Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump lodash from 4.17.15 to 4.17.19 to fix a security vulnerability. #1707

Merged
merged 1 commit into from
Jul 23, 2020

Conversation

roberthbailey
Copy link
Member

What type of PR is this?

Uncomment only one /kind <> line, hit enter to put that in a new line, and remove leading whitespace from that line:

/kind breaking
/kind bug

/kind cleanup

/kind documentation
/kind feature
/kind hotfix

What this PR does / Why we need it: This is a manually created version of #1706 without the version change to the agones sdk.

/assign @steven-supersolid

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 247ff26f-edb8-4796-b97c-60362d01d566

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@roberthbailey
Copy link
Member Author

It failed on the html test. Trying again.

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 0d6f8c39-c54b-4d25-8bca-83899113c6d7

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@roberthbailey
Copy link
Member Author

Another flake, this time in site-static (in the hugo tests): fatal error: concurrent map read and map write

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 556ce411-da1c-44f0-8689-4f74ba5e73ec

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@google-oss-robot
Copy link

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: aLekSer, roberthbailey, steven-supersolid

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: a0112ea8-7b7f-465d-abc3-0842d1ec35c8

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 7b85a1af-a409-4a14-926b-63c1b52ba756

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@aLekSer
Copy link
Collaborator

aLekSer commented Jul 22, 2020

Last failure was caused by error on wget from cmake.org:

Step 9/18 : RUN wget -q https://cmake.org/files/v3.14/cmake-3.14.1-Linux-x86_64.sh
 ---> Running in 79f1b3968f34
includes/sdk.mk:106: recipe for target 'build-build-sdk-image' failed
make[3]: Leaving directory '/workspace/build'
The command '/bin/sh -c wget -q https://cmake.org/files/v3.14/cmake-3.14.1-Linux-x86_64.sh' returned a non-zero code: 4
make[3]: *** [build-build-sdk-image] Error 4
make[2]: *** [ensure-image] Error 2
includes/build-image.mk:54: recipe for target 'ensure-image' failed
make[1]: *** [ensure-build-sdk-image] Error 2
includes/sdk.mk:123: recipe for target 'ensure-build-sdk-image' failed
make: *** [run-sdk-conformance-test-rust] Error 2
make: *** Waiting for unfinished jobs....
includes/sdk.mk:168: recipe for target 'run-sdk-conformance-test-rust' failed

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 90f74226-204b-4072-ab64-618a91e369db

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@google-oss-robot
Copy link

New changes are detected. LGTM label has been removed.

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 89c02bde-3911-4063-a591-c1ff65b494f2

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: dd946106-ba3b-4dad-9c96-ef7f38492daf

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 1faa4435-8617-44fc-8e70-16692500af8a

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@aLekSer
Copy link
Collaborator

aLekSer commented Jul 23, 2020

Error with lodash@4.17.19 exctracting:

npm ERR! code EINTEGRITY
npm ERR! Verification failed while extracting lodash@4.17.19:
npm ERR! Verification failed while extracting lodash@4.17.19:
npm ERR! sha512-JNvd8XER9GQX0v2qJgsaN/mzFCNA5BRe/j8JN9d+tWyGLSodKQHKFicdwNYzWwI3wjRnaKPsGj1XkBjx/F96DQ== integrity checksum failed when using sha512: wanted sha512-JNvd8XER9GQX0v2qJgsaN/mzFCNA5BRe/j8JN9d+tWyGLSodKQHKFicdwNYzWwI3wjRnaKPsGj1XkBjx/F96DQ== but got sha512-8xOcRHvCjnocdS5cpwXQXVzmmh5e5+saE2QGoeQmbKmRS6J3VQppPOIt0MnmE+4xlZoumy0GPG0D0MVIQbNA1A==. (314170 bytes)
=== RUN   TestAlphaGetAndSetPlayerCapacity

@roberthbailey
Copy link
Member Author

Interesting. That was the sha that was set by dependabot...

@roberthbailey
Copy link
Member Author

The sha512-8xOcRHvCjnoc... hash is from 4.17.15.

@agones-bot
Copy link
Collaborator

Build Failed 😱

Build Id: 0e98661c-f98d-44de-83e1-b50fae7f1248

To get permission to view the Cloud Build view, join the agones-discuss Google Group.

@roberthbailey
Copy link
Member Author

Looks like I made a typo, which is why it was still pulling the old tar.gz file. Should be fixed now. Thanks for catching this @aLekSer.

@agones-bot
Copy link
Collaborator

Build Succeeded 👏

Build Id: bb87ecaa-4881-4fbb-9ee9-246edb11262c

The following development artifacts have been built, and will exist for the next 30 days:

A preview of the website (the last 30 builds are retained):

To install this version:

  • git fetch https://github.com/googleforgames/agones.git pull/1707/head:pr_1707 && git checkout pr_1707
  • helm install ./install/helm/agones --namespace agones-system --name agones --set agones.image.tag=1.8.0-9272028

@roberthbailey roberthbailey merged commit ff6ec62 into googleforgames:master Jul 23, 2020
@markmandel markmandel added this to the 1.8.0 milestone Aug 11, 2020
@markmandel markmandel added the area/security Issues pertaining to security label Aug 11, 2020
@roberthbailey roberthbailey deleted the lodash-4-17-19 branch August 24, 2020 23:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants