Skip to content
This repository has been archived by the owner on Jan 9, 2023. It is now read-only.

1.27.2

Compare
Choose a tag to compare
released this 18 Dec 21:54

LGTM Enterprise 1.27.2

We're very happy to announce the release of LGTM Enterprise 1.27.2. You can find details of what's new, installation instructions and documentation for this release at help.semmle.com. Please note that use of the LGTM Enterprise application requires a separate license agreement with GitHub.

Debian/Ubuntu

LGTM Enterprise can be installed on one or more Debian or Ubuntu machines using the bundle of DEB files attached to this release. Debian 9, Ubuntu 16.04 and Ubuntu 18.04 are all officially supported.

CentOS/RedHat

LGTM Enterprise can be installed on one or more CentOS or RedHat machines using the bundle of RPM files attached to this release. CentOS 7 (>=7.4) and RedHat Enterprise Linux 7 (>=7.4) are both officially supported.

Additionally, if you are installing LGTM Enterprise on CentOS or RedHat machines without internet access, a bundle of third-party dependencies is also included.

Windows workers

You can run LGTM Enterprise workers on Windows using the Windows worker MSI provided for this release.

Amazon Web Services images

Remember to attach a data disk and configure your security group rules correctly when deploying the AMI image. Detailed instructions can be found in the Installation and Upgrade Guide.

LGTM Enterprise is available as an AMI in the following regions:

  • ap-northeast-1: ami-0ed5aacba480604b8
  • ap-northeast-2: ami-0564cd99d90797800
  • ap-northeast-3: ami-07947888ec655144a
  • ap-south-1: ami-0b8ab288149675622
  • ap-southeast-1: ami-0fb2c18d744fb895a
  • ap-southeast-2: ami-0290fb97fad05ceac
  • ca-central-1: ami-0773dcbe60c3d0eac
  • eu-central-1: ami-09a249664d0d251c6
  • eu-north-1: ami-0e7f2724bdb73bede
  • eu-west-1: ami-0413ab462347888c2
  • eu-west-2: ami-0499682442efb3205
  • eu-west-3: ami-080d306551f95c93c
  • sa-east-1: ami-0bd40df7f04c20ac3
  • us-east-1: ami-0c87c28c4669ceba0
  • us-east-2: ami-0b4be53abd50f2ed6
  • us-west-1: ami-0c8feae6b176623a2
  • us-west-2: ami-0c2fb318f7cfa3884

Helm (Kubernetes)

LGTM Enterprise can be installed to a Kubernetes cluster using a Helm chart. Some optional tools are also provided to make working with Kubernetes logs easier.

Jira add-on

The LGTM Enterprise Jira add-on is available on the LGTM Enterprise Jira Add-on releases page.

CodeQL for LGTM Enterprise 1.27 users

When using CodeQL to create and analyze databases to use in LGTM Enterprise, it's important that the CodeQL components you use are compatible with your version of LGTM. For the 1.27 release (and future releases), we are making directly compatible CodeQL components available to LGTM Enterprise users.

CodeQL for VS Code

To ensure CodeQL databases downloaded from LGTM Enterprise 1.27 can be analyzed in CodeQL for VS Code, you should you clone the 1.27.2 branch of the starter workspace. Alternatively, you can clone the tag v1.27.2 in the CodeQL and CodeQL for Go repositories, and add them to an existing workspace. For more information see Setting up CodeQL in Visual Studio Code.

CodeQL CLI

To ensure that databases created using the CodeQL CLI can be uploaded to LGTM Enterprise 1.27, download version 2.4.6 of the CLI. Clone the tag v1.27.2 in the CodeQL and CodeQL for Go repositories if you want to include compatible analysis results with the databases you upload to LGTM Enterprise. For more information, see Getting started with the CodeQL CLI and Preparing CodeQL databases to upload to LGTM.

Google Compute Engine Image

LGTM Enterprise is available as a Google Compute Engine Image which can be deployed with Google Deployment Manager. You can use this Google Cloud Shell tutorial for deploying LGTM Enterprise on Google Cloud:

Open in Cloud Shell

If you wish to deploy the image manually it can be found at:

  • Project: lgtm-enterprise
  • Image ID: lgtm-enterprise-1-27-2

Azure Image

LGTM Enterprise is available as an Azure virtual machine image which can be deployed with Azure Resource Manager.

The controller can be deployed by using this template:
Deploy to Azure

Worker groups can be deployed by using this template:
Deploy to Azure

If you wish to deploy the image manually it can be found with the image reference github:lgtm-enterprise:lgtm-enterprise:1.27.2.

Release Notes

  • A version of Log4j included in the bundled copy of Apache Solr that was vulnerable to CVE-2021-45046 has been updated to 2.16.0. This has been done out of an abundance of caution, and at this time, we believe that LGTM users are not at any elevated risk due to CVE-2021-45046 or CVE-2021-45105.