    65234           
  Branches                             ?    16986           
============================================================
  Hits                                 ?    38862           
  Misses                               ?    25977           
  Partials                             ?      395           
Flag Coverage Δ *Carryforward flag
adoption-insights 83.58% <ø> (?) Carriedforward from 18023a1
ai-integrations 70.03% <ø> (?) Carriedforward from 18023a1
app-defaults 69.60% <ø> (?) Carriedforward from 18023a1
augment 69.36% <ø> (?) Carriedforward from 18023a1
bulk-import 72.86% <ø> (?) Carriedforward from 18023a1
cost-management 16.49% <ø> (?) Carriedforward from 18023a1
dcm 32.85% <ø> (?) Carriedforward from 18023a1
extensions 61.79% <ø> (?) Carriedforward from 18023a1
global-floating-action-button 74.30% <ø> (?) Carriedforward from 18023a1
global-header 61.68% <ø> (?) Carriedforward from 18023a1
homepage 50.95% <ø> (?) Carriedforward from 18023a1
konflux 91.01% <ø> (?) Carriedforward from 18023a1
lightspeed 68.34% <ø> (?) Carriedforward from 18023a1
mcp-integrations 81.59% <ø> (?) Carriedforward from 18023a1
orchestrator 37.54% <ø> (?)
quickstart 62.64% <ø> (?) Carriedforward from 18023a1
sandbox 79.56% <ø> (?) Carriedforward from 18023a1
scorecard 83.58% <ø> (?) Carriedforward from 18023a1
theme 64.54% <ø> (?) Carriedforward from 18023a1
translations 8.49% <ø> (?) Carriedforward from 18023a1
x2a 57.33% <ø> (?) Carriedforward from 18023a1

*This pull request uses carry forward flags. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 5fdb48f...3f3937d. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

…to 3.1.7

Signed-off-by: Jessica He <jhe@redhat.com>
@JessicaJHee
JessicaJHee force-pushed the fast-uri-CVE-2026-76172-CVE-2026-75899-CVE-2026-6322-CVE-2026-75931-CVE-2026-84394-CVE-2026-84292-release-1.10-orchestrator branch from 94fa626 to 3f3937d Compare September 3, 2026 23:26
@sonarqubecloud

sonarqubecloud Bot commented Sep 3, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant