Skip to content

Reject orphaned lockfiles whose Gemfile was removed - #6422

Open
p-datadog wants to merge 11 commits into
masterfrom
dependency/orphaned-lockfile-gate
Open

p-datadog wants to merge 11 commits into
masterfrom
dependency/orphaned-lockfile-gate

Conversation

@p-datadog

@p-datadog p-datadog commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

What does this PR do?

Fails rake dependency:orphans and rake dependency:audit when a gemfiles/*.gemfile.lock has no matching *.gemfile. The pairing rule lives in a new Lockfile companion API (Lockfile#orphaned?, Lockfile.orphaned_lockfile_paths) with unit tests. The failure mode is documented in docs/DevelopmentGuide.md. The obsolete ruby_llm advisory entry is dropped from .bundler-audit.yml since the active ruby_llm appraisals resolve 2.0.0, which contains the fix for that advisory. The changelog release-only check now diffs the pull request head from its merge base with the current base tip, matching the pull request's Files changed view.

Motivation:

PR #6394 removed the RubyLLM 1.x gemfiles and left the five matching lockfiles in place. dependency:orphans matched *.gemfile only and could not see the orphaned lockfiles. dependency:audit scanned them on every PR. Once ruby-advisory-db published two ruby_llm advisories, every PR's bundler-audit job failed with 10 findings from those lockfiles. PR #6421 removed the orphaned lockfiles from master. These gates make the same orphaning fail CI, with messages naming the lockfiles to delete. The changelog release-only check anchored its diff at the base SHA recorded for the pull request. Once master advanced past that SHA with the 2.44.0 release commit, the check flagged the release's CHANGELOG.md bump as this pull request's change and failed the changelog/check job.

Change log entry

No.

Additional Notes:

Follow-up to #6421.

How to test the change?

  • Unit tests added
  • Existing CI

dependency:orphans and dependency:audit now fail when gemfiles/*.gemfile.lock
has no matching *.gemfile, instead of silently auditing dead lockfiles.
Its removal condition is met: the active ruby_llm appraisals resolve 2.0.0
and the orphaned 1.x lockfiles that needed the suppression are gone.
@p-datadog p-datadog added the AI Generated Largely based on code generated by an AI or LLM. This label is the same across all dd-trace-* repos label Oct 5, 2026
@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Tests

✅ All CI checks and tests passed.

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🎯 Code Coverage (details)
• Patch Coverage: 100.00%
• Overall Coverage: 90.65% (-0.02%)

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 35288a7 | Docs | View more details | Give us feedback!

@p-datadog
p-datadog marked this pull request as ready for review October 5, 2026 17:22
@p-datadog
p-datadog requested a review from a team as a code owner October 5, 2026 17:22
@p-datadog
p-datadog requested review from vpellan and removed request for a team October 5, 2026 17:22
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T17:54:31.166560Z 3d9a6ca Manual request
🔒 Security Review ✅ Completed 2026-10-05T17:53:33.234451Z 3d9a6ca Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@p-datadog

Copy link
Copy Markdown
Member Author

@codex review

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The safeguard is correctly shared across both dependency checks and has focused unit coverage; the remaining comment cleanup is non-blocking.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Adds CI safeguards against lockfiles whose companion Gemfiles were removed.

Changes:

  • Adds reusable orphan-lockfile detection with unit tests.
  • Fails dependency orphan and audit tasks with actionable errors.
  • Documents remediation and removes the obsolete RubyLLM advisory exception.
File Description
tasks/​lockfile.rb Adds companion Gemfile and orphan detection APIs.
tasks/​dependency_audit.rake Rejects orphaned lockfiles before auditing.
appraisal/​orphans.rb Reports orphaned lockfiles and fails the task.
spec/​tasks/​lockfile_spec.rb Tests validation and orphan detection.
docs/​DevelopmentGuide.md Documents orphan remediation.
.bundler-audit.yml Removes the satisfied RubyLLM CVE exception.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tasks/lockfile.rb
@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 3d9a6ca183

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 3d9a6ca183

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

CI's changelog/check job failed on PR #6422 reporting that the pull
request modifies CHANGELOG.md directly, but the pull request has no
CHANGELOG.md changes: its branch forked at the recorded base SHA and
master advanced afterwards with the "Bump to version 2.44.0" release
commit.

Root cause: the job checks out the merge ref, whose history contains
base-branch commits, while the diff anchor came from
github.event.pull_request.base.sha, the base recorded for the pull
request. Once the base branch moves past that recording, the
BASE_SHA...HEAD range includes base-branch release commits and the gate
flags the base branch's CHANGELOG.md bump as a pull request change.

The task was to fix the defect reported by the failing CI on PR #6422
only. Diffing the pull request head
(github.event.pull_request.head.sha) from its merge base with the
current base tip (refs/remotes/origin/${github.base_ref}) instead is
my own design decision; this matches the pull request's Files changed
view and keeps base-branch-only commits out of the range. The
existence and reachability validation blocks for HEAD_SHA and
BASE_REF are my own decision, mirroring the existing validation
style. Error message text and all other script logic are unchanged.

Verified with shellcheck, yamllint --strict, the unreleased:lint and
unreleased:render tasks, and scratch-clone runs reproducing the
failing CI inputs plus the release-branch, changelog_fix, violation
and validation cases. actionlint is unavailable in this environment;
CI runs it on push.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI Generated Largely based on code generated by an AI or LLM. This label is the same across all dd-trace-* repos

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants