Hi, First time interacting here, so please forgive...
# pact-broker
j
Hi, First time interacting here, so please forgive me if I'm in the wrong place and please point me to any documentation my question indicates I might have missed. Since I'm really interested in issues #88, #92, #93 of the pact-broker-docker repo I've done the upgrades locally in any places of the repo where I could find the version numbers. I've also run the build and test commands described in this page. And I've tried to poke around a bit in the GUI after starting the Pact-Broker up. To me, it seems to work just fine, but since I'm totally new to the product that might not mean a whole lot. The reason I want these issues fixed (and ideally also #94, which I still haven't had a look at) is that I need the security issues out of the way to be able to bring the Pact-Broker into my organisation for further testing and evaluation. Now for my questions: • Is there any other documentation to follow on how to contribute to the pact-broker-docker repo that I might have missed? • Are there any other test suites that should/could be run against an upgraded docker image? • Would it be helpful to you if I packaged my changes up into three pull-requests, one for each issue? • The issues got comments about a Jira-ticket being created. However, I haven't been able to find any link or hint to where that Jira-instance might be located, hence not been able to read up on any ongoing discussions or work on the issues. Any hints on this would be appreciated. Best Regards Jörgen
👋 1
m
Hello and thanks for raising the issues and your interest in helping - it’s much appreciated! This label, and the corresponding ticket is just a reference to a Smartbear team’s backlog. Basically, it means that we will pick up the work and get it done. We are just toying around with the best ways to track work across OSS and within our organisation to create visibility, so our apologies whilst the process is not documented - perhaps we can have the bot put more information in the response, so the next steps are clearer (cc @Ilia). I’ll wait for a maintainer to respond with more info, but I can’t see why a PR that upgrades the dependencies and makes the security issues go away wouldn’t be helpful. I think it might need to be in upstream repositories though.
👍 1
b
I'll accept any PRs that fix vulnerabilities. If they're not fixed, it's because I haven't had time to look at them. The tests that run in Github Actions are enough to ensure any changes are OK.
👍 2
j
Great. I'll put together some PRs over the next couple of days.
🙏 1
@Beth (pactflow.io/Pact Broker/pact-ruby) It seems the build/test-flows for my three PR:s (#98, #99 and #100) failed due to not being able to login to DockerHub
Run script/release-workflow/docker-login.sh
Error: Cannot perform an interactive login from a non TTY device
Error: Process completed with exit code 1.
A temporary failure? Could they be easily restarted?
b
It’s because secrets aren’t accessible in PRs.
I don’t know how to fix this, but it’s a massive problem across all the builds.
👍 1