Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Add Unused Dependency Check for Ruby Gems

Aperta
#63 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
42/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
ruby
Ambito
ci-cd, tooling

Direzione di ricerca

Start by reviewing the main CI workflow and the current Gemfile, then investigate whether degem works reliably and compare the suggested alternatives bundle-checker and gem-unused. Done means a stable dependency check is integrated, reports current unused gems, handles documented false positives, and fails CI when unused dependencies are detected.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

feat: Add Unused Dependency Check for Ruby Gems

Description:
To maintain a clean and efficient codebase, we need to add an automated process to the zitadel/client-ruby CI pipeline. The goal of this process is to detect and report any gems listed in the Gemfile that are no longer used in the project. The initial tool considered for this task was degem.

Problem:
The proposed tool, degem, does not appear to be functional in our current environment. Further investigation suggests the tool may be unmaintained, with its last commit several years ago. This makes it an unreliable choice for our CI pipeline, as it may have compatibility issues with modern Ruby versions and bundler.

Impact:

  • Without an automated check, the project is at risk of accumulating unused dependencies over time.
  • Unused gems lead to project bloat, slower bundle install times, and an increased potential security surface.
  • The dependency tree is less clear, making maintenance more difficult for developers.

Tasks:

  1. Attempt a final investigation to determine if degem can be made to work reliably.
  2. If degem is not viable, research and evaluate alternative tools for detecting unused Ruby gems (e.g., bundle-checker, gem-unused).
  3. Select a reliable tool and integrate it into the CI pipeline as a new check.
  4. Run the tool on the codebase and generate an initial report of unused dependencies.
  5. Configure the tool to ignore any known false positives (e.g., gems used by frameworks or other tools but not directly required in the code).
  6. Create a follow-up pull request to remove the confirmed unused gems from the Gemfile.

Expected Outcomes:

  • The CI pipeline includes a job that automatically fails if it detects unused gems in the Gemfile.
  • The project's dependencies are kept clean and minimal, improving maintainability and reducing bloat.
  • Developers are immediately notified of unused dependencies when contributing code.

Additional Notes:

  • The primary goal is to establish a reliable dependency check, not necessarily to use degem. The chosen solution should be stable and actively maintained.
  • This task will likely require updating the main CI workflow file to add a new step for the dependency analysis.
Lingua principale
Ruby
Stelle
6
Fork
2
Merge medio
11m
PR unite (30g)
2

Preparare l'ambiente

  • Include un Dockerfile o un file Docker Compose
  • Ha un modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di zitadel/client-ruby

Tutte le issue di zitadel/client-ruby

Issue simili

Altre issue su Ruby

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.