Ruby dependencies are locked
ruby/lockfile-committed@v1
The project commits Gemfile.lock, so an install of the same commit resolves the same gem versions.
| Id | ruby/lockfile-committed |
| Version | v1 |
| Category | ruby |
| Default severity | warning |
| Interpreter | python3 |
| Timeout | 30 seconds |
| Violations tolerated | 0 |
| Collects | ruby |
Collectors
This guardrail gathers nothing itself. It depends on the collectors below, which the CLI runs once per build before any check, and reads what they found out of GUARDRAIL_FACTS. A collector that collects nothing skips this guardrail rather than failing it.
| Collector | Gathers | Inputs it is given |
|---|---|---|
ruby | The Bundler project in the project directory: the Ruby version it asks for, the gem sources it resolves from, the gems each manifest declares with their groups and origins, and the lock file beside them. The Gemfile is Ruby rather than a declaration, so what it declares conditionally is not seen and scanned says so. | projectDir |
The inputs above are this guardrail's own, passed straight through. Configuring one in buildnote.json changes what is collected, and two guardrails configured the same way share the one collection.
Configuration
{
"guardrails": {
"failOn": "error",
"comment": true,
"checks": [
{
"use": "ruby/lockfile-committed@v1",
"severity": "warning",
"with": {
"projectDir": "."
},
"exemptions": []
}
]
}
}Inputs
| Input | Description | Default | Environment variable |
|---|---|---|---|
projectDir | Directory holding the project, relative to the directory the CLI runs in. | . | GUARDRAIL_INPUT_PROJECTDIR |
How to fix
Resolve the gems once and commit what Bundler writes beside the Gemfile:
bundle install
git add Gemfile.lockA ~> or >= requirement resolves to whatever RubyGems serves that day, so an application without a lock file resolves differently on every deploy and the gems that shipped are not the gems that were reviewed.
More in ruby
ruby/no-git-dependencies. No gem the manifests declare is fetched from a git repository rather than from a gem source. TheGemfileis Ruby rather than a declaration and is read by pattern, so a git gem that is found is a real finding, but finding none is not proof that there is none: a gem added inside a condition, a loop or anevalis not seen.ruby/single-gem-source. TheGemfileresolves gems from at most one source, and that source is one the repository trusts. TheGemfileis Ruby rather than a declaration and is read by pattern, so a second source that is found is a real finding, but finding one source is not proof that there is only one: a source named inside a condition, a loop or anevalis not seen.ruby/version-declared. The project declares the Ruby version it is built and run against, and that version is no older than the configured floor.