From 888cd188ee9d7a73dab4c8973018921961a79659 Mon Sep 17 00:00:00 2001 From: roxblnfk Date: Fri, 9 Oct 2026 21:28:23 +0400 Subject: [PATCH] ci: run `composer audit` instead of roave/security-advisories The old job installed roave/security-advisories on every run and relied on the deprecated `set-output` command; `composer audit` checks the installed tree against the same advisories without touching `composer.json`. Assisted-By: Claude Opus 5.5 --- .github/workflows/security.yml | 109 +++++++++++++++++---------------- 1 file changed, 55 insertions(+), 54 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index be8c8af..53d3a8f 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -1,56 +1,57 @@ -on: - pull_request: null - push: - branches: - - 1.x - -name: build +--- + +name: 🔐 Security analysis + +on: # yamllint disable-line rule:truthy + pull_request: + push: + branches: [1.x] + +# `head_ref` is the PR source branch on `pull_request` events and empty on `push` +# (falls back to `github.ref` = `refs/heads/`). Different PRs from different +# branches → different groups, so they never cross-cancel. Same PR pushed again +# → same group, the new run cancels the previous one. +# +# `cancel-in-progress` is only enabled on PR events: pushes to the default branch +# (1.x) keep their full history of CI runs. +concurrency: + group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} jobs: - security: - name: Security - runs-on: ${{ matrix.os }} - - strategy: - fail-fast: false - matrix: - php: ['8.2'] - os: [ubuntu-latest] - - steps: - - name: Set Git To Use LF - run: | - git config --global core.autocrlf false - git config --global core.eol lf - - name: Checkout - uses: actions/checkout@v6 - - - name: Setup PHP ${{ matrix.php }} - uses: shivammathur/setup-php@v2 - with: - php-version: ${{ matrix.php }} - - - name: Validate Composer - run: composer validate - - - name: Get Composer Cache Directory - # Docs: - id: composer-cache - run: echo "::set-output name=dir::$(composer config cache-files-dir)" - - - name: Restore Composer Cache - uses: actions/cache@v5 - with: - path: ${{ steps.composer-cache.outputs.dir }} - key: ${{ runner.os }}-${{ matrix.php }}-composer-${{ hashFiles('**/composer.json') }} - restore-keys: ${{ runner.os }}-${{ matrix.php }}-composer- - - - name: Install Dependencies - uses: nick-invision/retry@v3 - with: - timeout_minutes: 5 - max_attempts: 5 - command: composer update --prefer-dist --no-interaction --no-progress - - - name: Security Advisories - run: composer require --dev roave/security-advisories:dev-latest + security-analysis: + timeout-minutes: 4 + runs-on: ${{ matrix.os }} + strategy: + fail-fast: true + matrix: + os: + - ubuntu-latest + php-version: + - '8.2' + dependencies: + - highest + steps: + - name: 📦 Check out the codebase + uses: actions/checkout@v7 + + - name: 🛠️ Setup PHP + uses: shivammathur/setup-php@v2 + with: + php-version: ${{ matrix.php-version }} + ini-values: error_reporting=E_ALL + coverage: none + + - name: 🛠️ Setup problem matchers + run: echo "::add-matcher::${{ runner.tool_cache }}/php.json" + + - name: 🤖 Validate composer.json + run: composer validate --ansi --strict + + - name: 📥 Install dependencies with composer + uses: ramsey/composer-install@v3 + with: + dependency-versions: ${{ matrix.dependencies }} + + - name: 🐛 Check installed packages for security vulnerability advisories + run: composer audit --ansi