Uh oh!
There was an error while loading. Please reload this page.
feat(search): add RW docs search collator module - #41
Merged
Conversation
yumikeforce-pushed
the
feat/search-collator
branch
from
April 10, 2026 04:34
4c26874 to
bbeb8beCompareAdd @rwdocs/backstage-plugin-search-backend-module-rw package that indexes RW documentation sites for Backstage search. Discovers entities via the catalog API, renders pages through @rwdocs/core, and emits search documents with configurable result type and schedule. Also extracts shared utilities (config reading, annotation parsing) into @rwdocs/backstage-plugin-rw-common and wires search plugins into the test instance. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
yumikeforce-pushed
the
feat/search-collator
branch
from
April 10, 2026 04:38
bbeb8be to
6b51c46CompareUh oh!
There was an error while loading. Please reload this page.
yumike added a commit
that referenced
this pull request
Aug 9, 2026
…161) Alerts #121 (high, GHSA-mwp4-54f8-5fhr / CVE-2026-69192 — Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass) and #41 (medium) were both unreachable: express-rate-limit 8.3.1 pins ip-address to exactly "10.1.0", and an exact pin admits no upgrade. express-rate-limit 8.5.1 relaxed that to "^10.2.0", and @backstage/backend- defaults already declares "^8.2.2", which accepts 8.6.2. Re-resolving it therefore lifts ip-address, and a second pass collapses the remaining socks copy ("^10.0.1", left at 10.1.0 by the first step) onto the same version: express-rate-limit 8.3.1 -> 8.6.2 ip-address 10.1.0 -> 10.4.0 (single copy, was two mid-way) express-rate-limit uses ip-address to parse client IPs for rate limiting, which is itself a trust boundary — an octal/decimal parsing discrepancy there is a rate-limit evasion primitive. It reaches us only through backend-defaults, a devDependency of rw-backend and a dependency of the private demo backend, so it is not in any published plugin's graph. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@rwdocs/backstage-plugin-search-backend-module-rwpackage that indexes RW documentation pages for Backstage searchRwDocsCollatorFactoryqueries the catalog for entities withrwdocs.org/refannotations, walks navigation trees, and callsrenderSearchDocument()to produce indexable documentsprojectDir) and S3 storage modes, configurable schedule, and custom location templatesTest Plan
make test)npx tsc --project tsconfig.json)@rwdocs/corev0.1.22🤖 Generated with Claude Code