Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

One of the dependencies is likely compromised - do not update #276

Closed
elbojoloco opened this issue Jan 10, 2022 · 4 comments · Fixed by #277
Closed

One of the dependencies is likely compromised - do not update #276

elbojoloco opened this issue Jan 10, 2022 · 4 comments · Fixed by #277

Comments

@elbojoloco
Copy link

Hello, this morning I tried updating to the latest version of soketi and the next thing I know my logs are full of garbage, GB's of garbage. The system storage filled up within seconds. I then stopped the process cleared the logs and downgraded to the previous version I was using (0.21.0) and yet again I am met with a full filesystem. I created a fresh ubuntu docker image, installed fresh node and @soketi/soketi version 0.26.0 and was met with the same issue.

Example output after the upgrade:
image

I think it would be a good habit to start hard locking top-level dependencies. That doesn't fully prevent issues like this but it could catch some. For now I would discourage anyone from updating this package.

@rennokki
Copy link
Member

Marak/colors.js#296

@rennokki
Copy link
Member

Assessing a bit the situation, this happens only if you fresh install or update the existing soketi version. Docker doesn't seem to have this issue as the dependencies were bundled at the given time when they worked.

I'm locking the dependencies for this. I'm never letting the dependencies flow freely again for production apps. 😨

@elbojoloco
Copy link
Author

Thank you for the fast action taken. All this drama around Marak's GH and packages...

@rennokki
Copy link
Member

It can happen to anyone. This remembered me of left-pad incident

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging a pull request may close this issue.

2 participants