Jens-G opened a new pull request, #3982: URL: https://github.com/apache/thrift/pull/3982
[THRIFT-6395](https://issues.apache.org/jira/browse/THRIFT-6395) The `Release Ruby Gem` workflow has never published a gem. The runs for 0.24.0 and 0.25.0 stopped at the trusted publishing step, and both gems were pushed by hand. With a trusted publisher on RubyGems.org it would still fail one step later: `rubygems/release-gem` runs `bundle exec rake release`, and the job never installs the bundle, since THRIFT-5965 turned `bundler-cache` off. **Changes to `.github/workflows/release_ruby.yml`** - A step installs the bundle, frozen to `Gemfile.lock`. It does not use `bundler-cache`, so the publishing job restores no cache. - A step checks that the run is for a `vX.Y.Z` release tag and that `thrift.gemspec` has that version, as `release_rust.yml` does for the crate. Bundler's release task pushes the version tag if it does not exist yet, so without the check a manual run from master would push `v0.26.0` and publish 0.26.0. - `contents: read` instead of `write`, so the job cannot push a tag. - Pre-releases are skipped, as in the other publishing workflows. `doc/ReleaseManagement.md` gets a `[ruby]` entry. **Verification** A script replays the job's steps from the workflow file in `ruby:4.0`, with Bundler 2.2.34, the version setup-ruby installs from `Gemfile.lock`. Nothing can be published: `gem_push=no`, and the scratch repository has no remote. | Case | master | this PR | |---|---|---| | release, tag `v0.26.0` | `Bundler::GemNotFound` | check passes, bundle installs, `thrift-0.26.0.gem` built, "Tag v0.26.0 has already been created." | | manual run from `master` | `Bundler::GemNotFound` | stops at the check: not a release tag | | tag `v0.25.0` on a 0.26.0 tree | `Bundler::GemNotFound` | stops at the check: version mismatch | With the install step but without the check, a run from `master` builds the gem and then runs `git push` for the new tag, which fails in the replay only because there is no remote. actionlint and zizmor (`--persona regular`, with a token) report nothing. After this is merged, RubyGems.org still needs a trusted publisher for `apache/thrift`, workflow `release_ruby.yml`, environment `release`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
