Skip to content

Commit 9ff5ddb

Browse files
authored
feat!: upgrade ci, image, packages, audit (#202)
* feat!: upgrade ci, image, packages, audit * chore: lint * chore(snapshot): 12.0.0-snapshot.0 * chore: audit * chore(snapshot): 12.0.0-snapshot.1
1 parent c43e3c0 commit 9ff5ddb

11 files changed

Lines changed: 21337 additions & 6857 deletions

File tree

‎.circleci/config.yml‎

Lines changed: 386 additions & 84 deletions
Large diffs are not rendered by default.

‎.ncurc.yaml‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
## Add a TODO comment indicating the reason for each rejected dependency upgrade added to this list, and what should be done to resolve it (i.e. handle it through a story, etc).
2+
reject: []

‎.nvmrc‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
16.15.0

‎CODEOWNERS‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
# These owners will be the default owners for everything in
2+
# the repo. Unless a later match takes precedence,
3+
# The below users will be requested for
4+
# review when someone opens a pull request.
5+
* @mdebarros @elnyry-sam-k @vijayg10

‎Dockerfile‎

Lines changed: 14 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -1,36 +1,33 @@
1-
FROM node:12.16.1-alpine as builder
2-
USER root
3-
4-
WORKDIR /opt/email-notifier
1+
FROM node:16.15.0-alpine as builder
2+
WORKDIR /opt/app
53

64
RUN apk --no-cache add git
7-
RUN apk add --no-cache -t build-dependencies make gcc g++ python libtool autoconf automake \
5+
RUN apk add --no-cache -t build-dependencies make gcc g++ python3 libtool libressl-dev openssl-dev autoconf automake \
86
&& cd $(npm root -g)/npm \
97
&& npm config set unsafe-perm true \
108
&& npm install -g node-gyp
119

12-
COPY package.json package-lock.json* /opt/email-notifier/
13-
RUN npm install
14-
15-
COPY src /opt/email-notifier/src
16-
COPY config /opt/email-notifier/config
17-
COPY app.js /opt/email-notifier/
18-
COPY templates /opt/email-notifier/templates
10+
COPY package.json package-lock.json* /opt/app/
11+
RUN npm ci
1912

20-
FROM node:12.16.1-alpine
13+
COPY src /opt/app/src
14+
COPY config /opt/app/config
15+
COPY app.js /opt/app/
16+
COPY templates /opt/app/templates
2117

22-
WORKDIR /opt/email-notifier
18+
FROM node:16.15.0-alpine
19+
WORKDIR /opt/app
2320

2421
# Create empty log file & link stdout to the application log file
2522
RUN mkdir ./logs && touch ./logs/combined.log
2623
RUN ln -sf /dev/stdout ./logs/combined.log
2724

2825
# Create a non-root user: ml-user
29-
RUN adduser -D ml-user
26+
RUN adduser -D ml-user
3027
USER ml-user
3128

32-
COPY --chown=ml-user --from=builder /opt/email-notifier .
29+
COPY --chown=ml-user --from=builder /opt/app .
3330
RUN npm prune --production
3431

3532
EXPOSE 3081
36-
CMD node app.js
33+
CMD node app.js

‎README.md‎

Lines changed: 32 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,9 @@
44
[![Docker pulls](https://img.shields.io/docker/pulls/mojaloop/email-notifier.svg?style=flat)](https://hub.docker.com/r/mojaloop/email-notifier)
55
[![CircleCI](https://circleci.com/gh/mojaloop/email-notifier.svg?style=svg)](https://app.circleci.com/pipelines/github/mojaloop/email-notifier)
66

7-
Email Notifier is a stand-alone email service that consumes messages from kafka topic, produced by the central-event-processor service.
8-
The central-event-processor repo is available [here](https://github.com/mojaloop/central-event-processor/tree/master)
9-
The email-notifier flow is available [here](https://github.com/mojaloop/central-event-processor/tree/master#Notifierflowseparateservice)
7+
Email Notifier is a stand-alone email service that consumes messages from kafka topic, produced by the central-event-processor service.
8+
The central-event-processor repo is available [here](https://github.com/mojaloop/central-event-processor/tree/master)
9+
The email-notifier flow is available [here](https://github.com/mojaloop/central-event-processor/tree/master#Notifierflowseparateservice)
1010

1111
## Contents
1212

@@ -45,7 +45,7 @@ For configuring email:
4545
}
4646
```
4747

48-
Those can be passed as the following environment variables:
48+
Those can be passed as the following environment variables:
4949

5050
```json
5151
{
@@ -63,7 +63,7 @@ Those can be passed as the following environment variables:
6363
}
6464
}
6565
}
66-
}
66+
}
6767
```
6868

6969
## Troubleshooting `npm install` on MacOS
@@ -76,36 +76,59 @@ npm install
7676
clang: error: linker command failed with exit code 1
7777
```
7878

79-
add the following environment variables:
79+
add the following environment variables:
8080
```bash
8181
export CPPFLAGS=-I/usr/local/opt/openssl/include
8282
export LDFLAGS=-L/usr/local/opt/openssl/lib
8383
```
8484

85-
8685
## Auditing Dependencies
8786

8887
We use `npm-audit-resolver` along with `npm audit` to check dependencies for node vulnerabilities, and keep track of resolved dependencies with an `audit-resolve.json` file.
8988

9089
To start a new resolution process, run:
90+
9191
```bash
9292
npm run audit:resolve
9393
```
9494

9595
You can then check to see if the CI will pass based on the current dependencies with:
96+
9697
```bash
9798
npm run audit:check
9899
```
99100

100-
And commit the changed `audit-resolv.json` to ensure that CircleCI will build correctly.
101-
101+
And commit the changed `audit-resolve.json` to ensure that CircleCI will build correctly.
102102
## Container Scans
103103

104104
As part of our CI/CD process, we use anchore-cli to scan our built docker container for vulnerabilities upon release.
105105

106106
If you find your release builds are failing, refer to the [container scanning](https://github.com/mojaloop/ci-config#container-scanning) in our shared Mojaloop CI config repo. There is a good chance you simply need to update the `mojaloop-policy-generator.js` file and re-run the circleci workflow.
107107

108108
For more information on anchore and anchore-cli, refer to:
109+
109110
- [Anchore CLI](https://github.com/anchore/anchore-cli)
110111
- [Circle Orb Registry](https://circleci.com/orbs/registry/orb/anchore/anchore-engine)
111112

113+
## Automated Releases
114+
115+
As part of our CI/CD process, we use a combination of CircleCI, standard-version
116+
npm package and github-release CircleCI orb to automatically trigger our releases
117+
and image builds. This process essentially mimics a manual tag and release.
118+
On a merge to master, CircleCI is configured to use the mojaloopci github account
119+
to push the latest generated CHANGELOG and package version number.
120+
Once those changes are pushed, CircleCI will pull the updated master, tag and
121+
push a release triggering another subsequent build that also publishes a docker image.
122+
### Potential problems
123+
* There is a case where the merge to master workflow will resolve successfully, triggering
124+
a release. Then that tagged release workflow subsequently failing due to the image scan,
125+
audit check, vulnerability check or other "live" checks.
126+
This will leave master without an associated published build. Fixes that require
127+
a new merge will essentially cause a skip in version number or require a clean up
128+
of the master branch to the commit before the CHANGELOG and bump.
129+
This may be resolved by relying solely on the previous checks of the
130+
merge to master workflow to assume that our tagged release is of sound quality.
131+
We are still mulling over this solution since catching bugs/vulnerabilities/etc earlier
132+
is a boon.
133+
* It is unknown if a race condition might occur with multiple merges with master in
134+
quick succession, but this is a suspected edge case.

‎audit-resolve.json‎

Lines changed: 95 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -103,6 +103,101 @@
103103
"1771|@mojaloop/event-sdk>grpc>@mapbox/node-pre-gyp>tar": {
104104
"decision": "fix",
105105
"madeAt": 1629388377187
106+
},
107+
"1075703|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs": {
108+
"decision": "ignore",
109+
"madeAt": 1658272999117,
110+
"expiresAt": 1660864995559
111+
},
112+
"1075703|@mojaloop/event-sdk>grpc>protobufjs": {
113+
"decision": "ignore",
114+
"madeAt": 1658272999117,
115+
"expiresAt": 1660864995559
116+
},
117+
"1075704|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs": {
118+
"decision": "ignore",
119+
"madeAt": 1658272999914,
120+
"expiresAt": 1660864995559
121+
},
122+
"1075704|@mojaloop/event-sdk>grpc>protobufjs": {
123+
"decision": "ignore",
124+
"madeAt": 1658272999914,
125+
"expiresAt": 1660864995559
126+
},
127+
"1081008|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs>moment": {
128+
"decision": "ignore",
129+
"madeAt": 1658273000619,
130+
"expiresAt": 1660864995559
131+
},
132+
"1081008|@mojaloop/event-sdk>grpc>protobufjs>moment": {
133+
"decision": "ignore",
134+
"madeAt": 1658273000619,
135+
"expiresAt": 1660864995559
136+
},
137+
"1070030|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs>moment>shins>markdown-it": {
138+
"decision": "ignore",
139+
"madeAt": 1658273001409,
140+
"expiresAt": 1660864995559
141+
},
142+
"1070030|widdershins>markdown-it": {
143+
"decision": "ignore",
144+
"madeAt": 1658273001409,
145+
"expiresAt": 1660864995559
146+
},
147+
"1068155|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs>moment>shins>markdown-it>sanitize-html": {
148+
"decision": "ignore",
149+
"madeAt": 1658273002128,
150+
"expiresAt": 1660864995559
151+
},
152+
"1070260|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs>moment>shins>markdown-it>sanitize-html": {
153+
"decision": "ignore",
154+
"madeAt": 1658273002891,
155+
"expiresAt": 1660864995559
156+
},
157+
"1070412|ejs": {
158+
"decision": "ignore",
159+
"madeAt": 1658273003969,
160+
"expiresAt": 1660864995559
161+
},
162+
"1067553|swagger2openapi>better-ajv-errors>jsonpointer": {
163+
"decision": "ignore",
164+
"madeAt": 1658273005097,
165+
"expiresAt": 1660864995559
166+
},
167+
"1067946|swagger2openapi>better-ajv-errors>jsonpointer>oas-validator>ajv": {
168+
"decision": "ignore",
169+
"madeAt": 1658273005844,
170+
"expiresAt": 1660864995559
171+
},
172+
"1068310|widdershins>markdown-it>yargs>yargs-parser": {
173+
"decision": "ignore",
174+
"madeAt": 1658273006615,
175+
"expiresAt": 1660864995559
176+
},
177+
"1070030|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs>moment>widdershins>markdown-it": {
178+
"decision": "ignore",
179+
"madeAt": 1658274180235,
180+
"expiresAt": 1660866172578
181+
},
182+
"1070030|shins>markdown-it": {
183+
"decision": "ignore",
184+
"madeAt": 1658274180235,
185+
"expiresAt": 1660866172578
186+
},
187+
"1068310|@mojaloop/central-services-shared>@mojaloop/event-sdk>grpc>protobufjs>moment>widdershins>markdown-it>yargs>yargs-parser": {
188+
"decision": "ignore",
189+
"madeAt": 1658274181044,
190+
"expiresAt": 1660866172578
191+
},
192+
"1068155|shins>markdown-it>sanitize-html": {
193+
"decision": "ignore",
194+
"madeAt": 1658274181822,
195+
"expiresAt": 1660866172578
196+
},
197+
"1070260|shins>markdown-it>sanitize-html": {
198+
"decision": "ignore",
199+
"madeAt": 1658274182566,
200+
"expiresAt": 1660866172578
106201
}
107202
},
108203
"rules": {},

0 commit comments

Comments
 (0)