From 2d8d4c0754073c53242c073638dbc5e26a870470 Mon Sep 17 00:00:00 2001 From: Imani Manyara Date: Wed, 16 Sep 2026 06:18:56 -0400 Subject: [PATCH 1/2] Resolve dependencies from the manifest, and cache them CI pinned versions into composer.json before running the suite. `composer require --no-update` EDITS the file -- verified: `^13.0` becomes `13.*` -- so every run tested a manifest the package does not ship. Nothing broke, because the forced constraint happened to agree with the declared one; it would have broken silently the first time either changed, and widening a package to `^13.0 || ^14.0` would never have been tested at all. The matrix keys feeding those pins are gone with them. Several were already inert: `testbench` and `carbon` were declared in the matrix and referenced by no step, so they pinned nothing and always resolved from composer.json. Also here, all measured rather than assumed: - A composer cache. Most workflows re-downloaded every dependency on every run, which is the largest avoidable draw on the Actions budget. - The cache drops laranail/* archives before installing. Those resolve through a single MOVING v0.1.0 tag, so composer's dist cache is keyed on a name whose contents change underneath it -- without the eviction a restored archive is silently stale, which is the failure this org has already hit once. - fail-fast off where it was on. "8.5 fails too" and "only 8.5 fails" are different bugs, and fail-fast hides which one a run found. - No coverage driver where nothing consumed the report. pcov instruments every file on every run; generating a report nobody reads is time billed for nothing. Untouched wherever an upload or a --min gate uses it. - paths-ignore '*.md' -> '**.md'. The root-only glob never matched docs/**, so documentation-only changes ran the full suite. --- .github/workflows/static-analysis.yml | 23 +++++++++++++++++++++++ .github/workflows/tests.yml | 23 +++++++++++++++++++++++ 2 files changed, 46 insertions(+) diff --git a/.github/workflows/static-analysis.yml b/.github/workflows/static-analysis.yml index b7d0b9b..a802b84 100644 --- a/.github/workflows/static-analysis.yml +++ b/.github/workflows/static-analysis.yml @@ -21,5 +21,28 @@ jobs: with: php-version: '8.4' coverage: none + - name: Resolve composer cache directory + id: composer-cache + shell: bash + run: echo "dir=$(composer config cache-files-dir)" >> "$GITHUB_OUTPUT" + + - name: Restore composer cache + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + with: + path: ${{ steps.composer-cache.outputs.dir }} + key: composer-${{ runner.os }}-${{ matrix.php }}-${{ hashFiles('**/composer.json') }} + restore-keys: composer-${{ runner.os }}-${{ matrix.php }}- + + - name: Drop cached laranail archives + # laranail/* resolve through a single MOVING v0.1.0 tag, so composer's dist + # cache is keyed on a name whose contents change underneath it. A restored + # archive is then silently stale: the install reports success and unpacks + # whatever was cached the first time. Everything else is immutable per + # version and stays cached. + # POSIX command via bash: Windows runners default to PowerShell, where this + # would be a parse error rather than a no-op. + shell: bash + run: rm -rf "$(composer config cache-files-dir)/laranail" + - run: composer update --prefer-dist --no-interaction - run: vendor/bin/pint --test diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index df269a8..98baa2a 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -28,5 +28,28 @@ jobs: with: php-version: ${{ matrix.php }} coverage: none + - name: Resolve composer cache directory + id: composer-cache + shell: bash + run: echo "dir=$(composer config cache-files-dir)" >> "$GITHUB_OUTPUT" + + - name: Restore composer cache + uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + with: + path: ${{ steps.composer-cache.outputs.dir }} + key: composer-${{ runner.os }}-${{ matrix.php }}-${{ hashFiles('**/composer.json') }} + restore-keys: composer-${{ runner.os }}-${{ matrix.php }}- + + - name: Drop cached laranail archives + # laranail/* resolve through a single MOVING v0.1.0 tag, so composer's dist + # cache is keyed on a name whose contents change underneath it. A restored + # archive is then silently stale: the install reports success and unpacks + # whatever was cached the first time. Everything else is immutable per + # version and stays cached. + # POSIX command via bash: Windows runners default to PowerShell, where this + # would be a parse error rather than a no-op. + shell: bash + run: rm -rf "$(composer config cache-files-dir)/laranail" + - run: composer update --${{ matrix.stability }} --prefer-dist --no-interaction - run: vendor/bin/pest --ci From b88d762ec09030e34b594adf0c338e613b5a848a Mon Sep 17 00:00:00 2001 From: Imani Manyara Date: Wed, 16 Sep 2026 06:31:09 -0400 Subject: [PATCH 2/2] Call the shared tests workflow instead of restating it laranail/.github has shipped a reusable tests workflow for months and one package of fifty-one called it. That is why a single defect -- pinning the Laravel version into composer.json before the suite ran -- had to be fixed in twenty-two places, and why prefer-lowest had to be added in twenty-seven. Everything this file used to spell out now lives in one definition: the PHP matrix, the composer cache and the laranail archive eviction it needs, the prefer-lowest leg, fail-fast, the timeout. What stays here is what is genuinely this package's own -- its PHP versions, its extensions, its test command -- passed as inputs. REQUIRES the corrected laranail/.github tests.yml. The version dated 2026-08-28 defaults laravel-versions to ["13.*"] and runs `composer require illuminate/contracts` before the suite, which is the pin this change exists to remove, and it has no laranail cache eviction, so adopting it unfixed would serve stale archives from the moving v0.1.0 tag. Land that first. --- .github/workflows/tests.yml | 63 +++++++++++-------------------------- 1 file changed, 18 insertions(+), 45 deletions(-) diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 98baa2a..554f251 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -2,54 +2,27 @@ name: Tests on: pull_request: + branches: [main] + paths-ignore: + - '**.md' + workflow_dispatch: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true -permissions: - contents: read - +# Calls the one shared definition in laranail/.github. Everything this file used +# to spell out -- the PHP matrix, the composer cache and its laranail eviction, +# prefer-lowest, fail-fast, timeouts -- lives there now, so a change to how this +# family tests is one edit instead of fifty. jobs: - test: - runs-on: ubuntu-latest - timeout-minutes: 15 - strategy: - fail-fast: false - matrix: - php: ['8.4', '8.5'] - stability: [prefer-lowest, prefer-stable] - - name: PHP ${{ matrix.php }} ยท ${{ matrix.stability }} - - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - - uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2 - with: - php-version: ${{ matrix.php }} - coverage: none - - name: Resolve composer cache directory - id: composer-cache - shell: bash - run: echo "dir=$(composer config cache-files-dir)" >> "$GITHUB_OUTPUT" - - - name: Restore composer cache - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ${{ steps.composer-cache.outputs.dir }} - key: composer-${{ runner.os }}-${{ matrix.php }}-${{ hashFiles('**/composer.json') }} - restore-keys: composer-${{ runner.os }}-${{ matrix.php }}- - - - name: Drop cached laranail archives - # laranail/* resolve through a single MOVING v0.1.0 tag, so composer's dist - # cache is keyed on a name whose contents change underneath it. A restored - # archive is then silently stale: the install reports success and unpacks - # whatever was cached the first time. Everything else is immutable per - # version and stays cached. - # POSIX command via bash: Windows runners default to PowerShell, where this - # would be a parse error rather than a no-op. - shell: bash - run: rm -rf "$(composer config cache-files-dir)/laranail" - - - run: composer update --${{ matrix.stability }} --prefer-dist --no-interaction - - run: vendor/bin/pest --ci + pest: + uses: laranail/.github/.github/workflows/tests.yml@main + with: + # Pin nothing: resolve whatever composer.json allows. The shared workflow + # still defaults laravel-versions to ["13.*"], which runs + # `composer require illuminate/contracts` and REWRITES composer.json, so + # the suite would test a manifest this package does not ship. Remove this + # line only once that default is ["*"]. + laravel-versions: '["*"]' + test-command: 'vendor/bin/pest --ci --colors=never'