Repository navigation
Bump friendsofphp/php-cs-fixer from 3.95.25 to 3.95.26 #81
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: "REST API CI" | |
| on: | |
| push: | |
| paths-ignore: | |
| - '**.md' | |
| - '**.txt' | |
| pull_request: | |
| workflow_dispatch: | |
| env: | |
| # Phalcon v5 C extension constraint (installed from source via PIE) | |
| PHALCON_CONSTRAINT: "^5.0" | |
| EXTENSIONS: "mbstring, intl, json, openssl, redis, pdo_mysql" | |
| # The application reads DATA_API_*; Talon reads DATA_* for its own settings. | |
| # Both resolve getenv() before $_ENV, so these beat the files that point at | |
| # the compose service names (.env for the app, tests/.env.test for Talon). | |
| DATA_API_MYSQL_HOST: "127.0.0.1" | |
| DATA_API_REDIS_HOST: "127.0.0.1" | |
| DATA_MYSQL_HOST: "127.0.0.1" | |
| DATA_REDIS_HOST: "127.0.0.1" | |
| # The api suite crosses a real HTTP boundary; this is the built-in server | |
| # started below. APP_URL stays http://localhost:8080 - it is what the app | |
| # echoes back in `links`, and the expectations must match the app. | |
| TALON_REST_URL: "http://127.0.0.1:8080" | |
| permissions: { } | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: ${{ github.ref != 'refs/heads/master' }} | |
| jobs: | |
| quality: | |
| name: "Code quality" | |
| permissions: | |
| contents: read | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | |
| fetch-depth: 1 | |
| - name: "Setup PHP" | |
| uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2 | |
| with: | |
| php-version: '8.3' | |
| extensions: ${{ env.EXTENSIONS }} | |
| tools: composer:v2 | |
| # The quality tools do not need the Phalcon extension: phpstan analyzes the | |
| # phalcon/phalcon (v6) source pulled in by Composer. | |
| - name: "Validate composer" | |
| run: composer validate --no-check-all --no-check-publish | |
| - name: "Install dependencies" | |
| uses: ramsey/composer-install@26d8a556604053a9612623447203a691f406fbe6 # v4 | |
| with: | |
| composer-options: "--prefer-dist" | |
| - name: "PHPCS" | |
| run: composer cs | |
| - name: "PHP CS Fixer (dry-run)" | |
| run: composer cs-fixer | |
| - name: "PHPStan" | |
| run: composer analyze | |
| tests: | |
| name: "Tests (PHP ${{ matrix.php }}, Phalcon ${{ matrix.variant }})" | |
| permissions: | |
| contents: read | |
| runs-on: ubuntu-latest | |
| needs: | |
| - quality | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| php: | |
| - '8.1' | |
| - '8.2' | |
| - '8.3' | |
| - '8.4' | |
| variant: | |
| # v5 = cphalcon C extension; v6 = phalcon/phalcon composer package | |
| - 'v5' | |
| - 'v6' | |
| services: | |
| mysql: | |
| image: mysql:8.0 | |
| ports: | |
| - "3306:3306" | |
| env: | |
| MYSQL_ROOT_PASSWORD: secret | |
| MYSQL_DATABASE: phalcon_api | |
| options: >- | |
| --health-cmd "mysqladmin ping --silent" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| redis: | |
| image: redis:alpine | |
| ports: | |
| - "6379:6379" | |
| options: >- | |
| --health-cmd "redis-cli ping" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | |
| fetch-depth: 1 | |
| - name: "Setup PHP" | |
| uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2 | |
| with: | |
| php-version: ${{ matrix.php }} | |
| extensions: ${{ env.EXTENSIONS }} | |
| tools: composer:v2 | |
| # v5 = cphalcon C extension, built from source via PIE (pecl caps at PHP 8.4). | |
| # v6 needs no extension: it runs on the phalcon/phalcon composer package (a require-dev dep). | |
| - name: "Install Phalcon v5 (cphalcon) via PIE" | |
| if: matrix.variant == 'v5' | |
| run: | | |
| curl -fsSL https://github.com/php/pie/releases/latest/download/pie.phar -o pie.phar | |
| sudo "$(which php)" pie.phar install --no-interaction "phalcon/cphalcon:${{ env.PHALCON_CONSTRAINT }}" | |
| php -m | grep -i phalcon | |
| - name: "Install dependencies" | |
| uses: ramsey/composer-install@26d8a556604053a9612623447203a691f406fbe6 # v4 | |
| with: | |
| composer-options: "--prefer-dist" | |
| - name: "Prepare environment" | |
| run: | | |
| cp resources/.env.example .env | |
| sed -i 's/^DATA_API_MYSQL_HOST=.*/DATA_API_MYSQL_HOST=127.0.0.1/' .env | |
| sed -i 's/^DATA_API_REDIS_HOST=.*/DATA_API_REDIS_HOST=127.0.0.1/' .env | |
| # storage/logs is not tracked (only the cache dirs carry .gitignore | |
| # placeholders), so a fresh checkout has nowhere to write the log. | |
| mkdir -p storage/logs storage/cache/data storage/cache/metadata tests/_output | |
| - name: "Migrate" | |
| run: composer migrate | |
| # The api suite talks to this over the network. .htrouter.php is a router | |
| # script: it serves anything that exists under public/ and hands the rest | |
| # to public/index.php. | |
| - name: "Start the application" | |
| run: | | |
| php -S 127.0.0.1:8080 .htrouter.php > storage/logs/server.log 2>&1 & | |
| # Any HTTP status means the application answered - /sommething is | |
| # expected to 404. curl reports "000" when it could not connect at | |
| # all, which is the only case worth waiting on. | |
| for i in $(seq 1 30); do | |
| code=$(curl -sS -o /dev/null -w '%{http_code}' "${TALON_REST_URL}/sommething" 2>/dev/null || true) | |
| if [ "$code" != "000" ]; then | |
| echo "application answered with HTTP ${code} after ${i}s" | |
| exit 0 | |
| fi | |
| sleep 1 | |
| done | |
| echo "the application did not answer within 30s" | |
| cat storage/logs/server.log || true | |
| exit 1 | |
| - name: "Tests" | |
| run: vendor/bin/talon run all | |
| - name: "Server log" | |
| if: failure() | |
| run: cat storage/logs/server.log || true | |
| coverage: | |
| name: "Coverage" | |
| permissions: | |
| contents: read | |
| pull-requests: write | |
| actions: read | |
| runs-on: ubuntu-latest | |
| needs: | |
| - quality | |
| services: | |
| mysql: | |
| image: mysql:8.0 | |
| ports: | |
| - "3306:3306" | |
| env: | |
| MYSQL_ROOT_PASSWORD: secret | |
| MYSQL_DATABASE: phalcon_api | |
| options: >- | |
| --health-cmd "mysqladmin ping --silent" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| redis: | |
| image: redis:alpine | |
| ports: | |
| - "6379:6379" | |
| options: >- | |
| --health-cmd "redis-cli ping" | |
| --health-interval 10s | |
| --health-timeout 5s | |
| --health-retries 5 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| ref: ${{ github.event.pull_request.head.sha || github.sha }} | |
| # SonarQube needs full history for blame/new-code detection; | |
| # octocov uses it for the base-branch diff. | |
| fetch-depth: 0 | |
| - name: "Setup PHP" | |
| uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2 | |
| with: | |
| php-version: '8.3' | |
| extensions: ${{ env.EXTENSIONS }} | |
| coverage: pcov | |
| tools: composer:v2 | |
| # pecl's phalcon release metadata caps at PHP 8.4; PIE builds it from source. | |
| - name: "Install Phalcon (v5) via PIE" | |
| run: | | |
| curl -fsSL https://github.com/php/pie/releases/latest/download/pie.phar -o pie.phar | |
| sudo "$(which php)" pie.phar install --no-interaction "phalcon/cphalcon:${{ env.PHALCON_CONSTRAINT }}" | |
| php -m | grep -i phalcon | |
| - name: "Install dependencies" | |
| uses: ramsey/composer-install@26d8a556604053a9612623447203a691f406fbe6 # v4 | |
| with: | |
| composer-options: "--prefer-dist" | |
| - name: "Prepare environment" | |
| run: | | |
| cp resources/.env.example .env | |
| sed -i 's/^DATA_API_MYSQL_HOST=.*/DATA_API_MYSQL_HOST=127.0.0.1/' .env | |
| sed -i 's/^DATA_API_REDIS_HOST=.*/DATA_API_REDIS_HOST=127.0.0.1/' .env | |
| mkdir -p storage/logs storage/cache/data storage/cache/metadata tests/_output | |
| - name: "Migrate" | |
| run: composer migrate | |
| - name: "Start the application" | |
| run: | | |
| php -S 127.0.0.1:8080 .htrouter.php > storage/logs/server.log 2>&1 & | |
| for i in $(seq 1 30); do | |
| code=$(curl -sS -o /dev/null -w '%{http_code}' "${TALON_REST_URL}/sommething" 2>/dev/null || true) | |
| if [ "$code" != "000" ]; then | |
| echo "application answered with HTTP ${code} after ${i}s" | |
| exit 0 | |
| fi | |
| sleep 1 | |
| done | |
| echo "the application did not answer within 30s" | |
| cat storage/logs/server.log || true | |
| exit 1 | |
| # Runs phpunit over resources/phpunit.xml.dist directly rather than | |
| # through talon: `talon run all` starts one process per suite, and each | |
| # would overwrite the others' coverage.xml. One process, all four suites, | |
| # one merged report. | |
| # | |
| # NOTE: the api suite exercises the application in the php -S process | |
| # above, which pcov does not instrument - so the controllers read as 0% | |
| # covered here despite being tested. See resources/octocov.yml. | |
| - name: "Tests with coverage" | |
| run: composer test-coverage | |
| # SonarQube first (push only) so a failing octocov gate can't skip the upload. | |
| - name: "SonarQube Scan" | |
| if: github.event_name == 'push' | |
| uses: SonarSource/sonarqube-scan-action@22918119ff8e1ca75a623e15c8296b6ea4fbe28f # v8.2.1 | |
| env: | |
| SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} | |
| with: | |
| args: > | |
| -Dsonar.organization=phalcon | |
| -Dsonar.projectKey=phalcon_rest-api | |
| -Dsonar.sources=src | |
| -Dsonar.tests=tests | |
| -Dsonar.exclusions=resources/** | |
| -Dsonar.php.coverage.reportPaths=tests/_output/coverage.xml | |
| # octocov last: PR comment + coverage gate (strict on PRs via | |
| # octocov.pr.yml, floor only on pushes via octocov.yml), stores the | |
| # baseline report on the default branch, and writes the badge SVG. | |
| - name: "octocov" | |
| uses: k1LoW/octocov-action@a167dc0dee441b7ffc45e1b862ab55ec0d87f278 # v1.5.2 | |
| with: | |
| config: ${{ github.event_name == 'pull_request' && 'resources/octocov.pr.yml' || 'resources/octocov.yml' }} | |
| - name: "Upload coverage badge" | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: coverage-badge | |
| path: tests/_output/coverage.svg | |
| if-no-files-found: ignore |