diff --git a/.changeset/afraid-needles-divide.md b/.changeset/afraid-needles-divide.md
deleted file mode 100644
index 6db7f449b0..0000000000
--- a/.changeset/afraid-needles-divide.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/create-app': patch
----
-
-Removed `packages/backend/src/types.ts` from the template as it is unused. It was mistakenly left in after moving the template to the new backend system.
diff --git a/.changeset/beige-eagles-cheat.md b/.changeset/beige-eagles-cheat.md
new file mode 100644
index 0000000000..5b5081d2ee
--- /dev/null
+++ b/.changeset/beige-eagles-cheat.md
@@ -0,0 +1,5 @@
+---
+'@backstage/cli-node': patch
+---
+
+Updated doc link.
diff --git a/.changeset/brave-apples-move.md b/.changeset/brave-apples-move.md
new file mode 100644
index 0000000000..7a1fa86a56
--- /dev/null
+++ b/.changeset/brave-apples-move.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-app-api': patch
+---
+
+Fixed a potential crash when passing an object with a `null` prototype as log meta.
diff --git a/.changeset/breezy-badgers-train.md b/.changeset/breezy-badgers-train.md
new file mode 100644
index 0000000000..8f747b8602
--- /dev/null
+++ b/.changeset/breezy-badgers-train.md
@@ -0,0 +1,5 @@
+---
+'@backstage/cli-node': patch
+---
+
+Upgraded @yarnpkg/parsers to stable 3.0
diff --git a/.changeset/bright-pumpkins-rule.md b/.changeset/bright-pumpkins-rule.md
deleted file mode 100644
index 07de4f313c..0000000000
--- a/.changeset/bright-pumpkins-rule.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications': patch
----
-
-Allow overriding `NotificationsPage` page properties
diff --git a/.changeset/calm-cars-serve.md b/.changeset/calm-cars-serve.md
new file mode 100644
index 0000000000..5df2a18cd4
--- /dev/null
+++ b/.changeset/calm-cars-serve.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-tasks': patch
+---
+
+Marked all exports as deprecated and pointed at `@backstage/backend-plugin-api` and `@backstage/backend-defaults`
diff --git a/.changeset/calm-plums-wink.md b/.changeset/calm-plums-wink.md
new file mode 100644
index 0000000000..edb991f616
--- /dev/null
+++ b/.changeset/calm-plums-wink.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-techdocs': patch
+---
+
+mkdocs-material have updated their CSS variable template, and a few are unset in Backstage. This patch adds the missing variables to ensure coverage.
diff --git a/.changeset/chatty-cycles-unite.md b/.changeset/chatty-cycles-unite.md
deleted file mode 100644
index 93dffbb143..0000000000
--- a/.changeset/chatty-cycles-unite.md
+++ /dev/null
@@ -1,9 +0,0 @@
----
-'@backstage/plugin-scaffolder-backend-module-github': patch
-'@backstage/core-compat-api': patch
-'@backstage/create-app': patch
-'@backstage/plugin-api-docs': patch
-'@backstage/plugin-catalog': patch
----
-
-Update local development dependencies.
diff --git a/.changeset/chilly-adults-sing.md b/.changeset/chilly-adults-sing.md
deleted file mode 100644
index 82f4cb88b2..0000000000
--- a/.changeset/chilly-adults-sing.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-catalog-backend': patch
----
-
-Add lifecycle monitoring for the catalog processing
diff --git a/.changeset/chilly-fireants-roll.md b/.changeset/chilly-fireants-roll.md
deleted file mode 100644
index 93c05fecb7..0000000000
--- a/.changeset/chilly-fireants-roll.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-home': patch
----
-
-Use relative time when displaying visits from the same day
diff --git a/.changeset/clever-radios-yawn.md b/.changeset/clever-radios-yawn.md
new file mode 100644
index 0000000000..e5600183f5
--- /dev/null
+++ b/.changeset/clever-radios-yawn.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-api-docs': patch
+---
+
+Make sure that the toggle button state is properly reflected in API cards
diff --git a/.changeset/cold-rats-leave.md b/.changeset/cold-rats-leave.md
deleted file mode 100644
index 6fe28d6371..0000000000
--- a/.changeset/cold-rats-leave.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-scaffolder-backend': patch
----
-
-Fix issue with the log format not being respected when logging from actions
diff --git a/.changeset/cold-seas-end.md b/.changeset/cold-seas-end.md
new file mode 100644
index 0000000000..96fa048fbd
--- /dev/null
+++ b/.changeset/cold-seas-end.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-common': patch
+---
+
+Updated configuration schema to include the `useRedisSets` cache config option.
diff --git a/.changeset/cool-elephants-march.md b/.changeset/cool-elephants-march.md
deleted file mode 100644
index 2396f9553d..0000000000
--- a/.changeset/cool-elephants-march.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-scaffolder-backend-module-gitea': patch
----
-
-Allow defining `repoVisibility` field for the action `publish:gitea`
diff --git a/.changeset/create-app-1716302437.md b/.changeset/create-app-1716302437.md
new file mode 100644
index 0000000000..b50d431d4b
--- /dev/null
+++ b/.changeset/create-app-1716302437.md
@@ -0,0 +1,5 @@
+---
+'@backstage/create-app': patch
+---
+
+Bumped create-app version.
diff --git a/.changeset/create-app-1716903719.md b/.changeset/create-app-1716903719.md
new file mode 100644
index 0000000000..b50d431d4b
--- /dev/null
+++ b/.changeset/create-app-1716903719.md
@@ -0,0 +1,5 @@
+---
+'@backstage/create-app': patch
+---
+
+Bumped create-app version.
diff --git a/.changeset/cuddly-chairs-kick.md b/.changeset/cuddly-chairs-kick.md
deleted file mode 100644
index ebb53b8e26..0000000000
--- a/.changeset/cuddly-chairs-kick.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/backend-app-api': patch
----
-
-Add ability to configure the Node.js HTTP Server when configuring the root HTTP Router service
diff --git a/.changeset/cuddly-eggs-sin.md b/.changeset/cuddly-eggs-sin.md
new file mode 100644
index 0000000000..bfe7de9680
--- /dev/null
+++ b/.changeset/cuddly-eggs-sin.md
@@ -0,0 +1,6 @@
+---
+'@backstage/plugin-techdocs-backend': patch
+'@backstage/plugin-techdocs-node': patch
+---
+
+Allow defining custom build log transport for techdocs builder
diff --git a/.changeset/curly-shirts-flow.md b/.changeset/curly-shirts-flow.md
deleted file mode 100644
index b9a73809ba..0000000000
--- a/.changeset/curly-shirts-flow.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/repo-tools': patch
----
-
-Update the paths logic in the api reports command to support complex subpaths
diff --git a/.changeset/curvy-planes-flash.md b/.changeset/curvy-planes-flash.md
deleted file mode 100644
index 0d3368e53d..0000000000
--- a/.changeset/curvy-planes-flash.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-catalog-backend-module-bitbucket-server': patch
----
-
-Allow skipping archived repositories (`skipArchivedRepos` flag) on Bitbucket.
diff --git a/.changeset/cyan-jobs-visit.md b/.changeset/cyan-jobs-visit.md
new file mode 100644
index 0000000000..ccc8c90adf
--- /dev/null
+++ b/.changeset/cyan-jobs-visit.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-test-utils': minor
+---
+
+Added `TestCaches` that functions just like `TestDatabases`
diff --git a/.changeset/cyan-paws-beg.md b/.changeset/cyan-paws-beg.md
new file mode 100644
index 0000000000..87c2b746a4
--- /dev/null
+++ b/.changeset/cyan-paws-beg.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-scaffolder-backend-module-github': patch
+---
+
+Added handling for dry run to githubPullRequest and githubWebhook and added tests for this functionality
diff --git a/.changeset/cyan-snails-peel.md b/.changeset/cyan-snails-peel.md
new file mode 100644
index 0000000000..4da79258fb
--- /dev/null
+++ b/.changeset/cyan-snails-peel.md
@@ -0,0 +1,12 @@
+---
+'@backstage/plugin-user-settings-backend': patch
+'@backstage/plugin-devtools-backend': patch
+'@backstage/plugin-techdocs-backend': patch
+'@backstage/plugin-catalog-backend': patch
+'@backstage/plugin-search-backend': patch
+'@backstage/plugin-proxy-backend': patch
+'@backstage/plugin-auth-backend': patch
+'@backstage/plugin-app-backend': patch
+---
+
+Updated local development setup.
diff --git a/.changeset/dry-sloths-impress.md b/.changeset/dry-sloths-impress.md
deleted file mode 100644
index 6bd5ba4156..0000000000
--- a/.changeset/dry-sloths-impress.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/catalog-model': minor
----
-
-Introduce a domain attribute to the domain entity to allow a hierarchy of domains to exist.
diff --git a/.changeset/eighty-apricots-kneel.md b/.changeset/eighty-apricots-kneel.md
deleted file mode 100644
index a9cabaf378..0000000000
--- a/.changeset/eighty-apricots-kneel.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@techdocs/cli': patch
----
-
-Fix cookie endpoint mock for `serve`
diff --git a/.changeset/eighty-bats-stare.md b/.changeset/eighty-bats-stare.md
deleted file mode 100644
index 6ebb2e9265..0000000000
--- a/.changeset/eighty-bats-stare.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-techdocs': patch
----
-
-Update path in Readme for Plugin Techdocs to show the correct setup information.
diff --git a/.changeset/eighty-kings-dress.md b/.changeset/eighty-kings-dress.md
new file mode 100644
index 0000000000..52aab627ab
--- /dev/null
+++ b/.changeset/eighty-kings-dress.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-common': patch
+---
+
+In preparation to the new backend system stable release, the `isDatabaseConflictError` helper have been moved to the `@backstage/backend-plugin-api` package and deprecated from `@backstage/backend-common`.
diff --git a/.changeset/eighty-yaks-switch.md b/.changeset/eighty-yaks-switch.md
new file mode 100644
index 0000000000..30e3374d70
--- /dev/null
+++ b/.changeset/eighty-yaks-switch.md
@@ -0,0 +1,5 @@
+---
+'@backstage/cli': patch
+---
+
+Fix readme for new plugins created using cli
diff --git a/.changeset/eleven-pandas-divide.md b/.changeset/eleven-pandas-divide.md
deleted file mode 100644
index 912d34570a..0000000000
--- a/.changeset/eleven-pandas-divide.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-catalog-backend-module-gitlab': patch
----
-
-Added events support for `GitlabDiscoveryEntityProvider` and `GitlabOrgDiscoveryEntityProvider`.
diff --git a/.changeset/empty-spoons-tell.md b/.changeset/empty-spoons-tell.md
new file mode 100644
index 0000000000..44e3dceb6f
--- /dev/null
+++ b/.changeset/empty-spoons-tell.md
@@ -0,0 +1,46 @@
+---
+'@backstage/plugin-proxy-backend': minor
+---
+
+**BREAKING**: The proxy backend plugin is now protected by Backstage auth, by
+default. Unless specifically configured (see below), all proxy endpoints will
+reject requests immediately unless a valid Backstage user or service token is
+passed along with the request. This aligns the proxy with how other Backstage
+backends behave out of the box, and serves to protect your upstreams from
+unauthorized access.
+
+A proxy configuration section can now look as follows:
+
+```yaml
+proxy:
+ endpoints:
+ '/pagerduty':
+ target: https://api.pagerduty.com
+ credentials: require # NEW!
+ headers:
+ Authorization: Token token=${PAGERDUTY_TOKEN}
+```
+
+There are three possible `credentials` settings at this point:
+
+- `require`: Callers must provide Backstage user or service credentials with
+ each request. The credentials are not forwarded to the proxy target.
+- `forward`: Callers must provide Backstage user or service credentials with
+ each request, and those credentials are forwarded to the proxy target.
+- `dangerously-allow-unauthenticated`: No Backstage credentials are required to
+ access this proxy target. The target can still apply its own credentials
+ checks, but the proxy will not help block non-Backstage-blessed callers. If
+ you also add `allowedHeaders: ['Authorization']` to an endpoint configuration,
+ then the Backstage token (if provided) WILL be forwarded.
+
+The value `dangerously-allow-unauthenticated` was the old default.
+
+The value `require` is the new default, so requests that were previously
+permitted may now start resulting in `401 Unauthorized` responses. If you have
+`backend.auth.dangerouslyDisableDefaultAuthPolicy` set to `true`, this does not
+apply; the proxy will behave as if all endpoints were set to
+`dangerously-allow-unauthenticated`.
+
+If you have proxy endpoints that require unauthenticated access still, please
+add `credentials: dangerously-allow-unauthenticated` to their declarations in
+your app-config.
diff --git a/.changeset/empty-tables-ring.md b/.changeset/empty-tables-ring.md
new file mode 100644
index 0000000000..c83a987228
--- /dev/null
+++ b/.changeset/empty-tables-ring.md
@@ -0,0 +1,8 @@
+---
+'@backstage/plugin-kubernetes-react': minor
+'@backstage/plugin-catalog-import': minor
+'@backstage/plugin-kubernetes': patch
+'@backstage/plugin-search': patch
+---
+
+Migrate from identityApi to fetchApi in frontend plugins.
diff --git a/.changeset/famous-monkeys-count.md b/.changeset/famous-monkeys-count.md
new file mode 100644
index 0000000000..c5151b38c3
--- /dev/null
+++ b/.changeset/famous-monkeys-count.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-app-api': patch
+---
+
+Add support for JWKS tokens in ExternalTokenHandler.
diff --git a/.changeset/fix-stackoverflow.md b/.changeset/fix-stackoverflow.md
deleted file mode 100644
index 6ce9f15737..0000000000
--- a/.changeset/fix-stackoverflow.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-catalog-backend-module-incremental-ingestion': patch
----
-
-Fix plugin/incremental-ingestion 'Maximum call stack size exceeded' error when ingest large entities.
diff --git a/.changeset/fluffy-hotels-wait.md b/.changeset/fluffy-hotels-wait.md
deleted file mode 100644
index a578f2fb4a..0000000000
--- a/.changeset/fluffy-hotels-wait.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/cli': patch
----
-
-Both the target and types library have been bumped from ES2021 to ES2022 in `@backstage/cli/config/tsconfig.json`.
diff --git a/.changeset/forty-adults-roll.md b/.changeset/forty-adults-roll.md
new file mode 100644
index 0000000000..50dd60da9e
--- /dev/null
+++ b/.changeset/forty-adults-roll.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-tasks': patch
+---
+
+Updated the `TaskScheduleDefinitionConfig` deprecated comment to point to `SchedulerServiceTaskScheduleDefinitionConfig`
diff --git a/.changeset/four-adults-mix.md b/.changeset/four-adults-mix.md
new file mode 100644
index 0000000000..5013166dc6
--- /dev/null
+++ b/.changeset/four-adults-mix.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-notifications': patch
+---
+
+Do not always show scrollbars in notification description
diff --git a/.changeset/four-cooks-serve.md b/.changeset/four-cooks-serve.md
deleted file mode 100644
index 864807cc49..0000000000
--- a/.changeset/four-cooks-serve.md
+++ /dev/null
@@ -1,6 +0,0 @@
----
-'@backstage/plugin-notifications-backend': patch
-'@backstage/plugin-notifications-node': patch
----
-
-Support for filtering entities from notification recipients after resolving them from the recipients
diff --git a/.changeset/fresh-crews-impress.md b/.changeset/fresh-crews-impress.md
deleted file mode 100644
index 18f98f1dd9..0000000000
--- a/.changeset/fresh-crews-impress.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/backend-app-api': patch
----
-
-Move the JWKS registration outside of the lifecycle middleware
diff --git a/.changeset/friendly-keys-fold.md b/.changeset/friendly-keys-fold.md
new file mode 100644
index 0000000000..218abe4efe
--- /dev/null
+++ b/.changeset/friendly-keys-fold.md
@@ -0,0 +1,6 @@
+---
+'@backstage/backend-plugin-api': patch
+'@backstage/backend-app-api': patch
+---
+
+Added an optional `accessRestrictions` to external access service tokens and service principals in general, such that you can limit their access to certain plugins or permissions.
diff --git a/.changeset/fuzzy-seahorses-tell.md b/.changeset/fuzzy-seahorses-tell.md
deleted file mode 100644
index f184e9ce95..0000000000
--- a/.changeset/fuzzy-seahorses-tell.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/core-components': patch
----
-
-Fixed an internal circular import that broke Jest mocks.
diff --git a/.changeset/gentle-baboons-peel.md b/.changeset/gentle-baboons-peel.md
new file mode 100644
index 0000000000..b51ad77283
--- /dev/null
+++ b/.changeset/gentle-baboons-peel.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-techdocs': patch
+---
+
+`TechDocsIndexPage` now accepts an optional `ownerPickerMode` for toggling the behavior of the `EntityOwnerPicker`, exposing a new mode `` particularly suitable for larger catalogs. In this new mode, `EntityOwnerPicker` will display all the users and groups present in the catalog.
diff --git a/.changeset/gold-teachers-wink.md b/.changeset/gold-teachers-wink.md
new file mode 100644
index 0000000000..0578e8d02b
--- /dev/null
+++ b/.changeset/gold-teachers-wink.md
@@ -0,0 +1,5 @@
+---
+'@backstage/cli': patch
+---
+
+Fix issue with `esm` loaded dependencies being different from the `cjs` import for Vite dependencies
diff --git a/.changeset/gold-waves-bake.md b/.changeset/gold-waves-bake.md
deleted file mode 100644
index 2883b7b967..0000000000
--- a/.changeset/gold-waves-bake.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/cli': patch
----
-
-Add support for `versions:migrate` to do code changes. Can be skipped with `--no-code-changes`
diff --git a/.changeset/gorgeous-cameras-cross.md b/.changeset/gorgeous-cameras-cross.md
deleted file mode 100644
index 50d7ddb2d7..0000000000
--- a/.changeset/gorgeous-cameras-cross.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-techdocs-addons-test-utils': patch
----
-
-Fix bug in TechDocsAddonTester when jest.resetAllMocks is called between tests
diff --git a/.changeset/great-cougars-guess.md b/.changeset/great-cougars-guess.md
new file mode 100644
index 0000000000..af1de3e8ce
--- /dev/null
+++ b/.changeset/great-cougars-guess.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-test-utils': patch
+---
+
+Made it possible to give access restrictions to `mockCredentials.service`
diff --git a/.changeset/green-adults-push.md b/.changeset/green-adults-push.md
deleted file mode 100644
index 3edc21c385..0000000000
--- a/.changeset/green-adults-push.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/cli': patch
----
-
-Add preserveModules to rollup, which allows better async loading and tree-shaking in webpack
diff --git a/.changeset/green-boxes-rescue.md b/.changeset/green-boxes-rescue.md
deleted file mode 100644
index 146695a320..0000000000
--- a/.changeset/green-boxes-rescue.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications-backend-module-email': patch
----
-
-Allow sending notifications by email with the new notifications module
diff --git a/.changeset/hip-carrots-drive.md b/.changeset/hip-carrots-drive.md
deleted file mode 100644
index 5852916b74..0000000000
--- a/.changeset/hip-carrots-drive.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/backend-app-api': patch
----
-
-The default `TokenManager` implementation no longer requires keys to be configured in production, but it will throw an errors when generating or authenticating tokens. The default `AuthService` implementation will now also provide additional context if such an error is throw when falling back to using the `TokenManager` service to generate tokens for outgoing requests.
diff --git a/.changeset/hot-forks-train.md b/.changeset/hot-forks-train.md
deleted file mode 100644
index a5300085b6..0000000000
--- a/.changeset/hot-forks-train.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications': patch
----
-
-Allow showing notifications as snackbars in the UI
diff --git a/.changeset/itchy-gorillas-hope.md b/.changeset/itchy-gorillas-hope.md
deleted file mode 100644
index cd285161ff..0000000000
--- a/.changeset/itchy-gorillas-hope.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/create-app': patch
----
-
-Removed the Tech Radar and GitHub Actions plugins from the template, which have been moved to the community plugins repository.
diff --git a/.changeset/itchy-spoons-cry.md b/.changeset/itchy-spoons-cry.md
new file mode 100644
index 0000000000..20877e8087
--- /dev/null
+++ b/.changeset/itchy-spoons-cry.md
@@ -0,0 +1,6 @@
+---
+'@backstage/plugin-app-backend': patch
+---
+
+Restore the support of external config schema in the router of the `app-backend` plugin, which was broken in release `1.26.0`.
+This support is critical for dynamic frontend plugins to have access to their config values.
diff --git a/.changeset/large-months-decide.md b/.changeset/large-months-decide.md
new file mode 100644
index 0000000000..e9d4c47bbe
--- /dev/null
+++ b/.changeset/large-months-decide.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-notifications-node': minor
+---
+
+add notifications filtering by processors
diff --git a/.changeset/late-ants-impress.md b/.changeset/late-ants-impress.md
new file mode 100644
index 0000000000..44b2cbefb3
--- /dev/null
+++ b/.changeset/late-ants-impress.md
@@ -0,0 +1,11 @@
+---
+'@backstage/plugin-catalog-backend-module-bitbucket-cloud': patch
+'@backstage/plugin-scaffolder-node-test-utils': patch
+'@backstage/plugin-search-backend-module-elasticsearch': patch
+'@backstage/plugin-search-backend-module-pg': patch
+'@backstage/plugin-search-backend-node': patch
+'@backstage/plugin-signals-backend': patch
+'@backstage/plugin-events-node': patch
+---
+
+Replace the usage of `getVoidLogger` with `mockServices.logger.mock` in order to remove the dependency with the soon-to-be-deprecated `backend-common` package.
diff --git a/.changeset/late-planes-fix.md b/.changeset/late-planes-fix.md
deleted file mode 100644
index a57d7ec1d4..0000000000
--- a/.changeset/late-planes-fix.md
+++ /dev/null
@@ -1,6 +0,0 @@
----
-'@backstage/plugin-search-backend-node': patch
-'@backstage/plugin-search-backend': patch
----
-
-Add lifecycle monitoring for the search index registry
diff --git a/.changeset/late-students-live.md b/.changeset/late-students-live.md
new file mode 100644
index 0000000000..6a7c203e9e
--- /dev/null
+++ b/.changeset/late-students-live.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-techdocs': patch
+---
+
+Fixed bug in CopyToClipboardButton component where positioning of the "Copy to clipboard" button in techdocs code snippets was broken in some cases
diff --git a/.changeset/light-rice-argue.md b/.changeset/light-rice-argue.md
new file mode 100644
index 0000000000..23572b4cdd
--- /dev/null
+++ b/.changeset/light-rice-argue.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-scaffolder-backend-module-gitlab': patch
+---
+
+Added `gitlab:issue:edit` action to edit existing GitLab issues
diff --git a/.changeset/little-cooks-approve.md b/.changeset/little-cooks-approve.md
new file mode 100644
index 0000000000..d4088208ae
--- /dev/null
+++ b/.changeset/little-cooks-approve.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-notifications': patch
+---
+
+Fixes performance issue with Notifications title counter.
diff --git a/.changeset/loud-frogs-eat.md b/.changeset/loud-frogs-eat.md
deleted file mode 100644
index dd1ab978f1..0000000000
--- a/.changeset/loud-frogs-eat.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-scaffolder-backend-module-gitlab': patch
----
-
-Add examples for `gitlab:repo:push` scaffolder action & improve related tests
diff --git a/.changeset/loud-pumpkins-bow.md b/.changeset/loud-pumpkins-bow.md
new file mode 100644
index 0000000000..a55c97e19a
--- /dev/null
+++ b/.changeset/loud-pumpkins-bow.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-scaffolder-react': patch
+---
+
+Links that are rendered in the markdown in the `ScaffolderField` component are now opened in new tabs.
diff --git a/.changeset/loud-vans-greet.md b/.changeset/loud-vans-greet.md
deleted file mode 100644
index 732413174b..0000000000
--- a/.changeset/loud-vans-greet.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/backend-app-api': patch
----
-
-Internal refactor to only create one external token handler
diff --git a/.changeset/lovely-games-cry.md b/.changeset/lovely-games-cry.md
deleted file mode 100644
index 5209b93496..0000000000
--- a/.changeset/lovely-games-cry.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-auth-react': patch
----
-
-When using `CookieAuthRefreshProvider` or `useCookieAuthRefresh`, a 404 response from the cookie endpoint will now be treated as if cookie auth is disabled and is not needed.
diff --git a/.changeset/lovely-hats-pay.md b/.changeset/lovely-hats-pay.md
new file mode 100644
index 0000000000..117f50e5db
--- /dev/null
+++ b/.changeset/lovely-hats-pay.md
@@ -0,0 +1,5 @@
+---
+'@backstage/theme': patch
+---
+
+Internal refactor to fix an issue where the MUI 5 `v5-` class prefixing gets removed by tree shaking.
diff --git a/.changeset/lucky-news-guess.md b/.changeset/lucky-news-guess.md
deleted file mode 100644
index 9c2cc4e8b0..0000000000
--- a/.changeset/lucky-news-guess.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-scaffolder-backend-module-bitbucket-server': patch
----
-
-Add examples for `publish:bitbucketServer:pull-request` scaffolder action & improve related tests
diff --git a/.changeset/lucky-taxis-rule.md b/.changeset/lucky-taxis-rule.md
new file mode 100644
index 0000000000..eacbaaefbe
--- /dev/null
+++ b/.changeset/lucky-taxis-rule.md
@@ -0,0 +1,9 @@
+---
+'@backstage/backend-defaults': patch
+---
+
+Added core service factories and implementations from
+`@backstage/backend-app-api`. They are now available as subpath exports, e.g.
+`@backstage/backend-defaults/scheduler` is where the service factory and default
+implementation of `coreServices.scheduler` now lives. They have been marked as
+deprecated in their old locations.
diff --git a/.changeset/many-moles-sing.md b/.changeset/many-moles-sing.md
new file mode 100644
index 0000000000..8b49f674c7
--- /dev/null
+++ b/.changeset/many-moles-sing.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-common': patch
+---
+
+We are deprecating the legacy `createServiceBuilder` factory, so if you are still using it, please checkout the migration guide and [migrate](https://backstage.io/docs/backend-system/building-plugins-and-modules/migrating) your plugin to use the new backend system.
diff --git a/.changeset/many-windows-attack.md b/.changeset/many-windows-attack.md
new file mode 100644
index 0000000000..d0516244f4
--- /dev/null
+++ b/.changeset/many-windows-attack.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-catalog-backend-module-bitbucket-cloud': patch
+---
+
+Remove debug console logging statement
diff --git a/.changeset/mean-laws-lay.md b/.changeset/mean-laws-lay.md
new file mode 100644
index 0000000000..a7c629a9a5
--- /dev/null
+++ b/.changeset/mean-laws-lay.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-catalog-backend': minor
+---
+
+Pass through `EventsService` too in the new backend system
diff --git a/.changeset/neat-rivers-share.md b/.changeset/neat-rivers-share.md
new file mode 100644
index 0000000000..42649de977
--- /dev/null
+++ b/.changeset/neat-rivers-share.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-permission-node': patch
+---
+
+Ensure that service token access restrictions, when present, are taken into account
diff --git a/.changeset/nervous-queens-fly.md b/.changeset/nervous-queens-fly.md
new file mode 100644
index 0000000000..802034765c
--- /dev/null
+++ b/.changeset/nervous-queens-fly.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-test-utils': patch
+---
+
+Refactored `TestDatabases` to no longer depend on `backend-common`
diff --git a/.changeset/new-numbers-hug.md b/.changeset/new-numbers-hug.md
new file mode 100644
index 0000000000..e4e35a2825
--- /dev/null
+++ b/.changeset/new-numbers-hug.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-plugin-api': patch
+---
+
+Moved the declaration of the `SchedulerService` here, along with prefixed versions of all of the types it depends on, from `@backstage/backend-tasks`
diff --git a/.changeset/nice-pants-shave.md b/.changeset/nice-pants-shave.md
new file mode 100644
index 0000000000..500888a817
--- /dev/null
+++ b/.changeset/nice-pants-shave.md
@@ -0,0 +1,8 @@
+---
+'@backstage/plugin-auth-backend-module-cloudflare-access-provider': patch
+'@backstage/plugin-scaffolder-backend-module-sentry': patch
+'@backstage/plugin-scaffolder-backend-module-gitea': patch
+'@backstage/plugin-notifications-node': patch
+---
+
+Use `node-fetch` instead of native fetch, as per https://backstage.io/docs/architecture-decisions/adrs-adr013
diff --git a/.changeset/nine-hairs-kick.md b/.changeset/nine-hairs-kick.md
new file mode 100644
index 0000000000..e4160640b4
--- /dev/null
+++ b/.changeset/nine-hairs-kick.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-catalog-backend-module-gitlab': patch
+---
+
+Fixed an issue in `GitlabOrgDiscoveryEntityProvider` where a missing `orgEnabled` config key was throwing an error.
diff --git a/.changeset/itchy-keys-wonder.md b/.changeset/nine-ties-type.md
similarity index 59%
rename from .changeset/itchy-keys-wonder.md
rename to .changeset/nine-ties-type.md
index 879dc096a4..abb0661724 100644
--- a/.changeset/itchy-keys-wonder.md
+++ b/.changeset/nine-ties-type.md
@@ -3,4 +3,4 @@
'@backstage/backend-app-api': patch
---
-Redact `meta` fields too with the logger
+Fixing issue with log meta fields possibly being circular refs
diff --git a/.changeset/old-trees-check.md b/.changeset/old-trees-check.md
new file mode 100644
index 0000000000..b4d745ffb5
--- /dev/null
+++ b/.changeset/old-trees-check.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-tasks': patch
+---
+
+Deprecate the legacy `TaskScheduler.fromConfig` method and stop using the `getVoidlogger` in tests files to reduce the dependency on the soon-to-deprecate `backstage-common` package.
diff --git a/.changeset/olive-mangos-tickle.md b/.changeset/olive-mangos-tickle.md
new file mode 100644
index 0000000000..6033ec3ed6
--- /dev/null
+++ b/.changeset/olive-mangos-tickle.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-app-api': patch
+---
+
+Stop using `getVoidLogger` in tests to reduce the dependency on the soon-to-deprecate `backstage-common` package.
diff --git a/.changeset/orange-numbers-think.md b/.changeset/orange-numbers-think.md
deleted file mode 100644
index 21dc7ce76b..0000000000
--- a/.changeset/orange-numbers-think.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-search-backend-module-catalog': patch
----
-
-Fix wiring of the module exported at the `/alpha` path, which was causing authentication failures.
diff --git a/.changeset/perfect-bikes-invite.md b/.changeset/perfect-bikes-invite.md
new file mode 100644
index 0000000000..96a4ad5659
--- /dev/null
+++ b/.changeset/perfect-bikes-invite.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-catalog-backend-module-gitlab': patch
+---
+
+Fixed an issue in `GitlabDiscoveryEntityProvider` where the fallback branch was taking precedence over the GitLab default branch.
diff --git a/.changeset/perfect-points-hope.md b/.changeset/perfect-points-hope.md
deleted file mode 100644
index cfc42f77a3..0000000000
--- a/.changeset/perfect-points-hope.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-auth-backend-module-oidc-provider': patch
----
-
-Add nonce to authorize request to be added in ID token
diff --git a/.changeset/polite-otters-talk.md b/.changeset/polite-otters-talk.md
new file mode 100644
index 0000000000..e56b935c1e
--- /dev/null
+++ b/.changeset/polite-otters-talk.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-notifications-backend-module-email': minor
+---
+
+add notification filters
diff --git a/.changeset/pre.json b/.changeset/pre.json
index 809cd51567..bbf21bc6a4 100644
--- a/.changeset/pre.json
+++ b/.changeset/pre.json
@@ -2,336 +2,253 @@
"mode": "pre",
"tag": "next",
"initialVersions": {
- "example-app": "0.2.96",
- "@backstage/app-defaults": "1.5.4",
- "example-app-next": "0.0.10",
- "app-next-example-plugin": "0.0.10",
- "example-backend": "0.2.97",
- "@backstage/backend-app-api": "0.7.0",
- "@backstage/backend-common": "0.21.7",
- "@backstage/backend-defaults": "0.2.17",
+ "example-app": "0.2.97",
+ "@backstage/app-defaults": "1.5.5",
+ "example-app-next": "0.0.11",
+ "app-next-example-plugin": "0.0.11",
+ "example-backend": "0.0.26",
+ "@backstage/backend-app-api": "0.7.3",
+ "@backstage/backend-common": "0.22.0",
+ "@backstage/backend-defaults": "0.2.18",
"@backstage/backend-dev-utils": "0.1.4",
- "@backstage/backend-dynamic-feature-service": "0.2.9",
- "example-backend-next": "0.0.25",
- "@backstage/backend-openapi-utils": "0.1.10",
- "@backstage/backend-plugin-api": "0.6.17",
- "@backstage/backend-tasks": "0.5.22",
- "@backstage/backend-test-utils": "0.3.7",
- "@backstage/catalog-client": "1.6.4",
- "@backstage/catalog-model": "1.4.5",
- "@backstage/cli": "0.26.3",
+ "@backstage/backend-dynamic-feature-service": "0.2.10",
+ "example-backend-legacy": "0.2.98",
+ "@backstage/backend-openapi-utils": "0.1.11",
+ "@backstage/backend-plugin-api": "0.6.18",
+ "@backstage/backend-tasks": "0.5.23",
+ "@backstage/backend-test-utils": "0.3.8",
+ "@backstage/catalog-client": "1.6.5",
+ "@backstage/catalog-model": "1.5.0",
+ "@backstage/cli": "0.26.5",
"@backstage/cli-common": "0.1.13",
"@backstage/cli-node": "0.2.5",
"@backstage/codemods": "0.1.48",
"@backstage/config": "1.2.0",
"@backstage/config-loader": "1.8.0",
- "@backstage/core-app-api": "1.12.4",
- "@backstage/core-compat-api": "0.2.4",
- "@backstage/core-components": "0.14.4",
+ "@backstage/core-app-api": "1.12.5",
+ "@backstage/core-compat-api": "0.2.5",
+ "@backstage/core-components": "0.14.7",
"@backstage/core-plugin-api": "1.9.2",
- "@backstage/create-app": "0.5.14",
- "@backstage/dev-utils": "1.0.31",
- "e2e-test": "0.2.15",
+ "@backstage/create-app": "0.5.15",
+ "@backstage/dev-utils": "1.0.32",
+ "e2e-test": "0.2.16",
"@backstage/e2e-test-utils": "0.1.1",
"@backstage/errors": "1.2.4",
- "@backstage/eslint-plugin": "0.1.7",
- "@backstage/frontend-app-api": "0.6.4",
- "@backstage/frontend-plugin-api": "0.6.4",
- "@backstage/frontend-test-utils": "0.1.6",
- "@backstage/integration": "1.10.0",
+ "@backstage/eslint-plugin": "0.1.8",
+ "@backstage/frontend-app-api": "0.7.0",
+ "@backstage/frontend-plugin-api": "0.6.5",
+ "@backstage/frontend-test-utils": "0.1.7",
+ "@backstage/integration": "1.11.0",
"@backstage/integration-aws-node": "0.1.12",
- "@backstage/integration-react": "1.1.26",
+ "@backstage/integration-react": "1.1.27",
"@backstage/release-manifests": "0.0.11",
- "@backstage/repo-tools": "0.8.0",
- "@techdocs/cli": "1.8.9",
- "techdocs-cli-embedded-app": "0.2.95",
- "@backstage/test-utils": "1.5.4",
- "@backstage/theme": "0.5.3",
+ "@backstage/repo-tools": "0.9.0",
+ "@techdocs/cli": "1.8.11",
+ "techdocs-cli-embedded-app": "0.2.96",
+ "@backstage/test-utils": "1.5.5",
+ "@backstage/theme": "0.5.4",
"@backstage/types": "1.1.1",
"@backstage/version-bridge": "1.0.8",
- "@backstage/plugin-adr": "0.6.17",
- "@backstage/plugin-adr-backend": "0.4.14",
- "@backstage/plugin-adr-common": "0.2.22",
- "@backstage/plugin-airbrake": "0.3.34",
- "@backstage/plugin-airbrake-backend": "0.3.14",
- "@backstage/plugin-allure": "0.1.50",
- "@backstage/plugin-analytics-module-ga": "0.2.4",
- "@backstage/plugin-analytics-module-ga4": "0.2.4",
- "@backstage/plugin-analytics-module-newrelic-browser": "0.1.4",
- "@backstage/plugin-apache-airflow": "0.2.24",
- "@backstage/plugin-api-docs": "0.11.4",
+ "@backstage/plugin-api-docs": "0.11.5",
"@backstage/plugin-api-docs-module-protoc-gen-doc": "0.1.6",
- "@backstage/plugin-apollo-explorer": "0.2.0",
- "@backstage/plugin-app-backend": "0.3.65",
- "@backstage/plugin-app-node": "0.1.17",
- "@backstage/plugin-app-visualizer": "0.1.5",
- "@backstage/plugin-auth-backend": "0.22.4",
- "@backstage/plugin-auth-backend-module-atlassian-provider": "0.1.9",
- "@backstage/plugin-auth-backend-module-aws-alb-provider": "0.1.9",
- "@backstage/plugin-auth-backend-module-azure-easyauth-provider": "0.1.0",
- "@backstage/plugin-auth-backend-module-bitbucket-provider": "0.1.0",
- "@backstage/plugin-auth-backend-module-cloudflare-access-provider": "0.1.0",
- "@backstage/plugin-auth-backend-module-gcp-iap-provider": "0.2.12",
- "@backstage/plugin-auth-backend-module-github-provider": "0.1.14",
- "@backstage/plugin-auth-backend-module-gitlab-provider": "0.1.14",
- "@backstage/plugin-auth-backend-module-google-provider": "0.1.14",
- "@backstage/plugin-auth-backend-module-guest-provider": "0.1.3",
- "@backstage/plugin-auth-backend-module-microsoft-provider": "0.1.12",
- "@backstage/plugin-auth-backend-module-oauth2-provider": "0.1.14",
- "@backstage/plugin-auth-backend-module-oauth2-proxy-provider": "0.1.10",
- "@backstage/plugin-auth-backend-module-oidc-provider": "0.1.8",
- "@backstage/plugin-auth-backend-module-okta-provider": "0.0.10",
- "@backstage/plugin-auth-backend-module-pinniped-provider": "0.1.11",
- "@backstage/plugin-auth-backend-module-vmware-cloud-provider": "0.1.9",
- "@backstage/plugin-auth-node": "0.4.12",
- "@backstage/plugin-auth-react": "0.1.0",
- "@backstage/plugin-azure-devops": "0.4.3",
- "@backstage/plugin-azure-devops-backend": "0.6.4",
- "@backstage/plugin-azure-devops-common": "0.4.1",
- "@backstage/plugin-azure-sites": "0.1.23",
- "@backstage/plugin-azure-sites-backend": "0.3.4",
- "@backstage/plugin-azure-sites-common": "0.1.3",
- "@backstage/plugin-badges": "0.2.58",
- "@backstage/plugin-badges-backend": "0.4.0",
- "@backstage/plugin-bazaar": "0.2.26",
- "@backstage/plugin-bazaar-backend": "0.3.15",
- "@backstage/plugin-bitbucket-cloud-common": "0.2.18",
- "@backstage/plugin-bitrise": "0.1.61",
- "@backstage/plugin-catalog": "1.19.0",
- "@backstage/plugin-catalog-backend": "1.21.1",
- "@backstage/plugin-catalog-backend-module-aws": "0.3.12",
- "@backstage/plugin-catalog-backend-module-azure": "0.1.37",
- "@backstage/plugin-catalog-backend-module-backstage-openapi": "0.2.0",
- "@backstage/plugin-catalog-backend-module-bitbucket-cloud": "0.2.4",
- "@backstage/plugin-catalog-backend-module-bitbucket-server": "0.1.31",
- "@backstage/plugin-catalog-backend-module-gcp": "0.1.18",
- "@backstage/plugin-catalog-backend-module-gerrit": "0.1.34",
- "@backstage/plugin-catalog-backend-module-github": "0.6.0",
- "@backstage/plugin-catalog-backend-module-github-org": "0.1.12",
- "@backstage/plugin-catalog-backend-module-gitlab": "0.3.15",
- "@backstage/plugin-catalog-backend-module-incremental-ingestion": "0.4.22",
- "@backstage/plugin-catalog-backend-module-ldap": "0.5.33",
- "@backstage/plugin-catalog-backend-module-msgraph": "0.5.25",
- "@backstage/plugin-catalog-backend-module-openapi": "0.1.35",
- "@backstage/plugin-catalog-backend-module-puppetdb": "0.1.23",
- "@backstage/plugin-catalog-backend-module-scaffolder-entity-model": "0.1.15",
- "@backstage/plugin-catalog-backend-module-unprocessed": "0.4.4",
- "@backstage/plugin-catalog-common": "1.0.22",
- "@backstage/plugin-catalog-graph": "0.4.4",
- "@backstage/plugin-catalog-import": "0.10.10",
- "@backstage/plugin-catalog-node": "1.11.1",
- "@backstage/plugin-catalog-react": "1.11.3",
- "@backstage/plugin-catalog-unprocessed-entities": "0.2.3",
+ "@backstage/plugin-app-backend": "0.3.66",
+ "@backstage/plugin-app-node": "0.1.18",
+ "@backstage/plugin-app-visualizer": "0.1.6",
+ "@backstage/plugin-auth-backend": "0.22.5",
+ "@backstage/plugin-auth-backend-module-atlassian-provider": "0.1.10",
+ "@backstage/plugin-auth-backend-module-aws-alb-provider": "0.1.10",
+ "@backstage/plugin-auth-backend-module-azure-easyauth-provider": "0.1.1",
+ "@backstage/plugin-auth-backend-module-bitbucket-provider": "0.1.1",
+ "@backstage/plugin-auth-backend-module-cloudflare-access-provider": "0.1.1",
+ "@backstage/plugin-auth-backend-module-gcp-iap-provider": "0.2.13",
+ "@backstage/plugin-auth-backend-module-github-provider": "0.1.15",
+ "@backstage/plugin-auth-backend-module-gitlab-provider": "0.1.15",
+ "@backstage/plugin-auth-backend-module-google-provider": "0.1.15",
+ "@backstage/plugin-auth-backend-module-guest-provider": "0.1.4",
+ "@backstage/plugin-auth-backend-module-microsoft-provider": "0.1.13",
+ "@backstage/plugin-auth-backend-module-oauth2-provider": "0.1.15",
+ "@backstage/plugin-auth-backend-module-oauth2-proxy-provider": "0.1.11",
+ "@backstage/plugin-auth-backend-module-oidc-provider": "0.1.9",
+ "@backstage/plugin-auth-backend-module-okta-provider": "0.0.11",
+ "@backstage/plugin-auth-backend-module-pinniped-provider": "0.1.12",
+ "@backstage/plugin-auth-backend-module-vmware-cloud-provider": "0.1.10",
+ "@backstage/plugin-auth-node": "0.4.13",
+ "@backstage/plugin-auth-react": "0.1.2",
+ "@backstage/plugin-bitbucket-cloud-common": "0.2.19",
+ "@backstage/plugin-catalog": "1.20.0",
+ "@backstage/plugin-catalog-backend": "1.22.0",
+ "@backstage/plugin-catalog-backend-module-aws": "0.3.13",
+ "@backstage/plugin-catalog-backend-module-azure": "0.1.38",
+ "@backstage/plugin-catalog-backend-module-backstage-openapi": "0.2.1",
+ "@backstage/plugin-catalog-backend-module-bitbucket-cloud": "0.2.5",
+ "@backstage/plugin-catalog-backend-module-bitbucket-server": "0.1.32",
+ "@backstage/plugin-catalog-backend-module-gcp": "0.1.19",
+ "@backstage/plugin-catalog-backend-module-gerrit": "0.1.35",
+ "@backstage/plugin-catalog-backend-module-github": "0.6.1",
+ "@backstage/plugin-catalog-backend-module-github-org": "0.1.13",
+ "@backstage/plugin-catalog-backend-module-gitlab": "0.3.16",
+ "@backstage/plugin-catalog-backend-module-gitlab-org": "0.0.1",
+ "@backstage/plugin-catalog-backend-module-incremental-ingestion": "0.4.23",
+ "@backstage/plugin-catalog-backend-module-ldap": "0.5.34",
+ "@backstage/plugin-catalog-backend-module-msgraph": "0.5.26",
+ "@backstage/plugin-catalog-backend-module-openapi": "0.1.36",
+ "@backstage/plugin-catalog-backend-module-puppetdb": "0.1.24",
+ "@backstage/plugin-catalog-backend-module-scaffolder-entity-model": "0.1.16",
+ "@backstage/plugin-catalog-backend-module-unprocessed": "0.4.5",
+ "@backstage/plugin-catalog-common": "1.0.23",
+ "@backstage/plugin-catalog-graph": "0.4.5",
+ "@backstage/plugin-catalog-import": "0.11.0",
+ "@backstage/plugin-catalog-node": "1.12.0",
+ "@backstage/plugin-catalog-react": "1.12.0",
+ "@backstage/plugin-catalog-unprocessed-entities": "0.2.4",
"@backstage/plugin-catalog-unprocessed-entities-common": "0.0.1",
- "@backstage/plugin-cicd-statistics": "0.1.36",
- "@backstage/plugin-cicd-statistics-module-gitlab": "0.1.30",
- "@backstage/plugin-circleci": "0.3.34",
- "@backstage/plugin-cloudbuild": "0.5.1",
- "@backstage/plugin-code-climate": "0.1.34",
- "@backstage/plugin-code-coverage": "0.2.27",
- "@backstage/plugin-code-coverage-backend": "0.2.31",
- "@backstage/plugin-codescene": "0.1.26",
- "@backstage/plugin-config-schema": "0.1.54",
- "@backstage/plugin-cost-insights": "0.12.23",
- "@backstage/plugin-cost-insights-common": "0.1.2",
- "@backstage/plugin-devtools": "0.1.13",
- "@backstage/plugin-devtools-backend": "0.3.3",
+ "@backstage/plugin-config-schema": "0.1.55",
+ "@backstage/plugin-devtools": "0.1.14",
+ "@backstage/plugin-devtools-backend": "0.3.4",
"@backstage/plugin-devtools-common": "0.1.9",
- "@backstage/plugin-dynatrace": "10.0.3",
- "@backstage/plugin-entity-feedback": "0.2.17",
- "@backstage/plugin-entity-feedback-backend": "0.2.14",
- "@backstage/plugin-entity-feedback-common": "0.1.3",
- "@backstage/plugin-entity-validation": "0.1.19",
- "@backstage/plugin-events-backend": "0.3.4",
- "@backstage/plugin-events-backend-module-aws-sqs": "0.3.3",
- "@backstage/plugin-events-backend-module-azure": "0.2.3",
- "@backstage/plugin-events-backend-module-bitbucket-cloud": "0.2.3",
- "@backstage/plugin-events-backend-module-gerrit": "0.2.3",
- "@backstage/plugin-events-backend-module-github": "0.2.3",
- "@backstage/plugin-events-backend-module-gitlab": "0.2.3",
- "@backstage/plugin-events-backend-test-utils": "0.1.27",
- "@backstage/plugin-events-node": "0.3.3",
- "@internal/plugin-todo-list": "1.0.26",
- "@internal/plugin-todo-list-backend": "1.0.26",
+ "@backstage/plugin-events-backend": "0.3.5",
+ "@backstage/plugin-events-backend-module-aws-sqs": "0.3.4",
+ "@backstage/plugin-events-backend-module-azure": "0.2.4",
+ "@backstage/plugin-events-backend-module-bitbucket-cloud": "0.2.4",
+ "@backstage/plugin-events-backend-module-gerrit": "0.2.4",
+ "@backstage/plugin-events-backend-module-github": "0.2.4",
+ "@backstage/plugin-events-backend-module-gitlab": "0.2.4",
+ "@backstage/plugin-events-backend-test-utils": "0.1.28",
+ "@backstage/plugin-events-node": "0.3.4",
+ "@internal/plugin-todo-list": "1.0.27",
+ "@internal/plugin-todo-list-backend": "1.0.27",
"@internal/plugin-todo-list-common": "1.0.18",
- "@backstage/plugin-explore": "0.4.20",
- "@backstage/plugin-explore-backend": "0.0.27",
- "@backstage/plugin-explore-common": "0.0.2",
- "@backstage/plugin-explore-react": "0.0.38",
- "@backstage/plugin-firehydrant": "0.2.18",
- "@backstage/plugin-fossa": "0.2.66",
- "@backstage/plugin-gcalendar": "0.3.27",
- "@backstage/plugin-gcp-projects": "0.3.50",
- "@backstage/plugin-git-release-manager": "0.3.46",
- "@backstage/plugin-github-actions": "0.6.15",
- "@backstage/plugin-github-deployments": "0.1.65",
- "@backstage/plugin-github-issues": "0.4.1",
- "@backstage/plugin-github-pull-requests-board": "0.2.0",
- "@backstage/plugin-gitops-profiles": "0.3.49",
- "@backstage/plugin-gocd": "0.1.40",
- "@backstage/plugin-graphiql": "0.3.7",
- "@backstage/plugin-graphql-voyager": "0.1.16",
- "@backstage/plugin-home": "0.7.3",
- "@backstage/plugin-home-react": "0.1.12",
- "@backstage/plugin-ilert": "0.2.23",
- "@backstage/plugin-jenkins": "0.9.9",
- "@backstage/plugin-jenkins-backend": "0.4.4",
- "@backstage/plugin-jenkins-common": "0.1.25",
- "@backstage/plugin-kafka": "0.3.34",
- "@backstage/plugin-kafka-backend": "0.3.15",
- "@backstage/plugin-kubernetes": "0.11.9",
- "@backstage/plugin-kubernetes-backend": "0.17.0",
- "@backstage/plugin-kubernetes-cluster": "0.0.10",
- "@backstage/plugin-kubernetes-common": "0.7.5",
- "@backstage/plugin-kubernetes-node": "0.1.11",
- "@backstage/plugin-kubernetes-react": "0.3.4",
- "@backstage/plugin-lighthouse": "0.4.19",
- "@backstage/plugin-lighthouse-backend": "0.4.10",
- "@backstage/plugin-lighthouse-common": "0.1.5",
- "@backstage/plugin-linguist": "0.1.19",
- "@backstage/plugin-linguist-backend": "0.5.15",
- "@backstage/plugin-linguist-common": "0.1.2",
- "@backstage/plugin-microsoft-calendar": "0.1.16",
- "@backstage/plugin-newrelic": "0.3.49",
- "@backstage/plugin-newrelic-dashboard": "0.3.9",
- "@backstage/plugin-nomad": "0.1.15",
- "@backstage/plugin-nomad-backend": "0.1.19",
- "@backstage/plugin-notifications": "0.2.0",
- "@backstage/plugin-notifications-backend": "0.2.0",
+ "@backstage/plugin-home": "0.7.4",
+ "@backstage/plugin-home-react": "0.1.13",
+ "@backstage/plugin-kubernetes": "0.11.10",
+ "@backstage/plugin-kubernetes-backend": "0.17.1",
+ "@backstage/plugin-kubernetes-cluster": "0.0.11",
+ "@backstage/plugin-kubernetes-common": "0.7.6",
+ "@backstage/plugin-kubernetes-node": "0.1.12",
+ "@backstage/plugin-kubernetes-react": "0.3.5",
+ "@backstage/plugin-notifications": "0.2.1",
+ "@backstage/plugin-notifications-backend": "0.2.1",
+ "@backstage/plugin-notifications-backend-module-email": "0.0.1",
"@backstage/plugin-notifications-common": "0.0.3",
- "@backstage/plugin-notifications-node": "0.1.3",
- "@backstage/plugin-octopus-deploy": "0.2.16",
- "@backstage/plugin-opencost": "0.2.9",
- "@backstage/plugin-org": "0.6.24",
- "@backstage/plugin-org-react": "0.1.23",
- "@backstage/plugin-pagerduty": "0.7.6",
- "@backstage/plugin-periskop": "0.1.32",
- "@backstage/plugin-periskop-backend": "0.2.15",
- "@backstage/plugin-permission-backend": "0.5.41",
- "@backstage/plugin-permission-backend-module-allow-all-policy": "0.1.14",
+ "@backstage/plugin-notifications-node": "0.1.4",
+ "@backstage/plugin-org": "0.6.25",
+ "@backstage/plugin-org-react": "0.1.24",
+ "@backstage/plugin-permission-backend": "0.5.42",
+ "@backstage/plugin-permission-backend-module-allow-all-policy": "0.1.15",
"@backstage/plugin-permission-common": "0.7.13",
- "@backstage/plugin-permission-node": "0.7.28",
+ "@backstage/plugin-permission-node": "0.7.29",
"@backstage/plugin-permission-react": "0.4.22",
- "@backstage/plugin-playlist": "0.2.8",
- "@backstage/plugin-playlist-backend": "0.3.21",
- "@backstage/plugin-playlist-common": "0.1.15",
- "@backstage/plugin-proxy-backend": "0.4.15",
- "@backstage/plugin-puppetdb": "0.1.17",
- "@backstage/plugin-rollbar": "0.4.34",
- "@backstage/plugin-rollbar-backend": "0.1.62",
- "@backstage/plugin-scaffolder": "1.19.3",
- "@backstage/plugin-scaffolder-backend": "1.22.4",
- "@backstage/plugin-scaffolder-backend-module-azure": "0.1.9",
- "@backstage/plugin-scaffolder-backend-module-bitbucket": "0.2.7",
- "@backstage/plugin-scaffolder-backend-module-bitbucket-cloud": "0.1.7",
- "@backstage/plugin-scaffolder-backend-module-bitbucket-server": "0.1.7",
- "@backstage/plugin-scaffolder-backend-module-confluence-to-markdown": "0.2.18",
- "@backstage/plugin-scaffolder-backend-module-cookiecutter": "0.2.41",
- "@backstage/plugin-scaffolder-backend-module-gerrit": "0.1.9",
- "@backstage/plugin-scaffolder-backend-module-gitea": "0.1.7",
- "@backstage/plugin-scaffolder-backend-module-github": "0.2.7",
- "@backstage/plugin-scaffolder-backend-module-gitlab": "0.3.3",
- "@backstage/plugin-scaffolder-backend-module-rails": "0.4.34",
- "@backstage/plugin-scaffolder-backend-module-sentry": "0.1.25",
- "@backstage/plugin-scaffolder-backend-module-yeoman": "0.3.0",
- "@backstage/plugin-scaffolder-common": "1.5.1",
- "@backstage/plugin-scaffolder-node": "0.4.3",
- "@backstage/plugin-scaffolder-node-test-utils": "0.1.3",
- "@backstage/plugin-scaffolder-react": "1.8.4",
- "@backstage/plugin-search": "1.4.10",
- "@backstage/plugin-search-backend": "1.5.7",
- "@backstage/plugin-search-backend-module-catalog": "0.1.22",
- "@backstage/plugin-search-backend-module-elasticsearch": "1.4.0",
- "@backstage/plugin-search-backend-module-explore": "0.1.21",
- "@backstage/plugin-search-backend-module-pg": "0.5.26",
- "@backstage/plugin-search-backend-module-stack-overflow-collator": "0.1.10",
- "@backstage/plugin-search-backend-module-techdocs": "0.1.22",
- "@backstage/plugin-search-backend-node": "1.2.21",
+ "@backstage/plugin-proxy-backend": "0.4.16",
+ "@backstage/plugin-scaffolder": "1.20.0",
+ "@backstage/plugin-scaffolder-backend": "1.22.6",
+ "@backstage/plugin-scaffolder-backend-module-azure": "0.1.10",
+ "@backstage/plugin-scaffolder-backend-module-bitbucket": "0.2.8",
+ "@backstage/plugin-scaffolder-backend-module-bitbucket-cloud": "0.1.8",
+ "@backstage/plugin-scaffolder-backend-module-bitbucket-server": "0.1.8",
+ "@backstage/plugin-scaffolder-backend-module-confluence-to-markdown": "0.2.19",
+ "@backstage/plugin-scaffolder-backend-module-cookiecutter": "0.2.42",
+ "@backstage/plugin-scaffolder-backend-module-gerrit": "0.1.10",
+ "@backstage/plugin-scaffolder-backend-module-gitea": "0.1.8",
+ "@backstage/plugin-scaffolder-backend-module-github": "0.2.8",
+ "@backstage/plugin-scaffolder-backend-module-gitlab": "0.4.0",
+ "@backstage/plugin-scaffolder-backend-module-notifications": "0.0.1",
+ "@backstage/plugin-scaffolder-backend-module-rails": "0.4.35",
+ "@backstage/plugin-scaffolder-backend-module-sentry": "0.1.26",
+ "@backstage/plugin-scaffolder-backend-module-yeoman": "0.3.1",
+ "@backstage/plugin-scaffolder-common": "1.5.2",
+ "@backstage/plugin-scaffolder-node": "0.4.4",
+ "@backstage/plugin-scaffolder-node-test-utils": "0.1.4",
+ "@backstage/plugin-scaffolder-react": "1.8.5",
+ "@backstage/plugin-search": "1.4.11",
+ "@backstage/plugin-search-backend": "1.5.8",
+ "@backstage/plugin-search-backend-module-catalog": "0.1.24",
+ "@backstage/plugin-search-backend-module-elasticsearch": "1.4.1",
+ "@backstage/plugin-search-backend-module-explore": "0.1.24",
+ "@backstage/plugin-search-backend-module-pg": "0.5.27",
+ "@backstage/plugin-search-backend-module-stack-overflow-collator": "0.1.11",
+ "@backstage/plugin-search-backend-module-techdocs": "0.1.23",
+ "@backstage/plugin-search-backend-node": "1.2.22",
"@backstage/plugin-search-common": "1.2.11",
- "@backstage/plugin-search-react": "1.7.10",
- "@backstage/plugin-sentry": "0.5.19",
- "@backstage/plugin-shortcuts": "0.3.23",
- "@backstage/plugin-signals": "0.0.5",
- "@backstage/plugin-signals-backend": "0.1.3",
- "@backstage/plugin-signals-node": "0.1.3",
+ "@backstage/plugin-search-react": "1.7.11",
+ "@backstage/plugin-signals": "0.0.6",
+ "@backstage/plugin-signals-backend": "0.1.4",
+ "@backstage/plugin-signals-node": "0.1.4",
"@backstage/plugin-signals-react": "0.0.3",
- "@backstage/plugin-sonarqube": "0.7.16",
- "@backstage/plugin-sonarqube-backend": "0.2.19",
- "@backstage/plugin-sonarqube-react": "0.1.15",
- "@backstage/plugin-splunk-on-call": "0.4.23",
- "@backstage/plugin-stack-overflow": "0.1.29",
- "@backstage/plugin-stack-overflow-backend": "0.2.21",
- "@backstage/plugin-stackstorm": "0.1.15",
- "@backstage/plugin-tech-insights": "0.3.26",
- "@backstage/plugin-tech-insights-backend": "0.5.31",
- "@backstage/plugin-tech-insights-backend-module-jsonfc": "0.1.49",
- "@backstage/plugin-tech-insights-common": "0.2.12",
- "@backstage/plugin-tech-insights-node": "0.6.0",
- "@backstage/plugin-tech-radar": "0.7.3",
- "@backstage/plugin-techdocs": "1.10.4",
- "@backstage/plugin-techdocs-addons-test-utils": "1.0.31",
- "@backstage/plugin-techdocs-backend": "1.10.4",
- "@backstage/plugin-techdocs-module-addons-contrib": "1.1.9",
- "@backstage/plugin-techdocs-node": "1.12.3",
- "@backstage/plugin-techdocs-react": "1.2.3",
- "@backstage/plugin-todo": "0.2.38",
- "@backstage/plugin-todo-backend": "0.3.16",
- "@backstage/plugin-user-settings": "0.8.5",
- "@backstage/plugin-user-settings-backend": "0.2.16",
- "@backstage/plugin-vault": "0.1.29",
- "@backstage/plugin-vault-backend": "0.4.10",
- "@backstage/plugin-vault-node": "0.1.10",
- "@backstage/plugin-xcmetrics": "0.2.52",
- "@backstage/plugin-catalog-backend-module-gitlab-org": "0.0.0"
+ "@backstage/plugin-techdocs": "1.10.5",
+ "@backstage/plugin-techdocs-addons-test-utils": "1.0.32",
+ "@backstage/plugin-techdocs-backend": "1.10.5",
+ "@backstage/plugin-techdocs-module-addons-contrib": "1.1.10",
+ "@backstage/plugin-techdocs-node": "1.12.4",
+ "@backstage/plugin-techdocs-react": "1.2.4",
+ "@backstage/plugin-user-settings": "0.8.6",
+ "@backstage/plugin-user-settings-backend": "0.2.17"
},
"changesets": [
- "afraid-needles-divide",
- "bright-pumpkins-rule",
- "chatty-cycles-unite",
- "chilly-adults-sing",
- "chilly-fireants-roll",
- "cold-rats-leave",
- "cool-elephants-march",
- "cuddly-chairs-kick",
- "curvy-planes-flash",
- "dry-sloths-impress",
- "eighty-apricots-kneel",
- "eighty-bats-stare",
- "eleven-pandas-divide",
- "fix-stackoverflow",
- "fluffy-hotels-wait",
- "fresh-crews-impress",
- "gold-waves-bake",
- "gorgeous-cameras-cross",
- "green-adults-push",
- "hip-carrots-drive",
- "itchy-gorillas-hope",
- "itchy-keys-wonder",
- "late-planes-fix",
- "loud-frogs-eat",
- "loud-vans-greet",
- "lovely-games-cry",
- "lucky-news-guess",
- "orange-numbers-think",
- "perfect-points-hope",
- "proud-doors-cheat",
- "purple-parents-sin",
- "purple-waves-smile",
- "rare-fireants-tickle",
- "real-crabs-obey",
- "renovate-0d0bd5c",
- "selfish-pigs-glow",
- "shy-students-clap",
- "smart-avocados-invent",
- "smooth-garlics-behave",
- "sour-socks-approve",
- "stupid-onions-know",
- "tasty-apes-learn",
- "thick-llamas-itch",
- "tricky-cougars-shout",
- "unlucky-days-play",
- "unlucky-rivers-collect",
- "warm-fans-promise",
- "young-olives-drop"
+ "brave-apples-move",
+ "breezy-badgers-train",
+ "calm-cars-serve",
+ "calm-plums-wink",
+ "cold-seas-end",
+ "create-app-1716302437",
+ "create-app-1716903719",
+ "cyan-jobs-visit",
+ "cyan-paws-beg",
+ "cyan-snails-peel",
+ "eighty-kings-dress",
+ "eighty-yaks-switch",
+ "empty-spoons-tell",
+ "empty-tables-ring",
+ "famous-monkeys-count",
+ "forty-adults-roll",
+ "four-adults-mix",
+ "friendly-keys-fold",
+ "gentle-baboons-peel",
+ "gold-teachers-wink",
+ "great-cougars-guess",
+ "itchy-spoons-cry",
+ "large-months-decide",
+ "late-ants-impress",
+ "late-students-live",
+ "little-cooks-approve",
+ "loud-pumpkins-bow",
+ "lovely-hats-pay",
+ "lucky-taxis-rule",
+ "many-moles-sing",
+ "mean-laws-lay",
+ "neat-rivers-share",
+ "new-numbers-hug",
+ "nice-pants-shave",
+ "nine-hairs-kick",
+ "nine-ties-type",
+ "old-trees-check",
+ "olive-mangos-tickle",
+ "perfect-bikes-invite",
+ "polite-otters-talk",
+ "rude-kings-press",
+ "seven-geese-raise",
+ "shaggy-jokes-promise",
+ "six-llamas-give",
+ "slimy-fans-raise",
+ "smooth-gifts-nail",
+ "soft-flies-live",
+ "sour-colts-juggle",
+ "spicy-brooms-hang",
+ "spicy-camels-happen",
+ "spotty-plants-switch",
+ "strong-moose-work",
+ "stupid-tigers-bake",
+ "tall-lies-fetch",
+ "tall-pumas-teach",
+ "tender-seas-listen",
+ "thirty-plums-shout",
+ "tiny-pandas-return",
+ "warm-bees-hope",
+ "weak-gifts-occur",
+ "wet-crabs-guess",
+ "wild-doors-cheat",
+ "wild-ears-walk",
+ "wise-vans-sin",
+ "wise-wasps-look",
+ "young-camels-return"
]
}
diff --git a/.changeset/pretty-berries-live.md b/.changeset/pretty-berries-live.md
new file mode 100644
index 0000000000..e83ebeef13
--- /dev/null
+++ b/.changeset/pretty-berries-live.md
@@ -0,0 +1,6 @@
+---
+'@backstage/backend-defaults': patch
+'@backstage/backend-common': patch
+---
+
+Deprecated `dropDatabase`
diff --git a/.changeset/proud-doors-cheat.md b/.changeset/proud-doors-cheat.md
deleted file mode 100644
index 55ab7878d4..0000000000
--- a/.changeset/proud-doors-cheat.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/theme': patch
----
-
-Fixed bug where scrollbars don't pick up the theme when in dark mode
diff --git a/.changeset/purple-parents-sin.md b/.changeset/purple-parents-sin.md
deleted file mode 100644
index 4de90893ef..0000000000
--- a/.changeset/purple-parents-sin.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-catalog-backend-module-backstage-openapi': patch
----
-
-Fix incorrect dependency import.
diff --git a/.changeset/purple-waves-smile.md b/.changeset/purple-waves-smile.md
deleted file mode 100644
index 44da72ea70..0000000000
--- a/.changeset/purple-waves-smile.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-auth-backend-module-guest-provider': patch
----
-
-Error if used outside of a development environment without explicit allowance
diff --git a/.changeset/rare-fireants-tickle.md b/.changeset/rare-fireants-tickle.md
deleted file mode 100644
index 8668d4c287..0000000000
--- a/.changeset/rare-fireants-tickle.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/core-components': patch
----
-
-Added optional `initialShowDropDown` prop to `SidebarSubmenuItem` to internally manage the initial display state of the dropdown items.
diff --git a/.changeset/real-crabs-obey.md b/.changeset/real-crabs-obey.md
deleted file mode 100644
index 9a52f0e5a6..0000000000
--- a/.changeset/real-crabs-obey.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-search-backend-module-explore': patch
----
-
-Migrate search collator to use the new auth services.
diff --git a/.changeset/real-ghosts-return.md b/.changeset/real-ghosts-return.md
new file mode 100644
index 0000000000..9f81649254
--- /dev/null
+++ b/.changeset/real-ghosts-return.md
@@ -0,0 +1,5 @@
+---
+'@backstage/create-app': patch
+---
+
+Bumped TypeScript to version `5.4`.
diff --git a/.changeset/renovate-0d0bd5c.md b/.changeset/renovate-0d0bd5c.md
deleted file mode 100644
index ac3fe697f9..0000000000
--- a/.changeset/renovate-0d0bd5c.md
+++ /dev/null
@@ -1,11 +0,0 @@
----
-'@backstage/plugin-home-react': patch
-'@backstage/plugin-home': patch
-'@backstage/plugin-scaffolder-react': patch
-'@backstage/plugin-scaffolder': patch
----
-
-Updated dependency `@rjsf/utils` to `5.18.2`.
-Updated dependency `@rjsf/core` to `5.18.2`.
-Updated dependency `@rjsf/material-ui` to `5.18.2`.
-Updated dependency `@rjsf/validator-ajv8` to `5.18.2`.
diff --git a/.changeset/rude-kings-press.md b/.changeset/rude-kings-press.md
new file mode 100644
index 0000000000..5c10753f8a
--- /dev/null
+++ b/.changeset/rude-kings-press.md
@@ -0,0 +1,8 @@
+---
+'@backstage/backend-app-api': patch
+---
+
+Deprecated core service factories and implementations and moved them over to
+subpath exports on `@backstage/backend-defaults` instead. E.g.
+`@backstage/backend-defaults/scheduler` is where the service factory and default
+implementation of `coreServices.scheduler` now lives.
diff --git a/.changeset/selfish-pigs-glow.md b/.changeset/selfish-pigs-glow.md
deleted file mode 100644
index c7808c0283..0000000000
--- a/.changeset/selfish-pigs-glow.md
+++ /dev/null
@@ -1,6 +0,0 @@
----
-'@backstage/plugin-auth-backend': patch
-'@backstage/plugin-auth-node': patch
----
-
-Allow overriding default ownership resolving with the new `AuthOwnershipResolutionExtensionPoint`
diff --git a/.changeset/selfish-pugs-lick.md b/.changeset/selfish-pugs-lick.md
new file mode 100644
index 0000000000..1ac7ac7321
--- /dev/null
+++ b/.changeset/selfish-pugs-lick.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-permission-node': patch
+---
+
+Import `tokenManager` definition from `@backstage/backend-plugin-api`
diff --git a/.changeset/seven-geese-raise.md b/.changeset/seven-geese-raise.md
new file mode 100644
index 0000000000..3d6e2347b9
--- /dev/null
+++ b/.changeset/seven-geese-raise.md
@@ -0,0 +1,6 @@
+---
+'@backstage/plugin-search-backend-node': patch
+'@backstage/plugin-search-backend': patch
+---
+
+Split backend search plugin startup into "init" and "start" stages to ensure necessary initialization has happened before startup
diff --git a/.changeset/shaggy-jokes-promise.md b/.changeset/shaggy-jokes-promise.md
new file mode 100644
index 0000000000..e7788b69f4
--- /dev/null
+++ b/.changeset/shaggy-jokes-promise.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-search-backend': patch
+---
+
+Move @backstage/repo-tools to devDependencies
diff --git a/.changeset/shy-students-clap.md b/.changeset/shy-students-clap.md
deleted file mode 100644
index 0e6244f21d..0000000000
--- a/.changeset/shy-students-clap.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-catalog-backend-module-gitlab-org': patch
----
-
-Added a new `catalog-backend-module-gitlab-org` module which adds the `GitlabOrgDiscoveryEntityProvider` to the catalog's providers using the new backend system.
diff --git a/.changeset/six-llamas-give.md b/.changeset/six-llamas-give.md
new file mode 100644
index 0000000000..9bfbf52625
--- /dev/null
+++ b/.changeset/six-llamas-give.md
@@ -0,0 +1,6 @@
+---
+'@backstage/backend-defaults': minor
+'@backstage/backend-common': minor
+---
+
+Deprecated and moved over core services to `@backstage/backend-defaults`
diff --git a/.changeset/six-scissors-smile.md b/.changeset/six-scissors-smile.md
deleted file mode 100644
index 7680edbba6..0000000000
--- a/.changeset/six-scissors-smile.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/core-components': patch
----
-
-The `SignInPage` guest provider will now fall back to legacy guest auth if the backend request fails, allowing guest auth without a running backend.
diff --git a/.changeset/slimy-fans-raise.md b/.changeset/slimy-fans-raise.md
new file mode 100644
index 0000000000..782ef4bc82
--- /dev/null
+++ b/.changeset/slimy-fans-raise.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-techdocs': patch
+---
+
+Fix weird opening behaviour of the component.
diff --git a/.changeset/smart-avocados-invent.md b/.changeset/smart-avocados-invent.md
deleted file mode 100644
index c71b6fef37..0000000000
--- a/.changeset/smart-avocados-invent.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/backend-dynamic-feature-service': patch
----
-
-Updates the `scanRoot` method in the `PluginScanner` class to specifically ignore the `lost+found` directory, which is a system-generated directory used for file recovery on Unix-like systems. Skipping this directory avoids unnecessary errors.
diff --git a/.changeset/smooth-garlics-behave.md b/.changeset/smooth-garlics-behave.md
deleted file mode 100644
index ed972ae164..0000000000
--- a/.changeset/smooth-garlics-behave.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/backend-common': patch
----
-
-Added option to `ServerTokenManager.fromConfig` that allows it to be instantiated in production without any configured keys.
diff --git a/.changeset/smooth-gifts-nail.md b/.changeset/smooth-gifts-nail.md
new file mode 100644
index 0000000000..aa2585bc4f
--- /dev/null
+++ b/.changeset/smooth-gifts-nail.md
@@ -0,0 +1,6 @@
+---
+'@backstage/plugin-scaffolder-backend': patch
+'@backstage/backend-app-api': patch
+---
+
+Updating the logger redaction message to something less dramatic
diff --git a/.changeset/soft-flies-live.md b/.changeset/soft-flies-live.md
new file mode 100644
index 0000000000..b331269647
--- /dev/null
+++ b/.changeset/soft-flies-live.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-scaffolder-backend-module-gitlab': patch
+---
+
+Add new `gitlab:pipeline:trigger` action to trigger GitLab pipelines.
diff --git a/.changeset/sour-colts-juggle.md b/.changeset/sour-colts-juggle.md
new file mode 100644
index 0000000000..35dc79452a
--- /dev/null
+++ b/.changeset/sour-colts-juggle.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-test-utils': patch
+---
+
+Fix the logger service mock to prevent returning `undefined` from the `child` method.
diff --git a/.changeset/sour-socks-approve.md b/.changeset/sour-socks-approve.md
deleted file mode 100644
index db40806280..0000000000
--- a/.changeset/sour-socks-approve.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-catalog-backend': minor
----
-
-Emit well known relationships for the Domain entity kind.
diff --git a/.changeset/spicy-brooms-hang.md b/.changeset/spicy-brooms-hang.md
new file mode 100644
index 0000000000..23f7da309b
--- /dev/null
+++ b/.changeset/spicy-brooms-hang.md
@@ -0,0 +1,6 @@
+---
+'@backstage/plugin-scaffolder-react': patch
+'@backstage/plugin-scaffolder': patch
+---
+
+Fixing bug in `formData` type as it should be `optional` as it's possibly undefined
diff --git a/.changeset/spicy-camels-happen.md b/.changeset/spicy-camels-happen.md
new file mode 100644
index 0000000000..1017f042ad
--- /dev/null
+++ b/.changeset/spicy-camels-happen.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-common': patch
+---
+
+We are deprecating the legacy router handlers and contexts in preparation for the new backend system stable release.
diff --git a/.changeset/spotty-plants-switch.md b/.changeset/spotty-plants-switch.md
new file mode 100644
index 0000000000..a5951de05d
--- /dev/null
+++ b/.changeset/spotty-plants-switch.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-catalog-backend-module-ldap': minor
+---
+
+Migrate LDAP catalog module to the new backend system.
diff --git a/.changeset/strong-moose-work.md b/.changeset/strong-moose-work.md
new file mode 100644
index 0000000000..443b708e51
--- /dev/null
+++ b/.changeset/strong-moose-work.md
@@ -0,0 +1,5 @@
+---
+'@backstage/repo-tools': patch
+---
+
+Add `--client-additional-properties` option to `openapi generate` command
diff --git a/.changeset/stupid-onions-know.md b/.changeset/stupid-onions-know.md
deleted file mode 100644
index 3d028557be..0000000000
--- a/.changeset/stupid-onions-know.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications': patch
----
-
-Empty descriptions are not rendered to improve the look&feel.
diff --git a/.changeset/stupid-tigers-bake.md b/.changeset/stupid-tigers-bake.md
new file mode 100644
index 0000000000..a4579ab05a
--- /dev/null
+++ b/.changeset/stupid-tigers-bake.md
@@ -0,0 +1,7 @@
+---
+'@backstage/plugin-kubernetes-backend': minor
+'@backstage/plugin-kubernetes-common': minor
+'@backstage/plugin-kubernetes-react': minor
+---
+
+Update kubernetes plugins to use autoscaling/v2
diff --git a/.changeset/tall-lies-fetch.md b/.changeset/tall-lies-fetch.md
new file mode 100644
index 0000000000..a4484a5687
--- /dev/null
+++ b/.changeset/tall-lies-fetch.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-catalog': patch
+---
+
+Export `catalogTranslationRef` under `/alpha`
diff --git a/.changeset/tall-pumas-teach.md b/.changeset/tall-pumas-teach.md
new file mode 100644
index 0000000000..39e7c06297
--- /dev/null
+++ b/.changeset/tall-pumas-teach.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-scaffolder-react': patch
+---
+
+Fixed a typo '$' in the review step label
diff --git a/.changeset/tasty-apes-learn.md b/.changeset/tasty-apes-learn.md
deleted file mode 100644
index 7a4545cf10..0000000000
--- a/.changeset/tasty-apes-learn.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications': patch
----
-
-Fix to show web notifications even when browser is on foreground. Fix duplicate notifications with multiple tabs.
diff --git a/.changeset/tender-seas-listen.md b/.changeset/tender-seas-listen.md
new file mode 100644
index 0000000000..86b0bf4618
--- /dev/null
+++ b/.changeset/tender-seas-listen.md
@@ -0,0 +1,11 @@
+---
+'@backstage/plugin-scaffolder-react': patch
+'@backstage/plugin-scaffolder': patch
+'@backstage/plugin-catalog': patch
+---
+
+updated the ContextMenu, ActionsPage, OngoingTask and TemplateCard frontend components to support the new scaffolder permissions:
+
+- `scaffolder.task.create`
+- `scaffolder.task.cancel`
+- `scaffolder.task.read`
diff --git a/.changeset/thick-llamas-itch.md b/.changeset/thick-llamas-itch.md
deleted file mode 100644
index 17d4fb23b6..0000000000
--- a/.changeset/thick-llamas-itch.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications': patch
----
-
-Allow defining `className` and additional properties for `NotificationsSideBarItem`
diff --git a/.changeset/thirty-plums-shout.md b/.changeset/thirty-plums-shout.md
new file mode 100644
index 0000000000..56ac640326
--- /dev/null
+++ b/.changeset/thirty-plums-shout.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-catalog-backend': patch
+---
+
+Added a regex test to check commit hash. If url is from git commit branch ignore the edit url.
diff --git a/.changeset/tiny-pandas-return.md b/.changeset/tiny-pandas-return.md
new file mode 100644
index 0000000000..cc9210a368
--- /dev/null
+++ b/.changeset/tiny-pandas-return.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-api-docs': patch
+---
+
+`DefaultApiExplorerPage` now accepts an optional `ownerPickerMode` for toggling the behavior of the `EntityOwnerPicker`, exposing a new mode `` particularly suitable for larger catalogs. In this new mode, `EntityOwnerPicker` will display all the users and groups present in the catalog.
diff --git a/.changeset/tricky-cougars-shout.md b/.changeset/tricky-cougars-shout.md
deleted file mode 100644
index eed14c9eb8..0000000000
--- a/.changeset/tricky-cougars-shout.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-search-backend-module-explore': patch
----
-
-Update README.md to point to explore plugin in community-plugins repository.
diff --git a/.changeset/unlucky-days-play.md b/.changeset/unlucky-days-play.md
deleted file mode 100644
index b847ebd2fc..0000000000
--- a/.changeset/unlucky-days-play.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications': patch
----
-
-Fix infinite loop in the notification title counter
diff --git a/.changeset/unlucky-rivers-collect.md b/.changeset/unlucky-rivers-collect.md
deleted file mode 100644
index c5ec865658..0000000000
--- a/.changeset/unlucky-rivers-collect.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications-backend': patch
----
-
-Updated documentation for sending messages by external services.
diff --git a/.changeset/warm-bees-hope.md b/.changeset/warm-bees-hope.md
new file mode 100644
index 0000000000..2a3de7fda7
--- /dev/null
+++ b/.changeset/warm-bees-hope.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-plugin-api': patch
+---
+
+Renamed `BackendPluginConfig`, `BackendModuleConfig`, and `ExtensionPointConfig` respectively to `CreateBackendPluginOptions`, `CreateBackendModuleOptions`, and `CreateExtensionPointOptions` to standardize frontend and backend factories signatures.
diff --git a/.changeset/warm-fans-promise.md b/.changeset/warm-fans-promise.md
deleted file mode 100644
index a8a8f8a2c7..0000000000
--- a/.changeset/warm-fans-promise.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/plugin-notifications': patch
----
-
-The rendered size of a notification is limited for very long descriptions.
diff --git a/.changeset/weak-gifts-occur.md b/.changeset/weak-gifts-occur.md
new file mode 100644
index 0000000000..7834c0a9d9
--- /dev/null
+++ b/.changeset/weak-gifts-occur.md
@@ -0,0 +1,10 @@
+---
+'@backstage/plugin-scaffolder-backend': patch
+'@backstage/plugin-scaffolder-common': patch
+---
+
+added the following new permissions to the scaffolder backend endpoints:
+
+- `scaffolder.task.create`
+- `scaffolder.task.cancel`
+- `scaffolder.task.read`
diff --git a/.changeset/wet-crabs-guess.md b/.changeset/wet-crabs-guess.md
new file mode 100644
index 0000000000..c8a9282a47
--- /dev/null
+++ b/.changeset/wet-crabs-guess.md
@@ -0,0 +1,6 @@
+---
+'@backstage/backend-plugin-api': patch
+'@backstage/plugin-catalog-backend': patch
+---
+
+Start using the `isDatabaseConflictError` helper from the `@backstage/backend-plugin-api` package in order to avoid dependency with the soon to deprecate `@backstage/backend-common` package.
diff --git a/.changeset/wild-doors-cheat.md b/.changeset/wild-doors-cheat.md
new file mode 100644
index 0000000000..c302dde467
--- /dev/null
+++ b/.changeset/wild-doors-cheat.md
@@ -0,0 +1,5 @@
+---
+'@backstage/cli': patch
+---
+
+Fix `versions:check --fix` when `yarn.lock` has multiple joint versions in the same section
diff --git a/.changeset/wild-ears-walk.md b/.changeset/wild-ears-walk.md
new file mode 100644
index 0000000000..072c545f1a
--- /dev/null
+++ b/.changeset/wild-ears-walk.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-notifications-backend': minor
+---
+
+adding filtering of notifications by processors
diff --git a/.changeset/wise-vans-sin.md b/.changeset/wise-vans-sin.md
new file mode 100644
index 0000000000..37565c9300
--- /dev/null
+++ b/.changeset/wise-vans-sin.md
@@ -0,0 +1,5 @@
+---
+'@backstage/backend-common': patch
+---
+
+Deprecate legacy service logger helpers and stop using `getVoidLogger` in tests.
diff --git a/.changeset/wise-wasps-look.md b/.changeset/wise-wasps-look.md
new file mode 100644
index 0000000000..34f52b3a7b
--- /dev/null
+++ b/.changeset/wise-wasps-look.md
@@ -0,0 +1,5 @@
+---
+'@backstage/plugin-scaffolder': patch
+---
+
+Change owner to project for azure host
diff --git a/.changeset/young-camels-return.md b/.changeset/young-camels-return.md
new file mode 100644
index 0000000000..efdd822788
--- /dev/null
+++ b/.changeset/young-camels-return.md
@@ -0,0 +1,5 @@
+---
+'@backstage/cli': patch
+---
+
+Bump `esbuild` target for package builds to `ES2022`.
diff --git a/.changeset/young-olives-drop.md b/.changeset/young-olives-drop.md
deleted file mode 100644
index 4058293be8..0000000000
--- a/.changeset/young-olives-drop.md
+++ /dev/null
@@ -1,5 +0,0 @@
----
-'@backstage/backend-plugin-api': patch
----
-
-Removed explicit `toString()` method from `ServiceRef` type.
diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS
index 9fc63fbd04..9cd3bc0690 100644
--- a/.github/CODEOWNERS
+++ b/.github/CODEOWNERS
@@ -61,6 +61,7 @@ yarn.lock @backstage/maintainers @backst
/plugins/linguist-common @backstage/maintainers @backstage/reviewers @awanlin
/plugins/notifications @backstage/maintainers @backstage/notifications-maintainers
/plugins/notifications-* @backstage/maintainers @backstage/notifications-maintainers
+/plugins/scaffolder-backend-module-notifications @backstage/maintainers @backstage/notifications-maintainers
/plugins/octopus-deploy @backstage/maintainers @backstage/reviewers @jmezach
/plugins/permission-* @backstage/permission-maintainers
/plugins/playlist @backstage/maintainers @backstage/reviewers @kuangp
diff --git a/.github/renovate.json5 b/.github/renovate.json5
index a9cb54912a..5a70a25512 100644
--- a/.github/renovate.json5
+++ b/.github/renovate.json5
@@ -62,9 +62,21 @@
matchPackageNames: ['p-limit'],
allowedVersions: '<4.0.0',
},
+ {
+ matchPackageNames: ['p-throttle'],
+ allowedVersions: '<4.0.0',
+ },
{
matchPackageNames: ['p-queue'],
allowedVersions: '<7.0.0',
},
+ {
+ matchPackageNames: ['serialize-error'],
+ allowedVersions: '<9.0.0',
+ },
+ {
+ matchPackageNames: ['yn'],
+ allowedVersions: '<5.0.0',
+ },
],
}
diff --git a/.github/uffizzi/k8s/manifests/backstage-crb.yaml b/.github/uffizzi/k8s/manifests/backstage-crb.yaml
deleted file mode 100644
index a5dad3408a..0000000000
--- a/.github/uffizzi/k8s/manifests/backstage-crb.yaml
+++ /dev/null
@@ -1,12 +0,0 @@
-apiVersion: rbac.authorization.k8s.io/v1
-kind: ClusterRoleBinding
-metadata:
- name: backstage-cluster-ro
-subjects:
- - namespace: backstage
- kind: ServiceAccount
- name: backstage-service-account
-roleRef:
- apiGroup: rbac.authorization.k8s.io
- kind: ClusterRole
- name: system:aggregate-to-view
diff --git a/.github/uffizzi/k8s/manifests/backstage-deploy.yaml b/.github/uffizzi/k8s/manifests/backstage-deploy.yaml
deleted file mode 100644
index 2c1458cfea..0000000000
--- a/.github/uffizzi/k8s/manifests/backstage-deploy.yaml
+++ /dev/null
@@ -1,44 +0,0 @@
-apiVersion: apps/v1
-kind: Deployment
-metadata:
- name: backstage
-spec:
- replicas: 1
- selector:
- matchLabels:
- app: backstage
- template:
- metadata:
- labels:
- app: backstage
- spec:
- serviceAccountName: backstage-service-account
- containers:
- - name: backstage
- image: backstage
- command:
- - /bin/sh
- args:
- - '-c'
- - "APP_CONFIG_app_baseUrl=$$UFFIZZI_URL APP_CONFIG_backend_baseUrl=$$UFFIZZI_URL APP_CONFIG_auth_environment='production' node packages/backend --config app-config.yaml"
- imagePullPolicy: IfNotPresent
- ports:
- - name: http
- containerPort: 7007
- envFrom:
- - secretRef:
- name: postgres-secrets
- env:
- - name: POSTGRES_PORT
- value: '5432'
- - name: POSTGRES_HOST
- value: 'postgres.default.svc.cluster.local'
- - name: NODE_ENV
- value: production
- resources:
- limits:
- cpu: 1000m
- memory: 384Mi
- requests:
- cpu: 20m
- memory: 160Mi
diff --git a/.github/uffizzi/k8s/manifests/backstage-ingress.yaml b/.github/uffizzi/k8s/manifests/backstage-ingress.yaml
deleted file mode 100644
index 8a7f58c524..0000000000
--- a/.github/uffizzi/k8s/manifests/backstage-ingress.yaml
+++ /dev/null
@@ -1,20 +0,0 @@
-apiVersion: networking.k8s.io/v1
-kind: Ingress
-metadata:
- name: backstage
-spec:
- ingressClassName: uffizzi
- rules:
- - host: backstage.example.com
- http:
- paths:
- - backend:
- service:
- name: backstage
- port:
- number: 80
- path: /
- pathType: Prefix
- tls:
- - hosts:
- - backstage.example.com
diff --git a/.github/uffizzi/k8s/manifests/backstage-sa.yaml b/.github/uffizzi/k8s/manifests/backstage-sa.yaml
deleted file mode 100644
index db0b5bde38..0000000000
--- a/.github/uffizzi/k8s/manifests/backstage-sa.yaml
+++ /dev/null
@@ -1,5 +0,0 @@
-apiVersion: v1
-kind: ServiceAccount
-metadata:
- name: backstage-service-account
- namespace: default
diff --git a/.github/uffizzi/k8s/manifests/backstage-svc.yaml b/.github/uffizzi/k8s/manifests/backstage-svc.yaml
deleted file mode 100644
index 1f4abc79b4..0000000000
--- a/.github/uffizzi/k8s/manifests/backstage-svc.yaml
+++ /dev/null
@@ -1,11 +0,0 @@
-apiVersion: v1
-kind: Service
-metadata:
- name: backstage
-spec:
- selector:
- app: backstage
- ports:
- - name: http
- port: 80
- targetPort: http
diff --git a/.github/uffizzi/k8s/manifests/kustomization.yaml b/.github/uffizzi/k8s/manifests/kustomization.yaml
deleted file mode 100644
index d4db0e97b2..0000000000
--- a/.github/uffizzi/k8s/manifests/kustomization.yaml
+++ /dev/null
@@ -1,12 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-resources:
- - backstage-deploy.yaml
- - backstage-crb.yaml
- - backstage-ingress.yaml
- - backstage-sa.yaml
- - backstage-svc.yaml
- - pg-svc.yaml
- - pg-deploy.yaml
- - pg-secret.yaml
- - pg-volume.yaml
diff --git a/.github/uffizzi/k8s/manifests/pg-deploy.yaml b/.github/uffizzi/k8s/manifests/pg-deploy.yaml
deleted file mode 100644
index 950e64283f..0000000000
--- a/.github/uffizzi/k8s/manifests/pg-deploy.yaml
+++ /dev/null
@@ -1,41 +0,0 @@
-# kubernetes/postgres.yaml
-apiVersion: apps/v1
-kind: Deployment
-metadata:
- name: postgres
-spec:
- replicas: 1
- selector:
- matchLabels:
- app: postgres
- template:
- metadata:
- labels:
- app: postgres
- spec:
- containers:
- - name: postgres
- image: postgres:12-alpine
- imagePullPolicy: 'IfNotPresent'
- ports:
- - containerPort: 5432
- env:
- - name: PGDATA
- value: '/data/pgdata'
- envFrom:
- - secretRef:
- name: postgres-secrets
- resources:
- limits:
- cpu: 1000m
- memory: 256Mi
- requests:
- cpu: 10m
- memory: 96Mi
- volumeMounts:
- - mountPath: /data
- name: postgresdb
- volumes:
- - name: postgresdb
- persistentVolumeClaim:
- claimName: postgres-storage-claim
diff --git a/.github/uffizzi/k8s/manifests/pg-secret.yaml b/.github/uffizzi/k8s/manifests/pg-secret.yaml
deleted file mode 100644
index 28a31f7c53..0000000000
--- a/.github/uffizzi/k8s/manifests/pg-secret.yaml
+++ /dev/null
@@ -1,8 +0,0 @@
-apiVersion: v1
-kind: Secret
-metadata:
- name: postgres-secrets
-type: Opaque
-data:
- POSTGRES_USER: YmFja3N0YWdl
- POSTGRES_PASSWORD: aHVudGVyMg==
diff --git a/.github/uffizzi/k8s/manifests/pg-svc.yaml b/.github/uffizzi/k8s/manifests/pg-svc.yaml
deleted file mode 100644
index ab7e192a65..0000000000
--- a/.github/uffizzi/k8s/manifests/pg-svc.yaml
+++ /dev/null
@@ -1,9 +0,0 @@
-apiVersion: v1
-kind: Service
-metadata:
- name: postgres
-spec:
- selector:
- app: postgres
- ports:
- - port: 5432
diff --git a/.github/uffizzi/k8s/manifests/pg-volume.yaml b/.github/uffizzi/k8s/manifests/pg-volume.yaml
deleted file mode 100644
index 0dcb317e50..0000000000
--- a/.github/uffizzi/k8s/manifests/pg-volume.yaml
+++ /dev/null
@@ -1,10 +0,0 @@
-apiVersion: v1
-kind: PersistentVolumeClaim
-metadata:
- name: postgres-storage-claim
-spec:
- accessModes:
- - ReadWriteOnce
- resources:
- requests:
- storage: 2G
diff --git a/.github/uffizzi/uffizzi.production.app-config.yaml b/.github/uffizzi/uffizzi.production.app-config.yaml
deleted file mode 100644
index 53944256e1..0000000000
--- a/.github/uffizzi/uffizzi.production.app-config.yaml
+++ /dev/null
@@ -1,297 +0,0 @@
-app:
- title: Backstage Uffizzi Environment
- baseUrl: ${UFFIZZI_URL}
-
-organization:
- name: My Company
-
-backend:
- baseUrl: ${UFFIZZI_URL}
- auth:
- keys:
- # random mock key for Uffizzi deployments
- - secret: 5TXvdjVZFxF7qf9K5RAYRDoGrLzJooqa
- listen:
- port: 7007
- database:
- client: pg
- connection:
- host: ${POSTGRES_HOST}
- port: ${POSTGRES_PORT}
- user: ${POSTGRES_USER}
- password: ${POSTGRES_PASSWORD}
- cors:
- origin: ${UFFIZZI_URL}
- methods: [GET, HEAD, PATCH, POST, PUT, DELETE]
- credentials: true
- csp:
- connect-src: ["'self'", 'http:', 'https:']
- img-src: ["'self'", 'data:', 'https://cdnjs.cloudflare.com']
- # Content-Security-Policy directives follow the Helmet format: https://helmetjs.github.io/#reference
- # Default Helmet Content-Security-Policy values can be removed by setting the key to false
-
-auth:
- environment: production
- providers: {}
- proxy:
- enabled: true
- url: https://demo.backstage.io/api/auth
-
-catalog:
- rules:
- - allow:
- - Component
- - API
- - Resource
- - System
- - Domain
- - Location
- locations:
- - type: url
- target: https://github.com/backstage/backstage/blob/${REF_NAME}/packages/catalog-model/examples/all.yaml
-
- - type: url
- target: https://github.com/backstage/backstage/blob/${REF_NAME}/plugins/techdocs-backend/examples/documented-component-uffizzi/catalog-info.yaml
-
- - type: url
- target: https://github.com/backstage/backstage/blob/${REF_NAME}/packages/catalog-model/examples/acme-corp.yaml
- rules:
- - allow: [User, Group]
-
- - type: url
- target: https://github.com/backstage/backstage/blob/${REF_NAME}/plugins/scaffolder-backend/sample-templates/all-templates.yaml
- rules:
- - allow: [Template]
-
-proxy:
- endpoints:
- '/circleci/api':
- target: https://circleci.com/api/v1.1
- headers:
- Circle-Token: ${CIRCLECI_AUTH_TOKEN}
-
- '/jenkins/api':
- target: http://localhost:8080
- headers:
- Authorization: ${JENKINS_BASIC_AUTH_HEADER}
-
- '/travisci/api':
- target: https://api.travis-ci.com
- changeOrigin: true
- headers:
- Authorization: ${TRAVISCI_AUTH_TOKEN}
- travis-api-version: '3'
-
- '/newrelic/apm/api':
- target: https://api.newrelic.com/v2
- headers:
- X-Api-Key: ${NEW_RELIC_REST_API_KEY}
-
- '/newrelic/api':
- target: https://api.newrelic.com
- headers:
- X-Api-Key: ${NEW_RELIC_USER_KEY}
-
- '/pagerduty':
- target: https://api.pagerduty.com
- headers:
- Authorization: Token token=${PAGERDUTY_TOKEN}
-
- '/buildkite/api':
- target: https://api.buildkite.com/v2/
- headers:
- Authorization: ${BUILDKITE_TOKEN}
-
- '/sentry/api':
- target: https://sentry.io/api/
- allowedMethods: ['GET']
- headers:
- Authorization: ${SENTRY_TOKEN}
-
- '/ilert':
- target: https://api.ilert.com
- allowedMethods: ['GET', 'POST', 'PUT']
- allowedHeaders: ['Authorization']
- headers:
- Authorization: ${ILERT_AUTH_HEADER}
-
- '/airflow':
- target: https://your.airflow.instance.com/api/v1
- headers:
- Authorization: ${AIRFLOW_BASIC_AUTH_HEADER}
-
- '/gocd':
- target: https://your.gocd.instance.com/go/api
- allowedMethods: ['GET']
- allowedHeaders: ['Authorization']
- headers:
- Authorization: Basic ${GOCD_AUTH_CREDENTIALS}
-
- '/dynatrace':
- target: https://your.dynatrace.instance.com/api/v2
- headers:
- Authorization: 'Api-Token ${DYNATRACE_ACCESS_TOKEN}'
-
-techdocs:
- builder: 'local' # Alternatives - 'external'
- generator:
- runIn: 'local'
- # dockerImage: my-org/techdocs # use a custom docker image
- # pullImage: true # or false to disable automatic pulling of image (e.g. if custom docker login is required)
- publisher:
- type: 'local' # Alternatives - 'googleGcs' or 'awsS3' or 'azureBlobStorage' or 'openStackSwift'. Read documentation for using alternatives.
-
-dynatrace:
- baseUrl: https://your.dynatrace.instance.com
-
-nomad:
- addr: 0.0.0.0
-
-# Score-cards sample configuration.
-scorecards:
- jsonDataUrl: https://raw.githubusercontent.com/Oriflame/backstage-plugins/main/plugins/score-card/sample-data/
- wikiLinkTemplate: https://link-to-wiki/{id}
-
-sentry:
- organization: my-company
-
-rollbar:
- organization: my-company
- # NOTE: The rollbar-backend & accountToken key may be deprecated in the future (replaced by a proxy config)
- accountToken: my-rollbar-account-token
-
-lighthouse:
- baseUrl: http://localhost:3003
-
-kubernetes:
- serviceLocatorMethod:
- type: 'multiTenant'
- clusterLocatorMethods:
- - type: 'config'
- clusters:
- - url: ${UFFIZZI_CLUSTER_APISERVER}
- name: uffizzi
- authProvider: 'serviceAccount'
-
-kafka:
- clientId: backstage
- clusters:
- - name: cluster
- dashboardUrl: https://akhq.io/
- brokers:
- - localhost:9092
-
-allure:
- baseUrl: http://localhost:5050/allure-docker-service
-
-integrations:
- github:
- - host: github.com
- token: ${GITHUB_TOKEN}
- ### Example for how to add your GitHub Enterprise instance using the API:
- # - host: ghe.example.net
- # apiBaseUrl: https://ghe.example.net/api/v3
- # token: ${GHE_TOKEN}
- ### Example for how to add your GitHub Enterprise instance using raw HTTP fetches (token is optional):
- # - host: ghe.example.net
- # rawBaseUrl: https://ghe.example.net/raw
- # token: ${GHE_TOKEN}
- gitlab:
- - host: gitlab.com
- token: ${GITLAB_TOKEN}
- ### Example for how to add a bitbucket cloud integration
- # bitbucketCloud:
- # - username: ${BITBUCKET_USERNAME}
- # appPassword: ${BITBUCKET_APP_PASSWORD}
- ### Example for how to add your bitbucket server instance using the API:
- # - host: server.bitbucket.com
- # apiBaseUrl: server.bitbucket.com
- # username: ${BITBUCKET_SERVER_USERNAME}
- # appPassword: ${BITBUCKET_SERVER_APP_PASSWORD}
- azure:
- - host: dev.azure.com
- token: ${AZURE_TOKEN}
- # googleGcs:
- # clientEmail: 'example@example.com'
- # privateKey: ${GCS_PRIVATE_KEY}
- awsS3:
- - host: amazonaws.com
- accessKeyId: ${AWS_ACCESS_KEY_ID}
- secretAccessKey: ${AWS_SECRET_ACCESS_KEY}
-
-costInsights:
- engineerCost: 200000
- engineerThreshold: 0.5
- products:
- computeEngine:
- name: Compute Engine
- icon: compute
- cloudDataflow:
- name: Cloud Dataflow
- icon: data
- cloudStorage:
- name: Cloud Storage
- icon: storage
- bigQuery:
- name: BigQuery
- icon: search
- events:
- name: Events
- icon: data
- metrics:
- DAU:
- name: Daily Active Users
- default: true
- MSC:
- name: Monthly Subscribers
- currencies:
- engineers:
- label: 'Engineers 🛠'
- unit: 'engineer'
- usd:
- label: 'US Dollars 💵'
- kind: 'USD'
- unit: 'dollar'
- prefix: '$'
- rate: 1
- carbonOffsetTons:
- label: 'Carbon Offset Tons ♻️⚖️s'
- kind: 'CARBON_OFFSET_TONS'
- unit: 'carbon offset ton'
- rate: 3.5
- beers:
- label: 'Beers 🍺'
- kind: 'BEERS'
- unit: 'beer'
- rate: 4.5
- pintsIceCream:
- label: 'Pints of Ice Cream 🍦'
- kind: 'PINTS_OF_ICE_CREAM'
- unit: 'ice cream pint'
- rate: 5.5
-pagerduty:
- eventsBaseUrl: 'https://events.pagerduty.com/v2'
-jenkins:
- instances:
- - name: default
- baseUrl: https://jenkins.example.com
- username: backstage-bot
- apiKey: 123456789abcdef0123456789abcedf012
-
-azureDevOps:
- host: dev.azure.com
- token: my-token
- organization: my-company
-
-apacheAirflow:
- baseUrl: https://your.airflow.instance.com
-
-gocd:
- baseUrl: https://your.gocd.instance.com
-
-permission:
- enabled: true
-
-search:
- query:
- pageLimit: 50
diff --git a/.github/vale/config/vocabularies/Backstage/accept.txt b/.github/vale/config/vocabularies/Backstage/accept.txt
index 026e5a9b18..f2fe96f3ab 100644
--- a/.github/vale/config/vocabularies/Backstage/accept.txt
+++ b/.github/vale/config/vocabularies/Backstage/accept.txt
@@ -152,6 +152,8 @@ graphviz
Hackathons
haproxy
hardcoded
+Harness
+harness
Helidon
Henneke
Heroku
@@ -433,7 +435,6 @@ transpilers
truthy
TSDoc
typeahead
-Uffizzi
ui
unbreak
Unconference
@@ -445,6 +446,7 @@ unregistering
unregistration
untracked
upsert
+upstreams
upvote
URIs
url
@@ -464,6 +466,7 @@ Weaveworks
Webpack
widget's
winston
+Wolfi
www
WWW
XCMetrics
diff --git a/.github/workflows/api-breaking-changes-comment.yml b/.github/workflows/api-breaking-changes-comment.yml
new file mode 100644
index 0000000000..9ae32e1d4a
--- /dev/null
+++ b/.github/workflows/api-breaking-changes-comment.yml
@@ -0,0 +1,111 @@
+name: API Breaking Changes (comment)
+
+on:
+ workflow_run:
+ workflows:
+ - 'API Breaking Changes (Trigger)'
+ types:
+ - completed
+
+jobs:
+ setup:
+ name: Add values from previous step
+ runs-on: ubuntu-latest
+ if: ${{ github.event.workflow_run.conclusion == 'success' }}
+ permissions:
+ # "If you specify the access for any of these scopes, all of those that are not specified are set to none."
+ # https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
+ actions: read # Access cache
+ outputs:
+ git-ref: ${{ steps.event.outputs.GIT_REF }}
+ pr-number: ${{ steps.event.outputs.PR_NUMBER }}
+ action: ${{ steps.event.outputs.ACTION }}
+ steps:
+ - name: Harden Runner
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
+ with:
+ disable-sudo: true
+ egress-policy: block
+ allowed-endpoints: >
+ api.github.com:443
+
+ - name: 'Download artifacts'
+ # Fetch output (zip archive) from the workflow run that triggered this workflow.
+ uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
+ with:
+ script: |
+ let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({
+ owner: context.repo.owner,
+ repo: context.repo.repo,
+ run_id: context.payload.workflow_run.id,
+ });
+ let matchArtifact = allArtifacts.data.artifacts.filter((artifact) => {
+ return artifact.name == "preview-spec"
+ })[0];
+ if (matchArtifact === undefined) {
+ throw TypeError('Build Artifact not found!');
+ }
+ let download = await github.rest.actions.downloadArtifact({
+ owner: context.repo.owner,
+ repo: context.repo.repo,
+ artifact_id: matchArtifact.id,
+ archive_format: 'zip',
+ });
+ let fs = require('fs');
+ fs.writeFileSync(`${process.env.GITHUB_WORKSPACE}/preview-spec.zip`, Buffer.from(download.data));
+
+ - name: 'Accept event from first stage'
+ run: unzip preview-spec.zip event.json
+
+ - name: Read Event into ENV
+ id: event
+ run: |
+ echo PR_NUMBER=$(jq '.number | tonumber' < event.json) >> $GITHUB_OUTPUT
+ echo ACTION=$(jq --raw-output '.action | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT
+ echo GIT_REF=$(jq --raw-output '.pull_request.head.sha | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT
+
+ - name: DEBUG - Print Job Outputs
+ if: ${{ runner.debug }}
+ run: |
+ echo "PR number: ${{ steps.event.outputs.PR_NUMBER }}"
+ echo "Git Ref: ${{ steps.event.outputs.GIT_REF }}"
+ echo "Action: ${{ steps.event.outputs.ACTION }}"
+ cat event.json
+
+ - name: Get Comment
+ id: get-comment
+ run: |
+ unzip preview-spec.zip comment.md
+ ls
+ grep
+
+ add-comment:
+ name: Write comment about issues
+ needs:
+ - setup
+ if: ${{ github.event.workflow_run.conclusion == 'success' }}
+ permissions:
+ contents: read
+ pull-requests: write
+ runs-on: ubuntu-latest
+ steps:
+ - name: Checkout
+ uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
+
+ # Identify comment to be updated
+ - name: Find comment for API Changes
+ uses: peter-evans/find-comment@3eae4d37986fb5a8592848f6a574fdf654e61f9e # v3
+ id: find-comment
+ with:
+ issue-number: ${{ needs.setup.outputs.pr-number }}
+ comment-author: 'github-actions[bot]'
+ body-includes: API changes
+ direction: last
+
+ - name: Create or Update Comment with API Changes
+ uses: peter-evans/create-or-update-comment@71345be0265236311c031f5c7866368bd1eff043 # v4
+ with:
+ comment-id: ${{ steps.find-comment.outputs.comment-id }}
+ issue-number: ${{ github.event.pull_request.number }}
+ body-path: comment.md
+ edit-mode: replace
diff --git a/.github/workflows/api-breaking-changes.yml b/.github/workflows/api-breaking-changes.yml
new file mode 100644
index 0000000000..d44e524ccb
--- /dev/null
+++ b/.github/workflows/api-breaking-changes.yml
@@ -0,0 +1,56 @@
+name: API Breaking Changes (Trigger)
+on:
+ pull_request:
+ types: [opened, synchronize, reopened, closed]
+ paths:
+ - '**/openapi.yaml'
+
+jobs:
+ get-backstage-changes:
+ env:
+ NODE_OPTIONS: --max-old-space-size=4096
+ name: Build PR image
+ runs-on: ubuntu-latest
+ if: ${{ github.event_name != 'pull_request' || github.event.action != 'closed' }}
+ steps:
+ - name: Harden Runner
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
+ with:
+ egress-policy: audit
+
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
+ with:
+ # Fetch the commit that's merged into the base rather than the target ref
+ # This will let us diff only the contents of the PR, without fetching more history
+ ref: 'refs/pull/${{ github.event.pull_request.number }}/merge'
+ - name: fetch base
+ run: git fetch --depth 1 origin ${{ github.base_ref }}
+
+ - name: setup-node
+ uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
+ with:
+ node-version: 18.x
+ registry-url: https://registry.npmjs.org/
+
+ - name: yarn install
+ uses: backstage/actions/yarn-install@a674369920067381b450d398b27df7039b7ef635 # v0.6.5
+ with:
+ cache-prefix: linux-v18
+
+ - name: breaking changes check
+ run: |
+ yarn backstage-repo-tools repo schema openapi diff --since origin/${{ github.base_ref }} > comment.md
+
+ - name: clone artifacts to current directory
+ run: |
+ cat ${{ github.event_path }} > event.json
+
+ - name: Upload Artifacts
+ uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4
+ with:
+ name: preview-spec
+ path: |
+ comment.md
+ event.json
+ retention-days: 2
+ overwrite: true
diff --git a/.github/workflows/automate_area-labels.yml b/.github/workflows/automate_area-labels.yml
index 632624bd50..74f577f360 100644
--- a/.github/workflows/automate_area-labels.yml
+++ b/.github/workflows/automate_area-labels.yml
@@ -13,7 +13,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/automate_changeset_feedback.yml b/.github/workflows/automate_changeset_feedback.yml
index 4d965499d2..95b0a808a1 100644
--- a/.github/workflows/automate_changeset_feedback.yml
+++ b/.github/workflows/automate_changeset_feedback.yml
@@ -23,11 +23,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
# Fetch the commit that's merged into the base rather than the target ref
# This will let us diff only the contents of the PR, without fetching more history
diff --git a/.github/workflows/automate_merge_message.yml b/.github/workflows/automate_merge_message.yml
index 38243ee0ac..a53369c884 100644
--- a/.github/workflows/automate_merge_message.yml
+++ b/.github/workflows/automate_merge_message.yml
@@ -24,11 +24,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
ref: '${{ github.event.pull_request.merge_commit_sha }}'
diff --git a/.github/workflows/automate_stale.yml b/.github/workflows/automate_stale.yml
index c7674e853d..afb8f3b838 100644
--- a/.github/workflows/automate_stale.yml
+++ b/.github/workflows/automate_stale.yml
@@ -15,7 +15,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/ci-noop.yml b/.github/workflows/ci-noop.yml
index 2c66da768f..4dc8594bc9 100644
--- a/.github/workflows/ci-noop.yml
+++ b/.github/workflows/ci-noop.yml
@@ -40,7 +40,7 @@ jobs:
name: Test ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
index fdd31b2d57..00181adb5e 100644
--- a/.github/workflows/ci.yml
+++ b/.github/workflows/ci.yml
@@ -28,11 +28,11 @@ jobs:
name: Install ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
@@ -64,11 +64,11 @@ jobs:
name: Verify ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
@@ -187,6 +187,15 @@ jobs:
--health-retries 5
ports:
- 3306/tcp
+ redis:
+ image: redis:7
+ options: >-
+ --health-cmd "redis-cli ping"
+ --health-interval 10s
+ --health-timeout 5s
+ --health-retries 5
+ ports:
+ - 6379/tcp
env:
CI: true
@@ -197,7 +206,7 @@ jobs:
INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }}
steps:
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: fetch master branch
run: git fetch origin master
@@ -231,6 +240,7 @@ jobs:
BACKSTAGE_TEST_DATABASE_POSTGRES16_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres16.ports[5432] }}
BACKSTAGE_TEST_DATABASE_POSTGRES12_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres12.ports[5432] }}
BACKSTAGE_TEST_DATABASE_MYSQL8_CONNECTION_STRING: mysql://root:root@localhost:${{ job.services.mysql8.ports[3306] }}/ignored
+ BACKSTAGE_TEST_CACHE_REDIS7_CONNECTION_STRING: redis://localhost:${{ job.services.redis.ports[6379] }}
# We run the test cases before verifying the specs to prevent any failing tests from causing errors.
- name: verify openapi specs against test cases
diff --git a/.github/workflows/cron.yml b/.github/workflows/cron.yml
index c32d50ced5..7dcb4a9c0f 100644
--- a/.github/workflows/cron.yml
+++ b/.github/workflows/cron.yml
@@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/deploy_docker-image.yml b/.github/workflows/deploy_docker-image.yml
index 020254c872..ddf01fa49c 100644
--- a/.github/workflows/deploy_docker-image.yml
+++ b/.github/workflows/deploy_docker-image.yml
@@ -20,12 +20,12 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- name: checkout
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
path: backstage
ref: ${{ github.event.client_payload.version && env.RELEASE_VERSION || github.ref }}
diff --git a/.github/workflows/deploy_microsite.yml b/.github/workflows/deploy_microsite.yml
index 6864ec67dc..fd7766e643 100644
--- a/.github/workflows/deploy_microsite.yml
+++ b/.github/workflows/deploy_microsite.yml
@@ -24,11 +24,11 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js 18.x
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
@@ -66,7 +66,7 @@ jobs:
run: ls microsite/build && ls microsite/build/storybook
- name: Deploy both microsite and storybook to gh-pages
- uses: JamesIves/github-pages-deploy-action@ec9c88baef04b842ca6f0a132fd61c762aa6c1b0 # v4.6.0
+ uses: JamesIves/github-pages-deploy-action@5c6e9e9f3672ce8fd37b9856193d2a537941e66c # v4.6.1
with:
branch: gh-pages
folder: microsite/build
diff --git a/.github/workflows/deploy_nightly.yml b/.github/workflows/deploy_nightly.yml
index 07c3db0f11..02a1c65681 100644
--- a/.github/workflows/deploy_nightly.yml
+++ b/.github/workflows/deploy_nightly.yml
@@ -15,11 +15,11 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js 18.x
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
diff --git a/.github/workflows/deploy_packages.yml b/.github/workflows/deploy_packages.yml
index 775d8d00f8..04badd65b0 100644
--- a/.github/workflows/deploy_packages.yml
+++ b/.github/workflows/deploy_packages.yml
@@ -55,6 +55,15 @@ jobs:
--health-retries 5
ports:
- 3306/tcp
+ redis:
+ image: redis:7
+ options: >-
+ --health-cmd "redis-cli ping"
+ --health-interval 10s
+ --health-timeout 5s
+ --health-retries 5
+ ports:
+ - 6379/tcp
env:
CI: true
@@ -65,7 +74,7 @@ jobs:
INTEGRATION_TEST_AZURE_TOKEN: ${{ secrets.INTEGRATION_TEST_AZURE_TOKEN }}
steps:
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
@@ -105,16 +114,17 @@ jobs:
- name: test (and upload coverage)
run: |
yarn backstage-cli repo test --maxWorkers=3 --workerIdleMemoryLimit=1300M --coverage
- bash <(curl -s https://codecov.io/bash)
+ # bash <(curl -s https://codecov.io/bash)
# Upload code coverage for some specific flags. Also see .codecov.yml
- bash <(curl -s https://codecov.io/bash) -f packages/core-app-api/coverage/* -F core-app-api
- bash <(curl -s https://codecov.io/bash) -f packages/core-components/coverage/* -F core-components
- bash <(curl -s https://codecov.io/bash) -f packages/core-plugin-api/coverage/* -F core-plugin-api
+ # bash <(curl -s https://codecov.io/bash) -f packages/core-app-api/coverage/* -F core-app-api
+ # bash <(curl -s https://codecov.io/bash) -f packages/core-components/coverage/* -F core-components
+ # bash <(curl -s https://codecov.io/bash) -f packages/core-plugin-api/coverage/* -F core-plugin-api
env:
BACKSTAGE_TEST_DISABLE_DOCKER: 1
BACKSTAGE_TEST_DATABASE_POSTGRES16_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres16.ports[5432] }}
BACKSTAGE_TEST_DATABASE_POSTGRES12_CONNECTION_STRING: postgresql://postgres:postgres@localhost:${{ job.services.postgres12.ports[5432] }}
BACKSTAGE_TEST_DATABASE_MYSQL8_CONNECTION_STRING: mysql://root:root@localhost:${{ job.services.mysql8.ports[3306] }}/ignored
+ BACKSTAGE_TEST_CACHE_REDIS7_CONNECTION_STRING: redis://localhost:${{ job.services.redis.ports[6379] }}
- name: Discord notification
if: ${{ failure() }}
@@ -144,11 +154,11 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
diff --git a/.github/workflows/issue.yaml b/.github/workflows/issue.yaml
index f8f5efacc4..7afc0a81bb 100644
--- a/.github/workflows/issue.yaml
+++ b/.github/workflows/issue.yaml
@@ -10,7 +10,7 @@ jobs:
if: github.repository == 'backstage/backstage'
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/pr-review-comment-trigger.yaml b/.github/workflows/pr-review-comment-trigger.yaml
index 46f7dad8a3..bea1618608 100644
--- a/.github/workflows/pr-review-comment-trigger.yaml
+++ b/.github/workflows/pr-review-comment-trigger.yaml
@@ -20,7 +20,7 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
@@ -30,7 +30,8 @@ jobs:
run: |
mkdir -p ./pr
echo $PR_NUMBER > ./pr/pr_number
- - uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
+ - uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
with:
name: pr_number-${{ github.event.pull_request.number }}
path: pr/
+ overwrite: true
diff --git a/.github/workflows/pr-review-comment.yaml b/.github/workflows/pr-review-comment.yaml
index 72256a8c6e..232089e2f3 100644
--- a/.github/workflows/pr-review-comment.yaml
+++ b/.github/workflows/pr-review-comment.yaml
@@ -17,7 +17,7 @@ jobs:
steps:
# Inspired by https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#using-data-from-the-triggering-workflow
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/pr.yaml b/.github/workflows/pr.yaml
index 3aa20b1c96..779137b52a 100644
--- a/.github/workflows/pr.yaml
+++ b/.github/workflows/pr.yaml
@@ -18,7 +18,7 @@ jobs:
if: github.repository == 'backstage/backstage' && ( github.event.pull_request || github.event.issue.pull_request )
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 91f1b02fee..8d5b2522af 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -29,17 +29,17 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- name: 'Checkout code'
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
persist-credentials: false
- name: 'Run analysis'
- uses: ossf/scorecard-action@0864cf19026789058feabb7e87baa5f140aac736 # v2.3.1
+ uses: ossf/scorecard-action@dc50aa9510b46c811795eb24b2f1ba02a914e534 # v2.3.3
with:
results_file: results.sarif
results_format: sarif
@@ -58,14 +58,15 @@ jobs:
# Upload the results as artifacts (optional). Commenting out will disable uploads of run results in SARIF
# format to the repository Actions tab.
- name: 'Upload artifact'
- uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
+ uses: actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4.3.3
with:
name: SARIF file
path: results.sarif
retention-days: 5
+ overwrite: true
# Upload the results to GitHub's code scanning dashboard.
- name: 'Upload to code-scanning'
- uses: github/codeql-action/upload-sarif@c7f9125735019aa87cfc361530512d50ea439c71 # v3.25.1
+ uses: github/codeql-action/upload-sarif@d39d31e687223d841ef683f52467bd88e9b21c14 # v3.25.3
with:
sarif_file: results.sarif
diff --git a/.github/workflows/sync_code-formatting.yml b/.github/workflows/sync_code-formatting.yml
index 5dbd0361c1..bb2e00ffa6 100644
--- a/.github/workflows/sync_code-formatting.yml
+++ b/.github/workflows/sync_code-formatting.yml
@@ -10,11 +10,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
# Fetch changes to previous commit - required for 'only_changed' in Prettier action
fetch-depth: 0
diff --git a/.github/workflows/sync_dependabot-changesets.yml b/.github/workflows/sync_dependabot-changesets.yml
index 8b3be335ed..0102cf316a 100644
--- a/.github/workflows/sync_dependabot-changesets.yml
+++ b/.github/workflows/sync_dependabot-changesets.yml
@@ -11,12 +11,12 @@ jobs:
if: github.actor == 'dependabot[bot]' && github.repository == 'backstage/backstage'
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- name: Checkout
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
fetch-depth: 2
ref: ${{ github.head_ref }}
diff --git a/.github/workflows/sync_release-manifest.yml b/.github/workflows/sync_release-manifest.yml
index b0a2499d43..1f58969202 100644
--- a/.github/workflows/sync_release-manifest.yml
+++ b/.github/workflows/sync_release-manifest.yml
@@ -8,7 +8,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
@@ -21,7 +21,7 @@ jobs:
run: npm install semver@7.3.5 fs-extra@10.0.0 @manypkg/get-packages@1.1.1
- name: Checkout
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
path: backstage
# 'v' prefix is added here for the tag, we keep it out of the manifest logic
@@ -29,7 +29,7 @@ jobs:
# Checkout backstage/versions into /backstage/versions, which is where store the output
- name: Checkout versions
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
repository: backstage/versions
path: backstage/versions
diff --git a/.github/workflows/sync_renovate-changesets.yml b/.github/workflows/sync_renovate-changesets.yml
index d02e35483c..01e6ee6dfc 100644
--- a/.github/workflows/sync_renovate-changesets.yml
+++ b/.github/workflows/sync_renovate-changesets.yml
@@ -11,12 +11,12 @@ jobs:
if: github.actor == 'renovate[bot]' && github.repository == 'backstage/backstage'
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- name: Checkout
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
fetch-depth: 2
ref: ${{ github.head_ref }}
diff --git a/.github/workflows/sync_snyk-github-issues.yml b/.github/workflows/sync_snyk-github-issues.yml
index d5a4048044..cb5eaa1737 100644
--- a/.github/workflows/sync_snyk-github-issues.yml
+++ b/.github/workflows/sync_snyk-github-issues.yml
@@ -12,11 +12,11 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js 18.x
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
diff --git a/.github/workflows/sync_snyk-monitor.yml b/.github/workflows/sync_snyk-monitor.yml
index 70fb8a44d9..4678c36907 100644
--- a/.github/workflows/sync_snyk-monitor.yml
+++ b/.github/workflows/sync_snyk-monitor.yml
@@ -25,11 +25,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: Monitor and Synchronize Snyk Policies
uses: snyk/actions/node@8349f9043a8b7f0f3ee8885bf28f0b388d2446e8 # master
with:
@@ -58,6 +58,6 @@ jobs:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
NODE_OPTIONS: --max-old-space-size=7168
- name: Upload Snyk report
- uses: github/codeql-action/upload-sarif@c7f9125735019aa87cfc361530512d50ea439c71 # v3.25.1
+ uses: github/codeql-action/upload-sarif@d39d31e687223d841ef683f52467bd88e9b21c14 # v3.25.3
with:
sarif_file: snyk.sarif
diff --git a/.github/workflows/sync_version-packages.yml b/.github/workflows/sync_version-packages.yml
index b2ad80b6da..a7f8d3674e 100644
--- a/.github/workflows/sync_version-packages.yml
+++ b/.github/workflows/sync_version-packages.yml
@@ -14,11 +14,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
fetch-depth: 20000
fetch-tags: true
diff --git a/.github/workflows/uffizzi-build.yml b/.github/workflows/uffizzi-build.yml
deleted file mode 100644
index 4a52af21bc..0000000000
--- a/.github/workflows/uffizzi-build.yml
+++ /dev/null
@@ -1,129 +0,0 @@
-name: Preview (build)
-on:
- pull_request:
- types: [opened, synchronize, reopened, closed]
- paths-ignore:
- - '.changeset/**'
- - 'contrib/**'
- - 'docs/**'
- - 'microsite/**'
- - 'beps/**'
- - 'scripts/**'
- - 'storybook/**'
- - '**/*.test.*'
- - '**/package.json'
- - '*.md'
-
-jobs:
- build-backstage:
- env:
- NODE_OPTIONS: --max-old-space-size=4096
- UFFIZZI_URL: https://app.uffizzi.com
- name: Build PR image
- runs-on: ubuntu-latest
- if: ${{ github.event_name != 'pull_request' || github.event.action != 'closed' }}
- outputs:
- tags: ${{ steps.meta.outputs.tags }}
- steps:
- - name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
- with:
- egress-policy: audit
-
- - name: checkout
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
-
- - name: setup-node
- uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
- with:
- node-version: 18.x
- registry-url: https://registry.npmjs.org/
-
- - name: yarn install
- uses: backstage/actions/yarn-install@af61233abb88019335b07ab855873d991f43d25a # v0.6.7
- with:
- cache-prefix: linux-v18
-
- - name: Use Uffizzi's backstage app config
- run: |
- cp -f ./.github/uffizzi/uffizzi.production.app-config.yaml ./app-config.yaml
-
- - name: backstage build
- run: |
- yarn workspace example-backend build
-
- - name: Set up Docker Buildx
- uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb # v3.3.0
-
- - name: Generate UUID image name
- id: uuid
- run: echo "UUID_TAG_APP=backstage-$(uuidgen --time)" >> $GITHUB_ENV
-
- - name: Docker metadata
- id: meta
- uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 # v5.5.1
- with:
- images: registry.uffizzi.com/${{ env.UUID_TAG_APP }}
- tags: type=raw,value=60d
-
- - name: Build Image
- uses: docker/build-push-action@2cdde995de11925a030ce8070c3d77a52ffcf1c0 # v5.3.0
- with:
- context: .
- file: packages/backend/Dockerfile
- tags: ${{ steps.meta.outputs.tags }}
- labels: ${{ steps.meta.outputs.labels }}
- push: true
- cache-from: type=gha
- cache-to: type=gha,mode=max
-
- render-kustomize:
- name: Render Kustomize Manifests
- runs-on: ubuntu-latest
- needs:
- - build-backstage
- steps:
- - name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
- with:
- egress-policy: audit
-
- - name: Checkout git repo
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
- - name: Render Compose File
- run: |
- # update image after the build above
- cd ./.github/uffizzi/k8s/manifests
- kustomize edit set image backstage=${{ needs.build-backstage.outputs.tags }}
- kustomize build . > manifests.rendered.yml
- cat manifests.rendered.yml
- - name: Upload Rendered Manifests File as Artifact
- uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3
- with:
- name: preview-spec
- path: ./.github/uffizzi/k8s/manifests/manifests.rendered.yml
- retention-days: 2
- - name: Upload PR Event as Artifact
- uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
- with:
- name: preview-spec
- path: ${{ github.event_path }}
- retention-days: 2
-
- delete-preview:
- name: Call for Preview Deletion
- runs-on: ubuntu-latest
- if: ${{ github.event.action == 'closed' }}
- steps:
- - name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
- with:
- egress-policy: audit
-
- # If this PR is closing, we will not render a compose file nor pass it to the next workflow.
- - name: Upload PR Event as Artifact
- uses: actions/upload-artifact@a8a3f3ad30e3422c9c7b888a15615d19a852ae32 # v3.1.3
- with:
- name: preview-spec
- path: ${{ github.event_path }}
- retention-days: 2
diff --git a/.github/workflows/uffizzi-preview.yaml b/.github/workflows/uffizzi-preview.yaml
deleted file mode 100644
index b4c5aa3caa..0000000000
--- a/.github/workflows/uffizzi-preview.yaml
+++ /dev/null
@@ -1,238 +0,0 @@
-name: Preview (deploy)
-
-on:
- workflow_run:
- workflows:
- - 'Preview (build)'
- types:
- - completed
-
-jobs:
- cache-manifests-file:
- name: Cache Manifests File
- runs-on: ubuntu-latest
- if: ${{ github.event.workflow_run.conclusion == 'success' }}
- permissions:
- # "If you specify the access for any of these scopes, all of those that are not specified are set to none."
- # https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions
- actions: read # Access cache
- outputs:
- manifests-cache-key: ${{ steps.hash.outputs.MANIFESTS_FILE_HASH }}
- git-ref: ${{ steps.event.outputs.GIT_REF }}
- pr-number: ${{ steps.event.outputs.PR_NUMBER }}
- action: ${{ steps.event.outputs.ACTION }}
- steps:
- - name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
- with:
- disable-sudo: true
- egress-policy: block
- allowed-endpoints: >
- api.github.com:443
-
- - name: 'Download artifacts'
- # Fetch output (zip archive) from the workflow run that triggered this workflow.
- uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
- with:
- script: |
- let allArtifacts = await github.rest.actions.listWorkflowRunArtifacts({
- owner: context.repo.owner,
- repo: context.repo.repo,
- run_id: context.payload.workflow_run.id,
- });
- let matchArtifact = allArtifacts.data.artifacts.filter((artifact) => {
- return artifact.name == "preview-spec"
- })[0];
- if (matchArtifact === undefined) {
- throw TypeError('Build Artifact not found!');
- }
- let download = await github.rest.actions.downloadArtifact({
- owner: context.repo.owner,
- repo: context.repo.repo,
- artifact_id: matchArtifact.id,
- archive_format: 'zip',
- });
- let fs = require('fs');
- fs.writeFileSync(`${process.env.GITHUB_WORKSPACE}/preview-spec.zip`, Buffer.from(download.data));
-
- - name: 'Accept event from first stage'
- run: unzip preview-spec.zip event.json
-
- - name: Read Event into ENV
- id: event
- run: |
- echo PR_NUMBER=$(jq '.number | tonumber' < event.json) >> $GITHUB_OUTPUT
- echo ACTION=$(jq --raw-output '.action | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT
- echo GIT_REF=$(jq --raw-output '.pull_request.head.sha | tostring | [scan("\\w+")][0]' < event.json) >> $GITHUB_OUTPUT
-
- - name: Hash Rendered Manifests File
- id: hash
- # If the previous workflow was triggered by a PR close event, we will not have a manifests file artifact.
- if: ${{ steps.event.outputs.ACTION != 'closed' }}
- run: |
- unzip preview-spec.zip manifests.rendered.yml
- ls
- echo "MANIFESTS_FILE_HASH=$(md5sum manifests.rendered.yml | awk '{ print $1 }')" >> $GITHUB_OUTPUT
-
- - name: Cache Manifests File
- if: ${{ steps.event.outputs.ACTION != 'closed' }}
- uses: actions/cache@0c45773b623bea8c8e75f6c82b208c3cf94ea4f9 # v4.0.2
- with:
- path: manifests.rendered.yml
- key: ${{ steps.hash.outputs.MANIFESTS_FILE_HASH }}
-
- - name: DEBUG - Print Job Outputs
- if: ${{ runner.debug }}
- run: |
- echo "PR number: ${{ steps.event.outputs.PR_NUMBER }}"
- echo "Git Ref: ${{ steps.event.outputs.GIT_REF }}"
- echo "Action: ${{ steps.event.outputs.ACTION }}"
- echo "Manifests file hash: ${{ steps.hash.outputs.MANIFESTS_FILE_HASH }}"
- cat event.json
-
- deploy-uffizzi-preview:
- name: Deploy to Uffizzi Virtual Cluster
- needs:
- - cache-manifests-file
- if: ${{ github.event.workflow_run.conclusion == 'success' && needs.cache-manifests-file.outputs.action != 'closed' }}
- permissions:
- contents: read
- pull-requests: write
- id-token: write
- runs-on: ubuntu-latest
- steps:
- - name: Checkout
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
-
- # Identify comment to be updated
- - name: Find comment for Ephemeral Environment
- uses: peter-evans/find-comment@3eae4d37986fb5a8592848f6a574fdf654e61f9e # v3
- id: find-comment
- with:
- issue-number: ${{ needs.cache-manifests-file.outputs.pr-number }}
- comment-author: 'github-actions[bot]'
- body-includes: pr-${{ needs.cache-manifests-file.outputs.pr-number }}
- direction: last
-
- # Create/Update comment with action deployment status
- - name: Create or Update Comment with Deployment Notification
- id: notification
- uses: peter-evans/create-or-update-comment@71345be0265236311c031f5c7866368bd1eff043 # v4
- with:
- comment-id: ${{ steps.find-comment.outputs.comment-id }}
- issue-number: ${{ needs.cache-manifests-file.outputs.pr-number }}
- body: |
- ## Uffizzi Ephemeral Environment - Virtual Cluster
-
- :cloud: deploying cluster `pr-${{ needs.cache-manifests-file.outputs.pr-number }}`
-
- :gear: Updating now by workflow run [${{ github.run_id }}](${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}).
-
- Download the Uffizzi CLI to interact with the upcoming virtual cluster
- https://docs.uffizzi.com/install
- edit-mode: replace
-
- - name: Connect to Virtual Cluster
- uses: UffizziCloud/cluster-action@main
- with:
- cluster-name: pr-${{ needs.cache-manifests-file.outputs.pr-number }}
- server: https://app.uffizzi.com
-
- - name: Fetch cached Manifests File
- id: cache
- uses: actions/cache@0c45773b623bea8c8e75f6c82b208c3cf94ea4f9 # v4
- with:
- path: manifests.rendered.yml
- key: ${{ needs.cache-manifests-file.outputs.manifests-cache-key }}
-
- - name: Kustomize and Apply Manifests
- id: prev
- run: |
- # Apply kustomized manifests to virtual cluster.
- export KUBECONFIG=`pwd`/kubeconfig
- kubectl apply -f manifests.rendered.yml --kubeconfig ./kubeconfig
- # Allow uffizzi to sync the resources
- sleep 10
- # Get the hostnames assigned by uffizzi
- export BACKSTAGE_HOST=$(kubectl get ingress backstage --kubeconfig kubeconfig -o json | jq '.spec.rules[0].host' | tr -d '"')
- export UFFIZZI_CLUSTER_APISERVER=$(kubectl config view --minify | grep server | cut -f 2- -d ":" | tr -d " ")
- # Patch backstage deployment to use UFFIZZI_URL
- kubectl patch deployment backstage --kubeconfig kubeconfig -p '{"spec": {"template": {"spec": {"containers": [{"name": "backstage", "args":["-c", "APP_CONFIG_app_baseUrl='https://${BACKSTAGE_HOST}' APP_CONFIG_backend_baseUrl='https://${BACKSTAGE_HOST}' APP_CONFIG_auth_environment='production' node packages/backend --config app-config.yaml"], "env": [{"name": "UFFIZZI_URL", "value": "'https://${BACKSTAGE_HOST}'"}, {"name": "UFFIZZI_CLUSTER_APISERVER", "value": "'${UFFIZZI_CLUSTER_APISERVER}'"}, {"name": "GITHUB_SHA", "value": "'${GITHUB_SHA}'"}, {"name": "REF_NAME", "value": "'${{ needs.cache-manifests-file.outputs.git-ref }}'"}]}]}}}}'
- if [[ ${RUNNER_DEBUG} == 1 ]]; then
- kubectl get all --kubeconfig ./kubeconfig
- fi
- echo "backstage_url=${BACKSTAGE_HOST}" >> $GITHUB_OUTPUT
- echo "Access the \`backstage\` endpoint at [\`${BACKSTAGE_HOST}\`](http://${BACKSTAGE_HOST})" >> $GITHUB_STEP_SUMMARY
-
- - name: Create or Update Comment with Deployment URL
- uses: peter-evans/create-or-update-comment@71345be0265236311c031f5c7866368bd1eff043 # v4
- with:
- comment-id: ${{ steps.notification.outputs.comment-id }}
- issue-number: ${{ github.event.pull_request.number }}
- body: |
- ## Uffizzi Ephemeral Environment - Virtual Cluster
-
- Your cluster `pr-${{ needs.cache-manifests-file.outputs.pr-number }}` was successfully created. Learn more about [Uffizzi virtual clusters](https://docs.uffizzi.com/topics/virtual-clusters)
- To connect to this cluster, follow these steps:
-
- 1. Download and install the Uffizzi CLI from https://docs.uffizzi.com/install
- 2. Login to Uffizzi, then select the `backstage` account and project:
- ```
- uffizzi login
- ```
-
- ```
- Select an account:
- ‣ ${{ github.event.repository.name }}
- jdoe
-
- Select a project or create a new project:
- ‣ ${{ github.event.repository.name }}-6783521
- ```
- 3. Update your kubeconfig: `uffizzi cluster update-kubeconfig pr-${{ needs.cache-manifests-file.outputs.pr-number }} --kubeconfig=[PATH_TO_KUBECONFIG]`
- After updating your kubeconfig, you can manage your cluster with `kubectl`, `kustomize`, `helm`, and other tools that use kubeconfig files: `kubectl get namespace --kubeconfig [PATH_TO_KUBECONFIG]`
-
-
- Access the `backstage` endpoint at [`https://${{ steps.prev.outputs.backstage_url }}`](https://${{ steps.prev.outputs.backstage_url }})
-
- edit-mode: replace
-
- delete-uffizzi-preview:
- permissions:
- contents: read
- pull-requests: write
- id-token: write
- name: Delete the Uffizzi Virtual Cluster
- needs:
- - cache-manifests-file
- if: ${{ needs.cache-manifests-file.outputs.action == 'closed' }}
- runs-on: ubuntu-latest
- steps:
- - name: Checkout
- uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4
-
- - name: Delete Virtual Cluster
- uses: UffizziCloud/cluster-action@main
- with:
- cluster-name: pr-${{ needs.cache-manifests-file.outputs.pr-number }}
- server: https://app.uffizzi.com
- action: delete
-
- # Identify comment to be updated
- - name: Find comment for Ephemeral Environment
- uses: peter-evans/find-comment@3eae4d37986fb5a8592848f6a574fdf654e61f9e # v3
- id: find-comment
- with:
- issue-number: ${{ needs.cache-manifests-file.outputs.pr-number }}
- comment-author: 'github-actions[bot]'
- body-includes: pr-${{ needs.cache-manifests-file.outputs.pr-number }}
- direction: last
-
- - name: Update Comment with Deletion
- uses: peter-evans/create-or-update-comment@71345be0265236311c031f5c7866368bd1eff043 # v4
- with:
- comment-id: ${{ steps.find-comment.outputs.comment-id }}
- issue-number: ${{ needs.cache-manifests-file.outputs.pr-number }}
- body: |
- Uffizzi Cluster `pr-${{ needs.cache-manifests-file.outputs.pr-number }}` was deleted.
- edit-mode: replace
diff --git a/.github/workflows/verify_accessibility-noop.yml b/.github/workflows/verify_accessibility-noop.yml
index 07c92b5b5d..7ec67cbf0f 100644
--- a/.github/workflows/verify_accessibility-noop.yml
+++ b/.github/workflows/verify_accessibility-noop.yml
@@ -26,7 +26,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/verify_accessibility.yml b/.github/workflows/verify_accessibility.yml
index 1c25d709cb..996153f8d3 100644
--- a/.github/workflows/verify_accessibility.yml
+++ b/.github/workflows/verify_accessibility.yml
@@ -20,11 +20,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: Use Node.js 18.x
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
with:
diff --git a/.github/workflows/verify_codeql.yml b/.github/workflows/verify_codeql.yml
index e82577763e..bcac7e947c 100644
--- a/.github/workflows/verify_codeql.yml
+++ b/.github/workflows/verify_codeql.yml
@@ -42,12 +42,12 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- name: Checkout repository
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
# We must fetch at least the immediate parents so that if this is
# a pull request then we can checkout the head.
@@ -55,7 +55,7 @@ jobs:
# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
- uses: github/codeql-action/init@c7f9125735019aa87cfc361530512d50ea439c71 # v3.25.1
+ uses: github/codeql-action/init@d39d31e687223d841ef683f52467bd88e9b21c14 # v3.25.3
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
@@ -66,7 +66,7 @@ jobs:
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild
- uses: github/codeql-action/autobuild@c7f9125735019aa87cfc361530512d50ea439c71 # v3.25.1
+ uses: github/codeql-action/autobuild@d39d31e687223d841ef683f52467bd88e9b21c14 # v3.25.3
# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl
@@ -80,4 +80,4 @@ jobs:
# make release
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@c7f9125735019aa87cfc361530512d50ea439c71 # v3.25.1
+ uses: github/codeql-action/analyze@d39d31e687223d841ef683f52467bd88e9b21c14 # v3.25.3
diff --git a/.github/workflows/verify_docs-quality.yml b/.github/workflows/verify_docs-quality.yml
index 3550df6fc0..5b213f2c14 100644
--- a/.github/workflows/verify_docs-quality.yml
+++ b/.github/workflows/verify_docs-quality.yml
@@ -12,11 +12,11 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
# Vale does not support file excludes, so we use the script to generate a list of files instead
# The action also does not allow args or a local config file to be passed in, so the files array
diff --git a/.github/workflows/verify_e2e-kubernetes-noop.yml b/.github/workflows/verify_e2e-kubernetes-noop.yml
index 8d8b14d5ba..6352abce70 100644
--- a/.github/workflows/verify_e2e-kubernetes-noop.yml
+++ b/.github/workflows/verify_e2e-kubernetes-noop.yml
@@ -23,7 +23,7 @@ jobs:
name: Kubernetes ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/verify_e2e-kubernetes.yml b/.github/workflows/verify_e2e-kubernetes.yml
index 6ff41c8b74..77d2c3bdc1 100644
--- a/.github/workflows/verify_e2e-kubernetes.yml
+++ b/.github/workflows/verify_e2e-kubernetes.yml
@@ -22,11 +22,11 @@ jobs:
name: Kubernetes ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
diff --git a/.github/workflows/verify_e2e-linux-noop.yml b/.github/workflows/verify_e2e-linux-noop.yml
index 93d48caf22..2b7eb1d84b 100644
--- a/.github/workflows/verify_e2e-linux-noop.yml
+++ b/.github/workflows/verify_e2e-linux-noop.yml
@@ -29,7 +29,7 @@ jobs:
name: E2E Linux ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/verify_e2e-linux.yml b/.github/workflows/verify_e2e-linux.yml
index a750dfea3b..f8583ac178 100644
--- a/.github/workflows/verify_e2e-linux.yml
+++ b/.github/workflows/verify_e2e-linux.yml
@@ -41,11 +41,11 @@ jobs:
name: E2E Linux ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: Configure Git
run: |
diff --git a/.github/workflows/verify_e2e-techdocs.yml b/.github/workflows/verify_e2e-techdocs.yml
index 3bcda5f2b6..2ed566e36b 100644
--- a/.github/workflows/verify_e2e-techdocs.yml
+++ b/.github/workflows/verify_e2e-techdocs.yml
@@ -30,11 +30,11 @@ jobs:
name: Techdocs
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- uses: actions/setup-python@82c7e631bb3cdc910f68e0081d67478d79c6982d # v5.1.0
with:
python-version: '3.9'
diff --git a/.github/workflows/verify_e2e-windows-noop.yml b/.github/workflows/verify_e2e-windows-noop.yml
index a7ebdba4b5..fd90b86b0d 100644
--- a/.github/workflows/verify_e2e-windows-noop.yml
+++ b/.github/workflows/verify_e2e-windows-noop.yml
@@ -25,7 +25,7 @@ jobs:
name: E2E Windows ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/verify_e2e-windows.yml b/.github/workflows/verify_e2e-windows.yml
index 078ddd6855..e2a789d666 100644
--- a/.github/workflows/verify_e2e-windows.yml
+++ b/.github/workflows/verify_e2e-windows.yml
@@ -31,7 +31,7 @@ jobs:
name: E2E Windows ${{ matrix.node-version }}
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
@@ -42,7 +42,7 @@ jobs:
git config --global core.autocrlf false
git config --global core.eol lf
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: Configure Git
run: |
diff --git a/.github/workflows/verify_fossa.yml b/.github/workflows/verify_fossa.yml
index 801c5fbd28..ba5d177cc4 100644
--- a/.github/workflows/verify_fossa.yml
+++ b/.github/workflows/verify_fossa.yml
@@ -14,12 +14,12 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- name: Checkout
- uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: Install Fossa
run: "curl -H 'Cache-Control: no-cache' https://raw.githubusercontent.com/fossas/fossa-cli/master/install.sh | bash"
diff --git a/.github/workflows/verify_microsite-noop.yml b/.github/workflows/verify_microsite-noop.yml
index ad3e67ba70..a9a82b140b 100644
--- a/.github/workflows/verify_microsite-noop.yml
+++ b/.github/workflows/verify_microsite-noop.yml
@@ -21,7 +21,7 @@ jobs:
name: Microsite
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/verify_microsite.yml b/.github/workflows/verify_microsite.yml
index 68378aa086..256b00b160 100644
--- a/.github/workflows/verify_microsite.yml
+++ b/.github/workflows/verify_microsite.yml
@@ -24,17 +24,17 @@ jobs:
name: Microsite
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js 18.x
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
with:
node-version: 18.x
- - uses: actions/setup-python@v5
+ - uses: actions/setup-python@82c7e631bb3cdc910f68e0081d67478d79c6982d # v5
with:
python-version: '3.9'
diff --git a/.github/workflows/verify_microsite_accessibility-noop.yml b/.github/workflows/verify_microsite_accessibility-noop.yml
index 4b63dc41cc..8ac2672b22 100644
--- a/.github/workflows/verify_microsite_accessibility-noop.yml
+++ b/.github/workflows/verify_microsite_accessibility-noop.yml
@@ -24,7 +24,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/verify_microsite_accessibility.yml b/.github/workflows/verify_microsite_accessibility.yml
index e0fea1a72c..9986ae051e 100644
--- a/.github/workflows/verify_microsite_accessibility.yml
+++ b/.github/workflows/verify_microsite_accessibility.yml
@@ -15,11 +15,11 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: Use Node.js 18.x
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
diff --git a/.github/workflows/verify_storybook-noop.yml b/.github/workflows/verify_storybook-noop.yml
index 74aed57f5c..e98da4ae02 100644
--- a/.github/workflows/verify_storybook-noop.yml
+++ b/.github/workflows/verify_storybook-noop.yml
@@ -28,7 +28,7 @@ jobs:
name: Storybook
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
diff --git a/.github/workflows/verify_storybook.yml b/.github/workflows/verify_storybook.yml
index 940c136797..1859c0b8bc 100644
--- a/.github/workflows/verify_storybook.yml
+++ b/.github/workflows/verify_storybook.yml
@@ -28,11 +28,11 @@ jobs:
name: Storybook
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
with:
fetch-depth: 0 # Required to retrieve git history
diff --git a/.github/workflows/verify_windows.yml b/.github/workflows/verify_windows.yml
index 32b0452eec..5c4bed2d11 100644
--- a/.github/workflows/verify_windows.yml
+++ b/.github/workflows/verify_windows.yml
@@ -29,11 +29,11 @@ jobs:
steps:
- name: Harden Runner
- uses: step-security/harden-runner@63c24ba6bd7ba022e95695ff85de572c04a18142 # v2.7.0
+ uses: step-security/harden-runner@a4aa98b93cab29d9b1101a6143fb8bce00e2eac4 # v2.7.1
with:
egress-policy: audit
- - uses: actions/checkout@1d96c772d19495a3b5c517cd2bc0cb401ea0529f # v4.1.3
+ - uses: actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4.1.6
- name: use node.js ${{ matrix.node-version }}
uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 # v4.0.2
diff --git a/.yarn/patches/@changesets-assemble-release-plan-npm-6.0.0-f7b3005037.patch b/.yarn/patches/@changesets-assemble-release-plan-npm-6.0.0-f7b3005037.patch
new file mode 100644
index 0000000000..045e983dbe
--- /dev/null
+++ b/.yarn/patches/@changesets-assemble-release-plan-npm-6.0.0-f7b3005037.patch
@@ -0,0 +1,32 @@
+diff --git a/dist/changesets-assemble-release-plan.cjs.js b/dist/changesets-assemble-release-plan.cjs.js
+index ee5c0f67fabadeb112e9f238d8b144a4d125830f..9b0e1a156dd88cee35f82faf718d82a8a8f80325 100644
+--- a/dist/changesets-assemble-release-plan.cjs.js
++++ b/dist/changesets-assemble-release-plan.cjs.js
+@@ -179,12 +179,23 @@ function getDependencyVersionRanges(dependentPkgJSON, dependencyRelease) {
+ if (!versionRange) continue;
+
+ if (versionRange.startsWith("workspace:")) {
++ // intentionally keep other workspace ranges untouched
++ // this has to be fixed but this should only be done when adding appropriate tests
++ let workspaceRange = versionRange.replace(/^workspace:/, "");
++ switch (workspaceRange) {
++ case "*":
++ // workspace:* actually means the current exact version, and not a wildcard similar to a reguler * range
++ workspaceRange = dependencyRelease.oldVersion;
++ break;
++ case "~":
++ case "^":
++ // Use ^oldVersion for workspace:^ or ~oldVersion for workspace:~.
++ // The version range might have changed in dependent package, but that should have its own changeset bumping that package.
++ workspaceRange += dependencyRelease.oldVersion;
++ }
+ dependencyVersionRanges.push({
+ depType: type,
+- versionRange: // intentionally keep other workspace ranges untouched
+- // this has to be fixed but this should only be done when adding appropriate tests
+- versionRange === "workspace:*" ? // workspace:* actually means the current exact version, and not a wildcard similar to a reguler * range
+- dependencyRelease.oldVersion : versionRange.replace(/^workspace:/, "")
++ versionRange: workspaceRange,
+ });
+ } else {
+ dependencyVersionRanges.push({
diff --git a/ADOPTERS.md b/ADOPTERS.md
index 3878563683..2bb76a199e 100644
--- a/ADOPTERS.md
+++ b/ADOPTERS.md
@@ -154,7 +154,7 @@ _You can do this by using the [Adopter form](https://info.backstage.spotify.com/
| [Lendingkart](https://www.lendingkart.com/) | [Dinesh Rajpoot](mailto:dinesh.rajpoot@lendingkart.com) | Service catalog, Software templates to enforce best practices and tech insights to track mandates & migrations. |
| [Meltwater](https://underthehood.meltwater.com) | [@spier](https://github.com/spier), [@remen](https://github.com/remen) | Improving developer experience by centralizing documentation and internal APIs. Goal: Foster InnerSource collaboration and speed up onboarding time in our 500+ people Product & Engineering org. |
| [Doctolib](https://doctolib.engineering/) | [@djiit](https://github.com/djiit) | Rails modularization effort awareness, tech organization discoverability. Improving the daily workflows and collaboration processes of our engineers. |
-| [Twilio](https://www.twilio.com) | [Kyle Smith](https://github.com/knksmith57) | Developer portal, universal software catalog, and centralized taxonomy platform. |
+| [Twilio](https://www.twilio.com) | [Alec Jacobs](https://github.com/alecjacobs5401) | Developer portal, universal software catalog, and centralized taxonomy platform. |
| [OVHcloud](https://www.ovhcloud.com/fr/) | [Jean-Philippe Blary](https://github.com/blaryjp), [Arnaud Bauer](mailto:arnaud.bauer@ovhcloud.com), [Flavien Chantelot](https://github.com/Dorn-) | We're providing Backstage to our collaborators to ease their daily jobs, and let them extends it using plugins. |
| [Procter & Gamble](https://us.pg.com/) | [Binita Nayak](https://github.com/binitan), | P&G leverages Backstage to build internal developer portal to ensure developers' happiness. This developer portal shall act as single source of information needed by development teams to seamlessly create, find and maintain their software components/resources/documentation. |
| [SANS Institute](https://www.sans.org) | [Christopher Klewin](mailto:cklewin@sans.org) | Developer portal for centralized visibility, reporting, and tooling across multiple organizations. |
@@ -268,3 +268,5 @@ _You can do this by using the [Adopter form](https://info.backstage.spotify.com/
| [Aurora Innovation](https://aurorainnovation.com) | [@O5ten](https://github.com/O5ten) | Heavy usage of scaffolder, techdocs, homepage, k8s plugin and homegrown plugins to track migration paths and so on within a developer portal. It acts as a starting point for new and old developers to find all of our internal tooling in one place.
| [ENSEK](https://ensek.com/) | [Timothy Deakin](https://github.com/cftad) |We are using Backstage as our internal developer portal to provide a single pane of glass for our developers to access all the tools and services they need to build and maintain our software. |
| [OP Financial Group](https://www.op.fi/op-financial-group) | [Heikki Hellgren](https://github.com/drodil), [Jyrki Koistinen](https://github.com/snyvision) | We are using Backstage as a gateway into our internal development platform offering to simplify complexity. |
+| [Scania](https://www.scania.com) | [Santosh Rangavajjula](https://linkedin.com/in/rsbth) | We are implementing backstage at Scania to consolidate operational information from Gitlab, Jira, Confluence, Artifactory, Servicenow and other tools into one place. |
+| [Senora.dev](https://senora.dev) | [Shaked Braimok Yosef](https://github.com/ShakedBraimok) | We are using Backstage as a service catalog for our costumers. |
diff --git a/GOVERNANCE.md b/GOVERNANCE.md
deleted file mode 100644
index 2367dab99c..0000000000
--- a/GOVERNANCE.md
+++ /dev/null
@@ -1,233 +0,0 @@
-# Project Areas
-
-The Backstage project is divided into several project areas, each covering particular parts of the project. The main driver for each area is ownership of code in the main Backstage repository, as well as other repositories in the Backstage GitHub organization. Each area has a set of maintainers and repository content that they own. There may be no overlap in ownership between areas, which means that any given line in the GitHub code owners file should have only one owner specified. Each area is represented by a team in the Backstage GitHub organization. Apart from certain project-wide concerns, such as the release process, each area is self-governing and chooses their own ways of working. Project areas may also have special interest groups (SIGs) related to their area, but this is not required.
-
-The project areas as well as their maintainers are listed in the [OWNERS.md](./OWNERS.md) file.
-
-Each project area must have at least one maintainer. Project area maintainers may have shared ownership with the core maintainers, which in that case is considered an incubating area. The project area maintainers help drive work forward in the area, but they might not yet feel ready to take on ownership. The goal should generally be that these project area maintainers eventually become sole maintainers of the project area. This is to allow for a more smooth onboarding and transition of ownership, where members of the community might for example be new to open source maintainership.
-
-## Adding new project areas
-
-Project areas are added by nominating new maintainers for that area. See the sections for becoming a [Project Area Maintainer](#project-area-maintainer).
-
-Project areas may also by added by splitting existing areas. Every area that is created through this process must have at least one maintainer.
-
-## Removing project areas
-
-Project areas are removed by removing all maintainers for that area and removing the corresponding team from the Backstage GitHub organization. The project area can be re-added later if there is a need for it. Reasons for removal may include lack of activity, lack of maintainers, or lack of relevance to the project.
-
-# Project Roles
-
-## Contributor
-
-A Contributor contributes directly to the project and adds value to it. Contributions need not be code. People at the Contributor level may be new contributors, or they may only contribute occasionally.
-
-### Responsibilities
-
-- Follow the [CNCF CoC](https://github.com/cncf/foundation/blob/main/code-of-conduct.md)
-- Follow the project [contributing guide](CONTRIBUTING.md)
-
-### How to get involved
-
-- Participate in community discussions
-- Help other users
-- Submit bug reports
-- Comment on issues
-- Try out new releases
-- Attend community events
-
-### How to contribute
-
-- Report and sometimes resolve issues
-- Occasionally submit PRs
-- Contribute to the documentation
-- Show up at meetings, take notes
-- Answer questions from other community members
-- Submit feedback on issues and PRs
-- Test releases and patches and submit reviews
-- Run or help run events
-- Promote the project in public
-
-## Organization Member
-
-An org member is a frequent contributor that has become a member of the Backstage GitHub organization. In addition to the responsibilities of contributors, an org member is also expected to be reasonably active in the community through continuous contributions of any type.
-
-An Organization Member must meet the responsibilities and has the requirements of a Contributor.
-
-### Responsibilities
-
-- Continues to contribute regularly, as demonstrated by having at least 10 GitHub contributions per year in [Devstats](https://backstage.devstats.cncf.io/d/48/users-statistics-by-repository-group?orgId=1&var-period=y&var-metric=contributions&var-repogroup_name=All&from=now-1y&to=now&var-users=All), or contributions of a similar effort that might not be captured in Devstats.
-
-### Requirements
-
-- Must have at least 10 contributions to the projects in the form of:
- - Accepted PRs
- - Helpful PR reviews
- - Resolving GitHub issues
- - Or some equivalent contributions to the project
-- Must have been contributing for at least 3 months
-- Or is the member of a team that owns a project area, in which case the above requirements do not apply and the member is instead vetted by the project area maintainers
-
-### Becoming an Organization Member
-
-Open an issue towards [the community repository](https://github.com/backstage/community) using the [org membership request template](https://github.com/backstage/community/issues/new?template=org_member.yaml&title=Org+Member%3A+%3Cyour-github-login%3E).
-
-### Privileges
-
-- Membership in the Backstage GitHub organization
-
-## Plugin Maintainer
-
-A Plugin Maintainer is responsible for maintaining an individual Backstage plugin or module. This includes reviewing contributions and responding to issues towards an individual plugin, as well as keeping the plugin up to date.
-
-Plugin Maintainer is a lightweight form of ownership that is primarily reflected though code owners of the plugin packages in the [CODEOWNERS](./.github/CODEOWNERS) file. Each plugin can have one or more maintainers. If a plugin becomes a significant part of the Backstage ecosystem, it may be promoted to be a distinct project area instead.
-
-A Plugin Maintainer has all the rights and responsibilities of an Organization Member.
-
-### Responsibilities
-
-- Review the majority of PRs towards the plugin
-- Respond to GitHub issues related to the plugin
-- Keep the plugin up-to-date with Backstage libraries and other dependencies
-- Follow the [reviewing guide](REVIEWING.md)
-
-### Requirements
-
-- Is an Organization Member
-- Display knowledge of Backstage's review process and best practices for plugin design
-- Is supportive of new and occasional contributors and helps get useful PRs in shape to merge
-
-### Privileges
-
-- GitHub code owner of the plugin directory, with rights to approve and merge PRs towards the plugin
-
-### Becoming a Plugin Maintainer
-
-To become a Plugin Maintainer, you first need to be an Organization Member. You can then file a pull request towards [CODEOWNERS.md](./.github/CODEOWNERS) requesting to be added as a code owner of the plugin directory. Existing code owners of that plugin alongside the core maintainers will then review the request.
-
-## Project Area Maintainer
-
-Project Area Maintainers are owners of a particular project area. They are expected to review and merge pull requests towards their area, and also drive development and manage tech health. A Project Area Maintainer also need to commit a certain number of hours per month towards the project, and exercise judgment for the good of the project, independent of their employer. Project Area Maintainers should also mentor new maintainers and participate in and lead community meetings related to their area. New Project Area Maintainers need to be approved by the existing project area maintainers, or the core maintainers if it is a new area.
-
-The maintainers of a project area may be represented by a team in external organization. In this case, the state as a project area maintainer is tied to the membership in that team. New members of the team may automatically be added as maintainers, as well as removed when they leave. This process is governed autonomously by the team of project area maintainers.
-
-A Project Area Maintainer has all the rights and responsibilities of an Organization Member.
-
-### Responsibilities
-
-- Review PRs towards their project area. Project area maintainers are expected to review at least 20 PRs per year, or the majority of all PRs towards the area, if it is less than 20
-- Follow the [reviewing guide](REVIEWING.md)
-- Triage and respond to issues related to their project area
-- Mentor new project area maintainers
-- Write refactoring PRs
-- Determine strategy and policy for the project area
-- Participate in or leading community meetings related to their project area
-
-### Requirements
-
-- Is an Organization Member
-- Have made at least 5 meaningful contributions towards the project area
-- Demonstrates knowledge of their project area, and how it fits into the larger Backstage project
-- Is able to exercise judgment for the good of the project, independent of their employer, friends, or team
-- Mentors other contributors and project area maintainers
-- Can commit to spending at least 16 hours per month working on the project, preferably distributed evenly across the month
-
-### Privileges
-
-- Approve and merge PRs towards their project area
-- Drive the direction and roadmap of their project area
-
-### Becoming a Project Area Maintainer
-
-If you are interested in becoming a project area maintainer, reach out to the existing maintainers for that area. If you wish to become a maintainer for a new area, reach out to the core maintainers.
-
-Any current project area maintainer or core maintainer may nominate a new project area maintainer by opening a PR towards the [OWNERS.md](OWNERS.md) file. A majority of the project area maintainers for that area must approve the PR. If there are no existing maintainers for that area, the PR must be approved by a majority of the core maintainers.
-
-## Core Maintainer
-
-Core Maintainers are responsible for the Backstage project as a whole. They help review and merge project-level pull requests as well as coordinate work affecting multiple project areas. A core maintainer needs to commit the majority of their working time towards the project, and exercise judgment for the good of the project, independent of their employer. Core maintainers should also mentor and seek out new maintainers, lead community meetings, and communicate with the CNCF on behalf of the project. To become a core maintainer one needs to have been the maintainer of a number of different project areas, demonstrate a deep knowledge of large parts of the Backstage project, and be backed by the existing core maintainers.
-
-A Core Maintainer have all the rights and responsibilities of a Project Area Maintainer.
-
-### Responsibilities
-
-- Take part in the incoming issue and PR triage and review process. PRs are shared equally among all maintainers
-- Mentor new Project Area Maintainers and Plugin Maintainers
-- Drive refactoring and manage tech health across the entire project
-- Participate in CNCF maintainer activities
-- Respond to security incidents in accordance to our [security policy](./SECURITY.md)
-- Determine strategy and policy for the project
-- Participate in or leading community meetings
-
-### Requirements
-
-- Experience as a Project Area Maintainer for at least 6 months
-- Demonstrates a broad knowledge of the project across multiple areas
-- Is able to exercise judgment for the good of the project, independent of their employer, friends, or team
-- Mentors other contributors
-- Can commit to spending at least 10 days per month working on the project
-
-### Privileges
-
-- Approve PRs that fall outside any specific project area
-- Merge PRs to any area of the project
-- Represent the project in public as a Maintainer
-- Communicate with the CNCF on behalf of the project
-- Have a vote in Maintainer decision-making meetings
-
-### Becoming a Core Maintainer
-
-Any core maintainer or end user sponsor may nominate a new core maintainer by opening a PR towards the [OWNERS.md](OWNERS.md) file. Core maintainers must be approved by a majority of the existing core maintainers and end user sponsors.
-
-## End User Sponsors
-
-### Role of a Backstage End User Sponsor
-
-- Provide support for Backstage by removing blockers, securing funding, providing advocacy, feedback, and ensuring project continuity and long term success
-- Assist Backstage maintainers in prioritizing upcoming roadmap items and planned work
-- Provide neutral mediation for any disputes that arise as part of the project
-
-### Backstage End User Sponsor Membership
-
-The End User Sponsors group comprises at most 5 people. To be eligible for membership in the group, you or the company where you work you must:
-
-- Be responsible for and end user of a production Backstage deployment of non-trivial size
-- Be active contributors to the open source project
-- Be willing and able to attend regularly-scheduled End User Sponsor meetings
-- Abide by [CNCF CoC](https://github.com/cncf/foundation/blob/main/code-of-conduct.md)
-
-Candidates for membership will be nominated by current Sponsor members or by Backstage maintainers. If there are more nominations than Sponsor seats remaining, existing sponsors shall vote on the candidates, and the candidates with the most votes will become Sponsors. Any ties will be broken by current Backstage sponsors.
-
-# Conflict resolution and voting
-
-In general, we prefer that technical issues and membership are amicably worked out between the persons involved. If a dispute cannot be decided independently, the sponsors and core maintainers can be called in to decide an issue. If the sponsors and maintainers themselves cannot decide an issue, the issue will be resolved by voting.
-
-In all cases in this document where voting is mentioned, the voting process is a simple majority in which each sponsor receives two votes and each core maintainer receives one vote. If such a majority is reached, the vote is said to have _passed_.
-
-## Inactivity
-
-It is important for contributors to be and stay active to set an example and show commitment to the project. Inactivity is harmful to the project as it may lead to unexpected delays, contributor attrition, and a loss of trust in the project.
-
-Inactivity is measured by periods of no contributions without explanation, for longer than:
-
-- Core Maintainer: 2 months
-- Project Area Maintainer: 4 months
-- Plugin Maintainer: 6 months
-- Organization Member: 12 months
-
-Consequences of being inactive include:
-
-- Involuntary removal or demotion
-- Being asked to move to Emeritus status
-
-## Involuntary Removal or Demotion
-
-Involuntary removal/demotion of a contributor happens when responsibilities and requirements aren't being met. This may include repeated patterns of inactivity, extended period of inactivity, a period of failing to meet the requirements of your role, and/or a violation of the Code of Conduct. This process is important because it protects the community and its deliverables while also opens up opportunities for new contributors to step in.
-
-Involuntary removal or demotion is handled through a vote by a majority of the current Core Maintainers. Some aspects of this process may be automated, such as removal after periods of inactivity.
-
-## Stepping Down/Emeritus Process
-
-If and when contributors' commitment levels change, contributors can consider stepping down (moving down the contributor ladder) vs moving to emeritus status (completely stepping away from the project).
-
-Contact the Maintainers about changing to Emeritus status, or reducing your contributor level.
diff --git a/NOTICE b/NOTICE
index fb23d28ebc..1f1dfbccbb 100644
--- a/NOTICE
+++ b/NOTICE
@@ -5,3 +5,4 @@ Portions of this software were developed by third-party software vendors:
- Tech Radar Plugin (https://opensource.zalando.com/tech-radar/), Copyright (c) 2017 Zalando SE
- [OpenAPI Generator Templates](./packages/repo-tools/templates), Copyright 2018 OpenAPI-Generator Contributors (https://openapi-generator.tech) Copyright 2018 SmartBear Software
+- Optic CLI (https://github.com/opticdev/optic), Copyright 2022, Optic Labs Corporation
diff --git a/OWNERS.md b/OWNERS.md
index ab35b5b1e5..bf97c91685 100644
--- a/OWNERS.md
+++ b/OWNERS.md
@@ -1,5 +1,5 @@
- See [CONTRIBUTING.md](CONTRIBUTING.md) for general contribution guidelines.
-- See [GOVERNANCE.md](GOVERNANCE.md) for governance guidelines and responsibilities.
+- See [GOVERNANCE.md](https://github.com/backstage/community/blob/main/GOVERNANCE.md) for governance guidelines and responsibilities.
## Core Maintainers
@@ -22,14 +22,15 @@ Team: @backstage/catalog-maintainers
Scope: The catalog plugin and catalog model
-| Name | Organization | Team | GitHub | Discord |
-| --------------- | ------------ | --------- | ----------------------------------------- | ------------------- |
-| Rickard Dybeck | Spotify | Chipmunks | [alde](https://github.com/alde) | `rdybeck#8083` |
-| Mike Blockley | Spotify | Chipmunks | [mikeyhc](https://github.com/mikeyhc) | `mikey-spot#5363` |
-| Elon Jefferson | Spotify | Chipmunks | [Edje-C](https://github.com/Edje-C) | `elon-spotty#6086 ` |
-| Nurit Izrailov | Spotify | Chipmunks | [nuritizra](https://github.com/nuritizra) | - |
-| Hunter Dougless | Spotify | Chipmunks | [hntrdglss](https://github.com/hntrdglss) | `hntrdglss#1849` |
-| Seve Kim | Spotify | Chipmunks | [sevedkim](https://github.com/sevedkim) | `seve#9951` |
+| Name | Organization | Team | GitHub | Discord |
+| -------------------- | ------------ | ------------- | ----------------------------------------------- | --------------- |
+| Ben Lambert | Spotify | Cubic Belugas | [benjdlambert](https://github.com/benjdlambert) | `blam#2159` |
+| Camila Loiola | Spotify | Cubic Belugas | [camilaibs](http://github.com/camilaibs) | `camilal#0226` |
+| Fredrik Adelöw | Spotify | Cubic Belugas | [freben](https://github.com/freben) | `freben#3926` |
+| Johan Haals | Spotify | Cubic Belugas | [jhaals](https://github.com/jhaals) | `Johan#0679` |
+| Mihai Tabara | Spotify | Cubic Belugas | [MihaiTabara](http://github.com/MihaiTabara) | `mihait#3107` |
+| Patrik Oldsberg | Spotify | Cubic Belugas | [Rugvip](https://github.com/Rugvip) | `Rugvip#0019` |
+| Vincenzo Scamporlino | Spotify | Cubic Belugas | [vinzscam](http://github.com/vinzscam) | `vinzscam#6944` |
### Discoverability
@@ -73,14 +74,15 @@ Team: @backstage/permission-maintainers
Scope: The Permission Framework and plugins integrating with the permission framework
-| Name | Organization | Team | GitHub | Discord |
-| -------------------- | ------------ | --------------- | ------------------------------------------ | ------------- |
-| Ainhoa Larumbe | Spotify | Imaginary Goats | [ainhoaL](http://github.com/ainhoaL) | ainhoa#8085 |
-| Eric Peterson | Spotify | Imaginary Goats | [iamEAP](http://github.com/iamEAP) | iamEAP#3058 |
-| Harry Hogg | Spotify | Imaginary Goats | [HHogg](http://github.com/HHogg) | simplex#3451 |
-| Joon Park | Spotify | Imaginary Goats | [Joonpark13](http://github.com/Joonpark13) | Sixpool#5060 |
-| Mike Lewis | Spotify | Imaginary Goats | [mtlewis](http://github.com/mtlewis) | mtlewis#3658 |
-| Vincenzo Scamporlino | Spotify | Imaginary Goats | [vinzscam](http://github.com/vinzscam) | vinzscam#6944 |
+| Name | Organization | Team | GitHub | Discord |
+| -------------------- | ------------ | ------------- | ----------------------------------------------- | --------------- |
+| Ben Lambert | Spotify | Cubic Belugas | [benjdlambert](https://github.com/benjdlambert) | `blam#2159` |
+| Camila Loiola | Spotify | Cubic Belugas | [camilaibs](http://github.com/camilaibs) | `camilal#0226` |
+| Fredrik Adelöw | Spotify | Cubic Belugas | [freben](https://github.com/freben) | `freben#3926` |
+| Johan Haals | Spotify | Cubic Belugas | [jhaals](https://github.com/jhaals) | `Johan#0679` |
+| Mihai Tabara | Spotify | Cubic Belugas | [MihaiTabara](http://github.com/MihaiTabara) | `mihait#3107` |
+| Patrik Oldsberg | Spotify | Cubic Belugas | [Rugvip](https://github.com/Rugvip) | `Rugvip#0019` |
+| Vincenzo Scamporlino | Spotify | Cubic Belugas | [vinzscam](http://github.com/vinzscam) | `vinzscam#6944` |
### TechDocs
@@ -187,6 +189,7 @@ Scope: The Scaffolder frontend and backend plugins, and related tooling.
| Miklós Kiss | Roadie.io | [kissmikijr](https://github.com/kissmikijr) | `Miklos#7416` |
| Patrick Jungermann | Bonial International GmbH | [pjungermann](https://github.com/pjungermann) | `pjungermann#6933` |
| Phil Kuang | FactSet Research Systems | [kuangp](https://github.com/kuangp) | `pkuang#3202` |
+| Sebastian Poxhofer | N26 | [secustor](https://github.com/secustor) | `secustor` |
| Taras Mankovski | Frontside | [taras](https://github.com/taras) | `tarasm#1256` |
## Emeritus Core Maintainers
diff --git a/README-ko_kr.md b/README-ko_kr.md
index e5f50bd2b8..b2bba41567 100644
--- a/README-ko_kr.md
+++ b/README-ko_kr.md
@@ -10,7 +10,6 @@

[](https://codecov.io/gh/backstage/backstage)
[](https://github.com/backstage/backstage/releases)
-[](https://app.uffizzi.com/ephemeral-environments/backstage/backstage)
[](https://bestpractices.coreinfrastructure.org/projects/7678)
[](https://securityscorecards.dev/viewer/?uri=github.com/backstage/backstage)
diff --git a/README-zh_Hans.md b/README-zh_Hans.md
index 3e6cea4e95..2813ee0793 100644
--- a/README-zh_Hans.md
+++ b/README-zh_Hans.md
@@ -10,7 +10,6 @@

[](https://codecov.io/gh/backstage/backstage)
[](https://github.com/backstage/backstage/releases)
-[](https://app.uffizzi.com/ephemeral-environments/backstage/backstage)
[](https://bestpractices.coreinfrastructure.org/projects/7678)
[](https://securityscorecards.dev/viewer/?uri=github.com/backstage/backstage)
diff --git a/README.md b/README.md
index 6cea4235e0..47ae539b6b 100644
--- a/README.md
+++ b/README.md
@@ -10,7 +10,6 @@ English \| [한국어](README-ko_kr.md) \| [中文版](README-zh_Hans.md)

[](https://codecov.io/gh/backstage/backstage)
[](https://github.com/backstage/backstage/releases)
-[](https://app.uffizzi.com/ephemeral-environments/backstage/backstage)
[](https://bestpractices.coreinfrastructure.org/projects/7678)
[](https://securityscorecards.dev/viewer/?uri=github.com/backstage/backstage)
diff --git a/SECURITY.md b/SECURITY.md
index 5866fff2b4..8de1307356 100644
--- a/SECURITY.md
+++ b/SECURITY.md
@@ -66,7 +66,7 @@ The insecure example above should instead be written like this:
```ts
// THIS IS GOOD, DO THIS
-import { resolveSafeChildPath } from '@backstaghe/backend-common';
+import { resolveSafeChildPath } from '@backstage/backend-common';
import fs from 'fs-extra';
function writeTemporaryFile(tmpDir: string, name: string, content: string) {
diff --git a/app-config.yaml b/app-config.yaml
index 9e5b5c468c..cb70170541 100644
--- a/app-config.yaml
+++ b/app-config.yaml
@@ -9,6 +9,9 @@ app:
# applicationId: qwerty
# site: # datadoghq.eu default = datadoghq.com
# env: # optional
+ # sessionSampleRate: 100
+ # sessionReplaySampleRate: 0
+
support:
url: https://github.com/backstage/backstage/issues # Used by common ErrorPage
items: # Used by common SupportButton component
diff --git a/beps/0001-notifications-system/README.md b/beps/0001-notifications-system/README.md
index 4b4f3b0532..80751179dd 100644
--- a/beps/0001-notifications-system/README.md
+++ b/beps/0001-notifications-system/README.md
@@ -92,7 +92,7 @@ If the notification status is updated, the signal service shall emit a signal wi
The role of the notifications plugin is to manage the lifecycle of notifications. The backend plugin provides an API for other backends to send notifications, as well as an accompanying [backend service](https://backstage.io/docs/backend-system/architecture/services). It also provides a separate API for the frontend plugin to read notifications for an individual user and manage the read status of notifications.
-The notification backend stores notification using the [database service](https://backstage.io/docs/backend-system/core-services/index#database). In particular it needs to store the following information for each notification:
+The notification backend stores notification using the [database service](https://backstage.io/docs/backend-system/core-services/index#database). In particular, it needs to store the following information for each notification:
- ID
- Recipients
@@ -110,8 +110,9 @@ The notification backend stores notification using the [database service](https:
- Topic (optional)
- Scope (optional)
- Icon (optional)
+ - Metadata (optional)
-The recipients is **not** a list of users, but rather a filter that describes who should receive the notification. It must be possible to evaluate this filter in a database query, so that we can efficiently fetch all notifications for a given user. The same filter will also be used by the signal backend to determine which users should receive a signal.
+The recipients are **not** a list of users, but rather a filter that describes who should receive the notification. It must be possible to evaluate this filter in a database query, so that we can efficiently fetch all notifications for a given user. The same filter will also be used by the signal backend to determine which users should receive a signal.
The read date is a timestamp of marking the notifications as read by the user. If missing, the notification is still unread.
@@ -147,6 +148,8 @@ The link is a relative or absolute URL. As an example, it can be used:
- by an external system to request an action within an asynchronous task
- by a BE plugin to provide link to other part of the Backstage UI (i.e. to the Catalog)
+The metadata is an opaque JSON field, where an additional payload can be stored. The format of this data is owned by the notification sender and is tied to the notification topic, i.e. notifications sent from the source on the same topic should use a compatible metadata format. The primary purpose of this field is to allow for custom processing and rendering based on the additional metadata.
+
The additional links are an array of title-URL pairs. They can represent immediate actions on the notification (i.e. yes-no) or lead the user to additional details.
The `notification-backend` does not provide any new permissions, since creating notifications can only be done by other backend plugins, while reading notifications can only be done by the authenticated user. It is possible that we want to add a permissions for reading notifications, in particular for admin and impersonation use cases, but that is not part of this proposal or the initial implementation.
@@ -206,12 +209,16 @@ export type NotificationSeverity = 'critical' | 'high' | 'normal' | 'low';
export type NotificationPayload = {
title: string;
description?: string;
- link: string;
+ link?: string;
additionalLinks?: string[];
- severity: NotificationSeverity;
+ severity?: NotificationSeverity;
topic?: string;
scope?: string;
icon?: string;
+ metadata?: Array<{
+ type: string;
+ value: JsonValue;
+ }>;
};
export type Notification = {
@@ -236,7 +243,8 @@ interface NotificationService {
}
```
-Each notification contains a human readable `title`, `origin` and optionally `link` for additional details. The `created`, `id`, `read` and `saved` properties are handled by the backend based and cannot be passed during the notification creation.
+Each notification contains a human-readable `title`, `origin` and optionally `link` for additional details. The `created`, `id`, `read` and `saved` properties are handled by the backend based and cannot be passed during the notification creation.
+Any optional additional details could be stored in `metadata`. We advise to provide the name to the type which contains the information about the context and the version, for example: 'core.icon.v1'.
Calling `sendNotification` should never throw an error so that it doesn't block the current processing. Notifications should be considered as second-level citizens that are not critical if not delivered.
@@ -380,10 +388,39 @@ interface SignalApi {
- Render dynamic values with various different React elements such as the `EntityRefLink` for entity references (for example `{{ user:default/john.doe }}`) in the notification payload
- Handle `link` values that use route references. For example instead hard-coding link to `/catalog/default/component/artist-web` it should be possible to use `catalogPlugin.catalogEntity` route reference as a link of the notification. This should also allow using parameters to be passed to the route reference. Links to external systems are still supported.
- Add support for `analyticsApi` to notification actions like marking notifications done, saved or opening links in the notifications
-- Add support for user settings to control how notifications are shown to the user and which notifications user wants to receive. This should also include support for different `NotificationProcessor`s that can send notification to external systems
- Add a sound to be played when notification is received
- Add i18n internationalization support for the notification payload
+### User specific notification settings
+
+To allow the users more fine-grained control of notifications, user must have an option to unsubscribe from specific origins, topics and channels.
+
+By default, all notifications are enabled for the user in all notification channels. Frontend plugin provides an user interface to change these settings for example as described in the following image:
+
+
+
+Each notification processor with `send` functionality will be listed as a separate channel among the Backstage internal notification channel `Web`. For this, each notification processor must implement a function to get a human readable name to be rendered in the frontend.
+
+User must be able to save these settings to the notification database, and they are be checked each time a new notification is sent to the user.
+
+Disabling a notification from specific origin or topic in the `Web` channel will not remove the old notifications being visible in the frontend from that source but instead, it only prevents new notifications being sent.
+
+For performance reasons the notification settings will ignore all broadcast notifications and those will be sent to all users despite their origin or channel.
+
+```ts
+export type NotificationSetting = {
+ origin: string;
+ topic?: string;
+ channels: Record;
+};
+
+export type UserNotificationSettings = {
+ settings: NotificationSetting[];
+};
+```
+
+The backend plugin returns user notification settings for all known origins, topics and channels it knows of. As new origins, topics and channels will get added, also the notification settings list will get longer. This allows an easy way to add new notification origins, topics and channels without need to change the notification plugin. If the user is missing notification setting from specific origin/topic/channel, the backend considers it as enabled.
+
## Release Plan
The notification and signal plugins are released as two new plugins in the Backstage ecosystem. They will both start out in an experimental state.
diff --git a/beps/0001-notifications-system/UserNotificationSettings.png b/beps/0001-notifications-system/UserNotificationSettings.png
new file mode 100644
index 0000000000..de9a5881b4
Binary files /dev/null and b/beps/0001-notifications-system/UserNotificationSettings.png differ
diff --git a/beps/0002-dynamic-frontend-plugins/README.md b/beps/0002-dynamic-frontend-plugins/README.md
index 6581457e06..f26a3b488d 100644
--- a/beps/0002-dynamic-frontend-plugins/README.md
+++ b/beps/0002-dynamic-frontend-plugins/README.md
@@ -67,7 +67,7 @@ The overarching goal of this proposal is to outline the full path of how fronten
- **Distribution**: How these artifacts are deployed or published and made available for apps to load.
- **Loading**: How an app is able to load these artifacts from remote or local sources at runtime.
-Each of these may have multiple possible solutions, in particular the loading and distribution steps. This proposal should aim to provide the minimum solutions that avoids the need for each adopter to have to re-bundle open source plugins, while still making it simple to use dynamic installation for their own internal plugins.
+Each of these may have multiple possible solutions, in particular the loading and distribution steps. This proposal should aim to provide a solution that makes it possible to re-bundle 3rd party plugins to make it possible to install them dynamically, as well as a simple solution to deploy internal plugins for dynamic installation into an app.
There are a couple of sub-goals that are important for this to work:
@@ -84,6 +84,8 @@ and make progress.
The **integration** of installed plugins and features is not in scope for this proposal, that is the responsibility of the new frontend system.
+This proposal does not aim to provide a solution for re-building packages on the fly. Plugins must be pre-built for it to be possible to dynamically install them into an app. This means that a solution where you can directly install existing packages from NPM is not in scope.
+
This proposal does not contain any form of visual interface for managing dynamically installed plugins. The scope of this proposal only includes configuration of dynamic plugins through static configuration and TypeScript interfaces.
This proposal does not aim to make it possible to add or remove plugins into an already running frontend app instance as created by `createApp` from the Backstage core APIs. The page must be reloaded for any updates to take effect.
@@ -217,6 +219,12 @@ This can be checked by debugging network traffic and shared scopes:

+#### Limitations
+
+A limitation of module sharing is that each module name can only appear once in each context. This means that if you're trying to build a bundle of shared modules with a deeper dependency tree, you may end up needing to resolve conflicts by renaming some modules that appear multiple times with different versions. This will in turn limit sharing of those modules with other bundles.
+
+There is also a conflict with the chunk splitting currently used in the Backstage CLI that means that some singleton modules need to be configured to be eagerly loaded. More broadly we may also want to re-evaluate the chunk splitting strategy in the Backstage CLI when adding support for module federation.
+
### Plugin manifest
Each plugin should have a manifest file with important metadata. This metadata is used to load the remote assets to browser. The plugin manifest should be part of a build output.
@@ -496,6 +504,8 @@ Theoretically plugins can be hosted on some "public CDN" which is detached from
Assets can be also be hosted in the same way as they have always been.
+It's important to consider old deployments as part of this storage, to make sure that dynamic chunks are still available to users who have not yet refreshed the page to load the latest version of the app.
+
### Plugin discovery
How to notify/send data to browser
@@ -555,8 +565,16 @@ List any dependencies that this work has on other BEPs or features.
## Alternatives
-
+### Runtime packaging of NPM packages
+
+A solution that has been considered is to allow for the installation of NPM packages directly into the app, with them being repackaged for dynamic installation on the fly. This allows for a more direct way of installing plugins, without the need to change how plugins are published to NPM. The downside of this approach is that it leaves validation and dependency management to the runtime and operator of the Backstage instance.
+
+The NPM ecosystem is built around using version ranges along with lockfiles for dependency management. It is generally up to the maintainers of a repo to make sure that the specific dependency versions installed are all compatible with each other and do not introduce security vulnerabilities. This can be a fairly complex problem, and pushing it to the runtime installation of each plugin ends up being a significant risk.
+
+We consider it to be a better approach to push this responsibility down one step from Backstage operators, either to plugin maintainers, or to a service that is able to bundle and validate plugin bundles before they are installed into a Backstage instance. Building and running such as service as part of the Backstage open source project is out of scope for this proposal, but is something that could be considered in the future.
+
+### Publish dynamic bundle to NPM
+
+We could modify the plugin build process to also output a module federation bundle for dynamic installation. This would also allow for direct installation of plugins directly from NPM, but puts a responsibility on each plugin maintainer to keep publishing new versions of the plugin to NPM simply to update transitive dependencies. This significantly increases the effort of maintaining a Backstage plugin.
+
+The dynamic installation bundle can also be quite large, depending on the dependency tree of each plugin. There is a risk that the size of `node_modules` in a Backstage increases significantly, potentially hurting the development experience by increasing installation time both locally and in CI.
diff --git a/beps/0008-docs-personas-framework-portal/README.md b/beps/0008-docs-personas-framework-portal/README.md
new file mode 100644
index 0000000000..07468b7c4a
--- /dev/null
+++ b/beps/0008-docs-personas-framework-portal/README.md
@@ -0,0 +1,347 @@
+---
+title: Improved Backstage Documentation with Personas
+status: provisional
+authors:
+ - '@waldirmontoya25'
+ - '@aramissennyeyd'
+owners:
+project-areas:
+ - core
+creation-date: 2024-03-18
+---
+
+# BEP: Enhancing Backstage Documentation: Personas, Framework, and Developer Portal
+
+[**Discussion Issue**](https://github.com/backstage/backstage/issues/23689)
+
+- [BEP: Enhancing Backstage Documentation: Personas, Framework, and Developer Portal](#bep-enhancing-backstage-documentation-personas-framework-and-developer-portal)
+ - [Summary](#summary)
+ - [Motivation](#motivation)
+ - [Goals](#goals)
+ - [Non-Goals](#non-goals)
+ - [Proposal](#proposal)
+ - [Design Details](#design-details)
+ - [Personas](#personas)
+ - [User](#user)
+ - [Documentation Style](#documentation-style)
+ - [Administrator](#administrator)
+ - [Documentation Style](#documentation-style-1)
+ - [Integrator](#integrator)
+ - [Documentation Style](#documentation-style-2)
+ - [Contributor](#contributor)
+ - [Documentation Style](#documentation-style-3)
+ - [Business Stakeholder](#business-stakeholder)
+ - [Documentation Style](#documentation-style-4)
+ - [Release Plan](#release-plan)
+ - [Dependencies](#dependencies)
+ - [Example Table of Contents](#example-table-of-contents)
+
+## Summary
+
+This BEP proposes restructuring the Backstage documentation to emphasize the dual nature of Backstage as both a framework for building developer portals and a fully functional developer portal out of the box, as demonstrated by the demo site. The documentation will be divided into two main sections: One focusing on the developer portal that users get with the core plugins, and another on the framework that allows integrators and builders to create their own developer portal. The goal is to improve clarity, navigation, and adoption of Backstage by positioning it as both a ready-to-use developer portal and a framework for building custom developer portals.
+
+## Motivation
+
+The current Backstage documentation has been reported to be difficult to navigate, making it challenging for different personas across the DevEx ecosystem to extract value. The CNCF [**assessment**](https://github.com/cncf/techdocs/tree/main/assessments/0008-backstage/) and the resulting [**issues**](https://github.com/backstage/backstage/issues/21893) highlight the need for improvement in the documentation structure.
+
+### Goals
+
+- Divide the documentation into two section: Framework and Developer Portal
+- Define the personas Backstage is targeting
+- Structure the documentation to cater the different personas
+- Move the existing content to the appropriate section
+
+### Non-Goals
+
+- Rewrite the entire documentation from scratch
+- Write additional content beyond the scope of the existing documentation
+
+## Proposal
+
+The proposed restructuring of the Backstage documentation revolves around two core ideas:
+
+1. Positioning Backstage as both a framework to build developer portals and a developer portal itself, and splitting the documentation into two main sections:
+
+ - Developer Portal: Focusing on the features, configuration, and usage of the developer portal that users get out of the box with the core plugins.
+ - Framework: Covering the aspects of Backstage as a framework, including guides for integrators and builders who want to create their own developer portal using Backstage.
+
+2. Defining the personas participating in Backstage adoption journeys to improve documentation navigation. The identified personas are:
+
+ - **End User**: A person who uses Backstage to find information, use plugins, and consume the developer portal.
+ - **Administrator/Operator**: A person who configures, secures, and deploys the developer portal, manages plugins, and oversees the general administration of the developer portal.
+ - **Integrator/Builder**: A person who builds plugins, customizes the code and design, and creates custom-built developer portals based on the Backstage framework. This includes developers and designers and anyone adding new functionality to their own Backstage instance.
+ - **Product Manager/Business stakeholders**: A person who defines the strategy for adopting Backstage, identifies use cases, communicates the value proposition for adopting Backstage and connects the developer portal to the business strategy.
+ - **Contributor**: A person who contributes to the Backstage upstream ecosystem.
+
+The adoption strategy would be as follows:
+
+- Create a dedicated page describing the personas Backstage is targeting and the documentation sections that cater to each persona.
+- Restructure the documentation into the two new sections (Framework and Developer Portal) and redistribute the existing content accordingly.
+- Publish a blog post announcing the changes, highlighting Backstage's positioning as both a framework and a developer portal, and explaining the benefits of the restructured documentation.
+
+The benefits of restructuring the documentation according to these ideas include:
+
+1. Easier navigation and discoverability of information for different personas and use cases.
+2. Clear separation of runtime and development documentation.
+3. Simplified process for contributors to determine the appropriate location for new documentation.
+4. Streamlined Backstage adoption process for new adopters.
+
+## Design Details
+
+- The Docs section of the microsite will be divided into two top-level sections: Framework and Developer Portal.
+- The structure of the Table of Contents will align with the outline proposed in https://github.com/backstage/backstage/issues/21946.
+
+### Personas
+
+#### User
+
+Users navigate the developer portal to access tools, information, and plugins essential for their daily tasks. They rely on Backstage to effortlessly find resources, utilize integrations, and connect with other tools and services within their ecosystem. Their interaction is predominantly with the frontend of the portal, where ease of use, accessibility, and relevant content discovery are critical.
+
+##### Documentation Style
+
+Documentation for this persona should be about usability of the portal once it is running. For example:
+
+- Understanding the mechanics of the Software Catalog
+- Registering components
+- Deleting components
+- How the source of truth is the external tool linked through the plugins
+- Understand dependencies relations and the overall schema of the catalog
+- Using available scaffolder actions
+- Customizing new workflows with available actions
+- Searching
+- Using available plugins
+- Step by step tutorials
+
+#### Administrator
+
+Administrators are responsible for the behind-the-scenes technical setup and maintenance of the Backstage portal. This includes deploying the portal, configuring plugins, managing user access, and ensuring the security and performance of the system. They interact with both the frontend and backend, often using command-line tools, administrative dashboards, and configuration files to perform their tasks.
+
+##### Documentation Style
+
+Documentation written for this persona should be DevOps technical, assuming a strong DevOps background. The goal with administrator documentation is to give administrators a strong understanding of how to deploy and manage a Backstage Developer Portal, best practices. For example:
+
+- Installing and upgrading
+- Configuring
+ - Authentication
+ - Plugins
+- Ingesting data (users/groups/components, etc)
+- Installing plugins
+- Implement Git Flows for the Developer portal
+- Creating Pipelines for Docs generation
+- Troubleshooting
+
+#### Integrator
+
+Integrators actively work on extending and customizing Backstage. This includes developing new plugins, customizing the UI/UX, and integrating external services or data sources. Their work is deeply technical, involving coding, and engaging with the Backstage community for support and collaboration. They need a deep understanding of the Backstage architecture and APIs, working closely with both the framework's backend and frontend aspects.
+
+##### Documentation Style
+
+Documentation written for this persona should be software technical, assuming a strong software background. While we can assume an overall technical knowledge, where possible we should link out to useful guides for the technologies we use, ex: Node.js, express.js, React, etc. The goal with documentation written for integrators is to give them a strong understanding of how to use the Backstage framework to build/evolve a company's Backstage Developer Portal, orient them to get support from the open source community, and prepare them for continuing to deliver value for their Backstage Developer Portal. For example:
+
+- API references
+- Frontend and Backend systems
+- Package architecture
+- Extending the Software Catalog
+- Creating custom themes
+- Integrating new react components
+- Building custom authentication providers/strategies
+- Accessibility
+
+#### Contributor
+
+Contributors are involved in the development of the Backstage framework itself. They contribute to the core codebase, develop new features, fix bugs, create documentation and maintain the overall health of the project. They are deeply involved in the open-source community, collaborating with maintainers and other contributors to improve the framework and its ecosystem.
+
+##### Documentation Style
+
+The goal with documentation written for contributors is to give them a strong understanding of how to contribute to the Backstage framework, orient them to get support from the open source community, and prepare them for continuing to deliver value for the Backstage framework. For example:
+
+- Contributing to the Backstage framework
+- Setting up a development environment
+- Writing tests
+- Writing documentation
+
+#### Business Stakeholder
+
+Business stakeholders use Backstage to align technical capabilities with business goals, monitoring how features and plugins support operational efficiency, developer satisfaction, and strategic objectives. They are involved in defining the strategy and measuring the impact of the developer portal on the organization. They need to navigate through dashboards, reports, and analytics within Backstage to gather insights and make informed decisions.
+
+##### Documentation Style
+
+Documentation written for this persona should be strategic, assuming a strong background in business development and strategy. The goal for business documentation is to give a strong understanding of what Backstage Developer Portal can do for their company, how to deliver value quickly and continuously and guides for pitching or driving Backstage adoption. For example:
+
+- Adoption use cases
+- Adoption strategies
+- Measuring success
+- Case studies
+
+## Release Plan
+
+- Release the BEP by 03/24/2024.
+- Discuss the changes with the community and gather feedback by 04/24/2024.
+- Implement the changes by 04/30/2024.
+
+## Dependencies
+
+None
+
+## Example Table of Contents
+
+- Overview
+ - "The overview should introduce users to the concept of Backstage, what an IDP is, how to deliver value, why you should care about DevEx, etc."
+ - What is Backstage?
+ - Roadmap
+ - Vision
+ - Release and Versioning Policy
+ - Backstage Threat Model
+ - Logo assets
+ - Support and community
+- Framework
+ - Architecture Overview
+ - "The arch overview should explain how the framework is structured, where plugins and instances fit in and how to understand the current design of Backstage."
+ - Getting Started
+ - Integrator/Builder Guides
+ - Local Development
+ - "Prepare users for how to develop locally, debug problems, run tests, etc."
+ - CLI
+ - Linking in local packages
+ - Debugging Backstage
+ - Backstage core framework
+ - "Internal documentation."
+ - Systems
+ - Frontend
+ - Old
+ - New
+ - Backend
+ - Old
+ - New
+ - API Reference
+ - "Internal documentation"
+ - Building plugins
+ - "How to build a plugin, how to integrate it with other plugins, how to deploy and monitor it, and how to iterate on plugin development."
+ - Intro to plugins
+ - Existing plugins
+ - Creating a new plugin
+ - Plugin development
+ - Structuring a plugin
+ - Integrating with other systems
+ - Integrating with the Catalog
+ - Integrating Search
+ - Composability system
+ - Internationalization
+ - Plugin analytics
+ - Feature flags
+ - OpenAPI
+ - Backends and APIs
+ - Testing
+ - Publishing
+ - Core Plugins
+ - "How to leverage the existing plugins for your new plugin or customization options."
+ - Home Page
+ - Customizing the home page
+ - Software Catalog
+ - Extending the model
+ - External integrations
+ - Catalog Customization
+ - API
+ - Software Templates
+ - Writing custom actions
+ - Writing tests for actions
+ - Writing custom field extensions
+ - Writing custom step layouts
+ - Authorizing parameters, steps and actions
+ - Migrating to react-jsonschema-form@v5
+ - Migrating to v1beta3 templates
+ - Search
+ - Overview
+ - Getting Started with search
+ - Search concepts
+ - Search architecture
+ - Search Engines
+ - How to Guides
+ - TechDocs
+ - Customizing TechDocs
+ - TechDocs add-ons
+ - Kubernetes
+ - Customizing the kubernetes plugin
+ - Authentication
+ - Proxy
+ - Permissions
+ - Overview
+ - Concepts
+ - Getting Started
+ - Writing a permission policy
+ - Frontend integration
+ - Defining custom permission rules
+ - Using permissions in plugins
+ - Designing for Backstage
+ - ADRs
+ - Accessibility
+ - References
+ - Contributor Guides
+ - "How to get started contributing to OSS."
+ - Contributing to Backstage
+ - Reference
+- Developer Portal
+ - Architecture Overview
+ - Getting Started
+ - Administrator Guides
+ - Developer Portal
+ - "How do I deploy, monitor, configure and verify my Backstage Developer Portal?"
+ - Installing and Configuring
+ - Database
+ - Authentication
+ - Installing plugins
+ - Customize the design
+ - Securing
+ - Deploying in Production
+ - Integrating with other systems
+ - Managing
+ - Monitoring
+ - Troubleshooting
+ - Upgrading
+ - Keeping backstage up to date
+ - Customizing
+ - Core Plugins
+ - "How do I install and configure Backstage Developer Portal with plugins."
+ - Home Page
+ - Installing and Configuring
+ - Software Catalog
+ - Overview
+ - The life of an Entity
+ - Catalog Configuration
+ - System Model
+ - YAML file format
+ - Entity Reference
+ - Well Known annotations
+ - Well known relations
+ - Well known statuses
+ - Creating the catalog graph
+ - Software Templates
+ - Overview
+ - Configuring
+ - Adding a new template
+ - Writing a template
+ - Built in actions
+ - TechDocs
+ - Overview
+ - Getting Started
+ - Architecture
+ - Installing and configuring
+ - Using Cloud Storage for TechDocs generated files
+ - Configuring CI/CD to generate and publish TechDocs sites
+ - TechDocs CLI
+ - Troubleshooting
+ - Kubernetes
+ - Installing and Configuring
+ - Authentication
+ - Troubleshooting
+ - Search
+ - Product Manager Guides
+ - "How do I present Backstage to leadership, what are the benefits, why should I care, etc."
+ - Strategies for adopting
+ - Use cases
+ - User Guides
+ - "How do I use the default OSS Backstage"
+ - Logging in
+ - Registering a component
+ - Creating a new component
+ - Reference
diff --git a/contrib/docker/minimal-harded-image/README.md b/contrib/docker/minimal-harded-image/README.md
deleted file mode 100644
index accb2188ac..0000000000
--- a/contrib/docker/minimal-harded-image/README.md
+++ /dev/null
@@ -1,12 +0,0 @@
-# Minimal Hardened Image for Backstage
-
-DockerHub images in general did not seem ideal for Backstage as the number of vulnerabilities were quite high regardless of the image used.
-
-The `Dockerfile` in this directory uses a [`wolfi-base`](https://github.com/wolfi-dev) image from Chainguard Images. This improves the security of the application and reduces false positives in scanners.
-
-## Considerations
-
-- `Wolfi` only releases the `latest` tag for public consumption however digests can be pinned.
-- `Wolfi` OS uses packages from the [os repository](https://github.com/wolfi-dev/os) on GitHub. Some packages may be named differently.
-- While `Wolfi` uses `apk`, the OS is designed to support `glibc`.
-- Due to the stripped down nature of the base image, additional packages might be needed compared to a distribution like Debian or Ubuntu.
diff --git a/contrib/docker/minimal-harded-image/Dockerfile b/contrib/docker/minimal-hardened-image/Dockerfile
similarity index 100%
rename from contrib/docker/minimal-harded-image/Dockerfile
rename to contrib/docker/minimal-hardened-image/Dockerfile
diff --git a/contrib/docker/minimal-hardened-image/README.md b/contrib/docker/minimal-hardened-image/README.md
new file mode 100644
index 0000000000..62045a4ded
--- /dev/null
+++ b/contrib/docker/minimal-hardened-image/README.md
@@ -0,0 +1,25 @@
+# Minimal Hardened Image for Backstage
+
+DockerHub images in general did not seem ideal for Backstage as the number of vulnerabilities were quite high regardless of the image used.
+
+The `Dockerfile` in this directory uses a [wolfi-base](https://github.com/wolfi-dev) image from Chainguard Images. This improves the security of the application and reduces false positives in scanners.
+
+## Pinning Digest
+
+To reduce maintenance, the digest of the image has been removed from the `./Dockerfile` file. A complete example with the digest would be `cgr.dev/chainguard/wolfi-base:latest@sha256:3d6dece13cdb5546cd03b20e14f9af354bc1a56ab5a7b47dca3e6c1557211fcf` and it is suggested to update the `FROM` line in the `Dockerfile` to use a digest.
+
+Using the digest allows tools such as Dependabot or Renovate to know exactly which image digest is being utilized and allows for Pull Requests to be triggered when a new digest is available. It is suggested to setup Dependabot/Renovate or a similar tool to ensure the image is kept up to date so that vulnerability fixes that have been addressed are pulled in frequently.
+
+### Obtaining Digest
+
+To obtain the latest digest, perform a `docker pull` on the image to get the latest digest in the command output or use `crane digest `.
+
+## Considerations
+
+- Wolfi only releases the `latest` tag for public consumption however digests can be pinned.
+- Wolfi OS uses packages from the [os repository](https://github.com/wolfi-dev/os) on GitHub.
+ - Some packages may be named differently.
+- While Wolfi uses `apk`, the OS is designed to support `glibc`.
+- Due to the stripped down nature of the base image, additional packages might be needed compared to a distribution like Debian or Ubuntu.
+- Chainguard will maintain one version of each Wolfi package at a time, which will track the latest version of the upstream software in the package. Chainguard will end patch support for previous versions of packages in Wolfi. [Read more here](https://edu.chainguard.dev/chainguard/chainguard-images/faq/#what-packages-are-available-in-chainguard-images)
+ - It is encouraged to use a relative pin or use a third-party tool to ensure the packages are kept up to date
diff --git a/contrib/docs/tutorials/authenticate-api-requests.md b/contrib/docs/tutorials/authenticate-api-requests.md
index 838aaffef6..8c858bea0f 100644
--- a/contrib/docs/tutorials/authenticate-api-requests.md
+++ b/contrib/docs/tutorials/authenticate-api-requests.md
@@ -3,8 +3,7 @@
> [!CAUTION]
> This entire guide MUST NOT BE USED by users of Backstage 1.26 and
> newer. If you have applied the changes in this guide, you need to remove them
-> again as you upgrade to recent versions of Backstage. When [the new auth
-> changes](https://github.com/backstage/backstage/tree/master/beps/0003-auth-architecture-evolution)
+> again as you upgrade to recent versions of Backstage. When [the new auth changes](https://github.com/backstage/backstage/tree/master/beps/0003-auth-architecture-evolution)
> landed backends became natively secured through the framework, and the
> instructions outlined in here can interfere with the backend functioning
> correctly.
diff --git a/contrib/docs/tutorials/aws-deployment.md b/contrib/docs/tutorials/aws-deployment.md
index 6edbb73f9d..d43d8aefb0 100644
--- a/contrib/docs/tutorials/aws-deployment.md
+++ b/contrib/docs/tutorials/aws-deployment.md
@@ -1,11 +1,9 @@
# Deploying Backstage on AWS using ECR and EKS
-Backstage documentation shows how to build a [Docker
-image](https://backstage.io/docs/deployment/docker); this
+Backstage documentation shows how to build a [Docker image](https://backstage.io/docs/deployment/docker); this
tutorial shows how to deploy that Docker image to AWS using Elastic Container
Registry (ECR) and Elastic Kubernetes Service (EKS). Amazon also supports
-deployments with Helm, covered in the [Helm
-Kubernetes](../../kubernetes/basic_kubernetes_example_with_helm) example.
+deployments with Helm, covered in the [Helm Kubernetes](../../kubernetes/basic_kubernetes_example_with_helm) example.
The basic workflow for this method is to build a Backstage Docker image, upload
the new version to a container registry, and update a Kubernetes deployment with
@@ -13,8 +11,7 @@ the new image.
## Create a container registry
-To create an Elastic Container Registry on AWS, go to the [AWS ECR
-console](https://console.aws.amazon.com/ecr/repositories).
+To create an Elastic Container Registry on AWS, go to the [AWS ECR console](https://console.aws.amazon.com/ecr/repositories).
Click `Create repository` and give the repository a name, like `backstage`.
@@ -35,8 +32,7 @@ Go to [AWS IAM console](https://console.aws.amazon.com/iam/home) and select
## Publish a Backstage build
-Follow the [Docker
-image](https://backstage.io/docs/deployment/docker)
+Follow the [Docker image](https://backstage.io/docs/deployment/docker)
documentation to build a new Backstage Docker image:
```shell
@@ -56,8 +52,7 @@ Default region name:
Now you can use the AWS CLI to push the built image to the ECR repository. It's
a good practice to use a specific version tag as well as `latest` when pushing;
-more about [Semver tagging
-here](https://medium.com/@mccode/using-semantic-versioning-for-docker-image-tags-dfde8be06699).
+more about [Semver tagging here](https://medium.com/@mccode/using-semantic-versioning-for-docker-image-tags-dfde8be06699).
Go to the [AWS ECR console](https://console.aws.amazon.com/ecr/repositories) and
click on your repository, then `View push commands`. This will show the
@@ -83,12 +78,10 @@ Kubernetes deployment based on this image.
Creating an Elastic Kubernetes Service (EKS) cluster is beyond the scope of this
document, but it can be as easy as `eksctl create cluster` documented in the
-[AWS EKS getting started
-guide](https://docs.aws.amazon.com/eks/latest/userguide/getting-started-eksctl.html),
+[AWS EKS getting started guide](https://docs.aws.amazon.com/eks/latest/userguide/getting-started-eksctl.html),
which uses a Cloudformation template to create the necessary resources.
-To deploy the Docker image to EKS, follow the [Kubernetes
-guide](https://backstage.io/docs/deployment/k8s#creating-the-backstage-instance)
+To deploy the Docker image to EKS, follow the [Kubernetes guide](https://backstage.io/docs/deployment/k8s#creating-the-backstage-instance)
but set the Backstage deployment `image` to the ECR repository URL:
```yaml
@@ -110,8 +103,7 @@ spec:
...
```
-Create the [Service
-descriptor](https://backstage.io/docs/deployment/k8s#creating-a-backstage-service)
+Create the [Service descriptor](https://backstage.io/docs/deployment/k8s#creating-a-backstage-service)
as well, and apply these Kubernetes definitions to the EKS cluster to complete
the Backstage deployment:
@@ -120,16 +112,14 @@ $ kubectl apply -f kubernetes/backstage.yaml
$ kubectl apply -f kubernetes/backstage-service.yaml
```
-Now you can see your Backstage workload running from the [EKS
-console](https://console.aws.amazon.com/eks/home).
+Now you can see your Backstage workload running from the [EKS console](https://console.aws.amazon.com/eks/home).
## Further steps
### Exposing Backstage with a load balancer
To make the service useful, we need to expose the workload with a load balancer.
-Follow the [Application load balancing on
-EKS](https://docs.aws.amazon.com/eks/latest/userguide/alb-ingress.html) guide to
+Follow the [Application load balancing on EKS](https://docs.aws.amazon.com/eks/latest/userguide/alb-ingress.html) guide to
set up a Load Balancer controller and Kubernetes ingress to your application.
This is ultimately a `kubectl apply` with an ingress definition:
diff --git a/docs/accessibility/index.md b/docs/accessibility/index.md
index b4d63fd4e4..da10d60dd2 100644
--- a/docs/accessibility/index.md
+++ b/docs/accessibility/index.md
@@ -47,7 +47,10 @@ If you want to use the Lighthouse CLI and run the checks based on the config you
yarn dlx @lhci/cli@0.11.x autorun
```
-> Note: running this command will use the [Lighthouse config](https://github.com/backstage/backstage/blob/39ba2284d73885b7ca8290cb38e2b1e4d983c8d6/lighthouserc.js#L19-L34) so make sure to adjust it to your needs if needed.
+:::note Note
+Running this command will use the [Lighthouse config](https://github.com/backstage/backstage/blob/39ba2284d73885b7ca8290cb38e2b1e4d983c8d6/lighthouserc.js#L19-L34) so make sure to adjust it to your needs if needed.
+
+:::
### Use Lighthouse Github Action on your own repo
diff --git a/docs/assets/architecture-overview/package-architecture.drawio.svg b/docs/assets/architecture-overview/package-architecture.drawio.svg
index df8c0f8820..89fab2647d 100644
--- a/docs/assets/architecture-overview/package-architecture.drawio.svg
+++ b/docs/assets/architecture-overview/package-architecture.drawio.svg
@@ -1,69 +1,66 @@
-