Skip to content

[release-v1.23.x] chore: refactor applyParentUpgrade, correct applyResolutions orderfix and use exact-version resolution entries and discover historical descriptors - #1417

Merged
anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.23.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.23.x
Oct 5, 2026
Merged

anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.23.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.23.x

Conversation

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

This is an automated cherry-pick of #1414

/assign anwesha-palit-redhat

…nd use exact-version resolution entries and discover historical descriptors Co-Authored-By: Claude Opus 4.6
@openshift-ci

openshift-ci Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: openshift-cherrypick-robot
Once this PR has been reviewed and has the lgtm label, please assign vdemeester for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Warning

/review is deprecated. Use /agentic_review instead (removal date not yet scheduled).

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 No relevant tests
🔒 Security concerns

Dependency vulnerability:
Exact-version resolutions may leave range-declared vulnerable dependencies unpatched, while the parent-upgrade fallback can remove existing protections when it has no replacement entries. Verify the installed dependency tree after remediation.

⚡ Recommended focus areas for review

Unmatched Ranges

Exact-version resolution keys may not match dependencies declared with range descriptors such as pkg@^4.0.0. Verify that these entries actually override the vulnerable dependencies before removing the range-based entries.

for (const v of vulnerable) {
  entries[`${pkg}@${v}`] = fix;
}
Empty Fallback

If re-analysis cannot generate resolution entries, an empty recheck.resolutionEntries is still used. applyResolutions would then delete the package's existing resolutions and report a successful fallback. Guard against empty entries and require manual triage.

if (recheck.strategy !== 'already-remediated') {
  console.warn(
    `⚠ Parent upgrade of ${target.pkg} did not fix ${pkg} — falling back to resolution`,
  );
  return applyResolutions(
    pkg,
    recheck.resolutionEntries ?? resolutionEntries,
  );

@qodo-code-review

Copy link
Copy Markdown

Important

The /generate_labels command by Qodo is sunsetting on the 1st of October 2026 and will no longer be available. We recommend switching to the latest Qodo review capabilities. Learn more

@anwesha-palit-redhat
anwesha-palit-redhat merged commit 48cb46a into openshift-pipelines:release-v1.23.x Oct 5, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants