RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Apr 2026Clear ×Project: BackstageClear ×
Backstagev1.50.4CI/CD & App DeliveryApr 29, 2026

A security maintenance release with fixes affecting three Backstage catalog packages. The affected packages are @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, and @backstage/plugin-catalog-unprocessed-entities.

Check if affected (1)

  • securitySecurity fixes for Backstage catalog packages

    Applies if you use any of @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, or @backstage/plugin-catalog-unprocessed-entities.

    This release contains security fixes for @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, and @backstage/plugin-catalog-unprocessed-entities.

Source
Backstagev1.50.3CI/CD & App DeliveryApr 22, 2026

This is a maintenance release for Backstage with ordinary correctness fixes. It addresses home page widget interactions, facets endpoint performance under filters or permissions, and external links under a non-root base path.

Source
Backstagev1.50.2CI/CD & App DeliveryApr 18, 2026

This release combines a new TechDocs sidebar styling capability with dependency updates and constraints. It also corrects an active tab indicator issue in Backstage UI.

Action needed (1)

  • breakingReact Aria dependency ranges constrained to patch-only updates

    React Aria dependency ranges are limited to patch-only updates in Backstage v1.50.2.

Source
Backstagev1.49.5CI/CD & App DeliveryApr 17, 2026

This release narrows the allowed React Aria dependency range to prevent unintended breaking updates. The version heading itself carries no operator-facing change.

Source
Backstagev1.47.4CI/CD & App DeliveryApr 17, 2026

This release changes the dependency range for React Aria dependencies to prevent unintended breaking changes from minor-version updates. The release version is not stated as increasing.

Source
Backstagev1.46.7CI/CD & App DeliveryApr 17, 2026

This release has no operator-facing change. Its dependency constraints narrow the React Aria version range to avoid breaking updates from minor releases.

Source
Backstagev1.45.6CI/CD & App DeliveryApr 17, 2026

This release updates the React Aria dependency version constraint to prevent breaking changes from entering through minor updates. It carries no operator-facing change.

Source
Backstagev1.50.1CI/CD & App DeliveryApr 15, 2026

A release with a breaking configuration-schema replacement, a repo startup correctness fix, and a React Aria dependency update. It changes configuration values used by existing extensions and blueprints and updates React Aria to v1.17.0 with monopackage imports.

Check if affected (1)

  • breakingConfiguration schema values replaced

    Applies if you use existing extensions and blueprints.

    This release replaces old configuration schema values from existing extensions and blueprints.

Source
Backstagev1.50.0CI/CD & App DeliveryApr 14, 2026

A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the .well-known/oauth-protected-resource URL, and includes broad correctness and dependency updates.

Action needed (4)

  • securityhighThe glob and rollup dependencies, upgraded

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions. rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe glob dependency, upgraded to v13

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.

  • securityThe rollup dependency, upgraded to v4.59+

    rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe .well-known/oauth-protected-resource URL

    The .well-known/oauth-protected-resource resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.

Check if affected (22)

  • breakingThe auth.omitIdentityTokenOwnershipClaim setting

    Applies if you do not configure auth.omitIdentityTokenOwnershipClaim.

    The auth.omitIdentityTokenOwnershipClaim setting now defaults to true. Backstage user tokens issued by the auth backend no longer contain the ent claim with the user's ownership entity refs.

  • breakingThe SignInResolverFactoryOptions type parameters

    Applies if you use SignInResolverFactoryOptions.

    The type parameters for SignInResolverFactoryOptions changed from <TAuthResult, TOptionsOutput, TOptionsInput> to <TAuthResult, TSchema extends ZodType>.

  • breakingThe catalog permission exports, removed

    Applies if you use CatalogPermissionRuleInput, CatalogPermissionExtensionPoint, or catalogPermissionExtensionPoint.

    The CatalogPermissionRuleInput, CatalogPermissionExtensionPoint, and catalogPermissionExtensionPoint exports were removed. coreServices.permissionsRegistry is used directly instead.

  • + 19 more on the release page

Plan ahead (6)

  • deprecatedThe show and showModal compatibility implementation, deprecated

    Applies if you use show or showModal.

    The deprecated show and showModal methods now use open internally with a Material UI dialog wrapper for backward compatibility.

  • deprecatedThe auth.omitIdentityTokenOwnershipClaim setting, deprecatedremoval date not announced

    Applies if you configure auth.omitIdentityTokenOwnershipClaim.

    The setting can still be set to false, but it will be removed entirely in a future release.

  • deprecatedThe config.schema callback format, deprecated

    Applies if you use config.schema.

    The old config.schema callback format is deprecated.

  • + 3 more on the release page
Source
Backstagev1.49.4CI/CD & App DeliveryApr 7, 2026

This is a patch release for Backstage with operator-relevant correctness fixes. The recorded note tail points to fixes for OAuth 2.0 metadata URL handling, the legacy-frontend-plugin template name, and permissions on the scaffolder plugin's /.well-known endpoint.

Source
Browse by month