Hi all, Is there a way to store the Pact-CLI EXECU...
# pact-broker
p
Hi all, Is there a way to store the Pact-CLI EXECUTABLE somewhere inside Gitlab instead of curling it everytime the job runs?
m
you can download the bundle and put it wherever you like
👆 1
You could also use the docker image, and then using standard docker caching mechanisms available to tools like gitlab
p
@Matt (pactflow.io / pact-js / pact-go) Started with docker image but then switched to executable as with docker we need to open a few firewalls which is a security concern. Right now, switched to the executable but still looking for a way to avoid using curl commands in my gitlab job
👍 1
m
Maybe take a look at something like https://docs.gitlab.com/ee/ci/caching/
đź‘€ 1
p
I want to keep the cli inside company network but also don't want to miss out on any latest updates made to the CLI. Like some sort of version control Any suggestions for what I can do here?
m
I think you’d be overcomplicating it
I would either 1. Pin the version and cache it (if it’s really a problem) 2. Download the latest and use that
🙌 1
In most pipelines, that step should take < 10s. It’s not really a big problem to overcomplicate with caching, version control etc. etc.
p
I agree with you. A question that came up during one of our meetings was "When thinking about the CLI curl install are there approaches you can use to mitigate a supply chain attack?"
👍 1
t
The binaries are exposed by pact-js, so you could install that with npm
đź‘€ 1
(later on, there will be pact-js-cli in npm too)
eg:
Copy code
npx -p @pact-foundation/pact-core pact-broker [other args]
m
“When thinking about the CLI curl install are there approaches you can use to mitigate a supply chain attack?”
on this question, I can think of a few, but we could probably think about how we as an ecosystem better guard against these things. I’ll raise at a #C05HCLA3C93 catch up
🙌 2
(It likely won’t get onto this week’s agenda)
y
“When thinking about the CLI curl install are there approaches you can use to mitigate a supply chain attack?”
1. Store a copy within your network. Some companies mirror npm with verdaccio so they have a private proxy 2. Checksum the download file, rather than using the checksum from the repo (as that could change, if say the GH repo or token is comprimised) a. when you download it the file, check it against your own checksum, and if it fails chuck it away 3. You can now use the main install script, to pin to a specific version. You can copy this script to your own codebase, and therefore know you know that the
install.sh
can’t be modified
I want to keep the cli inside company network but also don’t want to miss out on any latest updates made to the CLI.
Like some sort of version control
I would assume that with this increased eye on security that would review the contents of each version bump, to ensure that it doesn’t bring in any vulns. Do you do that with other software? What considerations do you security team recommended.
I want to keep the cli inside company network but also don’t want to miss out on any latest updates made to the CLI.
Like some sort of version control
Any suggestions for what I can do here?
switched to the executable but still looking for a way to avoid using curl commands in my gitlab job
This answer means you avoid needing to use curl each time in a job, and have a fixed, vendored bundle.
you can download the bundle and put it wherever you like
âś… 1
p
Thank you so much @Yousaf Nabi (pactflow.io) for the detailed explanation. For now, I put the latest pact-cli within JFrog (Linked with company) and instead of curling from Github, now curling from within company network. I will take a look into how I can avoid using curl. Thank you so much @Matt (pactflow.io / pact-js / pact-go) @Yousaf Nabi (pactflow.io) @Timothy Jones for you insights and help! Much appreciated 🙂 Really have learnt so much this past couple of months from you three!
🙌 3
t
You're so welcome!
🙏 1
y
Our pleasure @Prakhar Roy! It can be a challenge on both sides on the fence, so it is really awesome to hear a success story and especially how empowering learning a set of new skills can be! You should if you are so inclined think about writing up something about your journey, I am sure others would appreciate it!
❤️ 1