Skip to content

Drop the bare command aliases, and group dependabot action updates - #56

Merged
imanimanyara merged 1 commit into
mainfrom
ci/alias-and-dependabot
Sep 16, 2026
Merged

imanimanyara merged 1 commit into
mainfrom
ci/alias-and-dependabot

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Two changes, both about names that live in a flat global registry.

The bare command aliases are gone. Every alias this package declared was an unscoped, generic name — env:set, make:crud, license, tidy. Artisan keeps command names in a flat map, so a second package claiming one does not collide loudly: it silently replaces the first, and the damage surfaces far away as the wrong code running under a familiar name. That is exactly the collision laranail::<slug>.<command> exists to prevent, and an unscoped alias hands it straight back. 127 of them across twelve packages, and not one was vendor-scoped.

The primary name is unchanged, so every command is still reachable as laranail::<slug>.<command>. The trait still applies $commandAliases when a command declares one, so a vendor-scoped alias remains possible where a short form genuinely earns it. Breaking for anyone typing an old short name.

Dependabot now groups action updates. github/codeql-action/init and /analyze must be the same version — CodeQL fails with "Loaded a configuration file for version X, but running version Y" — and dependabot proposed each subpath as its own pull request, so each one alone left the pair mismatched and red. laranail/confetti had two such PRs open, both failing, neither wrong on its own. Grouping fixes that for any paired action, not just CodeQL.

github/codeql-action/init and /analyze MUST be the same version -- CodeQL fails
with "Loaded a configuration file for version X, but running version Y" when
they differ. Dependabot proposed each subpath as its own pull request, so each
one alone left the pair mismatched and red; laranail/confetti had two such PRs
open, both failing, neither wrong on its own.

Grouping minor and patch action updates into one PR fixes that for any paired
action, not just CodeQL, and cuts the PR volume the comment above already
complains about.

Call the shared tests workflow instead of restating it

laranail/.github has shipped a reusable tests workflow for months and one
package of fifty-one called it. That is why a single defect -- pinning the
Laravel version into composer.json before the suite ran -- had to be fixed in
twenty-two places, and why prefer-lowest had to be added in twenty-seven.

Everything this file used to spell out now lives in one definition: the PHP
matrix, the composer cache and the laranail archive eviction it needs, the
prefer-lowest leg, fail-fast, the timeout. What stays here is what is genuinely
this package's own -- its PHP versions, its extensions, its test command --
passed as inputs.

REQUIRES the corrected laranail/.github tests.yml. The version dated 2026-08-28
defaults laravel-versions to ["13.*"] and runs `composer require
illuminate/contracts` before the suite, which is the pin this change exists to
remove, and it has no laranail cache eviction, so adopting it unfixed would
serve stale archives from the moving v0.1.0 tag. Land that first.

Test against the floor, not only the ceiling

The matrix only ever resolved prefer-stable, so nothing installed the minimum
versions composer.json advertises. A floor can be wrong for months that way:
the constraint says a consumer may use the old release, and no run ever proved
it. Adding the leg is the only thing that checks the claim.

Paired with --prefer-stable deliberately. Bare `composer update --prefer-lowest`
resolves the lowest UNSTABLE release of every dependency, which fails for a
reason that has nothing to do with this package. Verified on a scratch project:
--prefer-lowest --prefer-stable installs psr/log 3.0.0 where plain
--prefer-stable installs 3.0.2, and composer accepts the flag twice, so the
one-line form needs no branch.

Not applied where it would mean nothing: three packages install from a lock
with `composer install`, where there is no resolution to steer, and
tenancy-boilerplate is an application whose tracked lock is the point. Four
packages already carry a single floor cell in `include`, which is the cheaper
shape and is left alone.

Resolve dependencies from the manifest, and cache them

CI pinned versions into composer.json before running the suite. `composer
require --no-update` EDITS the file -- verified: `^13.0` becomes `13.*` -- so
every run tested a manifest the package does not ship. Nothing broke, because
the forced constraint happened to agree with the declared one; it would have
broken silently the first time either changed, and widening a package to
`^13.0 || ^14.0` would never have been tested at all.

The matrix keys feeding those pins are gone with them. Several were already
inert: `testbench` and `carbon` were declared in the matrix and referenced by
no step, so they pinned nothing and always resolved from composer.json.

Also here, all measured rather than assumed:

- A composer cache. Most workflows re-downloaded every dependency on every
  run, which is the largest avoidable draw on the Actions budget.
- The cache drops laranail/* archives before installing. Those resolve through
  a single MOVING v0.1.0 tag, so composer's dist cache is keyed on a name whose
  contents change underneath it -- without the eviction a restored archive is
  silently stale, which is the failure this org has already hit once.
- fail-fast off where it was on. "8.5 fails too" and "only 8.5 fails" are
  different bugs, and fail-fast hides which one a run found.
- No coverage driver where nothing consumed the report. pcov instruments every
  file on every run; generating a report nobody reads is time billed for
  nothing. Untouched wherever an upload or a --min gate uses it.
- paths-ignore '*.md' -> '**.md'. The root-only glob never matched docs/**, so
  documentation-only changes ran the full suite.
Copilot AI lite review requested due to automatic review settings September 16, 2026 12:33

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit b194429 into main Sep 16, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants