From 0eab2a6ff124781b704a1d2f7ed068f11f8f2a95 Mon Sep 17 00:00:00 2001 From: James Butters Date: Wed, 16 Sep 2026 21:51:13 -0600 Subject: [PATCH] build: commit Gemfile.lock and add dependabot MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Resolution was fresh on every run, so two checkouts a week apart could run different rspec-core or redis versions, and dependency drift never showed up in a diff. The lock pins the default resolution. The matrix still resolves past it — each leg pins its own combination through the gemspec env hooks — so build.yml drops the lock before installing. Without that, bundler re-resolves anyway and rewrites it on every run. Lint keeps the lock and fails if bundler had to rewrite it, which catches a version bump that forgot to regenerate it. Dependabot covers both ecosystems: github-actions to move the SHA pins, which otherwise freeze permanently, and bundler, which only becomes useful now that there is a lockfile to bump. refs DE-1818 Co-Authored-By: Claude Opus 5 --- .github/dependabot.yml | 11 ++++ .github/workflows/build.yml | 19 ++++--- .gitignore | 1 - Gemfile.lock | 105 ++++++++++++++++++++++++++++++++++++ 4 files changed, 128 insertions(+), 8 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 Gemfile.lock diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..38ad158 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,11 @@ +version: 2 +updates: + - package-ecosystem: github-actions + directory: "/" + schedule: + interval: weekly + + - package-ecosystem: bundler + directory: "/" + schedule: + interval: weekly diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 3e74f2b..5ad8927 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -23,6 +23,8 @@ jobs: with: ruby-version: "3.4" - run: bundle install + - name: Gemfile.lock is up to date + run: git diff --exit-code Gemfile.lock - run: bundle exec rubocop test: @@ -32,8 +34,7 @@ jobs: strategy: fail-fast: false matrix: - # Each leg varies exactly one value from the first (canvas's combination), - # so a red leg names its own cause. Not a cross product. + # Each leg varies one value from the first, so a red leg names its cause. include: - { ruby: "3.4", redis-gem: "6.0.0", redis-server: "7", rspec-core: "3.13.6" } - { ruby: "3.2", redis-gem: "6.0.0", redis-server: "7", rspec-core: "3.13.6" } @@ -51,9 +52,8 @@ jobs: --health-timeout 5s --health-retries 5 env: - # Job-level, not step-level: the gemspec reads these when CI is set, so - # they have to hold for `bundle install` and `bundle exec rake` alike or - # the run-time gems differ from the resolved ones. + # Job-level, not step-level: must hold for install and run alike, or the + # resolved gems differ from the loaded ones. RSPEC_CORE: ${{ matrix.rspec-core }} REDIS_GEM: ${{ matrix.redis-gem }} steps: @@ -61,11 +61,16 @@ jobs: - uses: ruby/setup-ruby@984c0c890880bbf811283d6f09c4607c62d210a4 # v1.323.0 with: ruby-version: ${{ matrix.ruby }} + + # Legs resolve their own deps via the gemspec env hooks; keeping the lock + # only means bundler rewrites it every run. + - run: rm -f Gemfile.lock + - run: bundle install - run: bundle exec rake - # Single stable name to wire into branch protection; the matrix leg names - # embed version strings and would need rewiring every time the matrix moves. + # Stable name for branch protection; leg names embed versions and would + # need rewiring whenever the matrix moves. build-complete: if: always() needs: [lint, test] diff --git a/.gitignore b/.gitignore index 0a55386..ac138b3 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,2 @@ *.gem dump.rdb -Gemfile.lock diff --git a/Gemfile.lock b/Gemfile.lock new file mode 100644 index 0000000..bb91649 --- /dev/null +++ b/Gemfile.lock @@ -0,0 +1,105 @@ +PATH + remote: . + specs: + rspecq (0.8.0.instructure2) + logger + redis (>= 5.0, < 7.0) + rspec-core + rspec_junit_formatter + sentry-ruby + +GEM + remote: https://rubygems.org/ + specs: + ast (2.4.3) + bigdecimal (4.1.3) + byebug (13.0.0) + reline (>= 0.6.0) + coderay (1.1.3) + concurrent-ruby (1.3.8) + connection_pool (3.0.2) + diff-lcs (1.6.2) + drb (2.2.3) + io-console (0.9.3) + json (3.0.2) + language_server-protocol (3.17.0.6) + lint_roller (1.1.0) + logger (1.7.0) + method_source (1.1.0) + minitest (6.0.6) + drb (~> 2.0) + prism (~> 1.5) + parallel (2.2.0) + parser (3.3.12.0) + ast (~> 2.4.1) + racc + prism (1.9.0) + pry (0.16.0) + coderay (~> 1.1) + method_source (~> 1.0) + reline (>= 0.6.0) + pry-byebug (3.12.0) + byebug (~> 13.0) + pry (>= 0.13, < 0.17) + racc (1.8.1) + rainbow (3.1.1) + rake (13.4.2) + redis (6.0.0) + redis-client (= 0.30.1) + redis-client (0.30.1) + connection_pool + regexp_parser (2.12.0) + reline (0.7.0) + io-console (~> 0.5) + rspec (3.13.2) + rspec-core (~> 3.13.0) + rspec-expectations (~> 3.13.0) + rspec-mocks (~> 3.13.0) + rspec-core (3.13.6) + rspec-support (~> 3.13.0) + rspec-expectations (3.13.5) + diff-lcs (>= 1.2.0, < 2.0) + rspec-support (~> 3.13.0) + rspec-mocks (3.13.8) + diff-lcs (>= 1.2.0, < 2.0) + rspec-support (~> 3.13.0) + rspec-support (3.13.7) + rspec_junit_formatter (0.6.0) + rspec-core (>= 2, < 4, != 2.12.0) + rubocop (1.91.0) + json (>= 2.3) + language_server-protocol (~> 3.17.0.2) + lint_roller (~> 1.1.0) + parallel (>= 1.10) + parser (>= 3.3.0.2) + rainbow (>= 2.2.2, < 4.0) + regexp_parser (>= 2.9.3, < 3.0) + rubocop-ast (>= 1.49.0, < 2.0) + ruby-progressbar (~> 1.7) + unicode-display_width (>= 2.4.0, < 4.0) + rubocop-ast (1.50.0) + parser (>= 3.3.7.2) + prism (~> 1.7) + ruby-progressbar (1.13.0) + sentry-ruby (7.0.0) + bigdecimal + concurrent-ruby (~> 1.0, >= 1.0.2) + logger + unicode-display_width (3.2.0) + unicode-emoji (~> 4.1) + unicode-emoji (4.2.0) + +PLATFORMS + arm64-darwin-24 + ruby + +DEPENDENCIES + minitest + pry-byebug + rake + rspec + rspecq! + rubocop (~> 1.91) + +BUNDLED WITH + 2.6.7