feat: require Ruby 3.1 or newer - #98
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
dc07d54 to
aa170fe
Compare
There was a problem hiding this comment.
🟡 Changes recommended
The README remains inaccurate, and publishing this breaking compatibility change as a minor release conflicts with the documented versioning policy.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Raises the minimum supported Ruby version from 3.0 to 3.1.
Changes:
- Updates the gem runtime requirement and RuboCop target.
- Removes Ruby 3.0 from compatibility checks.
File summaries
| File | Description |
|---|---|
zitadel-client.gemspec |
Requires Ruby 3.1+. |
.rubocop.yml |
Targets Ruby 3.1 syntax. |
.github/workflows/integration.yml |
Drops Ruby 3.0 compatibility checks. |
Review details
- Files reviewed: 3/3 changed files
- Comments generated: 2
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Qodana for PHPIt seems all right 👌 No new problems were found according to the checks applied 💡 Qodana analysis was run in the pull request mode: only the changed files were checked Contact Qodana teamContact us at qodana-support@jetbrains.com
|
Ruby 3.0 reached end of life on 23 April 2024 and no longer receives security fixes. Raise the minimum supported Ruby to 3.1 by bumping required_ruby_version in the gemspec, aligning the RuboCop target, dropping 3.0 from the compatibility matrix and updating the README minimum requirements. This also unblocks the Dependabot security update for excon (GHSA-48rx-c7pg-q66r). The first patched release, excon 1.5.0, requires Ruby 3.1, so the resolver currently fails against the 3.0 floor. The excon bump itself is left for Dependabot to open.
8fb1c26 to
639c469
Compare
# [4.2.0](v4.1.4...v4.2.0) (2026-09-11) ### Features * require Ruby 3.1 or newer ([#98](#98)) ([1430a80](1430a80))
This raises the minimum supported Ruby version to 3.1.
Description
This pull-request drops support for Ruby 3.0 and makes Ruby 3.1 the minimum supported version. It raises
required_ruby_versionin the gemspec to>= 3.1, alignsTargetRubyVersionin.rubocop.yml, removes 3.0 from the compatibility matrix in the integration workflow, and updates the minimum requirements section of the README to say Ruby 3.1 or higher. No library code changes.Related Issue
Dependabot alert https://github.com/zitadel/client-ruby/security/dependabot/26 (excon, GHSA-48rx-c7pg-q66r). No separate issue.
Motivation and Context
Ruby 3.0 reached end of life on 23 April 2024 and no longer receives security fixes. Keeping it as the floor also blocks the open Dependabot security update for
excon: the first patched release, excon 1.5.0, requires Ruby 3.1 or newer, so Dependabot's resolver currently fails against the 3.0 floor and cannot open a PR. Once this lands, Dependabot can bump excon to 1.5.0 on its own. That bump is intentionally not included here so it arrives through the normal Dependabot security-update flow.This ships as a minor release rather than a major. Under
VERSIONING.mdthe major version is aligned with the ZITADEL core major and only moves in lock-step with it, and dropping a runtime that has been end of life for over a year is treated as maintenance rather than a breaking feature change.How Has This Been Tested?
RuboCop reports no offenses across the 38 project files under the new 3.1 target, run locally on Ruby 4.0 via devbox. The remaining compatibility matrix (3.1 through 4.0) is unchanged and was passing on main. Separately, excon 1.5.0 was resolved into the lockfile locally to confirm the follow-up Dependabot bump will work: Bundler resolves it cleanly, docker-api loads against it, and all 32 unit tests pass. That lockfile change was reverted and is not part of this PR.
Documentation:
README minimum requirements updated in this PR. No wiki changes required.
Checklist: