Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FY25 Q3 Dependabot Updates #505

Closed
2 of 4 tasks
stdavis opened this issue Dec 23, 2024 · 5 comments
Closed
2 of 4 tasks

FY25 Q3 Dependabot Updates #505

stdavis opened this issue Dec 23, 2024 · 5 comments
Assignees
Labels
type: ongoing This is an ongoing task that is completed multiple times type: technical debt A technical debt pay down task

Comments

@stdavis
Copy link
Member

stdavis commented Dec 23, 2024

Benefit

UGRC applications have dependencies that are constantly updating to add new features, improve performance, and patch security issues. Keeping applications current with dependencies improves our security posture and allows for easier future enhancements since the amount of breaking changes is smaller and more trivial.

Acceptance Criteria

Close out the org-wide dependency PRs and merge the pending release pr's

Notes

Insecure applications using deprecated services

Risks

The deployment breaks the application

Issue Reference

@stdavis stdavis converted this from a draft issue Dec 23, 2024
@steveoh steveoh added the type: technical debt A technical debt pay down task label Dec 23, 2024
@steveoh
Copy link
Member

steveoh commented Jan 1, 2025

terraform drift

I took care of 99% of this. I didn't apply every change because I wasn't sure the situation.

  • firebase updated it's free tier and the default storage bucket has moved. electrofishing will want this update but i wasn't sure if that was ok or not.
  • the gis website had some iam policies and workload federation changes i wasn't ready to apply
  • honeycomb is missing a backup and patching entry for the compute engine module
  • portal had some compute engine metadata drift i'm not sure about
  • roadkill had github federation diffs
  • uic has federation and monitoring drift
  • vista dev and prod had a lot of drift

I believe we will need to update the github federation as the release action updates have broken some runs. Here is a running list while creating dbot updates

@chriswnek chriswnek added the type: ongoing This is an ongoing task that is completed multiple times label Jan 9, 2025
@stdavis
Copy link
Member Author

stdavis commented Jan 10, 2025

@steveoh I'm going to need your help with honeycomb.

@stdavis
Copy link
Member Author

stdavis commented Jan 10, 2025

The roadkill fed diffs can't be handled until this issue is completed.

@steveoh
Copy link
Member

steveoh commented Jan 14, 2025

FY25Q3 Sprint 1 Notes

  • We're down to 4 dependency pr's.
    • I'm working on wri and the api separately.
    • I assume scott's got the roadkill mobile one on his radar and the dabs one is 🤷.
  • We've got some release pr's to work through but that should be quick.
  • We got most of the terraform drift and will work through the checklist above.
  • Scott added a few github repo's to tf 👍🏼.
  • We didn't have all the elcids for the cloud resources but scott was able to add one to two projects 👍🏼

@steveoh
Copy link
Member

steveoh commented Jan 23, 2025

FY25Q3 Sprint 2 Notes

We have a few fallout items to resolve with supervisor, uic but we can track those in separate issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: ongoing This is an ongoing task that is completed multiple times type: technical debt A technical debt pay down task
Projects
Status: Done
Development

No branches or pull requests

4 participants