Skip to content

Drop the bare command aliases, and group dependabot action updates - #6

Merged
imanimanyara merged 1 commit into
mainfrom
ci/alias-and-dependabot
Sep 16, 2026
Merged

imanimanyara merged 1 commit into
mainfrom
ci/alias-and-dependabot

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Two changes, both about names that live in a flat global registry.

The bare command aliases are gone. Every alias this package declared was an unscoped, generic name — env:set, make:crud, license, tidy. Artisan keeps command names in a flat map, so a second package claiming one does not collide loudly: it silently replaces the first, and the damage surfaces far away as the wrong code running under a familiar name. That is exactly the collision laranail::<slug>.<command> exists to prevent, and an unscoped alias hands it straight back. 127 of them across twelve packages, and not one was vendor-scoped.

The primary name is unchanged, so every command is still reachable as laranail::<slug>.<command>. The trait still applies $commandAliases when a command declares one, so a vendor-scoped alias remains possible where a short form genuinely earns it. Breaking for anyone typing an old short name.

Dependabot now groups action updates. github/codeql-action/init and /analyze must be the same version — CodeQL fails with "Loaded a configuration file for version X, but running version Y" — and dependabot proposed each subpath as its own pull request, so each one alone left the pair mismatched and red. laranail/confetti had two such PRs open, both failing, neither wrong on its own. Grouping fixes that for any paired action, not just CodeQL.

laranail/.github has shipped a reusable tests workflow for months and one
package of fifty-one called it. That is why a single defect -- pinning the
Laravel version into composer.json before the suite ran -- had to be fixed in
twenty-two places, and why prefer-lowest had to be added in twenty-seven.

Everything this file used to spell out now lives in one definition: the PHP
matrix, the composer cache and the laranail archive eviction it needs, the
prefer-lowest leg, fail-fast, the timeout. What stays here is what is genuinely
this package's own -- its PHP versions, its extensions, its test command --
passed as inputs.

REQUIRES the corrected laranail/.github tests.yml. The version dated 2026-08-28
defaults laravel-versions to ["13.*"] and runs `composer require
illuminate/contracts` before the suite, which is the pin this change exists to
remove, and it has no laranail cache eviction, so adopting it unfixed would
serve stale archives from the moving v0.1.0 tag. Land that first.

Resolve dependencies from the manifest, and cache them

CI pinned versions into composer.json before running the suite. `composer
require --no-update` EDITS the file -- verified: `^13.0` becomes `13.*` -- so
every run tested a manifest the package does not ship. Nothing broke, because
the forced constraint happened to agree with the declared one; it would have
broken silently the first time either changed, and widening a package to
`^13.0 || ^14.0` would never have been tested at all.

The matrix keys feeding those pins are gone with them. Several were already
inert: `testbench` and `carbon` were declared in the matrix and referenced by
no step, so they pinned nothing and always resolved from composer.json.

Also here, all measured rather than assumed:

- A composer cache. Most workflows re-downloaded every dependency on every
  run, which is the largest avoidable draw on the Actions budget.
- The cache drops laranail/* archives before installing. Those resolve through
  a single MOVING v0.1.0 tag, so composer's dist cache is keyed on a name whose
  contents change underneath it -- without the eviction a restored archive is
  silently stale, which is the failure this org has already hit once.
- fail-fast off where it was on. "8.5 fails too" and "only 8.5 fails" are
  different bugs, and fail-fast hides which one a run found.
- No coverage driver where nothing consumed the report. pcov instruments every
  file on every run; generating a report nobody reads is time billed for
  nothing. Untouched wherever an upload or a --min gate uses it.
- paths-ignore '*.md' -> '**.md'. The root-only glob never matched docs/**, so
  documentation-only changes ran the full suite.
Copilot AI lite review requested due to automatic review settings September 16, 2026 12:33

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@imanimanyara
imanimanyara merged commit a6d8591 into main Sep 16, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants