From 57391c4969dc5a07e0e650f1687dd24c68b68b95 Mon Sep 17 00:00:00 2001 From: Lance Albertson Date: Sat, 3 Oct 2026 16:15:31 -0700 Subject: [PATCH] build(deps): bump ruby.wasm runtime to 2.10.1 ruby.wasm 2.10.1 is out. Its CRuby 3.4 "full" build is still Ruby 3.4.1 with the same asset name and layout; only the build tooling changed (wasi-vfs 0.6.2, wasmtime 40, no wizer pre-initialization). Cinc Workstation packages the same release for cinc-ng, and its build requires the module to match rubyWasmBinarySHA256, so this pin moves first. - Pin rubyWasmVersion to 2.10.1 with the release archive's SHA-256 and the SHA-256 of the extracted usr/local/bin/ruby module https://github.com/ruby/ruby.wasm/releases/tag/2.10.1 Co-Authored-By: Claude Opus 5.5 Signed-off-by: Lance Albertson --- cli/policyfile/rubyeval/loader.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/cli/policyfile/rubyeval/loader.go b/cli/policyfile/rubyeval/loader.go index 66175a2..8b36b2e 100644 --- a/cli/policyfile/rubyeval/loader.go +++ b/cli/policyfile/rubyeval/loader.go @@ -27,7 +27,7 @@ import ( // of truth and are asserted by loader_test.go without touching the network. const ( // rubyWasmVersion is the pinned ruby/ruby.wasm release tag. - rubyWasmVersion = "2.9.4" + rubyWasmVersion = "2.10.1" // rubyWasmAsset is the WASI "full" build (CRuby 3.4 + stdlib) we run. The // "full" build ships the standard library as host files we mount, not // packed into the module. @@ -36,14 +36,14 @@ const ( rubyWasmURL = "https://github.com/ruby/ruby.wasm/releases/download/" + rubyWasmVersion + "/" + rubyWasmAsset // rubyWasmSHA256 is the verified SHA-256 of rubyWasmAsset. A mismatch is a // hard failure (a corrupted or tampered download is never used). - rubyWasmSHA256 = "ccda86a375a4fe09849846d3b03a370172a4902a0c571087f48457388a2762c7" + rubyWasmSHA256 = "440f9a48a3bae258c70de610f7a78cfc56b536bdb9b81ef750f8d3918382515e" // rubyWasmBinarySHA256 is the SHA-256 of the CRuby wasm module extracted // from the pinned, checksum-verified archive (rubyWasmTreeBinary). It is // re-checked on every cache hit so a cached module tampered-with after // extraction is rejected and re-fetched, not executed. Because it's derived // deterministically from the pinned archive, anyone can reproduce it by // extracting rubyWasmAsset. - rubyWasmBinarySHA256 = "ea1ccf46994cd2441812c75fb058136850149f2a472ff4472f7085b086fd1d1a" + rubyWasmBinarySHA256 = "348305ee0b4e4cdb84ec169223e33721899548577a42a421725b71e481afff11" // rubyWasmTreeBinary is the path, within the extracted archive, of the // CRuby wasm module.