Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -305,6 +305,7 @@ npm-only and PHP-only repositories.
| --- | --- | --- |
| `working-directory` | `.` | `frontend`, `apps/web`. The npm hardening and audit checks run there |
| `php-version` | `'8.4'` | `'8.3'` |
| `composer-abandoned` | `report` (list, do not fail) | `ignore`, `fail` |
| `npm-audit-level` | `high` | `low`, `moderate`, `critical` |
| `strict-dev-configs` | `false` (warn only) | `true` (fail on suspicious commands) |
| `allowed-dev-scripts` | `''` (no scripts allowed) | `.claude/hooks/*.sh` (one glob per line; `*` also matches `/`) |
Expand Down Expand Up @@ -350,6 +351,7 @@ jobs:
| `Environment file '...' not found` (Laravel) | Your repository has no `.env.testing` and no `.env.example`, or `env-file` points to a missing file. |
| Browser tests also run in `Backend tests` (Laravel) | Exclude the browser suite in `test-command`, for example `vendor/bin/pest --exclude-testsuite=Browser`. |
| `Environment files are committed to the repository` | A real env file, such as `.env` or `.env.production`, is committed. Remove it and rotate its secrets. A template must end in `.example`, `.dist`, `.sample`, `.template`, `.tpl`, `.j2`, `.jinja` or `.jinja2`. |
| `Found 1 abandoned package` fails the `Dependency audit` job | The caller sets `composer-abandoned: fail`. Replace the package, or set `composer-abandoned: report`. |
| `Script files found in dev tool directories` | A script file is in `.vscode`, `.claude`, `.cursor` or `.idea`. Remove it, or review it and add it to `allowed-dev-scripts`. |
| PHPStan or Rector re-analyse every file on each run | `analysis-cache-paths` does not match `tmpDir` in `phpstan.neon` or `cacheDirectory` in `rector.php`. |

Expand Down
10 changes: 9 additions & 1 deletion .github/workflows/security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,10 @@ on:
description: PHP version used to run `composer audit`.
type: string
default: '8.4'
composer-abandoned:
description: 'What composer audit does with abandoned packages. One of: ignore, report, fail'
type: string
default: report
npm-audit-level:
description: Lowest npm advisory severity that fails the audit (low, moderate, high, critical).
type: string
Expand Down Expand Up @@ -183,9 +187,13 @@ jobs:
tools: composer:v2

# --locked reads composer.lock, so no `composer install` is needed.
# Abandoned packages only get reported by default: a transitive package
# without a replacement is not something a pull request can fix.
- name: Composer audit
if: hashFiles(format('{0}/composer.lock', inputs.working-directory)) != ''
run: composer audit --locked --format=table
env:
ABANDONED: ${{ inputs.composer-abandoned }}
run: composer audit --locked --abandoned="$ABANDONED" --format=table

- name: npm audit
if: hashFiles(format('{0}/package-lock.json', inputs.working-directory)) != ''
Expand Down
Loading