Repository navigation
build(deps): bump ruby.wasm runtime to 2.10.1 - #271
Merged
Merged
Conversation
ruby.wasm 2.10.1 is out. Its CRuby 3.4 "full" build is still Ruby 3.4.1 with the same asset name and layout; only the build tooling changed (wasi-vfs 0.6.2, wasmtime 40, no wizer pre-initialization). Cinc Workstation packages the same release for cinc-ng, and its build requires the module to match rubyWasmBinarySHA256, so this pin moves first. - Pin rubyWasmVersion to 2.10.1 with the release archive's SHA-256 and the SHA-256 of the extracted usr/local/bin/ruby module https://github.com/ruby/ruby.wasm/releases/tag/2.10.1 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Lance Albertson <lance@osuosl.org>
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThe PR upgrades the pinned ruby.wasm runtime to 2.10.1 and updates both archive and extracted-module checksums, preserving download, extraction, and cache-integrity validation for the existing CRuby 3.4.1 WASI asset. Sequence diagram for ruby.wasm download and integrity validationsequenceDiagram
participant Loader
participant Cache
participant GitHub
participant Archive
participant RubyWasm
Loader->>Cache: Load cached rubyWasmTreeBinary
Cache-->>Loader: Cached module
Loader->>RubyWasm: Verify rubyWasmBinarySHA256
alt Cache miss or binary hash mismatch
Loader->>GitHub: Download rubyWasmURL
GitHub-->>Loader: rubyWasmAsset
Loader->>Archive: Verify rubyWasmSHA256
Archive-->>Loader: Checksum valid
Loader->>Archive: Extract rubyWasmTreeBinary
Archive-->>Loader: rubyWasm module
Loader->>RubyWasm: Verify rubyWasmBinarySHA256
end
Loader->>RubyWasm: Execute validated CRuby 3.4.1 module
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. The pinned Ruby runtime can change policy evaluation or dependency-resolution results, potentially causing an incorrect policy artifact or lockfile to be generated. Reverting restores the previous runtime, but artifacts produced while the new version was active would need to be regenerated.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Move the pinned ruby.wasm runtime from 2.9.4 to 2.10.1, the current upstream release.
ruby.wasm 2.10.1 still builds the same CRuby 3.4.1, ships the same
ruby-3.4-wasm32-unknown-wasip1-full.tar.gzasset, and extracts to the same tree. The changes since 2.9.4 are in its build tooling. They are wasi-vfs 0.6.2, the wasmtime 40 stack, and the removal of wizer pre-initialization.Cinc Workstation packages this same release for the
cinc-ngpreview, and its build refuses a module whose hash differs fromrubyWasmBinarySHA256. So this pin has to move and be released before Workstation can take 2.10.1.rubyWasmVersionto2.10.1incli/policyfile/rubyeval/loader.gorubyWasmSHA256to the 2.10.1 release archive so a tampered download is still rejectedrubyWasmBinarySHA256to the extractedusr/local/bin/rubymodule so cached and packaged copies are checked against the new releaseA release after this merges lets the omnibus-software
cinc-ngandruby-wasmdefinitions move together in omnibus-software!302.References: