Repository navigation
Publish only a whitelist of files in the gem - #52
Merged
Merged
Conversation
Nine files that no consumer can reach: the VuePress site under docs/ (config.js, styles/index.styl, two READMEs), bin/setup and bin/console (this gem's executables come from exe/, so dropping bin/ changes nothing), the two .github/workflows, and yarn.lock. Packaged: 46 files / 20 KB -> 37 files / 16 KB. lib/ and exe/ intact.
The reject list only removes directories someone remembered to name. That is how spec/, .github/, screen/ and img/ got published in the first place — each needed a new pattern, and none was added until an audit went looking. A whitelist inverts the default: a new directory in the repo does not reach consumers until it is listed. Same shape the sibling gems activeadmin-oidc and credit_card_validations already use. Drops the remaining dev-only files the reject form kept: .gitignore .rspec .rubocop.yml capybara_active_admin.gemspec CODE_OF_CONDUCT.md Gemfile package.json Rakefile Packaged: 37 -> 29 files. The runtime payload — everything under lib/, app/, vendor/, config/ and exe/ — is byte-identical to before, verified by diffing the built .gem both ways.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The implementation removes additional files and can unintentionally package untracked local files.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates gem packaging to exclude development-only content through an explicit file whitelist.
Changes:
- Replaces the tracked-file reject list with a package whitelist.
- Limits packaged content to library files, executables, and essential documentation.
| File | Description |
|---|---|
capybara_active_admin.gemspec |
Defines the new package whitelist. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
`Dir[...]` globs the working tree, so any untracked or generated file under lib/, app/ or vendor/ would be published in a release — the build artifact depended on the releaser's local checkout. The reject form it replaced was tracked-only; this restores that property while keeping the whitelist. `git ls-files -- <paths>` also returns files only, where `Dir["**/*"]` returns directory entries too, so `files` no longer carries entries RubyGems just ignores. Built .gem is byte-for-byte the same file list as the Dir[] version.
CI dies every few runs with Ferrum::ProcessTimeoutError: Browser did not produce websocket url within 15 seconds `process_timeout` is already env-driven here, so CI just sets CAPYBARA_PROCESS_TIMEOUT=60 rather than changing the default that developers get locally. This is a mitigation and the comment says so. What the logs rule out is a cold-start problem: the failing `visit` is never the first in the run, and in the last occurrence the dummy app logged a request from a live browser three seconds into the window that was timing out — a restart racing a browser that has not finished dying. The suite does not reproduce it locally (15 consecutive clean full-suite runs).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What
filesis now an explicit whitelist, instead of publishing everything tracked minus whatever someone remembered to exclude.A reject list only removes what someone named. That is how CI config, the VuePress site ended up in the published gem — each needed its own pattern, and none was added until an audit went looking. A whitelist inverts the default: a new directory does not reach consumers until it is listed.
Every root
Rails::Engineloads from is listed, present in this repo or not. A whitelist fails quietly —git ls-files -- configagainst a tree with noconfig/exits 0 and prints nothing — so the day someone addsconfig/initializers/foo.rbthe gem would install, boot, and never run it. Naming the roots up front costs nothing (git ls-fileson a missing path is a no-op) and removes that trapdoor.Selected through
git ls-filesrather thanDir[...]so the artifact stays tracked-only — an untracked or generated file underlib/cannot leak into a release — and sofilescarries no directory entries.Verified
All 17 files that leave the package:
Nothing is added. The 26 files under
lib/— the entire runtime payload — are unchanged: