Skip to content

Add Gemfile.lock lockfile-hygiene scan to pre-commit hook - #810

Merged
shrutiburman merged 2 commits into
mainfrom
lockfile-hygiene-ruby
Sep 23, 2026
Merged

shrutiburman merged 2 commits into
mainfrom
lockfile-hygiene-ruby

Conversation

@shrutiburman

Copy link
Copy Markdown
Contributor

Summary

  • Mirrors the gems-lockfile-hygiene CI gate locally: rewrites an internal Artifactory gem-mirror URL in a staged Gemfile.lock to rubygems.org before the commit lands, the same way twilio-node does for package-lock.json.
  • githooks/pre-commit and the Makefile githooks target already existed on main; this only adds the actual hygiene scan.

Test plan

  • make test run locally via the hook on commit (377 examples, 0 failures)
  • Verified the new scan reports clean against the current Gemfile.lock

🤖 Generated with Claude Code

shrutiburman and others added 2 commits September 22, 2026 12:43
Mirrors the gems-lockfile-hygiene CI gate locally: rewrites an internal
Artifactory gem-mirror URL in a staged Gemfile.lock to rubygems.org before
the commit lands, the same way twilio-node does for package-lock.json.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
rubocop's ConfigStore does a non-atomic `@path_cache[dir] ||= ...`
read-modify-write (config_store.rb). --parallel runs worker threads via
Parallel.in_threads, and JRuby's true parallel threads (no GIL) can expose
that race, handing a thread a nil config path and crashing with "no
implicit conversion of nil into String" in File.absolute_path when
scanning examples/. CRuby's GIL happens to serialize the Hash access
enough in practice to avoid it, which is why only the jruby-9.4 leg failed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@shrutiburman
shrutiburman merged commit 1c69a9a into main Sep 23, 2026
14 of 16 checks passed
@shrutiburman
shrutiburman deleted the lockfile-hygiene-ruby branch September 23, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants