Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Refresh certificates #52

Merged
merged 1 commit into from Nov 22, 2023
Merged

Refresh certificates #52

merged 1 commit into from Nov 22, 2023

Conversation

djc
Copy link
Member

@djc djc commented Nov 22, 2023

I think we should backport this to a 0.25.3 release?

@djc djc requested a review from cpu November 22, 2023 16:32
@cpu
Copy link
Member

cpu commented Nov 22, 2023

I'm confused; why hasn't the CI task failed from an uncommitted diff based on upstream changes? 🤔

@djc djc marked this pull request as ready for review November 22, 2023 16:44
@djc
Copy link
Member Author

djc commented Nov 22, 2023

Not sure -- maybe they happened today? Or the workflow got disabled because there was no activity for 60 days?

@cpu
Copy link
Member

cpu commented Nov 22, 2023

Not sure -- maybe they happened today? Or the workflow got disabled because there was no activity for 60 days?

It looks like a scheduled run ran yesterday without error, so maybe it was just a recent change. I've been making a point to check this repo's action history to make sure it hasn't been silently failing. I'll see if I can figure something out conclusively.

I think we should backport this to a 0.25.3 release?

SGTM. I can do that.

@djc djc merged commit 54c63b9 into main Nov 22, 2023
2 checks passed
@djc djc deleted the update-certs branch November 22, 2023 16:49
@djc
Copy link
Member Author

djc commented Nov 22, 2023

SGTM. I can do that.

Thanks!

@cpu
Copy link
Member

cpu commented Nov 22, 2023

It looks like a scheduled run ran yesterday without error, so maybe it was just a recent change.

I found the relevant tickets in the Mozilla bug tracker and linked to them in the rel-0.25 backport release notes: #53

I can't find a source of historical data for the CCADB CSV reports but given the timestamps of the bugs being closed and action being taken to update NSS within the last ~7 days I think the CCADB update likely happened ~today/yesterday and we missed it with yesterday's scheduled run. When I ran the tooling locally before this branch landed it picked up the changes and failed the test as expected.

@cpu
Copy link
Member

cpu commented Nov 22, 2023

Further evidence things are working correctly: Firefox 121 is the first version with these updates and it was released 2023-11-21 so that would also coincide with ~yesterday being the date https://ccadb-public.secure.force.com/mozilla/IncludedCACertificateReportPEMCSV was updated.

Edit: Last confirmation: my fork wasn't sync'd and today's scheduled task failed.

@cpu cpu mentioned this pull request Nov 22, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants