Sitelet https://github.com/zitadel/client-ruby/pull/98
Skip to content

feat: require Ruby 3.1 or newer - #98

Merged
mridang merged 1 commit into
mainfrom
build/drop-ruby-3-0-support
Sep 11, 2026
Merged

mridang merged 1 commit into
mainfrom
build/drop-ruby-3-0-support

Conversation

@mridang

@mridang mridang commented Sep 11, 2026 •

Copy link
Copy Markdown
Collaborator

This raises the minimum supported Ruby version to 3.1.

Description

This pull-request drops support for Ruby 3.0 and makes Ruby 3.1 the minimum supported version. It raises required_ruby_version in the gemspec to >= 3.1, aligns TargetRubyVersion in .rubocop.yml, removes 3.0 from the compatibility matrix in the integration workflow, and updates the minimum requirements section of the README to say Ruby 3.1 or higher. No library code changes.

Related Issue

Dependabot alert https://github.com/zitadel/client-ruby/security/dependabot/26 (excon, GHSA-48rx-c7pg-q66r). No separate issue.

Motivation and Context

Ruby 3.0 reached end of life on 23 April 2024 and no longer receives security fixes. Keeping it as the floor also blocks the open Dependabot security update for excon: the first patched release, excon 1.5.0, requires Ruby 3.1 or newer, so Dependabot's resolver currently fails against the 3.0 floor and cannot open a PR. Once this lands, Dependabot can bump excon to 1.5.0 on its own. That bump is intentionally not included here so it arrives through the normal Dependabot security-update flow.

This ships as a minor release rather than a major. Under VERSIONING.md the major version is aligned with the ZITADEL core major and only moves in lock-step with it, and dropping a runtime that has been end of life for over a year is treated as maintenance rather than a breaking feature change.

How Has This Been Tested?

RuboCop reports no offenses across the 38 project files under the new 3.1 target, run locally on Ruby 4.0 via devbox. The remaining compatibility matrix (3.1 through 4.0) is unchanged and was passing on main. Separately, excon 1.5.0 was resolved into the lockfile locally to confirm the follow-up Dependabot bump will work: Bundler resolves it cleanly, docker-api loads against it, and all 32 unit tests pass. That lockfile change was reverted and is not part of this PR.

Documentation:

README minimum requirements updated in this PR. No wiki changes required.

Checklist:

  • I have updated the documentation accordingly.
  • I have assigned the correct milestone or created one if non-existent.
  • I have correctly labeled this pull request.
  • I have linked the corresponding issue in this description.
  • I have requested a review from at least 2 reviewers
  • I have checked the base branch of this pull request
  • I have checked my code for any possible security vulnerabilities

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@mridang
mridang force-pushed the build/drop-ruby-3-0-support branch from dc07d54 to aa170fe Compare September 11, 2026 02:27
@mridang mridang changed the title build!: drop support for Ruby 3.0 feat: require Ruby 3.1 or newer Sep 11, 2026
@mridang mridang self-assigned this Sep 11, 2026
@mridang
mridang requested a balanced review from Copilot September 11, 2026 02:28

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The README remains inaccurate, and publishing this breaking compatibility change as a minor release conflicts with the documented versioning policy.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Raises the minimum supported Ruby version from 3.0 to 3.1.

Changes:

  • Updates the gem runtime requirement and RuboCop target.
  • Removes Ruby 3.0 from compatibility checks.
File summaries
File Description
zitadel-client.gemspec Requires Ruby 3.1+.
.rubocop.yml Targets Ruby 3.1 syntax.
.github/workflows/integration.yml Drops Ruby 3.0 compatibility checks.
Review details
  • Files reviewed: 3/3 changed files
  • Comments generated: 2
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread zitadel-client.gemspec
Comment thread zitadel-client.gemspec
@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Qodana for PHP

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked
☁️ View the detailed Qodana report

Contact Qodana team

Contact us at qodana-support@jetbrains.com

@mridang mridang added ruby Pull requests that update Ruby code area/ci CI/CD pipelines and release tooling labels Sep 11, 2026
Ruby 3.0 reached end of life on 23 April 2024 and no longer receives security fixes.
Raise the minimum supported Ruby to 3.1 by bumping required_ruby_version in the
gemspec, aligning the RuboCop target, dropping 3.0 from the compatibility matrix
and updating the README minimum requirements.

This also unblocks the Dependabot security update for excon (GHSA-48rx-c7pg-q66r).
The first patched release, excon 1.5.0, requires Ruby 3.1, so the resolver currently
fails against the 3.0 floor. The excon bump itself is left for Dependabot to open.
@mridang
mridang force-pushed the build/drop-ruby-3-0-support branch from 8fb1c26 to 639c469 Compare September 11, 2026 02:38
@mridang
mridang merged commit 1430a80 into main Sep 11, 2026
10 checks passed
github-actions Bot pushed a commit that referenced this pull request Sep 11, 2026
# [4.2.0](v4.1.4...v4.2.0) (2026-09-11)

### Features

* require Ruby 3.1 or newer ([#98](#98)) ([1430a80](1430a80))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/ci CI/CD pipelines and release tooling ruby Pull requests that update Ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants