|
21 | 21 | matrix: |
22 | 22 | php: ["8.3"] |
23 | 23 | symfony: ["^5.4.21", "^6.4"] |
24 | | - sylius: ["~1.13.0", "~1.14.0"] |
| 24 | + sylius: ["~1.14.0"] |
25 | 25 | database: ["mysql", "postgres"] |
26 | 26 | mysql: ["8.4"] |
27 | 27 | postgres: ["15.8"] |
|
30 | 30 |
|
31 | 31 | include: |
32 | 32 | - |
33 | | - php: "8.1" |
| 33 | + php: "8.3" |
34 | 34 | symfony: "^6.4" |
35 | 35 | sylius: "~1.14.0" |
36 | 36 | database: "mysql" |
|
39 | 39 | wkhtmltopdf: "0.12.6-1" |
40 | 40 | state_machine_adapter: "symfony_workflow" |
41 | 41 | - |
42 | | - php: "8.2" |
| 42 | + php: "8.3" |
43 | 43 | symfony: "^6.4" |
44 | 44 | sylius: "~1.14.0" |
45 | 45 | database: "mysql" |
|
48 | 48 | wkhtmltopdf: "0.12.6-1" |
49 | 49 | state_machine_adapter: "winzou_state_machine" |
50 | 50 | - |
51 | | - php: "8.2" |
| 51 | + php: "8.3" |
52 | 52 | symfony: "^6.4" |
53 | 53 | sylius: "~1.14.0" |
54 | 54 | database: "mysql" |
@@ -143,6 +143,68 @@ jobs: |
143 | 143 | name: Install PHP dependencies |
144 | 144 | run: composer install --no-interaction |
145 | 145 |
|
| 146 | + - name: Run security checks |
| 147 | + run: | |
| 148 | + set -e |
| 149 | + |
| 150 | + composer audit --no-interaction --format=json > composer-audit.json || AUDIT_EXIT=$? |
| 151 | + |
| 152 | + IGNORED=$(jq -r '.config.audit.ignore[]?' composer.json | sort || true) |
| 153 | + |
| 154 | + if [ "${AUDIT_EXIT:-0}" -ne 0 ]; then |
| 155 | + FOUND=$(jq -r ' |
| 156 | + # Collect CVEs from both advisories and ignored-advisories |
| 157 | + (.advisories[]?.advisories[]?.cve? // empty), |
| 158 | + (.["ignored-advisories"][]?[]?.cve? // empty) |
| 159 | + ' composer-audit.json | sort | uniq) |
| 160 | + |
| 161 | + DIFF=$(comm -23 <(echo "$FOUND") <(echo "$IGNORED")) |
| 162 | + |
| 163 | + if [ -n "$DIFF" ]; then |
| 164 | + echo "❌ New vulnerabilities found by Composer audit:" |
| 165 | + echo "$DIFF" |
| 166 | + exit 1 |
| 167 | + else |
| 168 | + echo "✅ No new vulnerabilities found by Composer audit." |
| 169 | + fi |
| 170 | + else |
| 171 | + echo "✅ No new vulnerabilities found by Composer audit." |
| 172 | + fi |
| 173 | + |
| 174 | + symfony security:check --format=json > symfony-audit.json || true |
| 175 | + |
| 176 | + FOUND=$(jq -r '.[]?.advisories[]?.cve? // empty' symfony-audit.json | sort | uniq) |
| 177 | + |
| 178 | + DIFF=$(comm -23 <(echo "$FOUND") <(echo "$IGNORED")) |
| 179 | + |
| 180 | + if [ -n "$DIFF" ]; then |
| 181 | + echo "❌ New vulnerabilities found by Symfony security:check:" |
| 182 | + echo "$DIFF" |
| 183 | + exit 1 |
| 184 | + else |
| 185 | + echo "✅ No new vulnerabilities found by Symfony security:check." |
| 186 | + fi |
| 187 | +
|
| 188 | + - |
| 189 | + name: Run ECS |
| 190 | + run: vendor/bin/ecs check |
| 191 | + |
| 192 | + - |
| 193 | + name: Validate composer.json |
| 194 | + run: composer validate --ansi --strict |
| 195 | + |
| 196 | + - |
| 197 | + name: Run analysis |
| 198 | + run: composer analyse |
| 199 | + |
| 200 | + - |
| 201 | + name: Run PHPStan |
| 202 | + run: vendor/bin/phpstan analyse -c phpstan.neon.dist src/ |
| 203 | + |
| 204 | + - |
| 205 | + name: Run PHPSpec |
| 206 | + run: vendor/bin/phpspec run --ansi -f progress --no-interaction |
| 207 | + |
146 | 208 | - |
147 | 209 | name: Get Yarn cache directory |
148 | 210 | id: yarn-cache |
@@ -192,30 +254,6 @@ jobs: |
192 | 254 | name: Load fixtures in test application |
193 | 255 | run: (cd tests/Application && bin/console sylius:fixtures:load -n) |
194 | 256 |
|
195 | | - - |
196 | | - name: Run security check |
197 | | - run: symfony security:check |
198 | | - |
199 | | - - |
200 | | - name: Run ECS |
201 | | - run: vendor/bin/ecs check |
202 | | - |
203 | | - - |
204 | | - name: Validate composer.json |
205 | | - run: composer validate --ansi --strict |
206 | | - |
207 | | - - |
208 | | - name: Run analysis |
209 | | - run: composer analyse |
210 | | - |
211 | | - - |
212 | | - name: Run PHPStan |
213 | | - run: vendor/bin/phpstan analyse -c phpstan.neon.dist src/ |
214 | | - |
215 | | - - |
216 | | - name: Run PHPSpec |
217 | | - run: vendor/bin/phpspec run --ansi -f progress --no-interaction |
218 | | - |
219 | 257 | - |
220 | 258 | name: Run PHPUnit |
221 | 259 | run: vendor/bin/phpunit --colors=always |
|
0 commit comments