Skip to content

Harden CI: test against a committed, auditable dependency graph - #72

Merged
flavorjones merged 1 commit into
masterfrom
issue-31-lock-root-deps
Sep 29, 2026
Merged

flavorjones merged 1 commit into
masterfrom
issue-31-lock-root-deps

Conversation

@flavorjones

@flavorjones flavorjones commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Motivation

The root bundle is the set of gems the repository's own Gemfile installs for development and CI: the HotCell gems (from their gemspecs), Rails from the main branch, and the test and lint tools. .gitignore excluded every Gemfile.lock, so this bundle was never locked. Each CI run resolved its own graph, and nothing recorded which Rails commit or which transitive gems a green run had tested.

.github/dependabot.yml assumes the root Gemfile.lock exists. Without it, Dependabot has never proposed a gem update here, and its security alerts cannot see the gems the tests run against.

Details

  • Commit the root Gemfile.lock. It records the exact Rails main revision, e2b2c3d4, and every transitive gem.
  • ruby/setup-ruby switches to Bundler's deployment mode when a lockfile exists. Every job that installs the root bundle, except the ruby head lanes, now installs the locked graph unchanged and fails when the Gemfile disagrees with it.
  • The ruby head jobs delete Gemfile.lock before installing and test against the newest gems. Head's default Bundler lists lib/rubygems/yaml_serializer.rb among its files (ruby/rubygems@50ea015c). When the lockfile pins an older Bundler, a bundle exec subprocess that requires that file activates head's default Bundler alongside the running one, and Bundler raises Bundler::CorruptBundlerInstallError.
  • The Gemfile keeps branch: "main". The lockfile is the pin; the branch tells bundle update activestorage and Dependabot where to move it.

Additional information

Whether released Rubies also need a lane that tests against the latest of everything, as the issue asks, is still open. The cell image's own bundle is tracked separately under HC-PT-011.

Part of #31

Copilot AI balanced review requested due to automatic review settings September 28, 2026 20:35

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@flavorjones
flavorjones force-pushed the issue-31-lock-root-deps branch 4 times, most recently from f35849d to b7d93d4 Compare September 29, 2026 18:19
`.gitignore` excluded the root `Gemfile.lock`, so each CI run resolved
its own dependency graph, including whatever Rails `main` was that day,
and Dependabot had no lockfile to read. Commit it. CI now installs
exactly the locked graph, frozen, and fails when the `Gemfile` disagrees
with it.

On ruby head, a lockfile that pins an older Bundler than head's default
makes `bundle exec` subprocesses raise
`Bundler::CorruptBundlerInstallError`, so the head jobs delete the
lockfile and resolve the newest gems.

ref: #31
@flavorjones
flavorjones force-pushed the issue-31-lock-root-deps branch from b7d93d4 to dac2e17 Compare September 29, 2026 18:27
@flavorjones
flavorjones merged commit 33559aa into master Sep 29, 2026
28 of 29 checks passed
@flavorjones
flavorjones deleted the issue-31-lock-root-deps branch September 29, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants