Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SecureDrop core packages for 1.4.0-rc1 #44

Merged
merged 1 commit into from
Jun 8, 2020
Merged

Conversation

conorsch
Copy link
Contributor

@conorsch conorsch commented Jun 5, 2020

Status

Ready for review

Towards freedomofpress/securedrop#5289

Build logs available here: freedomofpress/build-logs@dd2aade

Description of changes

Debian packages for 1.4.0-rc1. Note that builder security updates check is failing due to out-of-date image. The builder image has not yet been updated accordingly, but should be before rc2.

Checklist

emkll
emkll previously requested changes Jun 5, 2020
Copy link
Contributor

@emkll emkll left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Based on the build logs, it appears the packages including here are built on the commit immediately following the 1.3.0 release (when 1.4.0-rc1 was updated) freedomofpress/securedrop@148392a

I would have expected, that the packages be built on (or close to) the following commit hash, which includes changes introduced after 1.3.0:
freedomofpress/securedrop@efd1121

@conorsch conorsch force-pushed the securedrop-1.4.0-rc1 branch from 5139f26 to 25ada24 Compare June 8, 2020 15:55
@conorsch
Copy link
Contributor Author

conorsch commented Jun 8, 2020

You're absolutely correct, @emkll, the packages were built from the wrong commit. Resolved and rebuilt.

Ready for re-review.

@sssoleileraaa sssoleileraaa self-requested a review June 8, 2020 16:42
Copy link
Contributor

@sssoleileraaa sssoleileraaa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✔️ confirmed https://github.com/freedomofpress/securedrop/releases/tag/1.4.0-rc1 points to the expected changelog commit: freedomofpress/securedrop@efd1121
✔️ confirmed deb checksums match build logs (see inline comments at the end of this diff: freedomofpress/build-logs@76c5242)

Copy link
Contributor

@redshiftzero redshiftzero left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • confirmed build commit hash is efd1121e14805e324bd719c3fc51fb69805cb960, 1.4.0-rc1 tag is correct
  • hashes of added packages match build logs

LGTM!

@redshiftzero redshiftzero dismissed emkll’s stale review June 8, 2020 17:29

Dismissing, review comments have been addressed. Thanks emkll

@redshiftzero redshiftzero merged commit e1e241b into master Jun 8, 2020
@redshiftzero redshiftzero deleted the securedrop-1.4.0-rc1 branch June 8, 2020 18:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants