From b3d2b138f10d5dac698a87fb3798b52622a5157b Mon Sep 17 00:00:00 2001 From: Paul Isaris Date: Wed, 30 Sep 2026 11:42:44 +0300 Subject: [PATCH] Report abandoned Composer packages instead of failing by default composer audit fails on abandoned packages since Composer 2.7. The first real run failed on a transitive dev dependency with no replacement. The new composer-abandoned input (ignore, report, fail) defaults to report. --- .github/workflows/README.md | 2 ++ .github/workflows/security.yml | 10 +++++++++- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/.github/workflows/README.md b/.github/workflows/README.md index 7690e96..000a482 100644 --- a/.github/workflows/README.md +++ b/.github/workflows/README.md @@ -305,6 +305,7 @@ npm-only and PHP-only repositories. | --- | --- | --- | | `working-directory` | `.` | `frontend`, `apps/web`. The npm hardening and audit checks run there | | `php-version` | `'8.4'` | `'8.3'` | +| `composer-abandoned` | `report` (list, do not fail) | `ignore`, `fail` | | `npm-audit-level` | `high` | `low`, `moderate`, `critical` | | `strict-dev-configs` | `false` (warn only) | `true` (fail on suspicious commands) | | `allowed-dev-scripts` | `''` (no scripts allowed) | `.claude/hooks/*.sh` (one glob per line; `*` also matches `/`) | @@ -350,6 +351,7 @@ jobs: | `Environment file '...' not found` (Laravel) | Your repository has no `.env.testing` and no `.env.example`, or `env-file` points to a missing file. | | Browser tests also run in `Backend tests` (Laravel) | Exclude the browser suite in `test-command`, for example `vendor/bin/pest --exclude-testsuite=Browser`. | | `Environment files are committed to the repository` | A real env file, such as `.env` or `.env.production`, is committed. Remove it and rotate its secrets. A template must end in `.example`, `.dist`, `.sample`, `.template`, `.tpl`, `.j2`, `.jinja` or `.jinja2`. | +| `Found 1 abandoned package` fails the `Dependency audit` job | The caller sets `composer-abandoned: fail`. Replace the package, or set `composer-abandoned: report`. | | `Script files found in dev tool directories` | A script file is in `.vscode`, `.claude`, `.cursor` or `.idea`. Remove it, or review it and add it to `allowed-dev-scripts`. | | PHPStan or Rector re-analyse every file on each run | `analysis-cache-paths` does not match `tmpDir` in `phpstan.neon` or `cacheDirectory` in `rector.php`. | diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 113d008..e5c4b37 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -32,6 +32,10 @@ on: description: PHP version used to run `composer audit`. type: string default: '8.4' + composer-abandoned: + description: 'What composer audit does with abandoned packages. One of: ignore, report, fail' + type: string + default: report npm-audit-level: description: Lowest npm advisory severity that fails the audit (low, moderate, high, critical). type: string @@ -183,9 +187,13 @@ jobs: tools: composer:v2 # --locked reads composer.lock, so no `composer install` is needed. + # Abandoned packages only get reported by default: a transitive package + # without a replacement is not something a pull request can fix. - name: Composer audit if: hashFiles(format('{0}/composer.lock', inputs.working-directory)) != '' - run: composer audit --locked --format=table + env: + ABANDONED: ${{ inputs.composer-abandoned }} + run: composer audit --locked --abandoned="$ABANDONED" --format=table - name: npm audit if: hashFiles(format('{0}/package-lock.json', inputs.working-directory)) != ''