Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade 7zip in ArchiveFilesV2 task #19842

Merged
merged 2 commits into from
May 7, 2024

Conversation

ismayilov-ismayil
Copy link
Contributor

@ismayilov-ismayil ismayilov-ismayil commented May 6, 2024

Task name: ArchiveFilesV2

Description: 7zip v19 has vulnerability, upgraded to v23

Documentation changes required: (Y/N) N

Added unit tests: (Y/N) N

Attached related issue: (Y/N) N

Checklist:

  • Task version was bumped - please check instruction how to do it
  • Checked that applied changes work as expected

Related WI: AB#2120588

@ismayilov-ismayil ismayilov-ismayil requested a review from a team as a code owner May 6, 2024 10:27
@ismayilov-ismayil ismayilov-ismayil added enhancement Area: ABTT Akvelon Build Tasks Team area of work Task: ArchiveFiles labels May 6, 2024
Copy link

azure-boards bot commented May 7, 2024

✅ Successfully linked to Azure Boards work item(s):

@ismayilov-ismayil ismayilov-ismayil merged commit f319813 into master May 7, 2024
11 checks passed
@synt-acks
Copy link

I would like to inform you that we have discovered an issue with the updated version in the compression process, while the extraction flow remains the same. Our analysis shows that the errors reported are linked to the recent changes made in this specific pull request. If a pipeline involves both compression and extraction processes, it may experience failures due to using different versions of 7zip simultaneously (v23.01 for compression and v19.00 for extraction). Thank you.

@HejdasGonnaHate
Copy link

I would like to inform you that we have discovered an issue with the updated version in the compression process, while the extraction flow remains the same. Our analysis shows that the errors reported are linked to the recent changes made in this specific pull request. If a pipeline involves both compression and extraction processes, it may experience failures due to using different versions of 7zip simultaneously (v23.01 for compression and v19.00 for extraction). Thank you.

Same issue for me. We had to revert back to ArchiveFilesV1 task which uses 7zip version 16.00

@synt-acks
Copy link

I would like to inform you that we have discovered an issue with the updated version in the compression process, while the extraction flow remains the same. Our analysis shows that the errors reported are linked to the recent changes made in this specific pull request. If a pipeline involves both compression and extraction processes, it may experience failures due to using different versions of 7zip simultaneously (v23.01 for compression and v19.00 for extraction). Thank you.

Same issue for me. We had to revert back to ArchiveFilesV1 task which uses 7zip version 16.00

We ultimately opted for using ".zip" files, which effectively solved our issue without the need to revert to a previous version of ArchiveFiles.

@wilbit
Copy link

wilbit commented May 27, 2024

I believe you have a high-urgency bug on your hands.
It seems you've updated ArchiveFiles task but didn't update ExtractFiles task (like here).
This broke some stages of our Release pipelines - hope you can release a fix soon!

@ismayilov-ismayil, @KonstantinTyukalov , @DergachevE , @kirill-ivlev FYI

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area: ABTT Akvelon Build Tasks Team area of work enhancement Task: ArchiveFiles
Projects
None yet
Development

Successfully merging this pull request may close these issues.

7 participants