Tuesday, 2025-09-09

-@gerrit:opendev.org- Simon Westphahl proposed: [zuul/zuul] 959428: Fix provider quota calculation https://review.opendev.org/c/zuul/zuul/+/95942809:20
-@gerrit:opendev.org- Simon Westphahl proposed: [zuul/zuul] 959428: Fix provider quota calculation https://review.opendev.org/c/zuul/zuul/+/95942809:25
-@gerrit:opendev.org- Benjamin Schanzel proposed on behalf of Tobias Henkel: [zuul/nodepool] 775797: Log openstack requests https://review.opendev.org/c/zuul/nodepool/+/77579709:27
-@gerrit:opendev.org- Simon Westphahl proposed: [zuul/zuul] 959428: Fix provider quota calculation https://review.opendev.org/c/zuul/zuul/+/95942809:39
-@gerrit:opendev.org- Simon Westphahl proposed: [zuul/zuul] 959428: Fix provider quota calculation https://review.opendev.org/c/zuul/zuul/+/95942810:36
-@gerrit:opendev.org- Tobias Henkel proposed: [zuul/zuul-jobs] 960275: Allow fetching zookeeper from local mirrors https://review.opendev.org/c/zuul/zuul-jobs/+/96027515:00
@clarkb:matrix.orgI removed my WIP vote on https://review.opendev.org/c/zuul/zuul-jobs/+/958605 as today is the day I announced this change would merge. Reviews welcome to make that happen on time15:32
@jim:acmegating.comit's got a +2 from me... i didn't immediately +w but feel free after you reckon it's been sufficient time15:45
@clarkb:matrix.orgack I can probably give it a couple of hours this morning15:46
@fajfer:reszka.orgwhat timezone are you guys in?16:05
@clarkb:matrix.orgI'm in pacific time UTC -7 now but will be -8 in a month or so16:07
@clarkb:matrix.orgapparently we don't change off of DST until November 216:07
@fajfer:reszka.orgoh, good morning then:)16:08
@fajfer:reszka.orgI'm asking since I have a change that is scheduled for merging tomorrow16:08
@fajfer:reszka.organd another one where I managed to bump React dependencies, however it requires another look to simplify package.json and clean it up, at least it passes all tests16:09
@fajfer:reszka.orgbut I'm only mentioning this since I saw you, Clark, tinkering with zuul-web16:09
@fajfer:reszka.org(the cleanup is something I will do so no worries lol)16:12
@clarkb:matrix.orgre changing dependencies we should be extra cautious that https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised didn't sneak in via those updates. I suspect not as the window of time those packages were available is small16:13
@clarkb:matrix.organd at this point they should all be unavailable too16:13
@fajfer:reszka.orgit was done few weeks ago already16:13
@clarkb:matrix.orgthat said its probably worth waiting for a bit to ensure that others don't pop up as apparently duckdb was also hit16:13
@clarkb:matrix.orgack16:13
@fajfer:reszka.orgwe're using such old packages that I don't think they're vector of attack for cybercriminals XD16:14
@jangutter:matrix.orgfajfer: I have a saying: the longer you defer to update, the more bugs you get to classify as features. "remote root as a service".19:01
@jangutter:matrix.orgWe have _so many features_19:01
@fajfer:reszka.orgI'm afraid migration from current framework is inevitable because it's long deprecated, the old packages are just the tip of the iceberg and they probably block it in the current state but I didn't really research that and I'm not comfortable picking new framework for Zuul19:05
@jangutter:matrix.orgOh, Zuul is brand new from our point of view... 19:06
@fajfer:reszka.orgI mean the frontend19:06
@fajfer:reszka.orgit's just a small part19:06
@fajfer:reszka.orgzuul-web19:07
@jangutter:matrix.orgYeah, it does get hilariously tricky with frontend stuff. But the attack surface for zuul-web is very different from something like a site where people can change stuff. 19:11
@jangutter:matrix.orgIt's not a free pass though. But I do gawk at the sheer amount of deps pulled in during a build. 19:12
@jangutter:matrix.orgBiggest worry is a set of zero days with privilege escalation of course 19:13
@fungicide:matrix.orgi also feel like zuul's dashboard has an insane number of js dependencies, but since i'm not a js developer it's probably just my lack of perspective. maybe thousands of dependencies is the norm19:15
@jangutter:matrix.orgI mean, after reading about left-pad I think it's the norm. 19:16
-@gerrit:opendev.org- Zuul merged on behalf of Clark Boylan: [zuul/zuul-jobs] 958605: Default configure_mirrors_extra_repos to False in configure-mirrors https://review.opendev.org/c/zuul/zuul-jobs/+/95860519:40

Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!