smarkets / marge-bot

A merge-bot for GitLab
BSD 3-Clause "New" or "Revised" License
701 stars 136 forks source link

LetsEncrypt cert from the included CA Bundle is expired #356

Open Sayrus opened 2 years ago

Sayrus commented 2 years ago

Following LetsEncrypt CA rotation in 2021, the ca-certs included in the latest image (0.10.1) are expired. I'm not familiar with Nix but it seems that nixos-19.03 might be a very old base amd tje cacert package is outdated (certifi is also from 2019).

As a workaround, I've included my own CA in my deployment.

Is there a plan for https://github.com/smarkets/marge-bot/issues/288 and https://github.com/smarkets/marge-bot/pull/291 to be merged soon? Is this something I can contribute on?

If not, is there a plan to upgrade the version?