Skip to content

build(deps): bump ruby.wasm runtime to 2.10.1 - #271

Merged
tas50 merged 1 commit into
mainfrom
build/ruby-wasm-2.10.1
Oct 4, 2026
Merged

tas50 merged 1 commit into
mainfrom
build/ruby-wasm-2.10.1

Conversation

@ramereth

@ramereth ramereth commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Move the pinned ruby.wasm runtime from 2.9.4 to 2.10.1, the current upstream release.

ruby.wasm 2.10.1 still builds the same CRuby 3.4.1, ships the same ruby-3.4-wasm32-unknown-wasip1-full.tar.gz asset, and extracts to the same tree. The changes since 2.9.4 are in its build tooling. They are wasi-vfs 0.6.2, the wasmtime 40 stack, and the removal of wizer pre-initialization.

Cinc Workstation packages this same release for the cinc-ng preview, and its build refuses a module whose hash differs from rubyWasmBinarySHA256. So this pin has to move and be released before Workstation can take 2.10.1.

  • Set rubyWasmVersion to 2.10.1 in cli/policyfile/rubyeval/loader.go
  • Pin rubyWasmSHA256 to the 2.10.1 release archive so a tampered download is still rejected
  • Pin rubyWasmBinarySHA256 to the extracted usr/local/bin/ruby module so cached and packaged copies are checked against the new release

A release after this merges lets the omnibus-software cinc-ng and ruby-wasm definitions move together in omnibus-software!302.

References:

ruby.wasm 2.10.1 is out. Its CRuby 3.4 "full" build is still Ruby 3.4.1
with the same asset name and layout; only the build tooling changed
(wasi-vfs 0.6.2, wasmtime 40, no wizer pre-initialization).

Cinc Workstation packages the same release for cinc-ng, and its build
requires the module to match rubyWasmBinarySHA256, so this pin moves first.

- Pin rubyWasmVersion to 2.10.1 with the release archive's SHA-256 and
  the SHA-256 of the extracted usr/local/bin/ruby module

https://github.com/ruby/ruby.wasm/releases/tag/2.10.1

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Lance Albertson <lance@osuosl.org>
@sourcery-ai

sourcery-ai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

The PR upgrades the pinned ruby.wasm runtime to 2.10.1 and updates both archive and extracted-module checksums, preserving download, extraction, and cache-integrity validation for the existing CRuby 3.4.1 WASI asset.

Sequence diagram for ruby.wasm download and integrity validation

sequenceDiagram
    participant Loader
    participant Cache
    participant GitHub
    participant Archive
    participant RubyWasm

    Loader->>Cache: Load cached rubyWasmTreeBinary
    Cache-->>Loader: Cached module
    Loader->>RubyWasm: Verify rubyWasmBinarySHA256
    alt Cache miss or binary hash mismatch
        Loader->>GitHub: Download rubyWasmURL
        GitHub-->>Loader: rubyWasmAsset
        Loader->>Archive: Verify rubyWasmSHA256
        Archive-->>Loader: Checksum valid
        Loader->>Archive: Extract rubyWasmTreeBinary
        Archive-->>Loader: rubyWasm module
        Loader->>RubyWasm: Verify rubyWasmBinarySHA256
    end
    Loader->>RubyWasm: Execute validated CRuby 3.4.1 module
Loading

File-Level Changes

Change Details Files
Update the pinned ruby.wasm runtime release and its integrity metadata.
  • Advance the runtime version from 2.9.4 to 2.10.1 while retaining the existing full WASI asset.
  • Replace the release archive SHA-256 checksum.
  • Replace the extracted CRuby wasm binary SHA-256 checksum used for cache and package validation.
cli/policyfile/rubyeval/loader.go

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. The pinned Ruby runtime can change policy evaluation or dependency-resolution results, potentially causing an incorrect policy artifact or lockfile to be generated. Reverting restores the previous runtime, but artifacts produced while the new version was active would need to be regenerated.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@ramereth
ramereth requested a review from tas50 October 3, 2026 23:24
@tas50
tas50 merged commit 4e1bb78 into main Oct 4, 2026
7 checks passed
@tas50
tas50 deleted the build/ruby-wasm-2.10.1 branch October 4, 2026 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants