Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

edx-internal kube-lint check was failing on new jq-action v2.3.0; pinned to 2.2.1 #193

Closed
timmc-edx opened this issue Feb 15, 2023 · 1 comment
Assignees
Labels

Comments

@timmc-edx
Copy link
Member

timmc-edx commented Feb 15, 2023

Summary: I've pinned an action dependency in edx-internal to a commit, but it needs followup.

This morning the kube-lint check in edx-internal started failing: https://github.com/edx/edx-internal/actions/runs/4184151642/workflow (private link)

This is because we had a dependency on sergeysova/jq-action@v2 which released v2.3.0 this week; the previous v2 had been v2.2.1. The intervening change was sergeysova/jq-action#9 which uses GitHub's new output-file rather than the deprecated set-output. It appears to be breaking on multiline outputs, and I'm not clear on whether that's kube-lint's or jq-action's fault. (There does seem to be more difficulty with multi-line outputs in the new output-file approach, unfortunately.)

In the meantime I've pinned jq-action to a commit, so I'm filing this ticket for followup so it doesn't stay pinned forever. I also don't know what SRE wants to do with respect to action pinning in general. I would recommend pinning to commits, for security, but that may conflict with other needs.

@timmc-edx timmc-edx added the esre label Feb 15, 2023
@rgraber rgraber added the backlog To be put on a team's backlog or wishlist label Feb 17, 2023
@rgraber rgraber removed the backlog To be put on a team's backlog or wishlist label Mar 2, 2023
@rgraber rgraber self-assigned this Mar 2, 2023
@rgraber
Copy link
Contributor

rgraber commented Mar 2, 2023

Closing this as the immediate issue has been resolved https://github.com/edx/edx-internal/pull/7907 and SRE has at least been made aware of the action-pinning issue.

@rgraber rgraber closed this as completed Mar 2, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Archived in project
Development

No branches or pull requests

2 participants