Jens Geyer created THRIFT-6395:
----------------------------------

             Summary: Fix the Ruby gem release workflow and limit it to release 
tags
                 Key: THRIFT-6395
                 URL: https://issues.apache.org/jira/browse/THRIFT-6395
             Project: Thrift
          Issue Type: Bug
          Components: Build Process, Ruby - Library
            Reporter: Jens Geyer


The {{Release Ruby Gem}} workflow ({{.github/workflows/release_ruby.yml}}) has 
not published a gem yet. For 0.24.0 and 0.25.0 it stopped at the trusted 
publishing step, because RubyGems.org has no trusted publisher for it, and both 
gems were pushed by hand.

With a trusted publisher in place it would still fail one step later. 
{{rubygems/release-gem}} runs {{bundle exec rake release}}, but the job never 
installs the bundle: THRIFT-5965 turned {{bundler-cache}} off, and nothing 
replaced it. Replaying the job in {{ruby:4.0}} with Bundler 2.2.34, the version 
setup-ruby installs from {{Gemfile.lock}}:
{noformat}
Could not find rack-2.2.23, rack-test-0.8.3, rspec-3.13.2, ... in locally 
installed gems (Bundler::GemNotFound)
{noformat}

Installing the bundle brings up a second problem. The workflow can also be 
started by hand, from any branch, and Bundler's release task creates and pushes 
the version tag before it publishes, if that tag does not exist yet. Started 
from master, it would push a v0.26.0 tag and publish 0.26.0.

h2. Change
* Install the bundle, frozen to {{Gemfile.lock}}, in a step of its own. Not 
through {{bundler-cache}}: a job that publishes should not restore a cache.
* Check that the run is for a release tag {{vX.Y.Z}} and that 
{{thrift.gemspec}} has the same version, as {{release_rust.yml}} does for the 
crate. The tag then always exists, and the release task never creates one.
* Give the job {{contents: read}} only, so that it cannot push a tag.
* Skip pre-releases, like the other publishing workflows.
* Describe the workflow in {{doc/ReleaseManagement.md}}.

_Drafted with AI assistance (Claude Opus 5.5)._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to