Skip to content

Update the gems that can move without breaking the app - #147

Merged
JuanVqz merged 8 commits into
mainfrom
maintenance/gem-updates
Jul 31, 2026
Merged

JuanVqz merged 8 commits into
mainfrom
maintenance/gem-updates

Conversation

@JuanVqz

@JuanVqz JuanVqz commented Jul 30, 2026

Copy link
Copy Markdown
Member

Updates every gem that can move without breaking the app, one gem per commit, ordered easiest first.

Depends on the Rails work in #146, now merged: web-console 4.3.0 requires railties >= 8.0.0, which only became true there.

What moved

Gem From To Why it is safe
tilt 2.0.10 2.8.0 sprockets' template wrapper; this app ships no Tilt templates
ffi 1.15.4 1.17.4 native ext reached only through rb-inotify; 1.15.4 predates Ruby 3.4
rb-fsevent 0.11.0 0.11.2 listen's macOS watcher, development only
rb-inotify 0.10.1 0.11.1 listen's Linux watcher, development only
listen 3.7.0 3.10.0 evented file watcher still resolves with 3.10.0 loaded
web-console 4.1.0 4.3.0 raises its floor to railties 8.0; boots with its railtie registered
dotenv-rails 2.7.6 3.2.0 dotenv 3 rewrote file order; .env still reaches ENV in dev and test
puma 7.2.1 8.0.2 Gemfile constraint moved to ~> 8.0; real server boot verified

Two of these are majors and got more than a test run.

dotenv 3 changed which files it reads and in what order, so the question was whether .env still arrives. It does, in both development and test, checked by reading ADMIN_USERNAME back out of ENV. The admin tests never depended on it anyway: test_helper.rb assigns both admin variables with ||=, which is why they pass on CI where no .env exists.

puma 8 got a real server on Ruby 4.0.6 rather than just the test harness. It serves the root page, and a POST /reports with a genuine skunk payload returns 200 with a report id, so the path the CLI uses works end to end. config/puma.rb is the generated one — threads, port, environment, pidfile from ENV, plus tmp_restart — and none of that changed shape in 8.x.

What is blocked, and why

madmin 1.2.5 → 2.3.3, and pagy 4.11.0 → 43.6.1 with it.

madmin 2 depends on propshaft, importmap-rails, turbo-rails and stimulus-rails. It resolves, but installing it puts propshaft in the bundle next to sprockets-rails and makes the admin serve madmin/application.js, which this app's Sprockets manifest does not declare. madmin_test.rb fails with four errors:

ActionView::Template::Error: Asset `madmin/application.js` was not declared to
be precompiled in production. Declare links to your assets in
`app/assets/config/manifest.js`.

pagy is pinned by madmin 1.2.5 at >= 3.5, < 5.0, so it cannot move until madmin does.

Doing this properly means picking an asset pipeline: Sprockets to Propshaft, plus importmap for JS. The app is a candidate for that anyway, since sassc is unmaintained libsass. It is its own piece of work with compiled-CSS diffs to review, so it is not in here.

Verification

Every commit was made with both boots green, not just the last one:

  • bin/rails test after each individual bump
  • BUNDLE_GEMFILE=Gemfile.next bin/rails test at each tier
  • rubocop clean
  • 28 runs, 84 assertions, 0 failures, 0 errors throughout

Note on notes/outdated-gems.md

The tool that produced the original list reported every release date as "Jan 2, 1980", an epoch-parsing bug rather than real data, and it was generated before the Ruby 4.0.6 bump. Six of its entries were already stale: ipaddr, psych, resolv, strscan and syntax_suggest are Ruby default gems that ship current with 4.0.6, and fastruby-styleguide comes from git at a pinned ref, so it has no release to be behind. That file has been regenerated against the current lockfiles.

JuanVqz added 8 commits July 30, 2026 17:27
Pulled in by sprockets as its template engine wrapper. This app ships no
Tilt templates of its own, so the jump from 2.0.10 spans six years of
releases with no call sites here.
A native extension reached only through rb-inotify, which listen uses to
watch files in development. 1.15.4 predates Ruby 3.4, so this is also the
version that has been built against the Ruby the app now runs.
The macOS half of listen's file watching, so it only runs on a developer
machine. Two patch releases, no API surface this app touches.
The Linux half of listen's file watching, and the reason ffi is in the
bundle at all. Same story as rb-fsevent: development only.
development.rb sets the evented file watcher, which is the one feature that
needs this gem, and it still resolves to
ActiveSupport::EventedFileUpdateChecker with Listen 3.10.0 loaded.

3.10.0 declares logger explicitly, which is why the lockfile gains a line:
Ruby moved logger out of the default gems, so gems that use it now have to
ask for it.
4.3.0 raises its floor to actionview and railties 8.0, which the app only
just cleared, and it drops the activemodel dependency. It boots in
development with its railtie registered.
dotenv 3 rewrote which files it reads and in what order, so the thing to
check was whether .env still reaches the app. It does, in both development
and test, verified by reading ADMIN_USERNAME back out of ENV.

The admin tests do not depend on that: test_helper.rb assigns both admin
variables with ||=, which is why they pass on CI where no .env exists.
The Gemfile constraint moves with it, since ~> 7.2 would not allow 8.x.

config/puma.rb is the generated one, reading threads, port, environment and
pidfile out of ENV plus the tmp_restart plugin, and none of that changed
shape in 8.x. Verified by booting a real server on Ruby 4.0.6: it serves the
root page and a POST /reports returns 200 with a report id, so the request
path works end to end and not just under the test harness.
@JuanVqz
JuanVqz temporarily deployed to skunk-maintenance-gem-u-yueafp July 31, 2026 00:07 Inactive
@JuanVqz
JuanVqz merged commit 3382ce0 into main Jul 31, 2026
3 checks passed
@JuanVqz
JuanVqz deleted the maintenance/gem-updates branch July 31, 2026 00:17

This branch was previously deployed

1 inactive deployment
skunk-maintenance-gem-u-yueafp — 7fe1f722 Deployed Jul 31, 2026 by JuanVqz
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant