fix(ci): align Ruby dependencies and verify release bundles - #394
Conversation
Bumps [rubyzip](https://github.com/rubyzip/rubyzip) from 2.4.1 to 3.4.0. - [Release notes](https://github.com/rubyzip/rubyzip/releases) - [Changelog](https://github.com/rubyzip/rubyzip/blob/main/Changelog.md) - [Commits](rubyzip/rubyzip@v2.4.1...v3.4.0) --- updated-dependencies: - dependency-name: rubyzip dependency-version: 3.4.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Quick104
left a comment
There was a problem hiding this comment.
One verified release blocker.
Reviewed by gpt-6.1-sol in T3 Code using the Codex provider; verification used GitHub CLI and a focused Bundler reproduction.
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
Code Review Completed! 🔥The code review was successfully completed based on your current configurations. Kody Guide: Usage and ConfigurationInteracting with Kody
Providing Context (Files & MCPs)Add these hints in your PR description (or a comment) to unlock deeper checks:
Current Kody ConfigurationReview OptionsThe following review options are enabled or disabled:
|
The rubyzip 3.4.0 update upgrades Fastlane and adds
rbs 4.2.0, which requires Ruby 3.3 or newer. The existing Ruby 3.2.9 pin made every Google Play release fail during frozen dependency installation.Pin the release runtime to Ruby 3.4.11, align the Gemfile and lockfile, update the Ruby setup action in CI and release workflows, and retain rubyzip 3.4.0 and Fastlane 2.240.1. Add a Release readiness job on pull requests and main pushes that installs the frozen bundle, loads the Fastlane lane and Play client, and builds both phone and TV release bundles through R8 and packaging.
Related issue: none.
Validation tasks: none; this changes release tooling, with no client behavior changes.
Validation: frozen Bundler 4.0.15 installation,
fastlane lanes, Play client loading, supply-chain policy checks, and workflow YAML parsing passed on Ruby 3.4.11. Both phone and TV release bundles (including R8 and packaging), unit tests, lint, and Kody review passed on046d3694: https://github.com/Silo-Server/silo-android/actions/runs/36616230490.Risk: the release runtime moves from Ruby 3.2 to 3.4. Signing and authenticated Google Play uploads require release secrets and are exercised by the release workflow.
AI disclosure: gpt-6.1-sol in T3 Code using the Codex provider; tooling: GitHub CLI, Bundler, Ruby, and Gradle through GitHub Actions.