From a8824927f8357a2d5d2fa1070383b4ff0b3c58f6 Mon Sep 17 00:00:00 2001 From: Andrew Longosz Date: Sun, 13 Sep 2026 17:19:36 +0200 Subject: [PATCH 1/2] IBX-11778: Updated GitHub Actions workflows to org standard (#118) For more details see https://ibexa.atlassian.net/browse/IBX-11778 and https://github.com/ibexa/content-forms/pull/118 Key changes: * Renamed the CI workflow to "Backend CI" and added a bare workflow_dispatch trigger (IBX-12062) * Bumped actions/checkout to v7 * Standardized all runner labels to ubuntu-26.04 * Dropped the non-existent main branch from the push triggers of backend-ci and browser-tests * Passed the PHP version to the shared composer-install action explicitly (IBX-11907) * Guarded the code style check with set -euo pipefail so cs2pr no longer masks check-cs failures (IBX-11853) * Removed the deprecated pr-assign.yaml workflow --------- Co-Authored-By: Claude Fable 5.1 --- .github/workflows/backend-ci.yaml | 24 +++++++++++++++--------- .github/workflows/browser-tests.yaml | 1 - .github/workflows/pr-assign.yaml | 10 ---------- 3 files changed, 15 insertions(+), 20 deletions(-) delete mode 100644 .github/workflows/pr-assign.yaml diff --git a/.github/workflows/backend-ci.yaml b/.github/workflows/backend-ci.yaml index e38ba7c1..c035ff87 100644 --- a/.github/workflows/backend-ci.yaml +++ b/.github/workflows/backend-ci.yaml @@ -1,38 +1,42 @@ -name: CI +name: Backend CI on: push: branches: - - main - '[0-9]+.[0-9]+' pull_request: ~ + workflow_dispatch: ~ jobs: cs-fix: name: Run code style check - runs-on: "ubuntu-22.04" + runs-on: "ubuntu-26.04" strategy: matrix: php: - '8.1' steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - uses: ibexa/gh-workflows/actions/setup-composer-root-version@main - uses: ibexa/gh-workflows/actions/composer-install@main with: + php-version: ${{ matrix.php }} gh-client-id: ${{ secrets.AUTOMATION_CLIENT_ID }} gh-client-secret: ${{ secrets.AUTOMATION_CLIENT_SECRET }} satis-network-key: ${{ secrets.SATIS_NETWORK_KEY }} satis-network-token: ${{ secrets.SATIS_NETWORK_TOKEN }} - name: Run code style check - run: composer run-script check-cs -- --format=checkstyle | cs2pr + shell: bash + run: | + set -euo pipefail + composer run-script check-cs -- --format=checkstyle | cs2pr tests: name: Unit tests & PHPStan static analysis - runs-on: "ubuntu-22.04" + runs-on: "ubuntu-26.04" timeout-minutes: 15 strategy: @@ -44,12 +48,13 @@ jobs: - '8.4' steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - uses: ibexa/gh-workflows/actions/setup-composer-root-version@main - uses: ibexa/gh-workflows/actions/composer-install@main with: + php-version: ${{ matrix.php }} gh-client-id: ${{ secrets.AUTOMATION_CLIENT_ID }} gh-client-secret: ${{ secrets.AUTOMATION_CLIENT_SECRET }} satis-network-key: ${{ secrets.SATIS_NETWORK_KEY }} @@ -66,7 +71,7 @@ jobs: integration-tests: name: Runs integration tests - runs-on: "ubuntu-22.04" + runs-on: "ubuntu-26.04" needs: tests timeout-minutes: 15 @@ -79,12 +84,13 @@ jobs: - '8.4' steps: - - uses: actions/checkout@v5 + - uses: actions/checkout@v7 - uses: ibexa/gh-workflows/actions/setup-composer-root-version@main - uses: ibexa/gh-workflows/actions/composer-install@main with: + php-version: ${{ matrix.php }} gh-client-id: ${{ secrets.AUTOMATION_CLIENT_ID }} gh-client-secret: ${{ secrets.AUTOMATION_CLIENT_SECRET }} satis-network-key: ${{ secrets.SATIS_NETWORK_KEY }} diff --git a/.github/workflows/browser-tests.yaml b/.github/workflows/browser-tests.yaml index 01ba58c0..08135684 100644 --- a/.github/workflows/browser-tests.yaml +++ b/.github/workflows/browser-tests.yaml @@ -3,7 +3,6 @@ name: Browser tests on: push: branches: - - main - '[0-9]+.[0-9]+' pull_request: ~ diff --git a/.github/workflows/pr-assign.yaml b/.github/workflows/pr-assign.yaml deleted file mode 100644 index 302423e3..00000000 --- a/.github/workflows/pr-assign.yaml +++ /dev/null @@ -1,10 +0,0 @@ -name: Assign Pull Request to maintainers - -on: - pull_request_target: - -jobs: - assign: - uses: ibexa/gh-workflows/.github/workflows/pr-assign.yml@main - secrets: - robot-token: ${{ secrets.EZROBOT_PAT }} From 10de5938cbe85f87dcbc7c7b767c7e0a3155d2ed Mon Sep 17 00:00:00 2001 From: Andrew Longosz Date: Sun, 13 Sep 2026 22:38:36 +0200 Subject: [PATCH 2/2] IBX-11778: [GHA][Rector PHP] Reused shared Rector workflow Replaced the inline job body in rector.yaml with a call to ibexa/gh-workflows' reusable Rector workflow (the ibexa/core 5.0 form: explicit php-version 8.3 and the full secrets block), matching the org standard applied to the 4.6 branch in the IBX-11778 sweep. Also dropped the stale `main` push trigger - the repository has no such branch. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/rector.yaml | 33 ++++++++------------------------- 1 file changed, 8 insertions(+), 25 deletions(-) diff --git a/.github/workflows/rector.yaml b/.github/workflows/rector.yaml index 6c9c42dd..804802ae 100644 --- a/.github/workflows/rector.yaml +++ b/.github/workflows/rector.yaml @@ -1,34 +1,17 @@ name: Rector PHP - on: push: branches: - - main - '[0-9]+.[0-9]+' pull_request: ~ - jobs: rector: name: Run rector - runs-on: "ubuntu-22.04" - strategy: - matrix: - php: - - '8.3' - steps: - - uses: actions/checkout@v5 - - - name: Setup PHP Action - uses: shivammathur/setup-php@v2 - with: - php-version: ${{ matrix.php }} - coverage: none - extensions: 'pdo_sqlite, gd' - tools: cs2pr - - - uses: ramsey/composer-install@v3 - with: - dependency-versions: highest - - - name: Run rector - run: vendor/bin/rector process --dry-run --ansi + uses: ibexa/gh-workflows/.github/workflows/rector.yml@main + with: + php-version: '8.3' + secrets: + AUTOMATION_CLIENT_ID: ${{ secrets.AUTOMATION_CLIENT_ID }} + AUTOMATION_CLIENT_SECRET: ${{ secrets.AUTOMATION_CLIENT_SECRET }} + SATIS_NETWORK_KEY: ${{ secrets.SATIS_NETWORK_KEY }} + SATIS_NETWORK_TOKEN: ${{ secrets.SATIS_NETWORK_TOKEN }}