Repository navigation
Update the gems that can move without breaking the app - #147
Merged
Merged
Conversation
Pulled in by sprockets as its template engine wrapper. This app ships no Tilt templates of its own, so the jump from 2.0.10 spans six years of releases with no call sites here.
A native extension reached only through rb-inotify, which listen uses to watch files in development. 1.15.4 predates Ruby 3.4, so this is also the version that has been built against the Ruby the app now runs.
The macOS half of listen's file watching, so it only runs on a developer machine. Two patch releases, no API surface this app touches.
The Linux half of listen's file watching, and the reason ffi is in the bundle at all. Same story as rb-fsevent: development only.
development.rb sets the evented file watcher, which is the one feature that needs this gem, and it still resolves to ActiveSupport::EventedFileUpdateChecker with Listen 3.10.0 loaded. 3.10.0 declares logger explicitly, which is why the lockfile gains a line: Ruby moved logger out of the default gems, so gems that use it now have to ask for it.
4.3.0 raises its floor to actionview and railties 8.0, which the app only just cleared, and it drops the activemodel dependency. It boots in development with its railtie registered.
dotenv 3 rewrote which files it reads and in what order, so the thing to check was whether .env still reaches the app. It does, in both development and test, verified by reading ADMIN_USERNAME back out of ENV. The admin tests do not depend on that: test_helper.rb assigns both admin variables with ||=, which is why they pass on CI where no .env exists.
The Gemfile constraint moves with it, since ~> 7.2 would not allow 8.x. config/puma.rb is the generated one, reading threads, port, environment and pidfile out of ENV plus the tmp_restart plugin, and none of that changed shape in 8.x. Verified by booting a real server on Ruby 4.0.6: it serves the root page and a POST /reports returns 200 with a report id, so the request path works end to end and not just under the test harness.
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates every gem that can move without breaking the app, one gem per commit, ordered easiest first.
Depends on the Rails work in #146, now merged: web-console 4.3.0 requires
railties >= 8.0.0, which only became true there.What moved
.envstill reaches ENV in dev and test~> 8.0; real server boot verifiedTwo of these are majors and got more than a test run.
dotenv 3 changed which files it reads and in what order, so the question was whether
.envstill arrives. It does, in both development and test, checked by readingADMIN_USERNAMEback out ofENV. The admin tests never depended on it anyway:test_helper.rbassigns both admin variables with||=, which is why they pass on CI where no.envexists.puma 8 got a real server on Ruby 4.0.6 rather than just the test harness. It serves the root page, and a
POST /reportswith a genuine skunk payload returns 200 with a report id, so the path the CLI uses works end to end.config/puma.rbis the generated one — threads, port, environment, pidfile from ENV, plustmp_restart— and none of that changed shape in 8.x.What is blocked, and why
madmin 1.2.5 → 2.3.3, and pagy 4.11.0 → 43.6.1 with it.
madmin 2 depends on
propshaft,importmap-rails,turbo-railsandstimulus-rails. It resolves, but installing it puts propshaft in the bundle next to sprockets-rails and makes the admin servemadmin/application.js, which this app's Sprockets manifest does not declare.madmin_test.rbfails with four errors:pagy is pinned by madmin 1.2.5 at
>= 3.5, < 5.0, so it cannot move until madmin does.Doing this properly means picking an asset pipeline: Sprockets to Propshaft, plus importmap for JS. The app is a candidate for that anyway, since
sasscis unmaintained libsass. It is its own piece of work with compiled-CSS diffs to review, so it is not in here.Verification
Every commit was made with both boots green, not just the last one:
bin/rails testafter each individual bumpBUNDLE_GEMFILE=Gemfile.next bin/rails testat each tierNote on notes/outdated-gems.md
The tool that produced the original list reported every release date as "Jan 2, 1980", an epoch-parsing bug rather than real data, and it was generated before the Ruby 4.0.6 bump. Six of its entries were already stale:
ipaddr,psych,resolv,strscanandsyntax_suggestare Ruby default gems that ship current with 4.0.6, andfastruby-styleguidecomes from git at a pinned ref, so it has no release to be behind. That file has been regenerated against the current lockfiles.