Skip to content

Drop cakephp/cakephp from the app skeleton to stop recurring Dependabot failures - #31

Merged
basi merged 1 commit into
mainfrom
work/drop-cakephp-from-app-skeleton
Sep 29, 2026
Merged

basi merged 1 commit into
mainfrom
work/drop-cakephp-from-app-skeleton

Conversation

@basi

@basi basi commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Summary

The Dependabot security update job composer in /app for cakephp/cakephp fails with dependency_file_not_resolvable. The latest failure is run 36533734936. The same job also failed on 2026-08-26, 08-27, 08-31 and 09-03.

app/composer.json (the application skeleton) requires cakephp/cakephp ~2.9 from Packagist, which resolves to upstream CakePHP 2.10.x. Two things make this fail:

  1. Many CakePHP advisories have no lower bound on the affected range (for example < 4.5.12), so Dependabot raises them against this manifest as well. No 2.x release fixes them.
  2. Composer also refuses to load cakephp/cakephp 2.9.0–2.10.24 because those versions are affected by security advisories. As a result, the manifest cannot be resolved at all:
Root composer.json requires cakephp/cakephp ~2.9, found cakephp/cakephp[2.9.0, ..., 2.10.24] but these were not loaded, because they are affected by security advisories ("PKSA-vxgj-bmcq-9b6x", "PKSA-wx2k-k564-z67n", "PKSA-hv96-tqmc-t3j9", "PKSA-8jvz-y796-qyx9").

This manifest has had four cakephp/cakephp alerts so far: 1, 2, 6 and 7. All four have been dismissed; alert 7 (GHSA-vjqc-q4mp-2rvf) was dismissed as inaccurate on 2026-09-29. No job is pending right now, but the next CakePHP advisory will start the cycle again.

The requirement is unused:

  • The in-repo app/ loads lib/Cake from the repository root. app/webroot/index.php:73-77 switches to app/Vendor/cakephp/cakephp/lib only if that directory exists, and app/Vendor/ contains nothing but an empty placeholder.
  • CI installs only the root composer.json (into vendors/), and the README tells consumers to use the VCS repository method.
  • If the requirement were installed, it would pull upstream 2.10.x (no PHP 8 support), and index.php would prefer it over this fork's lib/Cake.

This PR removes the requirement. The reasoning is the same as in 5bff587 (#21), which dropped phpunit/phpunit from this skeleton and resolved alert 3.

Changes

app/composer.json only:

 	"require": {
 		"php": ">=5.3.0",
-		"ext-mcrypt": "*",
-		"cakephp/cakephp": "~2.9"
+		"ext-mcrypt": "*"
 	},

The php and ext-mcrypt platform requirements stay as they are, to keep the diff small (this fork also imports upstream PRs).

Impact

  • Only the skeleton manifest changes. The root composer.json / composer.lock, lib/Cake and CI are unaffected.
  • The Tests workflow's Composer cache key (hashFiles('**/composer.json')) changes once.
  • Anyone who copies app/ out as a standalone project now needs to add CakePHP by following the README's VCS repository instructions. Before this change they would have gotten upstream 2.10.x, which Composer already blocks.

Verification

Reproduced in throwaway temp dirs with the Docker composer:2 image (Composer 2.10.2), using composer update --dry-run --ignore-platform-reqs. The platform flag is needed because the image has no mcrypt.

Manifest Exit Result
app/composer.json on origin/main 2 ... these were not loaded, because they are affected by security advisories ... (the same error as the Dependabot run)
This PR 0 Nothing to install, update or remove
  • composer validate --no-check-publish prints ./composer.json is valid for both.
  • jq parses the file, and git diff origin/main contains only the lines shown above.
  • Not verified by running it: the dependency graph and Dependabot pick up the change only after it is merged to main.

Post-merge QA

  • The dependency graph lists only php and ext-mcrypt for app/composer.json (GraphQL repository.dependencyGraphManifests)
  • gh api 'repos/basi/cakephp2-php8/dependabot/alerts?state=open&manifest=app/composer.json' returns []
  • No new failing composer in /app Dependabot Updates run appears
  • The Bump version run for the merge commit is green. This requires Skip the GitHub release when it already exists (fixes 422 on every merge to main) #30 to be merged first; otherwise that run hits the pre-existing 422.

Out of scope

🤖 Generated with Claude Code

The skeleton requires cakephp/cakephp ~2.9 from Packagist, which is
upstream CakePHP 2.10.x. It does not support PHP 8, and Composer now
refuses to load 2.9.0-2.10.24 because of security advisories. CakePHP
advisories without a lower bound keep raising Dependabot alerts on this
manifest (alerts 1, 2, 6 and 7) with no 2.x fix, and each one makes the
"composer in /app" security update job fail with
dependency_file_not_resolvable.

The in-repo app loads lib/Cake from the repository root, CI installs
only the root composer.json, and the README documents the VCS
repository method, so the requirement is unused. This is the same
rationale as 5bff587, which dropped phpunit from this skeleton.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@basi
basi requested a review from uepyon9 September 29, 2026 11:33
@basi
basi marked this pull request as ready for review September 29, 2026 11:33
@basi basi self-assigned this Sep 29, 2026
@basi
basi merged commit 11dd98e into main Sep 29, 2026
4 checks passed
@basi
basi deleted the work/drop-cakephp-from-app-skeleton branch September 29, 2026 11:49
@basi
basi removed the request for review from uepyon9 September 29, 2026 11:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants