Jens Geyer created THRIFT-6395:
----------------------------------
Summary: Fix the Ruby gem release workflow and limit it to release
tags
Key: THRIFT-6395
URL: https://issues.apache.org/jira/browse/THRIFT-6395
Project: Thrift
Issue Type: Bug
Components: Build Process, Ruby - Library
Reporter: Jens Geyer
The {{Release Ruby Gem}} workflow ({{.github/workflows/release_ruby.yml}}) has
not published a gem yet. For 0.24.0 and 0.25.0 it stopped at the trusted
publishing step, because RubyGems.org has no trusted publisher for it, and both
gems were pushed by hand.
With a trusted publisher in place it would still fail one step later.
{{rubygems/release-gem}} runs {{bundle exec rake release}}, but the job never
installs the bundle: THRIFT-5965 turned {{bundler-cache}} off, and nothing
replaced it. Replaying the job in {{ruby:4.0}} with Bundler 2.2.34, the version
setup-ruby installs from {{Gemfile.lock}}:
{noformat}
Could not find rack-2.2.23, rack-test-0.8.3, rspec-3.13.2, ... in locally
installed gems (Bundler::GemNotFound)
{noformat}
Installing the bundle brings up a second problem. The workflow can also be
started by hand, from any branch, and Bundler's release task creates and pushes
the version tag before it publishes, if that tag does not exist yet. Started
from master, it would push a v0.26.0 tag and publish 0.26.0.
h2. Change
* Install the bundle, frozen to {{Gemfile.lock}}, in a step of its own. Not
through {{bundler-cache}}: a job that publishes should not restore a cache.
* Check that the run is for a release tag {{vX.Y.Z}} and that
{{thrift.gemspec}} has the same version, as {{release_rust.yml}} does for the
crate. The tag then always exists, and the release task never creates one.
* Give the job {{contents: read}} only, so that it cannot push a tag.
* Skip pre-releases, like the other publishing workflows.
* Describe the workflow in {{doc/ReleaseManagement.md}}.
_Drafted with AI assistance (Claude Opus 5.5)._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)