Skip to content

[release-v1.22.x] chore: refactor applyParentUpgrade, correct applyResolutions orderfix and use exact-version resolution entries and discover historical descriptors - #1418

Merged
anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.22.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.22.x
Oct 5, 2026
Merged

anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.22.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.22.x

Conversation

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

This is an automated cherry-pick of #1414

/assign anwesha-palit-redhat

…nd use exact-version resolution entries and discover historical descriptors Co-Authored-By: Claude Opus 4.6
@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Warning

/review is deprecated. Use /agentic_review instead (removal date not yet scheduled).

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Range Coverage

Exact-version entries do not match range-based dependency descriptors. Removing the range resolution can leave vulnerable copies installed even when an exact-version entry is generated. Validate the generated entries against the descriptors in the lockfile.

for (const [, versions] of byMajor) {
  const fix = getFixForVersion(versions[0], fixedVersions);
  if (!fix) continue;

  const vulnerable = versions.filter((v) => !isVersionSatisfied(v, fix));
  if (vulnerable.length === 0) continue;

  for (const v of vulnerable) {
    entries[`${pkg}@${v}`] = fix;
  }
Override Loss

This deletes every existing resolution for the package, including range-based or manually maintained overrides that the new entries do not replace. Preserve entries that are still needed before rewriting package.json.

const existing = pj.resolutions ?? {};
for (const key of Object.keys(existing)) {
  if (key.startsWith(`${pkg}@`)) {
    delete existing[key];
  }
}
pj.resolutions = { ...existing, ...entries };

@qodo-code-review

Copy link
Copy Markdown

Important

The /generate_labels command by Qodo is sunsetting on the 1st of October 2026 and will no longer be available. We recommend switching to the latest Qodo review capabilities. Learn more

@anwesha-palit-redhat
anwesha-palit-redhat removed the request for review from vdemeester October 5, 2026 12:28

@anwesha-palit-redhat anwesha-palit-redhat left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm Looks Good to Me Label label Oct 5, 2026
@openshift-ci

openshift-ci Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: anwesha-palit-redhat, openshift-cherrypick-robot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [anwesha-palit-redhat]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Label for Approved PRs label Oct 5, 2026
@anwesha-palit-redhat
anwesha-palit-redhat merged commit fc12aeb into openshift-pipelines:release-v1.22.x Oct 5, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Label for Approved PRs Bug fix lgtm Looks Good to Me Label

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants