Skip to content

Commit a757732

Browse files
committed
Skip the bundle app config under BUNDLE_IGNORE_CONFIG
Bundler's load_config returns {} whenever BUNDLE_IGNORE_CONFIG is set, so a cache_path or gemfile setting in .bundle/config is then ignored. The stale-install guard still followed the ignored cache_path, skipped the vendor/cache archive bundler actually installs from, and attested the purl. Both settings now read the app config through one reader that honors the switch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MWt5CXPnmqVEUZe4wnCfgX
1 parent 477aae9 commit a757732

4 files changed

Lines changed: 79 additions & 23 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -113,6 +113,8 @@ limits, and required install commands.
113113
the committed archive in Bundler's configured cache dir (`cache_path` /
114114
`BUNDLE_CACHE_PATH`) instead of always `vendor/cache`, so a stale archive
115115
there now warns and keeps the same run's VEX from attesting it (#483).
116+
Both settings skip `.bundle/config` under `BUNDLE_IGNORE_CONFIG`, as Bundler
117+
does.
116118
- **npm dependencies installed from git, a URL or `file:` are no longer
117119
reported patched.** npm installs such a dependency from the dependent's
118120
spec (`github:user/repo`, `https://…/x.tgz`, `file:…`) and ignores the

0 commit comments

Comments
 (0)