Drop cakephp/cakephp from the app skeleton to stop recurring Dependabot failures - #31
Merged
Merged
Conversation
The skeleton requires cakephp/cakephp ~2.9 from Packagist, which is upstream CakePHP 2.10.x. It does not support PHP 8, and Composer now refuses to load 2.9.0-2.10.24 because of security advisories. CakePHP advisories without a lower bound keep raising Dependabot alerts on this manifest (alerts 1, 2, 6 and 7) with no 2.x fix, and each one makes the "composer in /app" security update job fail with dependency_file_not_resolvable. The in-repo app loads lib/Cake from the repository root, CI installs only the root composer.json, and the README documents the VCS repository method, so the requirement is unused. This is the same rationale as 5bff587, which dropped phpunit from this skeleton. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
uepyon9
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The Dependabot security update job
composer in /app for cakephp/cakephpfails withdependency_file_not_resolvable. The latest failure is run 36533734936. The same job also failed on 2026-08-26, 08-27, 08-31 and 09-03.app/composer.json(the application skeleton) requirescakephp/cakephp ~2.9from Packagist, which resolves to upstream CakePHP 2.10.x. Two things make this fail:< 4.5.12), so Dependabot raises them against this manifest as well. No 2.x release fixes them.cakephp/cakephp2.9.0–2.10.24 because those versions are affected by security advisories. As a result, the manifest cannot be resolved at all:This manifest has had four
cakephp/cakephpalerts so far: 1, 2, 6 and 7. All four have been dismissed; alert 7 (GHSA-vjqc-q4mp-2rvf) was dismissed as inaccurate on 2026-09-29. No job is pending right now, but the next CakePHP advisory will start the cycle again.The requirement is unused:
app/loadslib/Cakefrom the repository root.app/webroot/index.php:73-77switches toapp/Vendor/cakephp/cakephp/libonly if that directory exists, andapp/Vendor/contains nothing but anemptyplaceholder.composer.json(intovendors/), and the README tells consumers to use the VCS repository method.index.phpwould prefer it over this fork'slib/Cake.This PR removes the requirement. The reasoning is the same as in 5bff587 (#21), which dropped
phpunit/phpunitfrom this skeleton and resolved alert 3.Changes
app/composer.jsononly:"require": { "php": ">=5.3.0", - "ext-mcrypt": "*", - "cakephp/cakephp": "~2.9" + "ext-mcrypt": "*" },The
phpandext-mcryptplatform requirements stay as they are, to keep the diff small (this fork also imports upstream PRs).Impact
composer.json/composer.lock,lib/Cakeand CI are unaffected.hashFiles('**/composer.json')) changes once.app/out as a standalone project now needs to add CakePHP by following the README's VCS repository instructions. Before this change they would have gotten upstream 2.10.x, which Composer already blocks.Verification
Reproduced in throwaway temp dirs with the Docker
composer:2image (Composer 2.10.2), usingcomposer update --dry-run --ignore-platform-reqs. The platform flag is needed because the image has no mcrypt.app/composer.jsononorigin/main... these were not loaded, because they are affected by security advisories ...(the same error as the Dependabot run)Nothing to install, update or removecomposer validate --no-check-publishprints./composer.json is validfor both.jqparses the file, andgit diff origin/maincontains only the lines shown above.main.Post-merge QA
phpandext-mcryptforapp/composer.json(GraphQLrepository.dependencyGraphManifests)gh api 'repos/basi/cakephp2-php8/dependabot/alerts?state=open&manifest=app/composer.json'returns[]composer in /appDependabot Updates run appearsOut of scope
php >=5.3.0/ext-mcryptrequirements🤖 Generated with Claude Code