ruby
4 guardrails, all at version v1.
| Guardrail | Default severity | What it checks |
|---|---|---|
ruby/lockfile-committed | warning | The project commits Gemfile.lock, so an install of the same commit resolves the same gem versions. |
ruby/no-git-dependencies | warning | No gem the manifests declare is fetched from a git repository instead of a gem source. The Gemfile is Ruby code, not a declaration, so it is read by pattern. A git gem that is found is a real finding, but finding none doesn't prove there are none: a gem added inside a condition, a loop or an eval isn't detected. |
ruby/single-gem-source | error | The Gemfile resolves gems from at most one source, and that source is one the repository trusts. The Gemfile is Ruby code, not a declaration, so it is read by pattern. A second source that is found is a real finding, but finding only one doesn't prove there is only one: a source named inside a condition, a loop or an eval isn't detected. |
ruby/version-declared | warning | The project declares the Ruby version it is built and run against, and that version is no older than the configured floor. |
Shared inputs
Every ruby guardrail declares these inputs. Individual guardrails can add their own.
| Input | Description | Default |
|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . |
Shared collectors
Every ruby guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.
| Collector | Gathers |
|---|---|
ruby | The Bundler project in the project directory: the Ruby version it asks for, the gem sources it resolves from, the gems each manifest declares with their groups and origins, and the lock file beside them. The Gemfile is Ruby rather than a declaration, so what it declares conditionally is not seen and scanned says so. |
You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.