Security News
Fluent Assertions Faces Backlash After Abandoning Open Source Licensing
Fluent Assertions is facing backlash after dropping the Apache license for a commercial model, leaving users blindsided and questioning contributor rights.
A gem for distributing the v8 runtime libraries and headers in both source and binary form.
The goal of libv8 is two fold: provide a binary gem containing the a pre-compiled libv8_monolith.a for as many platforms as possible while at the same time supporting for an automated compilation for all others.
Not only does this drastically reduce gem install times, but it also reduces dependencies on the local machine receiving the gem. It also opens the door for supporting Windows.
That depends on your platform. Right now, we support the following platforms.
If you don't see your platform on this list, first, make sure that it installs from source, and second talk to us about setting up a binary distro for you.
If you're installing libv8 on a macOS system that is present in the list above,
and despite that, RubyGems insists on downloading a source version and compiling
it, check the output of ruby -e 'puts Gem::Platform.local'
. If it does not
reflect the current version of your OS, recompile Ruby.
The platform gets hardcoded in Ruby during compilation and if you've updated your OS since you've compiled Ruby, it does not represent correctly your current platform which leads to RubyGems trying to download a platform-specific gem for the older version of your OS.
Versions of the libv8 gem track the version of V8 itself, adding its
own point release after the main V8 version. So libv8 5.0.71.35.5
and 5.0.71.35.14
both correspond to V8 version 5.0.71.35
. Another
way to think about it would be that 5.0.71.35.14
is the 14th release
of the libv8 rubygem based on V8 version 5.0.71.35
Starting with libv8 3.11.8.0
, all even point releases contain
only a source-based distribution, while odd point releases contain both
a source-based distribution and binary distributions. However both
point releases correspond to the exact underlying code. The only
difference is the version number.
This way, the most recent version of the gem always has binary distributions, but if, for whatever reason, you have problems with the binaries, you can always "lock in" your dependency a single point version down, forcing it to compile from source.
So for example, 5.0.71.35.3
contains all the binary distributions,
while 5.0.71.35.2
is the exact same code, but contain only a
source-based distribution
This step release system is a workaround to carlhuda/bundler#1537
Building the V8 library from source imposes the following requirements:
If you want to use the latest unstable version of the gem you can do
so by specifying the git repo as a gem source. Just make sure you add
the following to your Gemfile
:
gem "libv8", github: "rubyjs/libv8", submodules: true
You can find more info on using a git repo as a gem source in Bundler's documentation.
If you can fix V8's build system so that it correctly compiles for your platform, we'll pull it right in!
To get the source, these commands will get you started:
git clone --recursive git://github.com/rubyjs/libv8.git
cd libv8
bundle install
bundle exec rake compile
This project spun off of therubyracer which depends on having a specific version of V8 to compile and run against. However, actually delivering that version reliably to all the different platforms proved to be a challenge to say the least.
We got tired of waiting 5 minutes for V8 to compile every time we installed that gem.
(The MIT License)
Copyright (c) 2009,2010 Charles Lowell
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the 'Software'), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
FAQs
Unknown package
We found that libv8 demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
Fluent Assertions is facing backlash after dropping the Apache license for a commercial model, leaving users blindsided and questioning contributor rights.
Research
Security News
Socket researchers uncover the risks of a malicious Python package targeting Discord developers.
Security News
The UK is proposing a bold ban on ransomware payments by public entities to disrupt cybercrime, protect critical services, and lead global cybersecurity efforts.