Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
version: 2

updates:
# Actions are pinned to commit SHAs so an upstream tag repoint can't run unreviewed code with the
# workflow token. That only stays safe if something bumps them — a pinned SHA never receives a
# security fix on its own. Dependabot rewrites the SHA and the `# version` comment together.
- package-ecosystem: github-actions
directory: /
schedule:
interval: weekly
groups:
actions:
patterns: ['*']
4 changes: 2 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ jobs:
release:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Extract the CHANGELOG section for this tag
run: |
Expand All @@ -29,7 +29,7 @@ jobs:
echo "See the [CHANGELOG](CHANGELOG.md)." > RELEASE_NOTES.md
fi

- uses: softprops/action-gh-release@v3
- uses: softprops/action-gh-release@3d0d9888cb7fd7b750713d6e236d1fcb99157228 # v3.0.2
with:
name: ${{ github.ref_name }}
body_path: RELEASE_NOTES.md
Expand Down
81 changes: 73 additions & 8 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,10 @@
name: Pint (code style)
steps:
- name: Checkout
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup PHP
uses: shivammathur/setup-php@v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.4'
coverage: none
Expand Down Expand Up @@ -42,10 +42,10 @@

steps:
- name: Checkout
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup PHP
uses: shivammathur/setup-php@v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: ${{ matrix.php }}
extensions: mbstring, sqlite3, pdo_sqlite
Expand All @@ -62,15 +62,80 @@
- name: Run tests
run: vendor/bin/pest

concurrency-engines:
runs-on: ubuntu-latest
name: Concurrency (${{ matrix.engine }})
strategy:
fail-fast: false
matrix:
engine: ['pgsql', 'mysql']

# sqlite :memory: serialises writers, so isolation-level behaviour is invisible in the
# default suite. These run against a real engine: they pin the family-revoke/rotation race
# which reproduces on PostgreSQL (READ COMMITTED) and not on MySQL.
services:
postgres:
image: postgres:17-alpine
env:
POSTGRES_USER: lukk
POSTGRES_PASSWORD: lukk
POSTGRES_DB: lukk
ports: ['55432:5432']
options: >-
--health-cmd "pg_isready -U lukk" --health-interval 2s
--health-timeout 3s --health-retries 30
mysql:
image: mysql:8.4
env:
MYSQL_ROOT_PASSWORD: lukk
MYSQL_DATABASE: lukk
MYSQL_USER: lukk
MYSQL_PASSWORD: lukk
ports: ['33306:3306']
options: >-
--health-cmd "mysqladmin ping -plukk" --health-interval 2s
--health-timeout 3s --health-retries 30

steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.4'
# pgsql/mysqli are needed for the ASYNC statement: firing the concurrent revoke without
# blocking is the only way to reproduce the interleaving from one process.
extensions: mbstring, sqlite3, pdo_sqlite, pdo_pgsql, pgsql, pdo_mysql, mysqli
coverage: none

- name: Install dependencies
run: composer update --prefer-dist --no-interaction --no-progress

- name: Run the concurrency suite
env:
LUKK_TEST_ENGINE: ${{ matrix.engine }}
LUKK_TEST_PGSQL: '1'
LUKK_TEST_MYSQL: '1'
# The tests skip themselves when the engine is unreachable — right locally, useless here,
# where a silent skip is indistinguishable from a pass. So fail on one.
run: |
set -o pipefail
vendor/bin/pest --group=concurrency | tee /tmp/concurrency.log
if grep -q 'skipped' /tmp/concurrency.log; then
echo "::error::the concurrency suite skipped — the ${{ matrix.engine }} service was not reachable"
exit 1
fi

coverage:

Check warning

Code scanning / CodeQL

Workflow does not contain permissions Medium test

Actions job or workflow does not limit the permissions of the GITHUB_TOKEN. Consider setting an explicit permissions block, using the following as a minimal starting point: {contents: read}
runs-on: ubuntu-latest
name: Coverage (100%)
steps:
- name: Checkout
uses: actions/checkout@v7
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Setup PHP
uses: shivammathur/setup-php@v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.4'
extensions: mbstring, sqlite3, pdo_sqlite
Expand All @@ -89,11 +154,11 @@
all-checks:
name: All checks passed
if: always()
needs: [lint, tests, coverage]
needs: [lint, tests, concurrency-engines, coverage]
runs-on: ubuntu-latest
steps:
- name: Fail if any job did not succeed
if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}
run: exit 1
- name: All required jobs passed
run: echo "lint + matrix + coverage all green."
run: echo "lint + matrix + concurrency + coverage all green."
91 changes: 0 additions & 91 deletions AUDIT.md

This file was deleted.

Loading