Repository navigation
Drop the bare command aliases, and group dependabot action updates - #56
Merged
Merged
Conversation
github/codeql-action/init and /analyze MUST be the same version -- CodeQL fails with "Loaded a configuration file for version X, but running version Y" when they differ. Dependabot proposed each subpath as its own pull request, so each one alone left the pair mismatched and red; laranail/confetti had two such PRs open, both failing, neither wrong on its own. Grouping minor and patch action updates into one PR fixes that for any paired action, not just CodeQL, and cuts the PR volume the comment above already complains about. Call the shared tests workflow instead of restating it laranail/.github has shipped a reusable tests workflow for months and one package of fifty-one called it. That is why a single defect -- pinning the Laravel version into composer.json before the suite ran -- had to be fixed in twenty-two places, and why prefer-lowest had to be added in twenty-seven. Everything this file used to spell out now lives in one definition: the PHP matrix, the composer cache and the laranail archive eviction it needs, the prefer-lowest leg, fail-fast, the timeout. What stays here is what is genuinely this package's own -- its PHP versions, its extensions, its test command -- passed as inputs. REQUIRES the corrected laranail/.github tests.yml. The version dated 2026-08-28 defaults laravel-versions to ["13.*"] and runs `composer require illuminate/contracts` before the suite, which is the pin this change exists to remove, and it has no laranail cache eviction, so adopting it unfixed would serve stale archives from the moving v0.1.0 tag. Land that first. Test against the floor, not only the ceiling The matrix only ever resolved prefer-stable, so nothing installed the minimum versions composer.json advertises. A floor can be wrong for months that way: the constraint says a consumer may use the old release, and no run ever proved it. Adding the leg is the only thing that checks the claim. Paired with --prefer-stable deliberately. Bare `composer update --prefer-lowest` resolves the lowest UNSTABLE release of every dependency, which fails for a reason that has nothing to do with this package. Verified on a scratch project: --prefer-lowest --prefer-stable installs psr/log 3.0.0 where plain --prefer-stable installs 3.0.2, and composer accepts the flag twice, so the one-line form needs no branch. Not applied where it would mean nothing: three packages install from a lock with `composer install`, where there is no resolution to steer, and tenancy-boilerplate is an application whose tracked lock is the point. Four packages already carry a single floor cell in `include`, which is the cheaper shape and is left alone. Resolve dependencies from the manifest, and cache them CI pinned versions into composer.json before running the suite. `composer require --no-update` EDITS the file -- verified: `^13.0` becomes `13.*` -- so every run tested a manifest the package does not ship. Nothing broke, because the forced constraint happened to agree with the declared one; it would have broken silently the first time either changed, and widening a package to `^13.0 || ^14.0` would never have been tested at all. The matrix keys feeding those pins are gone with them. Several were already inert: `testbench` and `carbon` were declared in the matrix and referenced by no step, so they pinned nothing and always resolved from composer.json. Also here, all measured rather than assumed: - A composer cache. Most workflows re-downloaded every dependency on every run, which is the largest avoidable draw on the Actions budget. - The cache drops laranail/* archives before installing. Those resolve through a single MOVING v0.1.0 tag, so composer's dist cache is keyed on a name whose contents change underneath it -- without the eviction a restored archive is silently stale, which is the failure this org has already hit once. - fail-fast off where it was on. "8.5 fails too" and "only 8.5 fails" are different bugs, and fail-fast hides which one a run found. - No coverage driver where nothing consumed the report. pcov instruments every file on every run; generating a report nobody reads is time billed for nothing. Untouched wherever an upload or a --min gate uses it. - paths-ignore '*.md' -> '**.md'. The root-only glob never matched docs/**, so documentation-only changes ran the full suite.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two changes, both about names that live in a flat global registry.
The bare command aliases are gone. Every alias this package declared was an unscoped, generic name —
env:set,make:crud,license,tidy. Artisan keeps command names in a flat map, so a second package claiming one does not collide loudly: it silently replaces the first, and the damage surfaces far away as the wrong code running under a familiar name. That is exactly the collisionlaranail::<slug>.<command>exists to prevent, and an unscoped alias hands it straight back. 127 of them across twelve packages, and not one was vendor-scoped.The primary name is unchanged, so every command is still reachable as
laranail::<slug>.<command>. The trait still applies$commandAliaseswhen a command declares one, so a vendor-scoped alias remains possible where a short form genuinely earns it. Breaking for anyone typing an old short name.Dependabot now groups action updates.
github/codeql-action/initand/analyzemust be the same version — CodeQL fails with "Loaded a configuration file for version X, but running version Y" — and dependabot proposed each subpath as its own pull request, so each one alone left the pair mismatched and red.laranail/confettihad two such PRs open, both failing, neither wrong on its own. Grouping fixes that for any paired action, not just CodeQL.