[ 
https://issues.apache.org/jira/browse/THRIFT-6395?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jens Geyer resolved THRIFT-6395.
--------------------------------
    Fix Version/s: 0.26.0
         Assignee: Jens Geyer
       Resolution: Fixed

> Fix the Ruby gem release workflow and limit it to release tags
> --------------------------------------------------------------
>
>                 Key: THRIFT-6395
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6395
>             Project: Thrift
>          Issue Type: Bug
>          Components: Build Process, Ruby - Library
>            Reporter: Jens Geyer
>            Assignee: Jens Geyer
>            Priority: Major
>             Fix For: 0.26.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> The {{Release Ruby Gem}} workflow ({{.github/workflows/release_ruby.yml}}) 
> has not published a gem yet. For 0.24.0 and 0.25.0 it stopped at the trusted 
> publishing step, because RubyGems.org has no trusted publisher for it, and 
> both gems were pushed by hand.
> With a trusted publisher in place it would still fail one step later. 
> {{rubygems/release-gem}} runs {{bundle exec rake release}}, but the job never 
> installs the bundle: THRIFT-5965 turned {{bundler-cache}} off, and nothing 
> replaced it. Replaying the job in {{ruby:4.0}} with Bundler 2.2.34, the 
> version setup-ruby installs from {{Gemfile.lock}}:
> {noformat}
> Could not find rack-2.2.23, rack-test-0.8.3, rspec-3.13.2, ... in locally 
> installed gems (Bundler::GemNotFound)
> {noformat}
> Installing the bundle brings up a second problem. The workflow can also be 
> started by hand, from any branch, and Bundler's release task creates and 
> pushes the version tag before it publishes, if that tag does not exist yet. 
> Started from master, it would push a v0.26.0 tag and publish 0.26.0.
> h2. Change
> * Install the bundle, frozen to {{Gemfile.lock}}, in a step of its own. Not 
> through {{bundler-cache}}: a job that publishes should not restore a cache.
> * Check that the run is for a release tag {{vX.Y.Z}} and that 
> {{thrift.gemspec}} has the same version, as {{release_rust.yml}} does for the 
> crate. The tag then always exists, and the release task never creates one.
> * Give the job {{contents: read}} only, so that it cannot push a tag.
> * Skip pre-releases, like the other publishing workflows.
> * Describe the workflow in {{doc/ReleaseManagement.md}}.
> _Drafted with AI assistance (Claude Opus 5.5)._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to