Vendor golang-* build dependencies

Bug #1896246 reported by Balint Reczey
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
google-guest-agent (Ubuntu)
Fix Released
Undecided
Unassigned
google-osconfig-agent (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

The packages are agents for the Google Cloud Platform and require prompt updates including SRUs to ensure proper integration of Ubuntu Instances to the cloud infrastructure.

The Go build dependencies include several Go projects which don't have fully coordinated release schedules and this makes upgrading them without breaking other packaged software hard and sometimes impossible.

To work around the problem of upgrading all related Go packages in the archive just for the cloud-specific agents and to make SRUs less risky it was decided to vendorize the Go build dependencies using versions used by upstream.

Balint Reczey (rbalint)
summary: - Vendor dependencies
+ Vendor golang-* build dependencies
Balint Reczey (rbalint)
Changed in google-guest-agent (Ubuntu):
status: New → Fix Released
Balint Reczey (rbalint)
description: updated
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package google-osconfig-agent - 20200625.00-0ubuntu2

---------------
google-osconfig-agent (20200625.00-0ubuntu2) groovy; urgency=medium

  * debian/extra/vendor/*: Add vendored module sources (LP: #1896246)
  * debian/control: Drop unused Go build dependencies

 -- Balint Reczey <email address hidden> Wed, 30 Sep 2020 16:14:25 +0200

Changed in google-osconfig-agent (Ubuntu):
status: New → Fix Released
Revision history for this message
Steve Beattie (sbeattie) wrote :

For the record, the Ubuntu Security team signs off on the plan to vendor the golang dependencies for the google-guest-agent and google-oslogin-agent packages as they go through the MIR process, for the reasons given above.

Thanks!

Revision history for this message
Christian Ehrhardt  (paelzer) wrote :

Thanks for that update Steve, worth to have a log of that to refer to.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.