Skip to content

Bump ci-queue to v0.100.0 - #435

Merged
mdwn merged 1 commit into
mainfrom
bump-v0.100.0
Oct 1, 2026
Merged

mdwn merged 1 commit into
mainfrom
bump-v0.100.0

Conversation

@mdwn

@mdwn mdwn commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the Ruby gem version to 0.100.0.

Changes since v0.99.0:

(#427 only touches the Python package.)

⚠️ Breaking: rediss:// now verifies server certificates

Versions 0.59.0 through 0.99.0 connected to rediss:// URLs with verify_mode: VERIFY_NONE on redis-rb > 5.0.0 (effectively every install since 0.67.0 pinned redis ~> 5.0). The traffic was encrypted, but ci-queue never checked the server's identity. Starting with 0.100.0, the certificate and hostname are verified against the system's trusted CAs.

Who is affected: anyone using a rediss:// queue URL whose Redis certificate doesn't verify, for example because it's self-signed or signed by a private CA (Heroku Redis is one case). redis:// URLs aren't affected, and neither is Redis with a publicly trusted certificate for the right hostname.

What it looks like: workers print Ran 0 tests and exit successfully. Connection errors are swallowed, just as they are for an unreachable Redis. report then fails with Redis::CannotConnectError … certificate verify failed.

How to fix: trust the issuing CA (e.g. SSL_CERT_FILE=/path/to/ca.pem), or accept the risk and set CI_QUEUE_REDIS_SSL_VERIFY=0 (or CI::Queue::Configuration#redis_ssl_verify = false). See "Redis over TLS" in ruby/README.md.

@mdwn
mdwn merged commit d62ff55 into main Oct 1, 2026
34 checks passed

This branch was successfully deployed

1 active deployment
rubygems — fe999a4c Deployed Oct 1, 2026 by shopify-shipit[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants