Skip to content

[release-v1.15.x] chore: refactor applyParentUpgrade, correct applyResolutions orderfix and use exact-version resolution entries and discover historical descriptors - #1419

Merged
anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.15.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.15.x
Oct 5, 2026
Merged

anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.15.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.15.x

Conversation

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

This is an automated cherry-pick of #1414

/assign anwesha-palit-redhat

…nd use exact-version resolution entries and discover historical descriptors Co-Authored-By: Claude Opus 4.6
@openshift-ci

openshift-ci Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: openshift-cherrypick-robot
Once this PR has been reviewed and has the lgtm label, please assign pratap0007 for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Warning

/review is deprecated. Use /agentic_review instead (removal date not yet scheduled).

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 No relevant tests
🔒 Security concerns

Incomplete CVE remediation:
Unmatched exact-version resolutions or an empty parent-upgrade fallback can leave vulnerable dependency versions installed despite the attempted fix.

⚡ Recommended focus areas for review

Unmatched Resolutions

Exact-version resolution keys may not match dependencies declared with ranges such as pkg@^1.2.0. Removing the range-based entries could leave vulnerable transitive copies installed; validate the generated keys against actual Yarn dependency descriptors.

for (const v of vulnerable) {
  entries[`${pkg}@${v}`] = fix;
Empty Fallback

If re-analysis returns an empty resolutionEntries object, ?? selects it instead of the original entries. The fallback then removes existing resolutions and installs without replacements. Check for nonempty entries before applying the fallback.

return applyResolutions(
  pkg,
  recheck.resolutionEntries ?? resolutionEntries,
);

@qodo-code-review qodo-code-review Bot added enhancement New feature or request Bug fix labels Oct 5, 2026
@qodo-code-review

Copy link
Copy Markdown

Important

The /generate_labels command by Qodo is sunsetting on the 1st of October 2026 and will no longer be available. We recommend switching to the latest Qodo review capabilities. Learn more

@anwesha-palit-redhat
anwesha-palit-redhat merged commit 4d09a68 into openshift-pipelines:release-v1.15.x Oct 5, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants