Skip to content

fix(ci): start OpenSearch 3.x service for integration tests #30

fix(ci): start OpenSearch 3.x service for integration tests

fix(ci): start OpenSearch 3.x service for integration tests #30

name: Static Analysis
on:
push:
branches: [master, develop, "dev/**"]
pull_request:
branches: [master, develop]
jobs:
static-analysis:
name: Static Analysis (PHP ${{ matrix.php }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# Static analysis is version-sensitive for syntax/deprecation checks.
php: ["8.3", "8.4", "8.5"]
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup PHP ${{ matrix.php }}
uses: shivammathur/setup-php@v2
with:
php-version: ${{ matrix.php }}
tools: composer:v2
coverage: none
# ── Mage-OS mirror ─────────────────────────────────────────────────────
#
# Registers the Mage-OS public mirror of repo.magento.com globally so
# any magento/* package resolves without credentials. The mirror is
# configured globally so it applies to all subsequent composer calls in
# this job without touching composer.json.
- name: Configure Mage-OS mirror
run: |
composer config --global repositories.mage-os composer https://mirror.mage-os.org/
# ── Install analysis tools ─────────────────────────────────────────────
#
# A minimal composer.json covers only the three analysis tools rather
# than the full extension to keep CI fast and dependency-free:
# • squizlabs/php_codesniffer (phpcs binary)
# • magento/magento-coding-standard (Magento2 phpcs standard)
# • phpmd/phpmd (mess detector binary)
#
# dealerdirect/phpcodesniffer-composer-installer is a plugin that
# automatically registers the Magento2 standard's path with phpcs after
# `composer install`, so no manual --config-set is required.
#
# The resulting composer.lock is also used by the `composer audit` step
# below to check these tools for known security advisories.
- name: Install analysis tools
run: |
mkdir -p /tmp/ci-tools
cat > /tmp/ci-tools/composer.json << 'JSON'
{
"require-dev": {
"squizlabs/php_codesniffer": "^3.13",
"magento/magento-coding-standard": ">=36",
"phpmd/phpmd": "^2.15"
},
"config": {
"allow-plugins": {
"dealerdirect/phpcodesniffer-composer-installer": true
}
}
}
JSON
composer install \
--working-dir=/tmp/ci-tools \
--no-interaction \
--no-progress \
--prefer-dist
# ── PHP_CodeSniffer ────────────────────────────────────────────────────
#
# Runs against phpcs.xml (Magento2 standard, errors only via -n flag).
# Current baseline: 0 errors.
- name: Run phpcs
run: |
/tmp/ci-tools/vendor/bin/phpcs \
--standard=phpcs.xml \
--report=full
# ── PHP Mess Detector ──────────────────────────────────────────────────
#
# Scans source directories only (Test/ excluded — tests use
# @SuppressWarnings annotations which PHPMD would report as violations).
# Ruleset: phpmd.xml (cleancode, codesize, design, naming, unusedcode).
# Current baseline: 0 violations.
- name: Run phpmd
run: |
/tmp/ci-tools/vendor/bin/phpmd \
Api,Component,Console,Exception,Model,Service \
text \
phpmd.xml
# ── Composer Audit ─────────────────────────────────────────────────────
#
# Checks the installed analysis tools (phpcs, phpmd, magento-coding-
# standard and their dependencies) for known security advisories.
#
# NOTE: Production dependencies (symfony/yaml, magento/module-catalog-import-export)
# are NOT audited here because the ci-tools composer.json is intentionally
# minimal. To audit production dependencies, run `composer audit` inside a
# Magento installation that has the extension installed as a path repository.
- name: Run composer audit
run: |
composer audit \
--working-dir=/tmp/ci-tools \
--no-interaction