Skip to content

Commit 2c872a4

Browse files
committed
fix(security): resolve CVE-2025-57319 by upgrading (resolution) pino to v10.1.0 which drops the usage of fast-redact
1 parent c9f2a42 commit 2c872a4

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

dynamic-plugins/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,8 @@
4141
"@backstage/plugin-auth-node@^0.4.16": "patch:@backstage/plugin-auth-node@npm%3A0.6.0#./.yarn/patches/@backstage-plugin-auth-node-npm-0.6.0-69f2f0dc3f.patch",
4242
"@backstage/plugin-scaffolder-node@^0.2.9": "^0.7.0",
4343
"@backstage/plugin-home@^0.8.11": "patch:@backstage/plugin-home@npm%3A0.8.12#./.yarn/patches/@backstage-plugin-home-npm-0.8.12-0d7fbcc764.patch",
44-
"refractor@npm:3.6.0/prismjs": "^1.30.0"
44+
"refractor@npm:3.6.0/prismjs": "^1.30.0",
45+
"pino": "^10.1.0" // fixes CVE-2025-57319
4546
},
4647
"packageManager": "[email protected]"
4748
}

0 commit comments

Comments
 (0)