Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

kyma-cli: update sha256, add livecheck #157653

Merged

Conversation

samford
Copy link
Member

@samford samford commented Dec 18, 2023

  • Have you followed the guidelines for contributing?
  • Have you ensured that your commits follow the commit style guide?
  • Have you checked that there aren't other open pull requests for the same formula update/change?
  • Have you built your formula locally with HOMEBREW_NO_INSTALL_FROM_API=1 brew install --build-from-source <formula>, where <formula> is the name of the formula you're submitting?
  • Is your test running fine brew test <formula>, where <formula> is the name of the formula you're submitting?
  • Does your build pass brew audit --strict <formula> (after doing HOMEBREW_NO_INSTALL_FROM_API=1 brew install --build-from-source <formula>)? If this is a new formula, does it pass brew audit --new <formula>?

kyma-cli was recently updated to 2.20.1 (#157340) but yesterday livecheck was reporting 2.20.0 as the newest version (from the Git tags), so the 2.20.1 tag was seemingly removed and re-created between the formula update and now. The GitHub release for 2.20.1 was only created a few hours ago (i.e., a few days after the formula was updated).

I've asked upstream to confirm the checksum change (kyma-project/cli#1888), so I've set this as a draft until I hear back. The only commit between now and then was to update the kyma-incubator/reconciler version in go.mod (kyma-project/cli@73bea7c) but we will seemingly need new bottles to account for that. I'm not sure how big of a change that is but this may need a revision bump.

Past that, this PR adds a livecheck block that uses the GithubLatest strategy, as it appears that upstream uses GitHub releases to indicate when a version is actually released. This will help to ensure that we don't run into this issue again, if upstream re-tags a version before the release is created.

@github-actions github-actions bot added the go Go use is a significant feature of the PR or issue label Dec 18, 2023
@samford samford added livecheck Issues or PRs related to livecheck and removed go Go use is a significant feature of the PR or issue labels Dec 18, 2023
@samford samford marked this pull request as ready for review December 21, 2023 17:26
@samford samford force-pushed the kyma-cli-update-sha256-add-livecheck branch from 2b3b138 to 2fee85c Compare December 21, 2023 17:40
@github-actions github-actions bot added the go Go use is a significant feature of the PR or issue label Dec 21, 2023
@chenrui333 chenrui333 added upstream issue An upstream issue report is needed checksum mismatch SHA-256 doesn't match the download labels Dec 21, 2023
@chenrui333
Copy link
Member

@samford
Copy link
Member Author

samford commented Dec 22, 2023

Upstream confirmed the re-tag in kyma-project/cli#1888 (comment)

How do we deal with the stable sha256 changed without the url/version also changing; please create an issue upstream to rule out malicious circumstances and to find out why the file changed audit failure?

@chenrui333 chenrui333 added the CI-no-fail-fast Continue CI tests despite failing GitHub Actions matrix builds. label Dec 22, 2023
@chenrui333 chenrui333 added the ready to merge PR can be merged once CI is green label Dec 22, 2023
Copy link
Contributor

@github-actions github-actions bot added the CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. label Dec 22, 2023
@BrewTestBot BrewTestBot added this pull request to the merge queue Dec 22, 2023
Merged via the queue into Homebrew:master with commit 1a93d34 Dec 22, 2023
12 checks passed
@samford samford deleted the kyma-cli-update-sha256-add-livecheck branch December 22, 2023 18:04
@stefanb stefanb mentioned this pull request Jan 14, 2024
@github-actions github-actions bot added the outdated PR was locked due to age label Jan 22, 2024
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jan 22, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
checksum mismatch SHA-256 doesn't match the download CI-no-fail-fast Continue CI tests despite failing GitHub Actions matrix builds. CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. go Go use is a significant feature of the PR or issue livecheck Issues or PRs related to livecheck outdated PR was locked due to age ready to merge PR can be merged once CI is green upstream issue An upstream issue report is needed
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants