From 7384fab1d664e8d944022bc2a7008e6ace3e2c78 Mon Sep 17 00:00:00 2001 From: Andre Lizardo Date: Wed, 17 Dec 2025 11:54:16 +0100 Subject: [PATCH] fix(security): resolve CVE-2025-57319 by upgrading (resolution) pino to v10.1.0 which drops the usage of fast-redact --- dynamic-plugins/package.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/dynamic-plugins/package.json b/dynamic-plugins/package.json index 03d5bb9b03..f6c86faa8e 100644 --- a/dynamic-plugins/package.json +++ b/dynamic-plugins/package.json @@ -41,7 +41,8 @@ "@backstage/plugin-auth-node@^0.4.16": "patch:@backstage/plugin-auth-node@npm%3A0.6.0#./.yarn/patches/@backstage-plugin-auth-node-npm-0.6.0-69f2f0dc3f.patch", "@backstage/plugin-scaffolder-node@^0.2.9": "^0.7.0", "@backstage/plugin-home@^0.8.11": "patch:@backstage/plugin-home@npm%3A0.8.12#./.yarn/patches/@backstage-plugin-home-npm-0.8.12-0d7fbcc764.patch", - "refractor@npm:3.6.0/prismjs": "^1.30.0" + "refractor@npm:3.6.0/prismjs": "^1.30.0", + "pino": "^10.1.0" }, "packageManager": "yarn@3.8.7" }