Compare commits

..
11 Commits
Author SHA1 Message Date
Benoit Daloze 6148f408d3 Test on ubuntu-22.04 2022-08-06 16:55:13 +02:00
Benoit Daloze 699560a00d Support all versions on Ubuntu 22.04 2022-08-06 16:54:03 +02:00
Benoit Daloze 8b5af312bd Fix permissions of release job 2022-07-29 18:24:39 +02:00
Benoit Daloze d5ee2364f0 Ensure Bundler 2.2+ is used for all Rubies which support Bundler 2 (Ruby >= 2.3) 2022-07-29 18:16:42 +02:00
Benoit Daloze 8731780d5e Remove extra condition 2022-07-29 18:16:42 +02:00
Benoit Daloze 3882fb634e Test gem github: in a Gemfile 2022-07-29 18:16:42 +02:00
Benoit Daloze d6ebfae201 Use read-only permissions for the test workflow 2022-07-27 19:16:35 +02:00
neilnaveen 3325fe2d4e chore: Set permissions for GitHub actions
Restrict the GitHub token permissions only to the required ones; this way, even if the attackers will succeed in compromising your workflow, they won’t be able to do much.

- Included permissions for the action. https://github.com/ossf/scorecard/blob/main/docs/checks.md#token-permissions

https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#permissions

https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs

[Keeping your GitHub Actions and workflows secure Part 1: Preventing pwn requests](https://securitylab.github.com/research/github-actions-preventing-pwn-requests/)

Signed-off-by: neilnaveen <42328488+neilnaveen@users.noreply.github.com>
2022-07-27 19:15:28 +02:00
Benoit Daloze e8f04a3cee Use latest Bundler on CRuby 2.6 and 2.7 as their default Bundler is too old 2022-07-26 21:55:37 +02:00
Benoit Daloze bb1d54ff77 Use a new cache version
* To make sure existing caches based on latest Bundler are not reused.
2022-07-26 21:17:48 +02:00
Benoit Daloze 4e1189c53d Use the Bundler shipped with that Ruby by default
* Fixes https://github.com/ruby/setup-ruby/issues/358
2022-07-26 20:57:23 +02:00
10 changed files with 151 additions and 90 deletions
+5
View File
@@ -2,9 +2,14 @@ name: Update the v1 branch when a release is published
on:
release:
types: [published]
permissions:
contents: read
jobs:
release:
runs-on: ubuntu-latest
permissions:
contents: write # for git push
steps:
- uses: actions/checkout@v3
with:
+8 -5
View File
@@ -9,19 +9,17 @@ on:
paths-ignore:
- README.md
workflow_dispatch:
permissions:
contents: read
jobs:
test:
strategy:
fail-fast: false
matrix:
os: [ ubuntu-18.04, ubuntu-20.04, macos-10.15, macos-11, macos-12, windows-2019, windows-2022 ]
os: [ ubuntu-18.04, ubuntu-20.04, ubuntu-22.04, macos-10.15, macos-11, macos-12, windows-2019, windows-2022 ]
ruby: [ '1.9', '2.0', '2.1', '2.2', '2.3', '2.4', '2.5', '2.6', '2.7', '3.0', '3.1', ruby-head, jruby, jruby-head, truffleruby, truffleruby-head, truffleruby+graalvm, truffleruby+graalvm-head ]
include:
- { os: ubuntu-22.04, ruby: '3.1.0' }
- { os: ubuntu-22.04, ruby: '3.1' }
- { os: ubuntu-22.04, ruby: '3.2.0-preview1' }
- { os: ubuntu-22.04, ruby: ruby-head }
- { os: windows-2019, ruby: mingw }
- { os: windows-2019, ruby: mswin }
- { os: windows-2022, ruby: mingw }
@@ -98,6 +96,11 @@ jobs:
- run: bundle exec rake --version
- run: bundle exec rake
- name: Test `gem github:` in a Gemfile
run: bundle install
env:
BUNDLE_GEMFILE: ${{ github.workspace }}/gemfiles/gem_from_github.gemfile
- name: which ruby, rake
if: "!startsWith(matrix.os, 'windows')"
run: which -a ruby rake
+7 -6
View File
@@ -39,12 +39,10 @@ The action works on these [GitHub-hosted runners](https://help.github.com/en/act
| Operating System | Recommended | Other Supported Versions |
| ----------- | -------- | -------- |
| Ubuntu | `ubuntu-latest` (= `ubuntu-20.04`) | `ubuntu-18.04`, `ubuntu-22.04` (beta, only `ruby: 3.1 - head, truffleruby`) |
| Ubuntu | `ubuntu-latest` (= `ubuntu-20.04`) | `ubuntu-18.04`, `ubuntu-22.04` |
| macOS | `macos-latest` (= `macos-11`) | `macos-10.15`, `macos-12` (beta) |
| Windows | `windows-latest` (= `windows-2022`) | `windows-2019` |
On `ubuntu-22.04` (beta), only `ruby: 3.1 - head, truffleruby` are supported, due to Ubuntu 22.04 only supporting OpenSSL 3.
The prebuilt releases are generated by [ruby-builder](https://github.com/ruby/ruby-builder)
and on Windows by [RubyInstaller2](https://github.com/oneclick/rubyinstaller2).
`mingw` and `mswin` builds are generated by [ruby-loco](https://github.com/MSP-Greg/ruby-loco).
@@ -155,9 +153,12 @@ should be able to fix them by setting `rubygems: 3.0.0` or higher.
### Bundler
By default, if there is a `Gemfile.lock` file (or `$BUNDLE_GEMFILE.lock` or `gems.locked`) with a `BUNDLED WITH` section,
that version of Bundler will be installed and used.
Otherwise, the latest compatible Bundler version is installed (Bundler 2 on Ruby >= 2.4, Bundler 1 on Ruby < 2.4).
By default, Bundler is installed as follows:
* If there is a `Gemfile.lock` file (or `$BUNDLE_GEMFILE.lock` or `gems.locked`) with a `BUNDLED WITH` section,
that version of Bundler will be installed and used.
* If the Ruby ships with Bundler 2.2+ (as a default gem), that version is used.
* Otherwise, the latest compatible Bundler version is installed (Bundler 2 on Ruby >= 2.3, Bundler 1 on Ruby < 2.3).
This behavior can be customized, see [action.yml](action.yml) for more details about the `bundler` input.
+5 -3
View File
@@ -16,9 +16,11 @@ inputs:
Similarly, if a version number is given, `gem update --system <version>` is run to update to that version of RubyGems, as long as that version is newer than the one provided by default.
bundler:
description: |
The version of Bundler to install. Either 'none', 'latest', 'Gemfile.lock', or a version number (e.g., 1, 2, 2.1, 2.1.4).
For 'Gemfile.lock', the version is determined based on the BUNDLED WITH section from the file Gemfile.lock, $BUNDLE_GEMFILE.lock or gems.locked.
Defaults to 'default', which means 'Gemfile.lock' if the file exists and 'latest' otherwise.
The version of Bundler to install. Either 'Gemfile.lock' (the default), 'default', 'latest', 'none', or a version number (e.g., 1, 2, 2.1, 2.1.4).
For 'Gemfile.lock', the version of the BUNDLED WITH section from the Gemfile.lock if it exists. If the file or section does not exist then the same as 'default'.
For 'default', if the Ruby ships with Bundler 2.2+ as a default gem, that version is used, otherwise the same as 'latest'.
For 'latest', the latest compatible Bundler version is installed (Bundler 2 on Ruby >= 2.3, Bundler 1 on Ruby < 2.3).
For 'none', nothing is done.
bundler-cache:
description: 'Run "bundle install", and cache the result automatically. Either true or false.'
default: 'false'
+30 -29
View File
@@ -53,15 +53,34 @@ async function afterLockFile(lockFile, platform, engine, rubyVersion) {
export async function installBundler(bundlerVersionInput, rubygemsInputSet, lockFile, platform, rubyPrefix, engine, rubyVersion) {
let bundlerVersion = bundlerVersionInput
if (rubygemsInputSet && bundlerVersion === 'default') {
if (rubygemsInputSet && (bundlerVersion === 'default' || bundlerVersion === 'Gemfile.lock')) {
console.log('Using the Bundler installed by updating RubyGems')
return 'unknown'
}
if (bundlerVersion === 'default' || bundlerVersion === 'Gemfile.lock') {
bundlerVersion = readBundledWithFromGemfileLock(lockFile)
if (bundlerVersion === 'Gemfile.lock') {
let bundlerVersionFromGemfileLock = readBundledWithFromGemfileLock(lockFile)
if (!bundlerVersion) {
if (bundlerVersionFromGemfileLock) {
bundlerVersion = bundlerVersionFromGemfileLock
} else {
bundlerVersion = 'default'
}
}
const floatVersion = common.floatVersion(rubyVersion)
if (bundlerVersion === 'default') {
if (common.isBundler2dot2Default(engine, rubyVersion)) {
console.log(`Using Bundler 2 shipped with ${engine}-${rubyVersion}`)
return '2'
} else if (common.hasBundlerDefaultGem(engine, rubyVersion)) {
// Those Rubies have a old Bundler default gem < 2.2 which does not work well for `gem 'foo', github: 'foo/foo'`:
// https://github.com/ruby/setup-ruby/issues/358#issuecomment-1195899304
// Also, Ruby 2.6 would get Bundler 1 yet Ruby 2.3 - 2.5 get latest Bundler 2 which might be unexpected.
console.log(`Using latest Bundler for ${engine}-${rubyVersion} because the default Bundler gem is too old for that Ruby version`)
bundlerVersion = 'latest'
} else {
bundlerVersion = 'latest'
}
}
@@ -76,8 +95,6 @@ export async function installBundler(bundlerVersionInput, rubygemsInputSet, lock
throw new Error(`Cannot parse bundler input: ${bundlerVersion}`)
}
const floatVersion = common.floatVersion(rubyVersion)
// Use Bundler 1 when we know Bundler 2 does not work
if (bundlerVersion.startsWith('2')) {
if (engine === 'ruby' && floatVersion <= 2.2) {
@@ -92,30 +109,14 @@ export async function installBundler(bundlerVersionInput, rubygemsInputSet, lock
}
}
// Workaround for truffleruby 22.0 + latest Bundler, use shipped Bundler instead: https://github.com/oracle/truffleruby/issues/2586
const truffleruby22workaround = engine.startsWith('truffleruby') && rubyVersion.startsWith('22.0')
const useShippedBundler2 = common.isHeadVersion(rubyVersion) || truffleruby22workaround
const gem = path.join(rubyPrefix, 'bin', 'gem')
// Workaround for https://github.com/rubygems/rubygems/issues/5245
const force = (platform.startsWith('windows-') && engine === 'ruby' && floatVersion >= 3.1) ? ['--force'] : []
if (useShippedBundler2 && common.isBundler2Default(engine, rubyVersion) && bundlerVersion.startsWith('2')) {
// Avoid installing a newer Bundler version for head versions as it might not work.
// For releases, even if they ship with Bundler 2 we install the latest Bundler.
if (truffleruby22workaround) {
console.log(`Using Bundler 2 shipped with ${engine}-${rubyVersion} (workaround for https://github.com/oracle/truffleruby/issues/2586 on truffleruby 22.0)`)
} else {
console.log(`Using Bundler 2 shipped with ${engine}-${rubyVersion} (head versions do not always support the latest Bundler release)`)
}
} else if (engine.startsWith('truffleruby') && common.isBundler1Default(engine, rubyVersion) && bundlerVersion.startsWith('1')) {
console.log(`Using Bundler 1 shipped with ${engine}-${rubyVersion} (required for truffleruby < 21.0)`)
} else {
const gem = path.join(rubyPrefix, 'bin', 'gem')
// Workaround for https://github.com/rubygems/rubygems/issues/5245
const force = (platform.startsWith('windows-') && engine === 'ruby' && floatVersion >= 3.1) ? ['--force'] : []
const versionParts = [...bundlerVersion.matchAll(/\d+/g)].length
const bundlerVersionConstraint = versionParts === 3 ? bundlerVersion : `~> ${bundlerVersion}.0`
const versionParts = [...bundlerVersion.matchAll(/\d+/g)].length
const bundlerVersionConstraint = versionParts === 3 ? bundlerVersion : `~> ${bundlerVersion}.0`
await exec.exec(gem, ['install', 'bundler', ...force, '-v', bundlerVersionConstraint])
}
await exec.exec(gem, ['install', 'bundler', ...force, '-v', bundlerVersionConstraint])
return bundlerVersion
}
@@ -204,7 +205,7 @@ export async function bundleInstall(gemfile, lockFile, platform, engine, rubyVer
async function computeBaseKey(platform, engine, version, lockFile, cacheVersion) {
const cacheVersionSuffix = DEFAULT_CACHE_VERSION === cacheVersion ? '' : `-cachever:${cacheVersion}`
let key = `setup-ruby-bundler-cache-v3-${platform}-${engine}-${version}${cacheVersionSuffix}`
let key = `setup-ruby-bundler-cache-v4-${platform}-${engine}-${version}${cacheVersionSuffix}`
if (common.isHeadVersion(version)) {
if (engine !== 'jruby') {
+25 -1
View File
@@ -55,8 +55,20 @@ export function isStableVersion(rubyVersion) {
return /^\d+(\.\d+)*$/.test(rubyVersion)
}
export function hasBundlerDefaultGem(engine, rubyVersion) {
return isBundler1Default(engine, rubyVersion) || isBundler2Default(engine, rubyVersion)
}
export function isBundler1Default(engine, rubyVersion) {
return !isBundler2Default(engine, rubyVersion)
if (engine === 'ruby') {
return floatVersion(rubyVersion) >= 2.6 && floatVersion(rubyVersion) < 2.7
} else if (engine.startsWith('truffleruby')) {
return floatVersion(rubyVersion) < 21.0
} else if (engine === 'jruby') {
return false
} else {
return false
}
}
export function isBundler2Default(engine, rubyVersion) {
@@ -71,6 +83,18 @@ export function isBundler2Default(engine, rubyVersion) {
}
}
export function isBundler2dot2Default(engine, rubyVersion) {
if (engine === 'ruby') {
return floatVersion(rubyVersion) >= 3.0
} else if (engine.startsWith('truffleruby')) {
return floatVersion(rubyVersion) >= 22.0
} else if (engine === 'jruby') {
return floatVersion(rubyVersion) >= 9.3
} else {
return false
}
}
export function floatVersion(rubyVersion) {
const match = rubyVersion.match(/^\d+\.\d+/)
if (match) {
Generated Vendored
+58 -38
View File
@@ -67,15 +67,34 @@ async function afterLockFile(lockFile, platform, engine, rubyVersion) {
async function installBundler(bundlerVersionInput, rubygemsInputSet, lockFile, platform, rubyPrefix, engine, rubyVersion) {
let bundlerVersion = bundlerVersionInput
if (rubygemsInputSet && bundlerVersion === 'default') {
if (rubygemsInputSet && (bundlerVersion === 'default' || bundlerVersion === 'Gemfile.lock')) {
console.log('Using the Bundler installed by updating RubyGems')
return 'unknown'
}
if (bundlerVersion === 'default' || bundlerVersion === 'Gemfile.lock') {
bundlerVersion = readBundledWithFromGemfileLock(lockFile)
if (bundlerVersion === 'Gemfile.lock') {
let bundlerVersionFromGemfileLock = readBundledWithFromGemfileLock(lockFile)
if (!bundlerVersion) {
if (bundlerVersionFromGemfileLock) {
bundlerVersion = bundlerVersionFromGemfileLock
} else {
bundlerVersion = 'default'
}
}
const floatVersion = common.floatVersion(rubyVersion)
if (bundlerVersion === 'default') {
if (common.isBundler2dot2Default(engine, rubyVersion)) {
console.log(`Using Bundler 2 shipped with ${engine}-${rubyVersion}`)
return '2'
} else if (common.hasBundlerDefaultGem(engine, rubyVersion)) {
// Those Rubies have a old Bundler default gem < 2.2 which does not work well for `gem 'foo', github: 'foo/foo'`:
// https://github.com/ruby/setup-ruby/issues/358#issuecomment-1195899304
// Also, Ruby 2.6 would get Bundler 1 yet Ruby 2.3 - 2.5 get latest Bundler 2 which might be unexpected.
console.log(`Using latest Bundler for ${engine}-${rubyVersion} because the default Bundler gem is too old for that Ruby version`)
bundlerVersion = 'latest'
} else {
bundlerVersion = 'latest'
}
}
@@ -90,8 +109,6 @@ async function installBundler(bundlerVersionInput, rubygemsInputSet, lockFile, p
throw new Error(`Cannot parse bundler input: ${bundlerVersion}`)
}
const floatVersion = common.floatVersion(rubyVersion)
// Use Bundler 1 when we know Bundler 2 does not work
if (bundlerVersion.startsWith('2')) {
if (engine === 'ruby' && floatVersion <= 2.2) {
@@ -106,30 +123,14 @@ async function installBundler(bundlerVersionInput, rubygemsInputSet, lockFile, p
}
}
// Workaround for truffleruby 22.0 + latest Bundler, use shipped Bundler instead: https://github.com/oracle/truffleruby/issues/2586
const truffleruby22workaround = engine.startsWith('truffleruby') && rubyVersion.startsWith('22.0')
const useShippedBundler2 = common.isHeadVersion(rubyVersion) || truffleruby22workaround
const gem = path.join(rubyPrefix, 'bin', 'gem')
// Workaround for https://github.com/rubygems/rubygems/issues/5245
const force = (platform.startsWith('windows-') && engine === 'ruby' && floatVersion >= 3.1) ? ['--force'] : []
if (useShippedBundler2 && common.isBundler2Default(engine, rubyVersion) && bundlerVersion.startsWith('2')) {
// Avoid installing a newer Bundler version for head versions as it might not work.
// For releases, even if they ship with Bundler 2 we install the latest Bundler.
if (truffleruby22workaround) {
console.log(`Using Bundler 2 shipped with ${engine}-${rubyVersion} (workaround for https://github.com/oracle/truffleruby/issues/2586 on truffleruby 22.0)`)
} else {
console.log(`Using Bundler 2 shipped with ${engine}-${rubyVersion} (head versions do not always support the latest Bundler release)`)
}
} else if (engine.startsWith('truffleruby') && common.isBundler1Default(engine, rubyVersion) && bundlerVersion.startsWith('1')) {
console.log(`Using Bundler 1 shipped with ${engine}-${rubyVersion} (required for truffleruby < 21.0)`)
} else {
const gem = path.join(rubyPrefix, 'bin', 'gem')
// Workaround for https://github.com/rubygems/rubygems/issues/5245
const force = (platform.startsWith('windows-') && engine === 'ruby' && floatVersion >= 3.1) ? ['--force'] : []
const versionParts = [...bundlerVersion.matchAll(/\d+/g)].length
const bundlerVersionConstraint = versionParts === 3 ? bundlerVersion : `~> ${bundlerVersion}.0`
const versionParts = [...bundlerVersion.matchAll(/\d+/g)].length
const bundlerVersionConstraint = versionParts === 3 ? bundlerVersion : `~> ${bundlerVersion}.0`
await exec.exec(gem, ['install', 'bundler', ...force, '-v', bundlerVersionConstraint])
}
await exec.exec(gem, ['install', 'bundler', ...force, '-v', bundlerVersionConstraint])
return bundlerVersion
}
@@ -218,7 +219,7 @@ async function bundleInstall(gemfile, lockFile, platform, engine, rubyVersion, b
async function computeBaseKey(platform, engine, version, lockFile, cacheVersion) {
const cacheVersionSuffix = DEFAULT_CACHE_VERSION === cacheVersion ? '' : `-cachever:${cacheVersion}`
let key = `setup-ruby-bundler-cache-v3-${platform}-${engine}-${version}${cacheVersionSuffix}`
let key = `setup-ruby-bundler-cache-v4-${platform}-${engine}-${version}${cacheVersionSuffix}`
if (common.isHeadVersion(version)) {
if (engine !== 'jruby') {
@@ -255,8 +256,10 @@ __nccwpck_require__.r(__webpack_exports__);
/* harmony export */ "measure": () => (/* binding */ measure),
/* harmony export */ "isHeadVersion": () => (/* binding */ isHeadVersion),
/* harmony export */ "isStableVersion": () => (/* binding */ isStableVersion),
/* harmony export */ "hasBundlerDefaultGem": () => (/* binding */ hasBundlerDefaultGem),
/* harmony export */ "isBundler1Default": () => (/* binding */ isBundler1Default),
/* harmony export */ "isBundler2Default": () => (/* binding */ isBundler2Default),
/* harmony export */ "isBundler2dot2Default": () => (/* binding */ isBundler2dot2Default),
/* harmony export */ "floatVersion": () => (/* binding */ floatVersion),
/* harmony export */ "hashFile": () => (/* binding */ hashFile),
/* harmony export */ "supportedPlatforms": () => (/* binding */ supportedPlatforms),
@@ -324,8 +327,20 @@ function isStableVersion(rubyVersion) {
return /^\d+(\.\d+)*$/.test(rubyVersion)
}
function hasBundlerDefaultGem(engine, rubyVersion) {
return isBundler1Default(engine, rubyVersion) || isBundler2Default(engine, rubyVersion)
}
function isBundler1Default(engine, rubyVersion) {
return !isBundler2Default(engine, rubyVersion)
if (engine === 'ruby') {
return floatVersion(rubyVersion) >= 2.6 && floatVersion(rubyVersion) < 2.7
} else if (engine.startsWith('truffleruby')) {
return floatVersion(rubyVersion) < 21.0
} else if (engine === 'jruby') {
return false
} else {
return false
}
}
function isBundler2Default(engine, rubyVersion) {
@@ -340,6 +355,18 @@ function isBundler2Default(engine, rubyVersion) {
}
}
function isBundler2dot2Default(engine, rubyVersion) {
if (engine === 'ruby') {
return floatVersion(rubyVersion) >= 3.0
} else if (engine.startsWith('truffleruby')) {
return floatVersion(rubyVersion) >= 22.0
} else if (engine === 'jruby') {
return floatVersion(rubyVersion) >= 9.3
} else {
return false
}
}
function floatVersion(rubyVersion) {
const match = rubyVersion.match(/^\d+\.\d+/)
if (match) {
@@ -64866,13 +64893,6 @@ function getAvailableVersions(platform, engine) {
throw new Error(`Unsupported platform ${platform}`)
}
if (platform === 'ubuntu-22.04') {
const rubyVersions = rubyBuilderVersions['ruby']
return {
ruby: rubyVersions.slice(rubyVersions.indexOf('3.1.0')),
}[engine]
}
return rubyBuilderVersions[engine]
}
@@ -65624,7 +65644,7 @@ const windows = common.windows
const inputDefaults = {
'ruby-version': 'default',
'rubygems': 'default',
'bundler': 'default',
'bundler': 'Gemfile.lock',
'bundler-cache': 'false',
'working-directory': '.',
'cache-version': bundler.DEFAULT_CACHE_VERSION,
+12
View File
@@ -0,0 +1,12 @@
source "https://rubygems.org"
# Ruby < 2.3 only support Bundler 1, which no longer works with gem github:
if RUBY_VERSION >= '2.3'
unless Gem::Version.new(Bundler::VERSION) >= Gem::Version.new("2.2.0")
raise "Expected Bundler 2.2+ is used on Ruby >= 2.3"
end
# From https://github.com/ruby/setup-ruby/issues/358#issuecomment-1195899304
# Tests using github: and the repository uses a non-master default branch.
gem 'rack-test', github: 'rack/rack-test'
end
+1 -1
View File
@@ -12,7 +12,7 @@ const windows = common.windows
const inputDefaults = {
'ruby-version': 'default',
'rubygems': 'default',
'bundler': 'default',
'bundler': 'Gemfile.lock',
'bundler-cache': 'false',
'working-directory': '.',
'cache-version': bundler.DEFAULT_CACHE_VERSION,
-7
View File
@@ -17,13 +17,6 @@ export function getAvailableVersions(platform, engine) {
throw new Error(`Unsupported platform ${platform}`)
}
if (platform === 'ubuntu-22.04') {
const rubyVersions = rubyBuilderVersions['ruby']
return {
ruby: rubyVersions.slice(rubyVersions.indexOf('3.1.0')),
}[engine]
}
return rubyBuilderVersions[engine]
}