Skip to content

Conversation

@deivid-rodriguez
Copy link
Contributor

@deivid-rodriguez deivid-rodriguez commented Aug 4, 2025

What was the end-user or developer problem that led to this PR?

If a user is explicitly requesting an upgrade of gem foo, through bundle update foo, and the latest version of foo is resolvable through bundle install without a lockfile, Bundler should be able to upgrade it, even if it requires downgrading an indirect dependency.

What is your fix for the problem, implemented in this PR?

The problem is that when calculating the latest resolvable version of foo, Bundler was still adding lower bound requirements on the locked versions of all dependencies to avoid downgrades, effectively pinning foo to a version older than the latest.

To fix this, instead of creating a second "unlocked" definition to figure out the latest resolvable version, create a second unlocked resolver, and DO NOT add lower bound requirements to it.

Closes #8893.

Make sure the following tasks are checked

@deivid-rodriguez deivid-rodriguez force-pushed the deivid-rodriguez/fix-failed-update-to-latest branch 3 times, most recently from 342d066 to 4a24b2d Compare August 5, 2025 03:40
@deivid-rodriguez deivid-rodriguez marked this pull request as ready for review August 5, 2025 11:21
@deivid-rodriguez deivid-rodriguez force-pushed the deivid-rodriguez/fix-failed-update-to-latest branch from 4a24b2d to eaf6bd1 Compare August 5, 2025 11:21
If upgrading `foo` needs an indirect dependency to be downgraded,
Bundler would not be able to upgrade foo.

This is because when calculating the latest resolvable version of foo,
Bundler was still adding lower bound requirements on the locked versions
of all dependencies to avoid downgrades, effectively pinning foo to a
version older than the latest.

To fix this, instead of creating a second "unlocked" definition to
figure out the latest resolvable version, create a second unlocked
resolver, and DO NOT add lower bound requirements to it.
@deivid-rodriguez deivid-rodriguez force-pushed the deivid-rodriguez/fix-failed-update-to-latest branch from eaf6bd1 to 00cc0ec Compare August 8, 2025 17:06
@deivid-rodriguez deivid-rodriguez merged commit e38c8fb into master Aug 8, 2025
76 checks passed
@deivid-rodriguez deivid-rodriguez deleted the deivid-rodriguez/fix-failed-update-to-latest branch August 8, 2025 18:32
deivid-rodriguez added a commit that referenced this pull request Sep 4, 2025
…date-to-latest

Fix `bundle update foo` unable to update foo in an edge case

(cherry picked from commit e38c8fb)
deivid-rodriguez added a commit that referenced this pull request Sep 9, 2025
…date-to-latest

Fix `bundle update foo` unable to update foo in an edge case

(cherry picked from commit e38c8fb)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Indirect dependency downgrade blocks update of direct dependency

1 participant