Skip to content

Fix Dependabot bundler jobs failing on gemspec constant lookup - #428

Merged
markdorison merged 1 commit into
mainfrom
gemspec-dependabot-constant
Sep 18, 2026
Merged

markdorison merged 1 commit into
mainfrom
gemspec-dependabot-constant

Conversation

@markdorison

Copy link
Copy Markdown
Contributor

What

Compute the release Lua script list in ruby/ci-queue.gemspec with Dir.glob('lib/ci/queue/redis/*.lua', base: __dir__) instead of going through CI::Queue::RELEASE_SCRIPTS_ROOT. Drops the now unused require 'pathname'.

Why

Every Dependabot bundler job for ruby/ has failed since at least 2025-08-11, most recently the three security updates for json, msgpack and concurrent-ruby after #427 merged:

uninitialized constant CI
>  dir = Pathname.new(CI::Queue::RELEASE_SCRIPTS_ROOT).relative_path_from(...)

Dependabot's GemspecSanitizer wraps each require in begin/rescue LoadError/end and evaluates the gemspec in a checkout without lib/ci/queue/version.rb. It rewrites spec.version = and spec.files = to literals, so the top-level Lua glob was the only thing left that needed the constant, and it raised before the spec block ran. Dependabot reported dependency_file_not_evaluatable and could not open any Bundler PR, security or otherwise.

Testing

Reproduced locally by applying the sanitizer's require rewrite to the gemspec and loading it with an empty gem path: the old gemspec fails with uninitialized constant Gem::Specification::CI, the new one loads. With the Lua scripts copied into lib/ci/queue/redis/, spec.files contains the same six Lua paths as before the change.

Once merged, the three failing Dependabot security runs should re-fire on the next push to main and open PRs.

Every Dependabot bundler job for ruby/ has failed since at least
2025-08-11 with:

    uninitialized constant CI
    >  dir = Pathname.new(CI::Queue::RELEASE_SCRIPTS_ROOT)...

Dependabot's GemspecSanitizer wraps each `require` in a rescue
LoadError block and evaluates the gemspec in a checkout without
lib/ci/queue/version.rb. spec.version and spec.files are rewritten to
literals, so the only thing that still needs the constant is the
top-level Lua glob. That line raises before the spec block runs, and
Dependabot reports dependency_file_not_evaluatable. No Bundler update
PR, including the open security updates for json, msgpack and
concurrent-ruby, has been able to open.

Glob the release scripts relative to __dir__ instead. Same paths in
spec.files (verified identical with the Lua files copied in), and the
gemspec now loads under a Dependabot-style evaluation with the require
rescued and no gems installed. The pathname require is no longer
needed.

Assisted-By: devx/6b388d1b-b275-4664-9297-6db9839a7769
@markdorison markdorison self-assigned this Sep 18, 2026
@markdorison
markdorison marked this pull request as ready for review September 18, 2026 21:06
@markdorison
markdorison merged commit bc68d99 into main Sep 18, 2026
34 checks passed

This branch was successfully deployed

1 active deployment
rubygems — d6c2f032 Deployed Sep 18, 2026 by shopify-shipit[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants