From: "Rafael Mendonça França" Date: 2019-02-24T14:42:59-05:00 Subject: [ruby-core:91617] Re: [CommonRuby Feature#15619] Blacklist certain dependency versions --===============0872077128== Content-Type: multipart/alternative; boundary="0000000000004893860582a90a0b" --0000000000004893860582a90a0b Content-Type: text/plain; charset="UTF-8" This constraint already exists and work. You can define `gem.add_dependency 'mail', '~> 2.6', '>= 2.6.4', '!= 2.7.0'`. See https://github.com/rubygems/rubygems/blob/89ce39a27611f7a791562cecf53bf2d773ae105f/lib/rubygems/requirement.rb#L7 On Sun, Feb 24, 2019 at 13:41 wrote: > Issue #15619 has been reported by skalee (Sebastian Skalacki). > > ---------------------------------------- > Feature #15619: Blacklist certain dependency versions > https://bugs.ruby-lang.org/issues/15619 > > * Author: skalee (Sebastian Skalacki) > * Status: Open > * Priority: Normal > * Assignee: > * Target version: > ---------------------------------------- > # Abstract > > This feature request proposes introducing a new dependency constraint > "!=", which will allow to blacklist a specific buggy version of some gem > dependency without dropping support for older releases. > > # Background > > I am developing a gem which extends functionality of the Mail gem. It > works with Mail 2.6.4 onwards (the current latest is 2.7.1), therefore I'd > normally define a dependency constraint as combination of "~> 2.6" AND ">= > 2.6.4". > > However, there is one exception: Mail version 2.7.0 has some bug, which is > fatal for my gem. This bug has been fixed in 2.7.1. I need to prevent > users from using the buggy version of Mail with my gem. Currently, I can > do following: > > 1. Bump version constraint on Mail gem to "~> 2.7" AND ">= 2.7.1". > > 2. Release two separate gems (or versions), one with constraint "~> > 2.6.4", and another with "~> 2.7" AND ">= 2.7.1". > > 3. Display a proper message in README and post-install step in order to > inform users that they should care about Mail version themselves (e.g. > constrain it in their gemfiles). > > 4. Perform a runtime check, and raise exception on incompatible Mail > version. > > 5. Any reasonable combination of above. > > Option 1 seems to be the best. It is easy and very straightforward, also > it does not break Bundler's gem resolution. However, it seems wrong to > remove support for older versions only because single version of Mail is > buggy. What is more, such change to dependencies may be considered as a > breaking one. Option 2 adds an unnecessary maintenance burden, and feels > odd in general. Options 3 and 4 are also quite odd, as they seem to be an > unnecessary complication, and may surprise users who have just upgraded my > gem. > > Actually, what I would really want to achieve is to be able to define > dependency constraint as "~> 2.6" AND ">= 2.6.4" BUT NOT "= 2.7.0". > > # Proposal > > For this reason, I propose introducing "!=" version constraints which > exclude unwanted version explicitly. For example, in my case I could write > "~> 2.6" AND ">= 2.6.4" AND "!= 2.7.0". > > > > -- > https://bugs.ruby-lang.org/ > > Unsubscribe: > > --0000000000004893860582a90a0b Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
This constraint al= ready exists and work.=C2=A0 You can define `gem.add_dependency = 9;mail', '~> 2.6', '>=3D 2.6.4', '!=3D 2.7.0&= #39;`.


=
On Sun, Fe= b 24, 2019 at 13:41 <skalee@gmail.com> wrote:
Issue #15619 has been reported by skalee (Sebastian Skal= acki).

----------------------------------------
Feature #15619: Blacklist certain dependency versions
https://bugs.ruby-lang.org/issues/15619

* Author: skalee (Sebastian Skalacki)
* Status: Open
* Priority: Normal
* Assignee:
* Target version:
----------------------------------------
# Abstract

This feature request proposes introducing a new dependency constraint "= ;!=3D", which will allow to blacklist a specific buggy version of some= gem dependency without dropping support for older releases.

# Background

I am developing a gem which extends functionality of the Mail gem.=C2=A0 It= works with Mail 2.6.4 onwards (the current latest is 2.7.1), therefore I&#= 39;d normally define a dependency constraint as combination of "~> = 2.6" AND ">=3D 2.6.4".

However, there is one exception: Mail version 2.7.0 has some bug, which is = fatal for my gem.=C2=A0 This bug has been fixed in 2.7.1.=C2=A0 I need to p= revent users from using the buggy version of Mail with my gem.=C2=A0 Curren= tly, I can do following:

1. Bump version constraint on Mail gem to "~> 2.7" AND "&= gt;=3D 2.7.1".

2. Release two separate gems (or versions), one with constraint "~>= 2.6.4", and another with "~> 2.7" AND ">=3D 2.7.= 1".

3. Display a proper message in README and post-install step in order to inf= orm users that they should care about Mail version themselves (e.g. constra= in it in their gemfiles).

4. Perform a runtime check, and raise exception on incompatible Mail versio= n.

5. Any reasonable combination of above.

Option 1 seems to be the best.=C2=A0 It is easy and very straightforward, a= lso it does not break Bundler's gem resolution.=C2=A0 However, it seems= wrong to remove support for older versions only because single version of = Mail is buggy.=C2=A0 What is more, such change to dependencies may be consi= dered as a breaking one.=C2=A0 Option 2 adds an unnecessary maintenance bur= den, and feels odd in general.=C2=A0 Options 3 and 4 are also quite odd, as= they seem to be an unnecessary complication, and may surprise users who ha= ve just upgraded my gem.

Actually, what I would really want to achieve is to be able to define depen= dency constraint as "~> 2.6" AND ">=3D 2.6.4" BUT= NOT "=3D 2.7.0".

# Proposal

For this reason, I propose introducing "!=3D" version constraints= which exclude unwanted version explicitly.=C2=A0 For example, in my case I= could write "~> 2.6" AND ">=3D 2.6.4" AND "= !=3D 2.7.0".



--
https://bugs.ruby-lang.org/

Unsubscribe: <mailto:ruby-core-request@ruby-lang.org?subject=3Dunsubscribe= >
<http://lists.ruby-lang.org/cgi-bin/m= ailman/options/ruby-core>
--0000000000004893860582a90a0b-- --===============0872077128== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline Unsubscribe: --===============0872077128==--