Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FY25 Q3 Dependabot Updates #505

Open
1 of 4 tasks
stdavis opened this issue Dec 23, 2024 · 3 comments
Open
1 of 4 tasks

FY25 Q3 Dependabot Updates #505

stdavis opened this issue Dec 23, 2024 · 3 comments
Assignees
Labels
type: ongoing This is an ongoing task that is completed multiple times type: technical debt A technical debt pay down task

Comments

@stdavis
Copy link
Member

stdavis commented Dec 23, 2024

Benefit

UGRC applications have dependencies that are constantly updating to add new features, improve performance, and patch security issues. Keeping applications current with dependencies improves our security posture and allows for easier future enhancements since the amount of breaking changes is smaller and more trivial.

Acceptance Criteria

Close out the org-wide dependency PRs and merge the pending release pr's

Notes

Insecure applications using deprecated services

Risks

The deployment breaks the application

Issue Reference

@stdavis stdavis converted this from a draft issue Dec 23, 2024
@steveoh steveoh added the type: technical debt A technical debt pay down task label Dec 23, 2024
@steveoh
Copy link
Member

steveoh commented Jan 1, 2025

terraform drift

I took care of 99% of this. I didn't apply every change because I wasn't sure the situation.

  • firebase updated it's free tier and the default storage bucket has moved. electrofishing will want this update but i wasn't sure if that was ok or not.
  • the gis website had some iam policies and workload federation changes i wasn't ready to apply
  • honeycomb is missing a backup and patching entry for the compute engine module
  • portal had some compute engine metadata drift i'm not sure about
  • roadkill had github federation diffs
  • uic has federation and monitoring drift
  • vista dev and prod had a lot of drift

I believe we will need to update the github federation as the release action updates have broken some runs. Here is a running list while creating dbot updates

@chriswnek chriswnek added the type: ongoing This is an ongoing task that is completed multiple times label Jan 9, 2025
@stdavis
Copy link
Member Author

stdavis commented Jan 10, 2025

@steveoh I'm going to need your help with honeycomb.

@stdavis
Copy link
Member Author

stdavis commented Jan 10, 2025

The roadkill fed diffs can't be handled until this issue is completed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: ongoing This is an ongoing task that is completed multiple times type: technical debt A technical debt pay down task
Projects
Status: No status
Development

No branches or pull requests

4 participants