Question
Should this repo commit Gemfile.lock? Right now .gitignore (line 42) excludes it.
Background
The sibling repo thedrunkfist commits its lockfile. Dependabot there raised alert #115, a high-severity rubyzip issue that needs rubyzip 3.4.0 or later. It can't be fixed: github-pages pulls in rubyzip through jekyll-remote-theme, which caps it below 3.0, and the newest jekyll-remote-theme (0.5.2) still caps it below 4.0. We dismissed that alert as "not used" because the site sets no remote_theme and GitHub Pages ignores the lockfile.
This repo never got the alert because Dependabot has no lockfile to scan. The same gems are still in play.
Points to weigh
- Bundler's guidance: commit the lockfile for an application and leave it out for a published gem. A Jekyll site counts as an application.
- The live site won't change: GitHub Pages builds with its own pinned gem set and ignores
Gemfile.lock either way.
- Local builds: without a lockfile, each fresh clone resolves the newest gems allowed that day, so a build can break with no change to the code. This repo has no CI workflow, so this only affects local builds.
- Dependabot noise: a committed lockfile brings alerts, and some can't be fixed while
github-pages pins old gems. Each one would need dismissing with a reason.
To do
Question
Should this repo commit
Gemfile.lock? Right now.gitignore(line 42) excludes it.Background
The sibling repo thedrunkfist commits its lockfile. Dependabot there raised alert #115, a high-severity rubyzip issue that needs rubyzip 3.4.0 or later. It can't be fixed:
github-pagespulls in rubyzip throughjekyll-remote-theme, which caps it below 3.0, and the newestjekyll-remote-theme(0.5.2) still caps it below 4.0. We dismissed that alert as "not used" because the site sets noremote_themeand GitHub Pages ignores the lockfile.This repo never got the alert because Dependabot has no lockfile to scan. The same gems are still in play.
Points to weigh
Gemfile.lockeither way.github-pagespins old gems. Each one would need dismissing with a reason.To do
Gemfile.lock..gitignore, runbundle install, checkbundle exec jekyll buildworks, commit the lockfile, then triage any Dependabot alerts that follow.