Skip to content

chore(deps): update dependency friendsofphp/php-cs-fixer to v3.95.21 #52550

chore(deps): update dependency friendsofphp/php-cs-fixer to v3.95.21

chore(deps): update dependency friendsofphp/php-cs-fixer to v3.95.21 #52550

Workflow file for this run

# MegaLinter GitHub Action configuration file
# More info at https://megalinter.io
---
name: MegaLinter
# Trigger mega-linter at every push. Action will also be visible from Pull
# Requests to main
on:
# push is restricted to main-line branches: feature branches are already
# covered by the pull_request event, and unrestricted push triggered a
# duplicate run for every commit of every open PR
push:
branches:
- main
- master
- alpha # ml workflow addition
pull_request:
branches:
- main
- master
- alpha # ml workflow addition
# Comment env block if you do not want to apply fixes
permissions: {}
env:
# Apply linter fixes configuration
#
# When active, APPLY_FIXES must also be defined as environment variable
# (in github/workflows/mega-linter.yml or other CI tool)
APPLY_FIXES: all
# Decide which event triggers application of fixes in a commit or a PR
# (pull_request, push, all)
APPLY_FIXES_EVENT: pull_request
# If APPLY_FIXES is used, defines if the fixes are directly committed (commit)
# or posted in a PR (pull_request)
APPLY_FIXES_MODE: commit
concurrency:
group: ${{ github.ref }}-${{ github.workflow }}
cancel-in-progress: true
jobs:
megalinter:
name: MegaLinter
runs-on: ubuntu-latest
# Give the default GITHUB_TOKEN write permission to commit and push, comment
# issues & post new PR; remove the ones you do not need
permissions:
contents: write
issues: write
pull-requests: write
environment: # ml workflow addition
name: dev # ml workflow addition
steps:
# Git Checkout
- name: Checkout Code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
# SECURITY NOTE: Using a Personal Access Token (PAT) is NOT
# recommended for end-users. Open-source projects have been heavily
# targeted by supply-chain attacks recently, and a leaked PAT can
# give attackers broad write access to your repository — better
# safe than sorry! If you only need workflows to re-trigger after
# MegaLinter applies fixes, prefer one of these safer alternatives:
# - Manually re-run the workflow from the GitHub Actions tab, or
# - Push another commit on the branch to trigger workflows again.
# The MegaLinter project itself uses a tightly-scoped PAT here for
# its own release automation needs — do not copy this pattern.
token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }}
# persist-credentials: false # Comment this line and uncomment the next one if you use APPLY_FIXES
persist-credentials: true # zizmor: ignore[artipacked]
# Shallow clone (default fetch-depth: 1): this workflow runs with
# VALIDATE_ALL_CODEBASE: true so MegaLinter never diffs against the
# base branch, and all secret scanners run in filesystem mode — full
# git history is not needed and fetching it costs 2+ minutes.
# If you switch VALIDATE_ALL_CODEBASE to false, restore:
# fetch-depth: 0
# Cache the grype vulnerability database between runs: downloading it is
# what makes REPOSITORY_GRYPE take ~2 minutes on a cold run. grype still
# refreshes the DB itself when the cached copy is older than its max age.
- name: Cache grype vulnerability DB
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6
with:
path: .megalinter-cache/grype
key: grype-db-${{ github.run_id }}
restore-keys: |
grype-db-
# MegaLinter
- name: MegaLinter
# You can override MegaLinter flavor used to have faster performances
# More info at https://megalinter.io/flavors/
uses: oxsecurity/megalinter/flavors/python@beta # zizmor: ignore[unpinned-uses,ref-confusion]
id: ml
# All available variables are described in documentation
# https://megalinter.io/configuration/
env:
# Validates all source when push on main, else just the git diff with
# main. Override with true if you always want to lint all sources
#
# To validate the entire codebase, set to:
# VALIDATE_ALL_CODEBASE: true
#
# To validate only diff with main, set to:
# VALIDATE_ALL_CODEBASE: >-
# ${{
# github.event_name == 'push' &&
# contains(fromJSON('["refs/heads/main", "refs/heads/master"]'), github.ref)
# }}
VALIDATE_ALL_CODEBASE: true # ml workflow change
# >-
# ${{
# github.event_name == 'push' &&
# contains(fromJSON('["refs/heads/main", "refs/heads/master"]'), github.ref)
# }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
EMAIL_REPORTER_SMTP_PASSWORD: ${{ secrets.SMTP_PASSWORD }} # ml workflow addtion
# Reuse the cached grype vulnerability DB (see "Cache grype vulnerability DB" step)
GRYPE_DB_CACHE_DIR: /github/workspace/.megalinter-cache/grype
# Disable LLM Advisor for bot PRs (dependabot, renovate, etc.)
LLM_ADVISOR_ENABLED: >-
${{
github.event_name != 'pull_request' ||
(
github.event.pull_request.user.login != 'dependabot[bot]' &&
github.event.pull_request.user.login != 'renovate[bot]' &&
github.event.pull_request.user.login != 'github-actions[bot]' &&
!startsWith(github.event.pull_request.user.login, 'dependabot') &&
!startsWith(github.event.pull_request.user.login, 'renovate')
)
}}
# Uncomment to use ApiReporter (Grafana)
API_REPORTER: true
API_REPORTER_URL: ${{ secrets.API_REPORTER_URL }}
API_REPORTER_BASIC_AUTH_USERNAME: ${{ secrets.API_REPORTER_BASIC_AUTH_USERNAME }}
API_REPORTER_BASIC_AUTH_PASSWORD: ${{ secrets.API_REPORTER_BASIC_AUTH_PASSWORD }}
API_REPORTER_METRICS_URL: ${{ secrets.API_REPORTER_METRICS_URL }}
API_REPORTER_METRICS_BASIC_AUTH_USERNAME: ${{ secrets.API_REPORTER_METRICS_BASIC_AUTH_USERNAME }}
API_REPORTER_METRICS_BASIC_AUTH_PASSWORD: ${{ secrets.API_REPORTER_METRICS_BASIC_AUTH_PASSWORD }}
API_REPORTER_DEBUG: false
# ADD YOUR CUSTOM ENV VARIABLES HERE OR DEFINE THEM IN A FILE
# .mega-linter.yml AT THE ROOT OF YOUR REPOSITORY
# Uncomment to disable copy-paste and spell checks
# DISABLE: COPYPASTE,SPELL
# Upload MegaLinter artifacts
- name: Archive production artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
if: success() || failure()
with:
name: MegaLinter reports
include-hidden-files: "true"
path: |
megalinter-reports
mega-linter.log
# Set APPLY_FIXES_IF var for use in future steps
- name: Set APPLY_FIXES_IF var
run: |
printf 'APPLY_FIXES_IF=%s\n' "${{
steps.ml.outputs.has_updated_sources == 1 &&
(
env.APPLY_FIXES_EVENT == 'all' ||
env.APPLY_FIXES_EVENT == github.event_name
) &&
(
github.event_name == 'push' ||
github.event.pull_request.head.repo.full_name == github.repository
)
}}" >> "${GITHUB_ENV}"
# Set APPLY_FIXES_IF_* vars for use in future steps
- name: Set APPLY_FIXES_IF_* vars
run: |
printf 'APPLY_FIXES_IF_PR=%s\n' "${{
env.APPLY_FIXES_IF == 'true' &&
env.APPLY_FIXES_MODE == 'pull_request'
}}" >> "${GITHUB_ENV}"
printf 'APPLY_FIXES_IF_COMMIT=%s\n' "${{
env.APPLY_FIXES_IF == 'true' &&
env.APPLY_FIXES_MODE == 'commit' &&
(!contains(fromJSON('["refs/heads/main", "refs/heads/master"]'), github.ref))
}}" >> "${GITHUB_ENV}"
# Create pull request if applicable
# (for now works only on PR from same repository, not from forks)
- name: Create Pull Request with applied fixes
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8
id: cpr
if: env.APPLY_FIXES_IF_PR == 'true'
with:
# SECURITY NOTE: see the warning on the checkout step above —
# using `secrets.PAT` is NOT recommended for end-users.
# Prefer manually re-running the workflow or pushing another
# commit on the branch to trigger workflows again.
token: ${{ secrets.PAT || secrets.GITHUB_TOKEN }}
commit-message: "[MegaLinter] Apply linters automatic fixes"
title: "[MegaLinter] Apply linters automatic fixes"
labels: bot
- name: Create PR output
if: env.APPLY_FIXES_IF_PR == 'true'
run: |
echo "PR Number - ${STEPS_CPR_OUTPUTS_PULL_REQUEST_NUMBER}"
echo "PR URL - ${STEPS_CPR_OUTPUTS_PULL_REQUEST_URL}"
env:
STEPS_CPR_OUTPUTS_PULL_REQUEST_NUMBER: ${{ steps.cpr.outputs.pull-request-number }}
STEPS_CPR_OUTPUTS_PULL_REQUEST_URL: ${{ steps.cpr.outputs.pull-request-url }}
# Push new commit if applicable
# (for now works only on PR from same repository, not from forks)
- name: Prepare commit
if: env.APPLY_FIXES_IF_COMMIT == 'true'
run: sudo chown -Rc $UID .git/
- name: Skip markdown/json-only fix commit for bot branches
if: env.APPLY_FIXES_IF_COMMIT == 'true'
shell: bash
env:
HEAD_REF: ${{ github.event.pull_request.head.ref || github.head_ref || github.ref_name }}
run: |
branch="${HEAD_REF}"
case "$branch" in
create-pull-request/patch|dependabot/*|renovate/*)
;;
*)
exit 0
;;
esac
changed_files=$(
{
git diff --name-only --diff-filter=ACMR HEAD
git ls-files --others --exclude-standard
} | sort -u
)
if [ -z "$changed_files" ]; then
exit 0
fi
if echo "$changed_files" | grep -viE '\.(md|json)$' > /dev/null; then
exit 0
fi
echo 'APPLY_FIXES_IF_COMMIT=false' >> "${GITHUB_ENV}"
- name: Commit and push applied linter fixes
uses: stefanzweifel/git-auto-commit-action@4a55954c782fc1ea30b9056cd3e7a2b40ca8887d # v7
if: env.APPLY_FIXES_IF_COMMIT == 'true'
with:
branch: >-
${{
github.event.pull_request.head.ref ||
github.head_ref ||
github.ref
}}
commit_message: "[MegaLinter] Apply linters fixes"
commit_user_name: megalinter-bot
commit_user_email: 129584137+megalinter-bot@users.noreply.github.com