-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy paththem-server.gemspec
More file actions
184 lines (165 loc) · 10.7 KB
/
Copy paththem-server.gemspec
File metadata and controls
184 lines (165 loc) · 10.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
# frozen_string_literal: true
# kettle-jem:freeze
# To retain chunks of comments & code during them-server templating:
# Wrap custom sections with freeze markers (e.g., as above and below this comment chunk).
# them-server will then preserve content between those markers across template runs.
# kettle-jem:unfreeze
Gem::Specification.new do |spec|
spec.name = "them-server"
spec.version = Module.new.tap { |mod| Kernel.load("#{__dir__}/lib/them/server/version.rb", mod) }::Them::Server::Version::VERSION
spec.authors = ["Peter H. Boling"]
spec.email = ["peter.boling@gmail.com"]
spec.summary = "💎 A Federated Server of Ruby Gems"
spec.description = "💎 A Federated Server of Ruby Gems"
spec.homepage = "https://github.com/rubythems/them-server"
spec.licenses = ["MIT"]
spec.required_ruby_version = ">= 3.2.0"
# Linux distros often package gems and securely certify them independent
# of the official RubyGem certification process. Allowed via ENV["SKIP_GEM_SIGNING"]
# Ref: https://gitlab.com/ruby-oauth/version_gem/-/issues/3
# Hence, only enable signing if `SKIP_GEM_SIGNING` is not set in ENV.
# See CONTRIBUTING.md
unless ENV.include?("SKIP_GEM_SIGNING")
user_cert = "certs/#{ENV.fetch("GEM_CERT_USER", ENV["USER"])}.pem"
cert_file_path = File.join(__dir__, user_cert)
cert_chain = cert_file_path.split(",")
cert_chain.select! { |fp| File.exist?(fp) }
if cert_file_path && cert_chain.any?
spec.cert_chain = cert_chain
if $PROGRAM_NAME.end_with?("gem") && ARGV[0] == "build"
spec.signing_key = File.join(Gem.user_home, ".ssh", "gem-private_key.pem")
end
end
end
spec.metadata["homepage_uri"] = "https://them-server.galtzo.com"
spec.metadata["source_code_uri"] = "#{spec.homepage}/tree/v#{spec.version}"
spec.metadata["changelog_uri"] = "#{spec.homepage}/blob/v#{spec.version}/CHANGELOG.md"
spec.metadata["bug_tracker_uri"] = "#{spec.homepage}/issues"
spec.metadata["documentation_uri"] = "https://www.rubydoc.info/gems/#{spec.name}/#{spec.version}"
spec.metadata["funding_uri"] = "https://github.com/sponsors/pboling"
spec.metadata["wiki_uri"] = "#{spec.homepage}/wiki"
spec.metadata["news_uri"] = "https://www.railsbling.com/tags/#{spec.name}"
spec.metadata["discord_uri"] = "https://discord.gg/3qme4XHNKN"
spec.metadata["rubygems_mfa_required"] = "true"
enumerate_package_files = lambda do |root|
Dir.glob(File.join(root, "**", "*"), File::FNM_DOTMATCH).select do |path|
File.file?(path) && ![".", ".."].include?(File.basename(path))
end
end
# Specify which files are part of the released package.
spec.files = [
# Code / tasks / data (NOTE: exe/ is specified via spec.bindir and spec.executables below)
*enumerate_package_files.call("lib"),
# Executables and executable support scripts
*enumerate_package_files.call("exe"),
# Public certs for gem signing
*enumerate_package_files.call("certs"),
# Signatures
*enumerate_package_files.call("sig")
]
# Automatically included with gem package, no need to list again in files.
spec.extra_rdoc_files = Dir[
# Files (alphabetical)
"CHANGELOG.md",
"CITATION.cff",
"CODE_OF_CONDUCT.md",
"CONTRIBUTING.md",
"FUNDING.md",
"LICENSE.md",
"README.md",
"RUBOCOP.md",
"SECURITY.md"
]
spec.rdoc_options += [
"--title",
"#{spec.name} - #{spec.summary}",
"--main",
"README.md",
"--exclude",
"^sig/",
"--line-numbers",
"--inline-source",
"--quiet"
]
spec.bindir = "exe"
# Listed files are the relative paths from bindir above.
spec.executables = []
spec.require_paths = ["lib"]
# Utilities
spec.add_dependency("bcrypt", "~> 3.1", ">= 3.1.20") # ruby >= 2.3.0, password hashing
spec.add_dependency("dry-operation", "~> 1.1") # ruby >= 3.1.0, Railway-oriented operation objects
spec.add_dependency("dry-struct", "~> 1.8") # ruby >= 3.1.0, Typed structs and value objects
spec.add_dependency("dry-types", "~> 1.8", ">= 1.8.3") # ruby >= 3.1.0, Type system for Ruby
spec.add_dependency("ed25519", "~> 1.4", ">= 1.4.0") # ruby >= 3.0.0, signing & verification for federation
spec.add_dependency("erubi", "~> 1.13") # ruby >= 2.5.0, ERB renderer used by Roda/Tilt
spec.add_dependency("faraday", "~> 2.14", ">= 2.14.0") # ruby >= 3.0.0, HTTP client wrapper library
spec.add_dependency("hanami", "~> 2.2", ">= 2.2.1") # ruby >= 3.1.0, Full-stack web framework
spec.add_dependency("hanami-assets", "~> 2.2", ">= 2.2.1") # ruby >= 3.1.0, Full-stack web framework
spec.add_dependency("hanami-cli", "~> 2.2", ">= 2.2.1") # ruby >= 3.1.0, Full-stack web framework
spec.add_dependency("hanami-controller", "~> 2.2", ">= 2.2.1") # ruby >= 3.1.0, Full-stack web framework
spec.add_dependency("hanami-db", "~> 2.2", ">= 2.2.1") # ruby >= 3.1.0, Full-stack web framework
spec.add_dependency("hanami-router", "~> 2.2", ">= 2.2.1") # ruby >= 3.1.0, Full-stack web framework
spec.add_dependency("hanami-utils", "~> 2.2", ">= 2.2.0") # ruby >= 3.1.0, Hanami utilities including inflector
spec.add_dependency("hanami-view", "~> 2.2", ">= 2.2.1") # ruby >= 3.1.0, Full-stack web framework
spec.add_dependency("mail", "~> 2.8", ">= 2.8.1") # ruby >= 2.5.0, email library
spec.add_dependency("oauth2", "~> 2.0", ">= 2.0.17") # ruby >= 2.2.0, OAuth2 client for federation
spec.add_dependency("puma", "~> 7.2") # ruby >= 2.7.0, Rack server
spec.add_dependency("rack", "~> 3.2", ">= 3.2.3") # ruby >= 2.4.0, Rack web server interface
spec.add_dependency("rack-protection", "~> 4.2", ">= 4.2.1") # ruby >= 2.7.8, Security middleware
spec.add_dependency("rackup", "~> 2.2", ">= 2.2.1") # ruby >= 2.5.0, Rackup command is separate dependency in rack >= v3
spec.add_dependency("rodauth", "~> 2.41", ">= 2.41.0") # ruby >= 1.9.2, Rodauth authentication framework
spec.add_dependency("rom-sql", "~> 3.7", ">= 3.7.0") # ruby >= 3.1.0, Database toolkit
spec.add_dependency("version_gem", "~> 1.1", ">= 1.1.9") # ruby >= 2.2.0
# NOTE: It is preferable to list development dependencies in the gemspec due to increased
# visibility and discoverability.
# However, development dependencies in gemspec will install on
# all versions of Ruby that will run in CI.
# This gem, and its gemspec runtime dependencies, will install on Ruby down to 3.2.0.
# This gem, and its gemspec development dependencies, will install on Ruby down to 3.2.0.
# Thus, dev dependencies in gemspec must have
#
# required_ruby_version ">= 3.2.0" (or lower)
#
# Development dependencies that require strictly newer Ruby versions should be in a "gemfile",
# and preferably a modular one (see gemfiles/modular/*.gemfile).
# Dev, Test, & Release Tasks
spec.add_development_dependency("kettle-dev", "~> 2.0", ">= 2.0.8") # ruby >= 3.2.0
# Security
spec.add_development_dependency("bundler-audit", "~> 0.9.3") # ruby >= 2.0.0
# Tasks
spec.add_development_dependency("rake", "~> 13.0") # ruby >= 2.2.0
spec.add_development_dependency("dotenv", "~> 3.2") # ruby >= 3.1.0
spec.add_development_dependency("require_bench", "~> 1.0", ">= 1.0.4") # ruby >= 2.2.0
# Testing
spec.add_development_dependency("appraisal2", "~> 3.0", ">= 3.0.6") # ruby >= 1.8.7, for testing against multiple versions of dependencies
spec.add_development_dependency("capybara", "~> 3.40") # ruby >= 2.6.0, integration testing
spec.add_development_dependency("cgi", "~> 0.5") # ruby >= 2.5.0, extracted stdlib needed by Capybara on Ruby 4
spec.add_development_dependency("database_cleaner-sequel", "~> 2.0") # ruby >= 2.5.0, test database cleanup
spec.add_development_dependency("kettle-test", "~> 2.0", ">= 2.0.3") # ruby >= 3.2.0
spec.add_development_dependency("launchy", "~> 3.1") # ruby >= 2.7.0, browser launch helper
spec.add_development_dependency("rack-test", "~> 2.2") # ruby >= 2.7.0, Rack integration testing
spec.add_development_dependency("rom-factory", "~> 0.13") # ruby >= 3.1.0, ROM test factories
spec.add_development_dependency("turbo_tests2", "~> 3.1", ">= 3.1.1") # ruby >= 2.4.0, default kettle-test runner
# Releasing
spec.add_development_dependency("ruby-progressbar", "~> 1.13") # ruby >= 0
spec.add_development_dependency("stone_checksums", "~> 1.0", ">= 1.0.3") # ruby >= 2.2.0
# Git integration (optional)
# The 'git' gem is optional; them-server falls back to shelling out to `git` if it is not present.
# The current release of the git gem depends on activesupport, which makes it too heavy to depend on directly
# spec.add_dependency("git", ">= 1.19.1") # ruby >= 2.3
# Development tasks
# The cake is a lie. erb v2.2, the oldest release, was never compatible with Ruby 2.3.
# This means we have no choice but to use the erb that shipped with Ruby 2.3
# /opt/hostedtoolcache/Ruby/2.3.8/x64/lib/ruby/gems/2.3.0/gems/erb-2.2.2/lib/erb.rb:670:in `prepare_trim_mode': undefined method `match?' for "-":String (NoMethodError)
# spec.add_development_dependency("erb", ">= 2.2") # ruby >= 2.3.0, not SemVer, old rubies get dropped in a patch.
spec.add_development_dependency("gitmoji-regex", "~> 2.0", ">= 2.0.1") # ruby >= 2.4
# HTTP recording for deterministic specs
# In Ruby 3.5 (HEAD) the CGI library has been pared down, so we also need to depend on gem "cgi" for ruby@head
# This is done in the "head" appraisal.
# See: https://github.com/vcr/vcr/issues/1057
# spec.add_development_dependency("vcr", ">= 4") # 6.0 claims to support ruby >= 2.3, but fails on ruby 2.4
# spec.add_development_dependency("webmock", ">= 3") # Last version to support ruby >= 2.3
spec.add_development_dependency("rspec-pending_for", "~> 0.0", ">= 0.0.17") # ruby >= 2.3, used to skip specs on incompatible Rubies
spec.add_development_dependency("vcr", ">= 4") # 6.0 claims to support ruby >= 2.3, but fails on ruby 2.4
spec.add_development_dependency("webmock", ">= 3") # Last version to support ruby >= 2.3
end