Skip to content

[release-v1.24.x] chore: refactor applyParentUpgrade, correct applyResolutions orderfix and use exact-version resolution entries and discover historical descriptors - #1416

Merged
anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.24.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.24.x
Oct 5, 2026
Merged

anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.24.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.24.x

Conversation

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

This is an automated cherry-pick of #1414

/assign anwesha-palit-redhat

…nd use exact-version resolution entries and discover historical descriptors Co-Authored-By: Claude Opus 4.6
@openshift-ci

openshift-ci Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: openshift-cherrypick-robot
Once this PR has been reviewed and has the lgtm label, please assign vdemeester for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Warning

/review is deprecated. Use /agentic_review instead (removal date not yet scheduled).

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Range Descriptors

Exact-version resolution keys may not match dependencies declared with ranges such as pkg@^6.0.0. The historical-descriptor scan also ignores range keys, while applyResolutions removes them. Validate that vulnerable range-based dependencies remain covered after installation.

const prefix = `${pkg}@`;
for (const key of Object.keys(resolutions)) {
  if (key.startsWith(prefix)) {
    const ver = key.slice(prefix.length);
    if (semver.valid(ver)) {
      historicalVersions.push(ver);
Empty Fallback

If re-analysis still finds a vulnerable package but generates an empty resolutionEntries object, the fallback passes that object to applyResolutions, which deletes existing resolutions without adding replacements. Check for empty entries and require manual triage instead.

// Re-analyze: did the transitive dep actually move to the fixed version?
const recheck = analyzePackage(pkg, fixedVersions);
if (recheck.strategy !== 'already-remediated') {
  console.warn(
    `⚠ Parent upgrade of ${target.pkg} did not fix ${pkg} — falling back to resolution`,
  );
  return applyResolutions(
    pkg,
    recheck.resolutionEntries ?? resolutionEntries,
  );

@qodo-code-review

Copy link
Copy Markdown

Important

The /generate_labels command by Qodo is sunsetting on the 1st of October 2026 and will no longer be available. We recommend switching to the latest Qodo review capabilities. Learn more

@anwesha-palit-redhat
anwesha-palit-redhat merged commit bde2a74 into openshift-pipelines:release-v1.24.x Oct 5, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants