Skip to content

TASK: Add a CI workflow for PHP, the inspector build and ESLint - #36

Merged
gradinarufelix merged 3 commits into
mainfrom
change-34-ci-workflow
Sep 27, 2026
Merged

gradinarufelix merged 3 commits into
mainfrom
change-34-ci-workflow

Conversation

@gradinarufelix

@gradinarufelix gradinarufelix commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Resolves #34

Adds .github/workflows/ci.yml. It runs on pull requests and pushes to main and needs no database. The workflow token can only read the repository, and no checkout keeps it.

Six checks run in seven jobs, because PHP lint runs for two PHP versions:

Check What it does
PHP lint php -l on Classes and Migrations with PHP 7.4 and 8.3.
PHPStan Installs Neos 8 in a throwaway distribution with this package as a path repository (composer init, then composer require neosidekick/revisions:*@dev phpstan/phpstan:2.2.16). Then runs PHPStan with phpstan.neon: level 5 on Classes, plus phpstan-baseline.neon.
Composer manifest composer validate --no-check-publish with PHP 8.3. Nothing is installed.
Translation files xmllint --noout on every .xlf file under Resources/Private/Translations, which must be well-formed XML.
Inspector build reproducibility Node from .nvmrc, which pins 14.21.3. Runs npm install --no-package-lock and node build.js in the plugin directory, then git diff --exit-code on Resources/Public/Assets/Plugin.js.
ESLint npm install --no-package-lock at the root, then npm run lint with the existing configuration.

PHPStan is pinned to 2.2.16, the version that generated the baseline, so a new PHPStan release cannot change the findings. The Neos packages that PHPStan analyses against are not pinned yet (#38). The Readme describes how to run the checks locally, including how to regenerate the baseline.

What main needed to pass

ESLint. The existing configuration could not run at all: @typescript-eslint 4 requires typescript, which was not a dev dependency. This PR adds typescript ~4.4.4, the newest version that @typescript-eslint 4.33 supports. On main, ESLint then reported 32 errors. The first commit fixes them:

  • 28 formatting findings, fixed with eslint --fix;
  • comments in two intentionally empty catch blocks;
  • rel="noreferrer" on the asset link that opens a new tab;
  • Record<string, unknown> instead of {} as the default response type of fetchFromBackend().

Plugin.js is rebuilt. Apart from the rel attribute, only the layout of the bundled code changes.

PHPStan. Error counts on main before #35 (bd4af63), measured with PHPStan 2.2.16 and Neos 8.4.7:

Level 0 1 2 3 4 5 6 7 8 9
Errors 0 0 5 7 18 18 57 68 78 91

Level 5 checks argument types but not the missing type declarations that level 6 adds. The 18 findings at level 5 are in the baseline, so only new ones fail. They fall into three groups:

  • docblocks that do not match the runtime types;
  • calls to methods that Node has but NodeInterface does not declare;
  • conditions PHPStan considers always true or always false.

The baseline was generated in CI. #35 adds no finding at level 5: the PHPStan job passes on the rebased branch with the unchanged baseline.

Runs

  • Before this PR, on this branch with a temporary push trigger that this PR no longer contains: run 36308226663, green on the five jobs the workflow had then.
  • The pull_request run of this PR is in the checks below.

Not in this PR

Formatting as Prettier expects it, comments in two intentionally empty
catch blocks, rel="noreferrer" on the asset link that opens a new tab,
and Record<string, unknown> instead of {} as the default response type.
Plugin.js is rebuilt; apart from the rel attribute, only the layout of
the bundled code changes.

Related: #34
Pull requests and pushes to main run these checks without a database:
- php -l on PHP 7.4 and 8.3;
- PHPStan level 5 against Neos 8, installed in a throwaway
  distribution with the package as a path repository. The 18
  existing findings are in phpstan-baseline.neon, so only new ones
  fail;
- a rebuild of the inspector with the Node version from .nvmrc,
  which must reproduce the committed Plugin.js byte for byte;
- ESLint with the existing configuration, which needs TypeScript as
  a dev dependency to run at all.

The Readme describes how to run the checks locally.

Resolves: #34
Node is pinned to 14.21.3 in .nvmrc and PHPStan to 2.2.16, the versions
of the first green run, so a patch release cannot break the build or
the baseline. The workflow only reads the repository and does not keep
the checkout token.

Two more jobs check composer.json with composer validate and the XLIFF
files for well-formed XML.

Related: #34
@gradinarufelix
gradinarufelix merged commit 57b90be into main Sep 27, 2026
7 checks passed
@gradinarufelix
gradinarufelix deleted the change-34-ci-workflow branch September 27, 2026 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TASK: Add a CI workflow (PHP lint and static analysis, inspector build reproducibility, ESLint)

1 participant