Skip to content

CI: resolve dependencies from the manifest, cache them, test the floor - #5

Merged
imanimanyara merged 2 commits into
mainfrom
ci/manifest-resolution
Sep 16, 2026
Merged

imanimanyara merged 2 commits into
mainfrom
ci/manifest-resolution

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Three changes, each measured across the family rather than assumed.

Resolve dependencies from the manifest. CI pinned versions into composer.json before running the suite. composer require --no-update edits the file — verified, ^13.0 becomes 13.* — so every run tested a manifest the package does not ship. Nothing was broken today, because the forced constraint agreed with the declared one; it breaks silently the first time they diverge, and widening to ^13.0 || ^14.0 would never have been tested. The matrix keys that fed those pins are gone with them; several (testbench, carbon) were already inert, declared in the matrix and referenced by no step.

Cache composer dependencies, with laranail/* archives dropped before install. That eviction is not optional: those packages resolve through a single moving v0.1.0 tag, so the dist cache is keyed on a name whose contents change underneath it, and a restored archive is silently stale.

Test against the floor. The matrix only ever resolved prefer-stable, so nothing installed the minimum composer.json advertises. Paired with --prefer-stable, because bare --prefer-lowest resolves the lowest unstable release and fails for unrelated reasons.

Where this branch also adopts laranail/.github, it requires the corrected reusable workflow to land first — the current one defaults laravel-versions to ["13.*"] (the pin) and has no laranail cache eviction.

CI pinned versions into composer.json before running the suite. `composer
require --no-update` EDITS the file -- verified: `^13.0` becomes `13.*` -- so
every run tested a manifest the package does not ship. Nothing broke, because
the forced constraint happened to agree with the declared one; it would have
broken silently the first time either changed, and widening a package to
`^13.0 || ^14.0` would never have been tested at all.

The matrix keys feeding those pins are gone with them. Several were already
inert: `testbench` and `carbon` were declared in the matrix and referenced by
no step, so they pinned nothing and always resolved from composer.json.

Also here, all measured rather than assumed:

- A composer cache. Most workflows re-downloaded every dependency on every
  run, which is the largest avoidable draw on the Actions budget.
- The cache drops laranail/* archives before installing. Those resolve through
  a single MOVING v0.1.0 tag, so composer's dist cache is keyed on a name whose
  contents change underneath it -- without the eviction a restored archive is
  silently stale, which is the failure this org has already hit once.
- fail-fast off where it was on. "8.5 fails too" and "only 8.5 fails" are
  different bugs, and fail-fast hides which one a run found.
- No coverage driver where nothing consumed the report. pcov instruments every
  file on every run; generating a report nobody reads is time billed for
  nothing. Untouched wherever an upload or a --min gate uses it.
- paths-ignore '*.md' -> '**.md'. The root-only glob never matched docs/**, so
  documentation-only changes ran the full suite.
laranail/.github has shipped a reusable tests workflow for months and one
package of fifty-one called it. That is why a single defect -- pinning the
Laravel version into composer.json before the suite ran -- had to be fixed in
twenty-two places, and why prefer-lowest had to be added in twenty-seven.

Everything this file used to spell out now lives in one definition: the PHP
matrix, the composer cache and the laranail archive eviction it needs, the
prefer-lowest leg, fail-fast, the timeout. What stays here is what is genuinely
this package's own -- its PHP versions, its extensions, its test command --
passed as inputs.

REQUIRES the corrected laranail/.github tests.yml. The version dated 2026-08-28
defaults laravel-versions to ["13.*"] and runs `composer require
illuminate/contracts` before the suite, which is the pin this change exists to
remove, and it has no laranail cache eviction, so adopting it unfixed would
serve stale archives from the moving v0.1.0 tag. Land that first.
Copilot AI lite review requested due to automatic review settings September 16, 2026 11:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit b126c00 into main Sep 16, 2026
2 checks passed
@imanimanyara
imanimanyara deleted the ci/manifest-resolution branch September 28, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants