Agent skill

Rigor Ruby Version Bump

by rigortype in rigortype/rigor

Update the development Ruby version markers while preserving the supported-version range.

MPL-2.0Auto-check passedDevelopment

Install Rigor Ruby Version Bump

skills CLI
$ npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rigortype/rigor rigor-ruby-version-bump --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rigortype/rigor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/rigor-ruby-version-bump .claude/skills/rigor-ruby-version-bump && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rigor-ruby-version-bump
GitHub stars
106
Token cost
~2.6k tokens
SKILL.md length
1,270 words
Files
1
Skills in repo
36
Repo updated
First seen
Licence
MPL-2.0

At a glance

Update the development Ruby version markers while preserving the supported-version range.

  • Works in 7 steps: Classify the bump → flake.nix (the source of truth for local… → .ruby-version and .tool-versions → …
  • The user asks to bump Ruby
  • SKILL.md covers Two kinds of marker — do not…, Step 0 — Classify the bump, Step 1 — flake.nix (the source… and Step 2 — .ruby-version and…, plus 6 more sections
  • Calls ruby, nix and bundle

What it does

Rigor Ruby Version Bump is an agent skill from rigortype/rigor. Update the development Ruby version markers while preserving the supported-version range. Use when the user asks to bump Ruby or adopt a new Ruby release; not for changing the gemspec range, CI matrix, or dependency lockfile.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Dependency management. It works with Ruby. The repository describes itself as: Inference-first static analysis for Ruby. The licence is MPL-2.0.

When your agent uses it

  • The user asks to bump Ruby
  • Adopt a new Ruby release
  • Not for changing the gemspec range
  • Dependency lockfile

Example prompts

  • “/rigor-ruby-version-bump”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Classify the bump
  2. flake.nix (the source of truth for local builds)
  3. .ruby-version and .tool-versions
  4. AGENTS.md — the Flake Ruby version
  5. Verify
  6. Commit
  7. Minor/major bumps only — the supported-range markers

What it can do on your machine

Read from SKILL.md and the folder at commit c7b6b60. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ruby
    • nix
    • bundle
    • make
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rigor Ruby Version Bump loads about 2.6k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rigortype/rigor at commit c7b6b60, republished under its MPL-2.0 licence (© rigortype). 1,270 words, ~2,602 tokens.

Download SKILL.mdSave it as .claude/skills/rigor-ruby-version-bump/SKILL.md (or your agent's skills folder).
name
rigor-ruby-version-bump
description
Update the development Ruby version markers while preserving the supported-version range. Use when the user asks to bump Ruby or adopt a new Ruby release; not for changing the gemspec range, CI matrix, or dependency lockfile.
metadata.internal
true

Bump the Ruby Version

Use this skill when the project's Ruby version needs to move (e.g. 4.0.4 → 4.0.5). The version is recorded in several independent places, and the first job is to understand that those places fall into two categories — conflating them is the mistake this skill exists to prevent.

Land the whole change as one commit so the markers never diverge in history.

Two kinds of marker — do not conflate them

Bumping every marker to the exact patch couples the development Ruby to the supported-range markers, which breaks CI and force-upgrades contributors. Keep the two groups separate.

Development Ruby — the exact patch the contributor shell runs. Flake-controlled; bump freely to any released patch.

  • flake.nix — the mkRuby version + re-derived hash.
  • .ruby-version — read by rbenv / chruby / asdf and by ruby/setup-ruby in CI.
  • .tool-versions — read by asdf / mise; a peer of .ruby-version.
  • AGENTS.md — the Flake Ruby version under "Development Environment".

Supported-range markers — express what Ruby the gem supports, not the dev patch. A patch bump MUST NOT touch these.

  • rigortype.gemspec — required_ruby_version ([">= 4.0.0", "< 4.1"]) — the binding contract for end users.
  • Gemfile — the ruby directive — a range mirroring the gemspec (ruby ">= 4.0.0", "< 4.1"), never an exact patch.
  • Gemfile.lock — the RUBY VERSION block — held at the supported floor (ruby 4.0.0), not the dev patch.
  • .github/workflows/ci.yml — the ruby: matrix — a minor series ("4.0"); ruby/setup-ruby resolves the patch.

Why the Gemfile directive must be a range, not an exact patch. Bundler treats ruby "x.y.z" as an exact match and aborts every bundle command when the running Ruby differs by even a patch. CI's setup-ruby installs whatever patch it currently ships (often a step behind the newest release), so an exact pin newer than that breaks CI; contributors not yet on the exact patch are likewise force-upgraded. A range — ruby ">= 4.0.0", "< 4.1" — accepts any 4.0.x and keeps the gemspec as the single source of truth for the supported range. Note that an exact ruby "4.0.0" is not a fix either: it would reject the Flake's own newer Ruby and break the dev shell.

Step 0 — Classify the bump

The scope depends on which digit moves:

  • Patch (4.0.4 → 4.0.5): development markers only — Steps 1–3. The supported-range markers already admit the new patch; leave them untouched.
  • Minor (4.0 → 4.1): Steps 1–3 plus Step 6 — a minor bump is also where the supported-range markers move (gemspec ceiling, Gemfile range, Gemfile.lock floor, ci.yml matrix). The references/ruby submodule tracks branch ruby_4_0 (see .gitmodules) — a minor bump may need that branch repointed.
  • Major: treat as a project decision, not a mechanical bump — confirm intent before proceeding.

Step 1 — flake.nix (the source of truth for local builds)

Edit the mkRuby call:

nix
ruby = (pkgs.mkRuby {
  version = pkgs.mkRubyVersion "4" "0" "5" "";   # ← new version digits
  hash = "sha256-...";                            # ← must be re-derived
  cargoHash = "sha256-...";                       # ← re-verify (see below)
}).override { docSupport = false; };

hash is the sha256 of the Ruby source tarball; it changes every release and cannot be guessed. Derive it with the Nix fake-hash technique:

  1. Set hash to an all-zero placeholder:
    nix
    hash = "sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=";
  2. Run the shell so Nix fetches and complains:
    sh
    nix develop --command true
  3. Nix prints a hash mismatch with a got: line — copy that value into hash:
    error: hash mismatch in fixed-output derivation '...ruby-4.0.5.tar.gz.drv':
             specified: sha256-AAAA...
                got:    sha256-fWFJB5pj+K4dMmyfplxgGbotwxVerns5FZgXkRyIlY4=

cargoHash (the vendored Rust deps for YJIT) is checked after hash resolves. Across patch releases it is usually unchanged — but verify, never assume: temporarily set it to the all-zero placeholder too and run the shell again. If Nix reports the same value it already had, restore it; if it differs, take the got: value.

Confirm the build:

sh
nix develop --command ruby -v
# => ruby 4.0.5 (...) +PRISM [...]

Step 2 — .ruby-version and .tool-versions

Two single-line version files. Set each to the full x.y.z version.

.ruby-version is read by rbenv / chruby / asdf and by ruby/setup-ruby in CI:

4.0.5

.tool-versions is the asdf / mise version file — a peer of .ruby-version recording the same development-Ruby patch, prefixed with the tool name:

ruby 4.0.5

Step 3 — AGENTS.md — the Flake Ruby version

Under "Development Environment", update the version in "The Flake owns Ruby 4.0.5 and the vendored vendor/bundle". AGENTS.md states no supported range; that lives in the gemspec (Step 6).

Then grep -rn the old version across docs/ and update live docs (docs/CURRENT_WORK.md). Leave dated records — docs/adr/*, docs/notes/*, and existing CHANGELOG.md entries — untouched: they record a point-in-time fact, not the current target.

Step 4 — Verify

sh
nix develop --command make verify

make verify chains test + lint + the rigor check lib self-check. It must stay clean on the new Ruby. bundle exec reads the Gemfile ruby directive — because that directive is a range, the new patch satisfies it without a Gemfile edit.

Show full SKILL.md (563 more words)Show less
Record the perf-gate shift

A Ruby change can move the release gate's allocation number with no engine change, and the per-PR "Engine allocations" job cannot see it, because both of its arms run on one Ruby. The gate runs on CI's Ruby, the ruby-version: "4.0" series ruby/setup-ruby floats to the latest patch in release-gate.yml (the same series as ci.yml), so a patch bump here moves only the Flake's Ruby: run nix develop --command make bench-perf before and after it. A minor bump moves CI's series too: dispatch the release gate on the base and on the branch (gh workflow run release-gate.yml --ref <branch>). Put both allocation numbers and the delta in the PR body; a release cut attributes its rise from these records (bench/README.md, "Over a release cycle").

Step 5 — Commit

One commit covering every marker that moved. Subject (plain imperative, no prefix):

Bump development Ruby to 4.0.5

Body — note what changed and why the supported-range markers were left alone, e.g.:

Only the development markers move on a patch bump: flake.nix,
.ruby-version, .tool-versions, and the AGENTS.md Flake Ruby version. The Gemfile `ruby`
directive (a >= 4.0.0, < 4.1 range), Gemfile.lock's RUBY VERSION
(held at the 4.0.0 floor), the gemspec range, and the ci.yml
"4.0" minor series are supported-range markers and deliberately
unchanged. flake.lock is unchanged (it pins only the nixpkgs
input).

Step 6 — Minor/major bumps only — the supported-range markers

A minor bump is the only time the supported-range markers move. They move together:

  • rigortype.gemspec — re-evaluate the required_ruby_version range. The ceiling/floor change only when deliberately changing the supported range — a separate decision from the development Ruby.
  • Gemfile — the ruby directive is a range mirroring the gemspec. If the gemspec range changed, update the directive to match. Keep it a range; never an exact patch.
  • Gemfile.lock — the RUBY VERSION block is held at the supported floor. Update it only if the floor moved. Hand-edit it; do not regenerate it from the running Ruby (see below).
  • .github/workflows/ci.yml — the ruby: matrix uses a minor series ("4.0"); ruby/setup-ruby resolves it to the latest patch automatically, so a patch bump needs no change. A minor bump updates the entry ("4.0" → "4.1").
Gemfile.lock's RUBY VERSION is not regenerated per bump

Bundler writes the RUBY VERSION block from the running Ruby whenever bundle install / bundle lock runs. The project deliberately keeps it at the supported floor (ruby 4.0.0) instead, so the lock stays stable across patch bumps and does not record the dev patch. If a bundle install rewrites it to the running Ruby, reset that block to the floor before committing. bundle exec (what make verify runs) does not rewrite the lock, so a normal verify leaves it alone.

Files that deliberately stay untouched on a patch bump

  • Gemfile, Gemfile.lock, rigortype.gemspec, .github/workflows/ci.yml — supported-range markers; a patch bump leaves all four alone (see Step 6 for when they do move).
  • flake.lock — pins only the nixpkgs input revision. mkRuby takes the version and hash inline, so a Ruby bump never touches the lock. (Refreshing nixpkgs is a separate nix flake update decision.)
  • docs/adr/*, docs/notes/* — dated design records; their version mentions are history.

Quick checklist

Patch bump
  • flake.nix — mkRubyVersion digits + re-derived hash; cargoHash verified (not assumed).
  • nix develop --command ruby -v reports the new version.
  • .ruby-version — full x.y.z.
  • .tool-versions — ruby x.y.z.
  • AGENTS.md Flake Ruby version; live docs/ updated, dated records left alone.
  • Gemfile, Gemfile.lock, rigortype.gemspec, ci.yml — NOT modified.
  • flake.lock — NOT modified.
  • make verify clean on the new Ruby.
  • Perf-gate allocations before and after the bump are in the PR body.
  • Single commit, Bump development Ruby to x.y.z.
Minor bump — additionally
  • rigortype.gemspec required_ruby_version range re-evaluated.
  • Gemfile ruby directive range updated to mirror the gemspec (still a range).
  • Gemfile.lock RUBY VERSION updated to the new floor (hand-edited, not regenerated).
  • ci.yml ruby: matrix entry bumped.
  • references/ruby submodule branch repointed if required.

© rigortype, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/rigor-ruby-version-bump of rigortype/rigor.

Open the folder on GitHubat commit c7b6b60

Compare with similar skills

Rigor Ruby Version Bump next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rigor Ruby Version Bump compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rigor Ruby Version Bump this skillrigortype/rigor106—~2.6kAutomated safety check: PassMPL-2.0
Dependency UpdaterAsvarox/allkaraoke2614 repos~3.5kAutomated safety check: PassMIT
Breaking Change Analysisruby-git/ruby-git1.8k—~1.7kAutomated safety check: PassMIT
Dep Auditorlaolaoshiren/claude-code-skills-zh877—~895Automated safety check: PassMIT
Gem Dependency Managementruby-git/ruby-git1.8k—~806Automated safety check: PassMIT
Dependency Update BotVarnan-Tech/opendirectory672—~3kAutomated safety check: NotesMIT

Similar skills

  • Dependency Updater

    Asvarox/allkaraoke

    Smart dependency management for any language. An agent skill from Asvarox/allkaraoke.

    261 GitHub starsUsed in 4 repos~3.5k tokens
    DevelopmentAuto-check passed
  • Breaking Change Analysis

    ruby-git/ruby-git

    Assesses what an API change would break before it is made, finds every usage, documents the impact and plans a deprecation or migration path.

    1.8k GitHub stars~1.7k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    877 GitHub stars~895 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Gem Dependency Management

    ruby-git/ruby-git

    Workflow for updating gem dependencies and fixing CVEs in the ruby-git project: assess with bundle outdated and audit, edit the gemspec, test, then commit with conventional messages.

    1.8k GitHub stars~806 tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Dependency Update Bot

    Varnan-Tech/opendirectory

    Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

    672 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Update Dependencies

    sesori-ai/sesori_apps_monorepo

    Weekly dependency update workflow for Sesori Apps Monorepo. An agent skill from sesori-ai/sesori_apps_monorepo.

    125 GitHub stars~7.8k tokensUpdated today
    DevelopmentAuto-check passed

More from rigortype/rigor

All 36 skills in this repo
  • Rigor Regression Sweep

    rigortype/rigor

    Measure Rigor's baseline drift across the tagged history of a real OSS Ruby project.

    106 GitHub stars~2.9k tokensUpdated 5 days ago
    Auto-check passed
  • Adjudicate a rigor unused report safely before proposing dead-code removal.

    106 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Rigor Baseline Reduce

    rigortype/rigor

    Reduce an existing .rigor-baseline.yml rule by rule by triaging sites, fixing or intentionally suppressing them, and regenerating the baseline.

    106 GitHub stars~1.3k tokensUpdated 5 days ago
    Auto-check passed
  • Rigor Doctor

    rigortype/rigor

    Validate that a project's Rigor configuration, plugins, paths, and baseline are actually healthy.

    106 GitHub stars~767 tokensUpdated 5 days ago
    Auto-check passed
  • Rigor Plugin Author

    rigortype/rigor

    Author a new Rigor plugin, choosing plugins/ for production support or examples/ for a contract walkthrough.

    106 GitHub stars~3.3k tokensUpdated 5 days ago
    Auto-check: notes
  • Rigor Plugin Author

    rigortype/rigor

    Author a Rigor plugin in an adopting project or standalone rigor- gem for a DSL, framework, or metaprogramming pattern.

    106 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Rigor Ruby Version Bump

What does Rigor Ruby Version Bump do?

Update the development Ruby version markers while preserving the supported-version range. Rigor Ruby Version Bump is an agent skill from rigortype/rigor. Update the development Ruby version markers while preserving the supported-version range.

When should I use Rigor Ruby Version Bump?

Rigor Ruby Version Bump fits situations like: the user asks to bump Ruby; adopt a new Ruby release; not for changing the gemspec range; dependency lockfile.

How do I install Rigor Ruby Version Bump in Claude Code?

Run `npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a claude-code`. Or copy the skill folder (.claude/skills/rigor-ruby-version-bump in rigortype/rigor) into .claude/skills/rigor-ruby-version-bump in your project. Claude Code loads it when a task matches its description.

How do I install Rigor Ruby Version Bump in Codex?

Run `npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a codex`. Or copy the skill folder (.claude/skills/rigor-ruby-version-bump in rigortype/rigor) into .agents/skills/rigor-ruby-version-bump in your project. Codex loads it when a task matches its description.

Can I use Rigor Ruby Version Bump in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rigortype/rigor --skill rigor-ruby-version-bump -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rigor-ruby-version-bump, .gemini/skills/rigor-ruby-version-bump, .github/skills/rigor-ruby-version-bump and .opencode/skills/rigor-ruby-version-bump in your project.

What does Rigor Ruby Version Bump need to run?

Going by SKILL.md and its folder, Rigor Ruby Version Bump needs the command-line tools its instructions call (ruby, nix, bundle, make and gh).

Does Rigor Ruby Version Bump access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Rigor Ruby Version Bump safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rigor Ruby Version Bump use?

Rigor Ruby Version Bump is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rigor Ruby Version Bump use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rigor Ruby Version Bump?

Skills that share tags, products or a category with Rigor Ruby Version Bump: Dependency Updater (Asvarox/allkaraoke, 261 stars), Breaking Change Analysis (ruby-git/ruby-git, 1.8k stars), Dep Auditor (laolaoshiren/claude-code-skills-zh, 877 stars) and Gem Dependency Management (ruby-git/ruby-git, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rigor Ruby Version Bump?

rigortype (a GitHub organization) maintains it in rigortype/rigor, which has 106 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 2, 2026.

Source: rigortype/rigor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.