Repository navigation
Conversation
dependency:orphans and dependency:audit now fail when gemfiles/*.gemfile.lock has no matching *.gemfile, instead of silently auditing dead lockfiles.
Its removal condition is met: the active ruby_llm appraisals resolve 2.0.0 and the orphaned 1.x lockfiles that needed the suppression are gone.
|
✅ All CI checks and tests passed. 🎉 All green!🧪 All tests passed 🎯 Code Coverage (details) 🔗 Commit SHA: 35288a7 | Docs | View more details | Give us feedback! |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The safeguard is correctly shared across both dependency checks and has focused unit coverage; the remaining comment cleanup is non-blocking.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds CI safeguards against lockfiles whose companion Gemfiles were removed.
Changes:
- Adds reusable orphan-lockfile detection with unit tests.
- Fails dependency orphan and audit tasks with actionable errors.
- Documents remediation and removes the obsolete RubyLLM advisory exception.
| File | Description |
|---|---|
tasks/lockfile.rb |
Adds companion Gemfile and orphan detection APIs. |
tasks/dependency_audit.rake |
Rejects orphaned lockfiles before auditing. |
appraisal/orphans.rb |
Reports orphaned lockfiles and fails the task. |
spec/tasks/lockfile_spec.rb |
Tests validation and orphan detection. |
docs/DevelopmentGuide.md |
Documents orphan remediation. |
.bundler-audit.yml |
Removes the satisfied RubyLLM CVE exception. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
Codex Review: Didn't find any major issues. Can't wait for the next one! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
CI's changelog/check job failed on PR #6422 reporting that the pull request modifies CHANGELOG.md directly, but the pull request has no CHANGELOG.md changes: its branch forked at the recorded base SHA and master advanced afterwards with the "Bump to version 2.44.0" release commit. Root cause: the job checks out the merge ref, whose history contains base-branch commits, while the diff anchor came from github.event.pull_request.base.sha, the base recorded for the pull request. Once the base branch moves past that recording, the BASE_SHA...HEAD range includes base-branch release commits and the gate flags the base branch's CHANGELOG.md bump as a pull request change. The task was to fix the defect reported by the failing CI on PR #6422 only. Diffing the pull request head (github.event.pull_request.head.sha) from its merge base with the current base tip (refs/remotes/origin/${github.base_ref}) instead is my own design decision; this matches the pull request's Files changed view and keeps base-branch-only commits out of the range. The existence and reachability validation blocks for HEAD_SHA and BASE_REF are my own decision, mirroring the existing validation style. Error message text and all other script logic are unchanged. Verified with shellcheck, yamllint --strict, the unreleased:lint and unreleased:render tasks, and scratch-clone runs reproducing the failing CI inputs plus the release-branch, changelog_fix, violation and validation cases. actionlint is unavailable in this environment; CI runs it on push.

What does this PR do?
Fails
rake dependency:orphansandrake dependency:auditwhen agemfiles/*.gemfile.lockhas no matching*.gemfile. The pairing rule lives in a newLockfilecompanion API (Lockfile#orphaned?,Lockfile.orphaned_lockfile_paths) with unit tests. The failure mode is documented indocs/DevelopmentGuide.md. The obsolete ruby_llm advisory entry is dropped from.bundler-audit.ymlsince the active ruby_llm appraisals resolve 2.0.0, which contains the fix for that advisory. The changelog release-only check now diffs the pull request head from its merge base with the current base tip, matching the pull request's Files changed view.Motivation:
PR #6394 removed the RubyLLM 1.x gemfiles and left the five matching lockfiles in place.
dependency:orphansmatched*.gemfileonly and could not see the orphaned lockfiles.dependency:auditscanned them on every PR. Once ruby-advisory-db published two ruby_llm advisories, every PR'sbundler-auditjob failed with 10 findings from those lockfiles. PR #6421 removed the orphaned lockfiles from master. These gates make the same orphaning fail CI, with messages naming the lockfiles to delete. The changelog release-only check anchored its diff at the base SHA recorded for the pull request. Once master advanced past that SHA with the 2.44.0 release commit, the check flagged the release's CHANGELOG.md bump as this pull request's change and failed the changelog/check job.Change log entry
No.
Additional Notes:
Follow-up to #6421.
How to test the change?