Skip to content

chore: refactor applyParentUpgrade, correct applyResolutions orderfix and use exact-version resolution entries and discover historical descriptors - #1414

Merged
openshift-merge-bot[bot] merged 1 commit into
openshift-pipelines:masterfrom
anwesha-palit-redhat:chore/update-cve-automation-scripts
Oct 5, 2026
Merged

openshift-merge-bot[bot] merged 1 commit into
openshift-pipelines:masterfrom
anwesha-palit-redhat:chore/update-cve-automation-scripts

Conversation

@anwesha-palit-redhat

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Refactoring
  • Migration
  • CVE Fix

Summary

Screen Recordings / Screenshot

@openshift-ci
openshift-ci Bot requested a review from vdemeester October 5, 2026 09:35
@openshift-ci openshift-ci Bot added the approved Label for Approved PRs label Oct 5, 2026
@anwesha-palit-redhat

Copy link
Copy Markdown
Contributor Author

/cherry-pick release-v1.25.x

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: once the present PR merges, I will cherry-pick it on top of release-v1.25.x in a new PR and assign it to you.

Details

In response to this:

/cherry-pick release-v1.25.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@anwesha-palit-redhat

Copy link
Copy Markdown
Contributor Author

/cherry-pick release-v1.24.x

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: once the present PR merges, I will cherry-pick it on top of release-v1.24.x in a new PR and assign it to you.

Details

In response to this:

/cherry-pick release-v1.24.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@anwesha-palit-redhat

Copy link
Copy Markdown
Contributor Author

/cherry-pick release-v1.23.x

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: once the present PR merges, I will cherry-pick it on top of release-v1.23.x in a new PR and assign it to you.

Details

In response to this:

/cherry-pick release-v1.23.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@anwesha-palit-redhat

Copy link
Copy Markdown
Contributor Author

/cherry-pick release-v1.22.x

@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Warning

/review is deprecated. Use /agentic_review instead (removal date not yet scheduled).

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Resolution Matching

Exact-version keys such as pkg@4.1.0 may not match dependency descriptors such as pkg@^4.0.0. Validate that generated entries actually override the vulnerable dependencies after installation, rather than only matching exact-pinned descriptors.

for (const v of vulnerable) {
  entries[`${pkg}@${v}`] = fix;
}
Lost Overrides

Removing every existing resolution for the package can discard range-based or other overrides that the new entries do not replace. Preserve needed overrides or verify that no vulnerable copies remain after installation.

const existing = pj.resolutions ?? {};
for (const key of Object.keys(existing)) {
  if (key.startsWith(`${pkg}@`)) {
    delete existing[key];
  }
}
pj.resolutions = { ...existing, ...entries };
Stale Fallback

The fallback uses resolution entries computed before yarn up. If the parent upgrade changes the transitive dependency descriptors, those entries may no longer apply; re-analyze and generate fallback entries from the updated tree.

runCmdOrThrow('yarn', ['up', `${target.pkg}@${target.version}`]);

// Re-analyze: did the transitive dep actually move?
const recheck = analyzePackage(pkg, fixedVersions);
if (recheck.strategy !== 'already-remediated') {
  console.warn(
    `⚠ Parent upgrade of ${target.pkg} did not fix ${pkg} — falling back to resolution`,
  );
  return applyResolutions(pkg, resolutionEntries);

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: once the present PR merges, I will cherry-pick it on top of release-v1.22.x in a new PR and assign it to you.

Details

In response to this:

/cherry-pick release-v1.22.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@anwesha-palit-redhat

Copy link
Copy Markdown
Contributor Author

/cherry-pick release-v1.15.x

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: once the present PR merges, I will cherry-pick it on top of release-v1.15.x in a new PR and assign it to you.

Details

In response to this:

/cherry-pick release-v1.15.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@anwesha-palit-redhat
anwesha-palit-redhat removed the request for review from vdemeester October 5, 2026 09:35
@qodo-code-review

Copy link
Copy Markdown

Important

The /generate_labels command by Qodo is sunsetting on the 1st of October 2026 and will no longer be available. We recommend switching to the latest Qodo review capabilities. Learn more

…nd use exact-version resolution entries and discover historical descriptors

Co-Authored-By: Claude Opus 4.6

@arvindk-softwaredev arvindk-softwaredev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Looks Good to Me Label label Oct 5, 2026
@openshift-ci

openshift-ci Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: anwesha-palit-redhat, arvindk-softwaredev

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [anwesha-palit-redhat,arvindk-softwaredev]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: new pull request created: #1416

Details

In response to this:

/cherry-pick release-v1.24.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: new pull request created: #1417

Details

In response to this:

/cherry-pick release-v1.23.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: new pull request created: #1418

Details

In response to this:

/cherry-pick release-v1.22.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: new pull request created: #1419

Details

In response to this:

/cherry-pick release-v1.15.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

@anwesha-palit-redhat: new pull request created: #1420

Details

In response to this:

/cherry-pick release-v1.25.x

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Label for Approved PRs jira/valid-reference lgtm Looks Good to Me Label

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants