Harden CI: test against a committed, auditable dependency graph - #72
Merged
Merged
Conversation
flavorjones
force-pushed
the
issue-31-lock-root-deps
branch
4 times, most recently
from
September 29, 2026 18:19
f35849d to
b7d93d4
Compare
`.gitignore` excluded the root `Gemfile.lock`, so each CI run resolved its own dependency graph, including whatever Rails `main` was that day, and Dependabot had no lockfile to read. Commit it. CI now installs exactly the locked graph, frozen, and fails when the `Gemfile` disagrees with it. On ruby head, a lockfile that pins an older Bundler than head's default makes `bundle exec` subprocesses raise `Bundler::CorruptBundlerInstallError`, so the head jobs delete the lockfile and resolve the newest gems. ref: #31
flavorjones
force-pushed
the
issue-31-lock-root-deps
branch
from
September 29, 2026 18:27
b7d93d4 to
dac2e17
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The root bundle is the set of gems the repository's own
Gemfileinstalls for development and CI: the HotCell gems (from their gemspecs), Rails from themainbranch, and the test and lint tools..gitignoreexcluded everyGemfile.lock, so this bundle was never locked. Each CI run resolved its own graph, and nothing recorded which Rails commit or which transitive gems a green run had tested..github/dependabot.ymlassumes the rootGemfile.lockexists. Without it, Dependabot has never proposed a gem update here, and its security alerts cannot see the gems the tests run against.Details
Gemfile.lock. It records the exact Railsmainrevision,e2b2c3d4, and every transitive gem.ruby/setup-rubyswitches to Bundler's deployment mode when a lockfile exists. Every job that installs the root bundle, except the ruby head lanes, now installs the locked graph unchanged and fails when theGemfiledisagrees with it.Gemfile.lockbefore installing and test against the newest gems. Head's default Bundler listslib/rubygems/yaml_serializer.rbamong its files (ruby/rubygems@50ea015c). When the lockfile pins an older Bundler, abundle execsubprocess that requires that file activates head's default Bundler alongside the running one, and Bundler raisesBundler::CorruptBundlerInstallError.Gemfilekeepsbranch: "main". The lockfile is the pin; the branch tellsbundle update activestorageand Dependabot where to move it.Additional information
Whether released Rubies also need a lane that tests against the latest of everything, as the issue asks, is still open. The cell image's own bundle is tracked separately under
HC-PT-011.Part of #31