Repository navigation
TASK: Add a CI workflow for PHP, the inspector build and ESLint - #36
Merged
Merged
Conversation
Formatting as Prettier expects it, comments in two intentionally empty
catch blocks, rel="noreferrer" on the asset link that opens a new tab,
and Record<string, unknown> instead of {} as the default response type.
Plugin.js is rebuilt; apart from the rel attribute, only the layout of
the bundled code changes.
Related: #34
Pull requests and pushes to main run these checks without a database: - php -l on PHP 7.4 and 8.3; - PHPStan level 5 against Neos 8, installed in a throwaway distribution with the package as a path repository. The 18 existing findings are in phpstan-baseline.neon, so only new ones fail; - a rebuild of the inspector with the Node version from .nvmrc, which must reproduce the committed Plugin.js byte for byte; - ESLint with the existing configuration, which needs TypeScript as a dev dependency to run at all. The Readme describes how to run the checks locally. Resolves: #34
Node is pinned to 14.21.3 in .nvmrc and PHPStan to 2.2.16, the versions of the first green run, so a patch release cannot break the build or the baseline. The workflow only reads the repository and does not keep the checkout token. Two more jobs check composer.json with composer validate and the XLIFF files for well-formed XML. Related: #34
gradinarufelix
force-pushed
the
change-34-ci-workflow
branch
from
September 27, 2026 21:09
f90a1ad to
5b72d9d
Compare
12 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves #34
Adds
.github/workflows/ci.yml. It runs on pull requests and pushes tomainand needs no database. The workflow token can only read the repository, and no checkout keeps it.Six checks run in seven jobs, because PHP lint runs for two PHP versions:
php -lonClassesandMigrationswith PHP 7.4 and 8.3.composer init, thencomposer require neosidekick/revisions:*@dev phpstan/phpstan:2.2.16). Then runs PHPStan withphpstan.neon: level 5 onClasses, plusphpstan-baseline.neon.composer validate --no-check-publishwith PHP 8.3. Nothing is installed.xmllint --noouton every.xlffile underResources/Private/Translations, which must be well-formed XML..nvmrc, which pins 14.21.3. Runsnpm install --no-package-lockandnode build.jsin the plugin directory, thengit diff --exit-codeonResources/Public/Assets/Plugin.js.npm install --no-package-lockat the root, thennpm run lintwith the existing configuration.PHPStan is pinned to 2.2.16, the version that generated the baseline, so a new PHPStan release cannot change the findings. The Neos packages that PHPStan analyses against are not pinned yet (#38). The Readme describes how to run the checks locally, including how to regenerate the baseline.
What main needed to pass
ESLint. The existing configuration could not run at all:
@typescript-eslint4 requirestypescript, which was not a dev dependency. This PR addstypescript~4.4.4, the newest version that@typescript-eslint4.33 supports. On main, ESLint then reported 32 errors. The first commit fixes them:eslint --fix;rel="noreferrer"on the asset link that opens a new tab;Record<string, unknown>instead of{}as the default response type offetchFromBackend().Plugin.jsis rebuilt. Apart from therelattribute, only the layout of the bundled code changes.PHPStan. Error counts on main before #35 (bd4af63), measured with PHPStan 2.2.16 and Neos 8.4.7:
Level 5 checks argument types but not the missing type declarations that level 6 adds. The 18 findings at level 5 are in the baseline, so only new ones fail. They fall into three groups:
Nodehas butNodeInterfacedoes not declare;The baseline was generated in CI. #35 adds no finding at level 5: the PHPStan job passes on the rebased branch with the unchanged baseline.
Runs
Not in this PR
npm ci, and pinned Neos versions for PHPStan. CI installs the npm packages without a lockfile, and the rootyarn.lockpredates the switch to esbuild and is not used. A new minor release of an ESLint plugin or a build dependency can therefore turn a job red without any change here.