Skip to content

Lint with the shared Pint config, and stop moving action pins backwards - #7

Merged
imanimanyara merged 1 commit into
mainfrom
ci/alias-and-dependabot
Sep 16, 2026
Merged

imanimanyara merged 1 commit into
mainfrom
ci/alias-and-dependabot

Conversation

@imanimanyara

Copy link
Copy Markdown
Member

Lint with the shared Pint config, and stop moving action pins backwards

Style. vendor/bin/laranail-pint resolves the one config in
vendor/laranail/package-tools and errors when it is absent. Bare
vendor/bin/pint takes a --config path that does not exist, silently falls
back to its own defaults and exits 0 -- so twelve workflows in this family were
reporting "code style clean" against a rule set no other package uses. Those now
call laranail-pint, and this is what the shared config actually wanted: import
order, . spacing, => alignment, brace position, single-line empty bodies,
phpdoc alignment. No behaviour changes; the suites are unchanged and green.

Pins. The release.yml consistency pass had copied one repo's pins over
fourteen others, and that repo was behind: softprops/action-gh-release went
v3.0.3 -> v3.0.2 (v3.0.3 -> v2 in enumerator) and anchore/sbom-action went
v0.24.2 -> v0.24.0. Pinning to a SHA is a supply-chain control, so a pin moving
backwards is the one direction that must never happen by accident -- and nothing
catches it, because the pin check verifies the SHA against its comment, not that
the version moved forward. Both are on one pin family-wide now, at the newest
release, with the exact release tag in the comment rather than a moving major.

And the alias debris. Where the $commandAliases declarations were deleted,
this also fixes the two command bases that read $this->commandAliases without
declaring it (an Undefined property at construction, which took out
artisan package:discover), a command that called a sibling by its deleted
alias, a success message naming a command that no longer exists, and the docs
that still documented the aliases as the way in.

**Style.** `vendor/bin/laranail-pint` resolves the one config in
vendor/laranail/package-tools and errors when it is absent. Bare
`vendor/bin/pint` takes a `--config` path that does not exist, silently falls
back to its own defaults and exits 0 -- so twelve workflows in this family were
reporting "code style clean" against a rule set no other package uses. Those now
call laranail-pint, and this is what the shared config actually wanted: import
order, `.` spacing, `=>` alignment, brace position, single-line empty bodies,
phpdoc alignment. No behaviour changes; the suites are unchanged and green.

**Pins.** The release.yml consistency pass had copied one repo's pins over
fourteen others, and that repo was behind: `softprops/action-gh-release` went
v3.0.3 -> v3.0.2 (v3.0.3 -> v2 in enumerator) and `anchore/sbom-action` went
v0.24.2 -> v0.24.0. Pinning to a SHA is a supply-chain control, so a pin moving
backwards is the one direction that must never happen by accident -- and nothing
catches it, because the pin check verifies the SHA against its comment, not that
the version moved forward. Both are on one pin family-wide now, at the newest
release, with the exact release tag in the comment rather than a moving major.

**And the alias debris.** Where the `$commandAliases` declarations were deleted,
this also fixes the two command bases that read `$this->commandAliases` without
declaring it (an `Undefined property` at construction, which took out
`artisan package:discover`), a command that called a sibling by its deleted
alias, a success message naming a command that no longer exists, and the docs
that still documented the aliases as the way in.
Copilot AI lite review requested due to automatic review settings September 16, 2026 16:45

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@imanimanyara
imanimanyara merged commit 2267ce5 into main Sep 16, 2026
6 checks passed
@imanimanyara
imanimanyara deleted the ci/alias-and-dependabot branch September 28, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants