Fix Dependabot bundler jobs failing on gemspec constant lookup - #428
Merged
Merged
Conversation
Every Dependabot bundler job for ruby/ has failed since at least
2025-08-11 with:
uninitialized constant CI
> dir = Pathname.new(CI::Queue::RELEASE_SCRIPTS_ROOT)...
Dependabot's GemspecSanitizer wraps each `require` in a rescue
LoadError block and evaluates the gemspec in a checkout without
lib/ci/queue/version.rb. spec.version and spec.files are rewritten to
literals, so the only thing that still needs the constant is the
top-level Lua glob. That line raises before the spec block runs, and
Dependabot reports dependency_file_not_evaluatable. No Bundler update
PR, including the open security updates for json, msgpack and
concurrent-ruby, has been able to open.
Glob the release scripts relative to __dir__ instead. Same paths in
spec.files (verified identical with the Lua files copied in), and the
gemspec now loads under a Dependabot-style evaluation with the require
rescued and no gems installed. The pathname require is no longer
needed.
Assisted-By: devx/6b388d1b-b275-4664-9297-6db9839a7769
markdorison
marked this pull request as ready for review
September 18, 2026 21:06
nikita8
approved these changes
Sep 18, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Compute the release Lua script list in
ruby/ci-queue.gemspecwithDir.glob('lib/ci/queue/redis/*.lua', base: __dir__)instead of going throughCI::Queue::RELEASE_SCRIPTS_ROOT. Drops the now unusedrequire 'pathname'.Why
Every Dependabot bundler job for
ruby/has failed since at least 2025-08-11, most recently the three security updates forjson,msgpackandconcurrent-rubyafter #427 merged:Dependabot's
GemspecSanitizerwraps eachrequireinbegin/rescue LoadError/endand evaluates the gemspec in a checkout withoutlib/ci/queue/version.rb. It rewritesspec.version =andspec.files =to literals, so the top-level Lua glob was the only thing left that needed the constant, and it raised before the spec block ran. Dependabot reporteddependency_file_not_evaluatableand could not open any Bundler PR, security or otherwise.Testing
Reproduced locally by applying the sanitizer's require rewrite to the gemspec and loading it with an empty gem path: the old gemspec fails with
uninitialized constant Gem::Specification::CI, the new one loads. With the Lua scripts copied intolib/ci/queue/redis/,spec.filescontains the same six Lua paths as before the change.Once merged, the three failing Dependabot security runs should re-fire on the next push to
mainand open PRs.