-
Notifications
You must be signed in to change notification settings - Fork 284
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade rouge #383
Upgrade rouge #383
Conversation
Can someone merge this? In rouge 2.0.7 are vulnerabilities. |
@supermarin Hello! can you merge this? |
Hey @AndriiZakhliupanyi, I've been long gone from this project and it's been in hands of @KrauseFx and others. I don't think anyone should be using xcpretty anymore since @KrauseFx is there any interest into finding maintainers or should this project be archived & steered off? |
@supermarin @KrauseFx fastlane uses xcpretty https://github.com/fastlane/fastlane/blob/master/Gemfile.lock#L42 |
Good point - @joshdholtz any interest of either removing xcpretty from Fastlane or maintaining it? |
@joshdholtz @supermarin hi, do you have any news? |
@AndriiZakhliupanyi I don't even have write access to merge this, sorry about that. @joshdholtz @KrauseFx another ping |
Oooops sorry! Was hard out with Covid during those initial pings. I'm pretty sure that I removed We support I can take a look later tomorrow when I have some more free time! |
@joshdholtz thanks! feel free to merge this one since you have commit access |
@joshdholtz hi! do you have any news? |
hi @joshdholtz, fastlane definitely still depends on xcpretty (see here), any updates on removing it? |
Sorry to bother again, but this issue is now over one year old and still active. Although fastlane also uses xcbeautify like you said, it's still also depending on xcpretty here. So please either fully remove xcpretty from fastlane or merge the rouge update here and then update to latest xcpretty on fastlane. Otherwise any good security review in a build pipeline will fail and prevent iOS app releases using the (compromised) fastlane at all: |
I went ahead and merged this PR. This allows you to point to the latest However, this still requires some work on @fastlane's end to remove |
Thx Felix! Thanks to the rouge update it's now up to @joshdholtz to either just still use the (now no longer vulnerable) xcpretty or remove it later. @KrauseFx Thanks for your work in any case ;-) |
Due to Google having stopped supporting projects like fastlane financially or through contributions, and not doing a proper handover, there is no structured approach right now. AFAIK we're happy to add you as a contributor to I'm full-time working on ContextSDK, and just happen to still have push access as a backup. |
Thanks for the clarification. For sure we can (and should) help contributing as much as we can. So feel free to add this account to the xcpretty project, so we could at least create a new version and help updating it within fastlane itself. |
closes #339
I upgraded rouge to latest version.
All checks passed locally: