Describe the problem as clearly as you can
When Rails release a security fix in, say, activerecord, Bundler users are not able to pickup the fix by doing bundle update activerecord, if they have a Gemfile.lock file locked to an insecure version.
This is because bundle update activerecord only "unlocks" (ignores locked version in the Gemfile.lock file) the activerecord gem and its dependencies. However, gems that have activerecord as a dependency, namely rails, are not unlocked and thus stay at the previous insecure version, making the upgrade impossible.
So bundle update activerecord ends up logging a message like
Bundler attempted to update activerecord but its version stayed the same
I think if Bundler is unable to update the requested dependency, it could try to also unlock gems that have the target gem as a dependency, in order to try to make the upgrade succeed.
Did you try upgrading rubygems & bundler?
Yes.
Post steps to reproduce the problem
Gemfile
# frozen_string_literal: true
source "https://rubygems.org"
gem "rails"
Gemfile.lock
GEM
remote: https://rubygems.org/
specs:
actioncable (7.0.2.2)
actionpack (= 7.0.2.2)
activesupport (= 7.0.2.2)
nio4r (~> 2.0)
websocket-driver (>= 0.6.1)
actionmailbox (7.0.2.2)
actionpack (= 7.0.2.2)
activejob (= 7.0.2.2)
activerecord (= 7.0.2.2)
activestorage (= 7.0.2.2)
activesupport (= 7.0.2.2)
mail (>= 2.7.1)
net-imap
net-pop
net-smtp
actionmailer (7.0.2.2)
actionpack (= 7.0.2.2)
actionview (= 7.0.2.2)
activejob (= 7.0.2.2)
activesupport (= 7.0.2.2)
mail (~> 2.5, >= 2.5.4)
net-imap
net-pop
net-smtp
rails-dom-testing (~> 2.0)
actionpack (7.0.2.2)
actionview (= 7.0.2.2)
activesupport (= 7.0.2.2)
rack (~> 2.0, >= 2.2.0)
rack-test (>= 0.6.3)
rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.0, >= 1.2.0)
actiontext (7.0.2.2)
actionpack (= 7.0.2.2)
activerecord (= 7.0.2.2)
activestorage (= 7.0.2.2)
activesupport (= 7.0.2.2)
globalid (>= 0.6.0)
nokogiri (>= 1.8.5)
actionview (7.0.2.2)
activesupport (= 7.0.2.2)
builder (~> 3.1)
erubi (~> 1.4)
rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.1, >= 1.2.0)
activejob (7.0.2.2)
activesupport (= 7.0.2.2)
globalid (>= 0.3.6)
activemodel (7.0.2.2)
activesupport (= 7.0.2.2)
activerecord (7.0.2.2)
activemodel (= 7.0.2.2)
activesupport (= 7.0.2.2)
activestorage (7.0.2.2)
actionpack (= 7.0.2.2)
activejob (= 7.0.2.2)
activerecord (= 7.0.2.2)
activesupport (= 7.0.2.2)
marcel (~> 1.0)
mini_mime (>= 1.1.0)
activesupport (7.0.2.2)
concurrent-ruby (~> 1.0, >= 1.0.2)
i18n (>= 1.6, < 2)
minitest (>= 5.1)
tzinfo (~> 2.0)
builder (3.2.4)
concurrent-ruby (1.1.10)
crass (1.0.6)
digest (3.1.0)
erubi (1.10.0)
globalid (1.0.0)
activesupport (>= 5.0)
i18n (1.10.0)
concurrent-ruby (~> 1.0)
loofah (2.16.0)
crass (~> 1.0.2)
nokogiri (>= 1.5.9)
mail (2.7.1)
mini_mime (>= 0.1.1)
marcel (1.0.2)
method_source (1.0.0)
mini_mime (1.1.2)
minitest (5.15.0)
net-imap (0.2.3)
digest
net-protocol
strscan
net-pop (0.1.1)
digest
net-protocol
timeout
net-protocol (0.1.3)
timeout
net-smtp (0.3.1)
digest
net-protocol
timeout
nio4r (2.5.8)
nokogiri (1.13.3-arm64-darwin)
racc (~> 1.4)
nokogiri (1.13.3-x86_64-linux)
racc (~> 1.4)
racc (1.6.0)
rack (2.2.3)
rack-test (1.1.0)
rack (>= 1.0, < 3)
rails (7.0.2.2)
actioncable (= 7.0.2.2)
actionmailbox (= 7.0.2.2)
actionmailer (= 7.0.2.2)
actionpack (= 7.0.2.2)
actiontext (= 7.0.2.2)
actionview (= 7.0.2.2)
activejob (= 7.0.2.2)
activemodel (= 7.0.2.2)
activerecord (= 7.0.2.2)
activestorage (= 7.0.2.2)
activesupport (= 7.0.2.2)
bundler (>= 1.15.0)
railties (= 7.0.2.2)
rails-dom-testing (2.0.3)
activesupport (>= 4.2.0)
nokogiri (>= 1.6)
rails-html-sanitizer (1.4.2)
loofah (~> 2.3)
railties (7.0.2.2)
actionpack (= 7.0.2.2)
activesupport (= 7.0.2.2)
method_source
rake (>= 12.2)
thor (~> 1.0)
zeitwerk (~> 2.5)
rake (13.0.6)
strscan (3.0.1)
thor (1.2.1)
timeout (0.2.0)
tzinfo (2.0.4)
concurrent-ruby (~> 1.0)
websocket-driver (0.7.5)
websocket-extensions (>= 0.1.0)
websocket-extensions (0.1.5)
zeitwerk (2.5.4)
PLATFORMS
arm64-darwin-21
x86_64-linux
DEPENDENCIES
rails
BUNDLED WITH
2.3.11
And run bundle update activerecord.
Which command did you run?
bundle update activerecord.
What were you expecting to happen?
My Gemfile.lock file to all Rails gems to latest version.
What actually happened?
The command warns
Bundler attempted to update activerecord but its version stayed the same
and doesn't update anything.
Describe the problem as clearly as you can
When Rails release a security fix in, say,
activerecord, Bundler users are not able to pickup the fix by doingbundle update activerecord, if they have aGemfile.lockfile locked to an insecure version.This is because
bundle update activerecordonly "unlocks" (ignores locked version in theGemfile.lockfile) theactiverecordgem and its dependencies. However, gems that haveactiverecordas a dependency, namelyrails, are not unlocked and thus stay at the previous insecure version, making the upgrade impossible.So
bundle update activerecordends up logging a message likeI think if Bundler is unable to update the requested dependency, it could try to also unlock gems that have the target gem as a dependency, in order to try to make the upgrade succeed.
Did you try upgrading rubygems & bundler?
Yes.
Post steps to reproduce the problem
Gemfile
Gemfile.lock
And run
bundle update activerecord.Which command did you run?
bundle update activerecord.What were you expecting to happen?
My
Gemfile.lockfile to all Rails gems to latest version.What actually happened?
The command warns
and doesn't update anything.