Skip to content

[release-v1.25.x] chore: refactor applyParentUpgrade, correct applyResolutions orderfix and use exact-version resolution entries and discover historical descriptors - #1420

Merged
anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.25.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.25.x
Oct 5, 2026
Merged

anwesha-palit-redhat merged 1 commit into
openshift-pipelines:release-v1.25.xfrom
openshift-cherrypick-robot:cherry-pick-1414-to-release-v1.25.x

Conversation

@openshift-cherrypick-robot

Copy link
Copy Markdown
Contributor

This is an automated cherry-pick of #1414

/assign anwesha-palit-redhat

…nd use exact-version resolution entries and discover historical descriptors Co-Authored-By: Claude Opus 4.6
@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Warning

/review is deprecated. Use /agentic_review instead (removal date not yet scheduled).

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 No relevant tests
🔒 Security concerns

Dependency vulnerability regression:
Removing range-based resolutions without equivalent replacements may reinstall vulnerable transitive dependencies.

⚡ Recommended focus areas for review

Lost Overrides

Removing every existing resolution for the package can discard range-based selectors. The replacement exact-version entries may not match those dependency descriptors, allowing vulnerable versions to return after installation. Preserve or regenerate overrides for affected ranges.

const existing = pj.resolutions ?? {};
for (const key of Object.keys(existing)) {
  if (key.startsWith(`${pkg}@`)) {
    delete existing[key];
  }
}
pj.resolutions = { ...existing, ...entries };
Empty Fallback

If re-analysis cannot generate resolution entries, the fallback can still call applyResolutions with an empty object. That removes existing overrides and reports a fallback without fixing the dependency. Reject empty entries and require manual triage.

const recheck = analyzePackage(pkg, fixedVersions);
if (recheck.strategy !== 'already-remediated') {
  console.warn(
    `⚠ Parent upgrade of ${target.pkg} did not fix ${pkg} — falling back to resolution`,
  );
  return applyResolutions(
    pkg,
    recheck.resolutionEntries ?? resolutionEntries,
  );
Incomplete Recheck

Re-analysis receives only analysis.fixedVersion. Validate that this covers packages with vulnerable copies on multiple major lines; otherwise the recheck and fallback may miss fixes for other majors.

return applyParentUpgrade(
  analysis.package,
  [analysis.fixedVersion],
  analysis.parentUpgradeSuggestions,
  analysis.resolutionEntries,

@qodo-code-review

Copy link
Copy Markdown

Important

The /generate_labels command by Qodo is sunsetting on the 1st of October 2026 and will no longer be available. We recommend switching to the latest Qodo review capabilities. Learn more

@openshift-ci openshift-ci Bot added the lgtm Looks Good to Me Label label Oct 5, 2026
@openshift-ci

openshift-ci Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: anwesha-palit-redhat, openshift-cherrypick-robot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [anwesha-palit-redhat]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Label for Approved PRs label Oct 5, 2026
@anwesha-palit-redhat
anwesha-palit-redhat merged commit d9dd724 into openshift-pipelines:release-v1.25.x Oct 5, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Label for Approved PRs Bug fix lgtm Looks Good to Me Label Possible security concern

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants