@backstage/plugin-app-backend@0.3.74-next.1 vulnerabilities

A Backstage backend plugin that serves the Backstage frontend app

Direct Vulnerabilities

Known vulnerabilities in the @backstage/plugin-app-backend package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Expected Behavior Violation

@backstage/plugin-app-backend is an A Backstage backend plugin that serves the Backstage frontend app

Affected versions of this package are vulnerable to Expected Behavior Violation due to the handling of APP_CONFIG_* environment variables, which ignores the visibility defined in the configuration schema. Note: This was an intended feature of the APP_CONFIG_* way of supplying configuration, but it goes against the expected behavior of the configuration system.

How to fix Expected Behavior Violation?

Upgrade @backstage/plugin-app-backend to version 0.3.75 or higher.

<0.3.75