-
Notifications
You must be signed in to change notification settings - Fork 62
114 lines (104 loc) · 4.67 KB
/
Copy pathstatic-analysis.yml
File metadata and controls
114 lines (104 loc) · 4.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
name: Static Analysis
on:
push:
branches: [master, develop, "dev/**"]
pull_request:
branches: [master, develop]
jobs:
static-analysis:
name: Static Analysis (PHP ${{ matrix.php }})
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# Static analysis is version-sensitive for syntax/deprecation checks.
php: ["8.3", "8.4"]
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup PHP ${{ matrix.php }}
uses: shivammathur/setup-php@v2
with:
php-version: ${{ matrix.php }}
tools: composer:v2
coverage: none
# ── Mage-OS mirror ─────────────────────────────────────────────────────
#
# Registers the Mage-OS public mirror of repo.magento.com globally so
# any magento/* package resolves without credentials. The mirror is
# configured globally so it applies to all subsequent composer calls in
# this job without touching composer.json.
- name: Configure Mage-OS mirror
run: |
composer config --global repositories.mage-os composer https://mirror.mage-os.org/
# ── Install analysis tools ─────────────────────────────────────────────
#
# A minimal composer.json covers only the three analysis tools rather
# than the full extension to keep CI fast and dependency-free:
# • squizlabs/php_codesniffer (phpcs binary)
# • magento/magento-coding-standard (Magento2 phpcs standard)
# • phpmd/phpmd (mess detector binary)
#
# dealerdirect/phpcodesniffer-composer-installer is a plugin that
# automatically registers the Magento2 standard's path with phpcs after
# `composer install`, so no manual --config-set is required.
#
# The resulting composer.lock is also used by the `composer audit` step
# below to check these tools for known security advisories.
- name: Install analysis tools
run: |
mkdir -p /tmp/ci-tools
cat > /tmp/ci-tools/composer.json << 'JSON'
{
"require-dev": {
"squizlabs/php_codesniffer": "^3.13",
"magento/magento-coding-standard": ">=36",
"phpmd/phpmd": "^2.15"
},
"config": {
"allow-plugins": {
"dealerdirect/phpcodesniffer-composer-installer": true
}
}
}
JSON
composer install \
--working-dir=/tmp/ci-tools \
--no-interaction \
--no-progress \
--prefer-dist
# ── PHP_CodeSniffer ────────────────────────────────────────────────────
#
# Runs against phpcs.xml (Magento2 standard, errors only via -n flag).
# Current baseline: 0 errors.
- name: Run phpcs
run: |
/tmp/ci-tools/vendor/bin/phpcs \
--standard=phpcs.xml \
--report=full
# ── PHP Mess Detector ──────────────────────────────────────────────────
#
# Scans source directories only (Test/ excluded — tests use
# @SuppressWarnings annotations which PHPMD would report as violations).
# Ruleset: phpmd.xml (cleancode, codesize, design, naming, unusedcode).
# Current baseline: 0 violations.
- name: Run phpmd
run: |
/tmp/ci-tools/vendor/bin/phpmd \
Api,Component,Console,Exception,Model,Service \
text \
phpmd.xml
# ── Composer Audit ─────────────────────────────────────────────────────
#
# Checks the installed analysis tools (phpcs, phpmd, magento-coding-
# standard and their dependencies) for known security advisories.
#
# NOTE: Production dependencies (symfony/yaml, firegento/fastsimpleimport)
# are NOT audited here because the ci-tools composer.json is intentionally
# minimal. To audit production dependencies, run `composer audit` inside a
# Magento installation that has the extension installed as a path repository.
- name: Run composer audit
run: |
composer audit \
--working-dir=/tmp/ci-tools \
--no-interaction