Skip to content

chore(deps): Bump the actions group with 5 updates (#97) #4

chore(deps): Bump the actions group with 5 updates (#97)

chore(deps): Bump the actions group with 5 updates (#97) #4

# SPDX-License-Identifier: MPL-2.0
#
# Promoted from journal-theme/.github/workflows/php-standards.yml (only root
# workflows run in this repo; the vendored copy is upstream history).
name: Journal Theme PHP/WordPress Standards
on:
push:
branches: [main, develop]
paths:
- 'journal-theme/**'
- '.github/workflows/journal-theme-php-standards.yml'
pull_request:
branches: [main, develop]
paths:
- 'journal-theme/**'
- '.github/workflows/journal-theme-php-standards.yml'
permissions:
contents: read
defaults:
run:
working-directory: journal-theme
jobs:
phpcs:
name: WordPress Coding Standards
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
with:
php-version: '8.3'
coverage: none
tools: composer, cs2pr
- name: Get Composer cache directory
id: composer-cache
run: echo "dir=$(composer config cache-files-dir)" >> $GITHUB_OUTPUT
- name: Cache Composer dependencies
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v4
with:
path: ${{ steps.composer-cache.outputs.dir }}
key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
restore-keys: ${{ runner.os }}-composer-
- name: Install dependencies
run: composer install --prefer-dist --no-progress
- name: Run PHPCS
run: vendor/bin/phpcs --report-full --report-checkstyle=./phpcs-report.xml
- name: Show PHPCS results in PR
if: always()
run: cs2pr ./phpcs-report.xml
- name: Upload PHPCS report
if: failure()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.0 (repinned: vendored ea165f8d does not resolve)
with:
name: phpcs-report
path: journal-theme/phpcs-report.xml
phpstan:
name: PHPStan Static Analysis
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
with:
php-version: '8.3'
coverage: none
tools: composer
- name: Get Composer cache directory
id: composer-cache
run: echo "dir=$(composer config cache-files-dir)" >> $GITHUB_OUTPUT
- name: Cache Composer dependencies
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v4
with:
path: ${{ steps.composer-cache.outputs.dir }}
key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
restore-keys: ${{ runner.os }}-composer-
- name: Install dependencies
run: composer install --prefer-dist --no-progress
- name: Run PHPStan
run: vendor/bin/phpstan analyse --error-format=github --memory-limit=1G
php-compatibility:
name: PHP ${{ matrix.php }} Compatibility
runs-on: ubuntu-latest
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
php: ['8.1', '8.2', '8.3', '8.4']
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
- name: Setup PHP ${{ matrix.php }}
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
with:
php-version: ${{ matrix.php }}
coverage: none
tools: composer
- name: Validate composer.json
run: composer validate --strict
- name: Install dependencies
run: composer install --prefer-dist --no-progress
- name: Check PHP syntax
run: find . -name "*.php" -not -path "./vendor/*" -print0 | xargs -0 -n1 php -l
- name: Run PHPCompatibility check
run: vendor/bin/phpcs --standard=PHPCompatibilityWP --runtime-set testVersion ${{ matrix.php }} -ps --ignore=vendor,node_modules .
wp-compatibility:
name: WordPress ${{ matrix.wp }} Compatibility
runs-on: ubuntu-latest
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
wp: ['6.4', '6.5', '6.6', '6.7']
php: ['8.1', '8.3']
exclude:
# WP 6.7 requires PHP 7.2+ but we test 8.1+
- wp: '6.4'
php: '8.3'
services:
mysql:
image: mariadb:10.11
env:
MYSQL_ROOT_PASSWORD: root
MYSQL_DATABASE: wordpress_test
ports:
- 3306:3306
options: >-
--health-cmd="mysqladmin ping" --health-interval=10s --health-timeout=5s --health-retries=5
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
- name: Setup PHP ${{ matrix.php }}
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
with:
php-version: ${{ matrix.php }}
extensions: mysqli, mbstring
coverage: none
tools: composer
- name: Install dependencies
run: composer install --prefer-dist --no-progress
- name: Install WordPress test suite
run: |
bash bin/install-wp-tests.sh wordpress_test root root 127.0.0.1:3306 ${{ matrix.wp }} true
- name: Run PHPUnit
run: vendor/bin/phpunit --testdox
theme-check:
name: WordPress Theme Check
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
with:
php-version: '8.3'
coverage: none
- name: Verify theme headers
run: |
echo "Checking style.css theme headers..."
# Required headers
REQUIRED=("Theme Name" "Version" "Requires at least" "Tested up to" "Requires PHP" "License" "Text Domain")
for header in "${REQUIRED[@]}"; do
if grep -q "^${header}:" style.css; then
echo "✅ Found: ${header}"
else
echo "❌ Missing: ${header}"
exit 1
fi
done
echo ""
echo "Theme header validation passed!"
- name: Verify required files
run: |
echo "Checking required theme files..."
REQUIRED_FILES=("style.css" "index.php" "functions.php" "header.php" "footer.php")
for file in "${REQUIRED_FILES[@]}"; do
if [ -f "$file" ]; then
echo "✅ Found: ${file}"
else
echo "❌ Missing: ${file}"
exit 1
fi
done
echo ""
echo "Required files check passed!"
- name: Check for common issues
run: |
echo "Checking for common theme issues..."
# Check for direct file access protection
for file in functions.php index.php header.php footer.php; do
if grep -q "defined.*ABSPATH" "$file" || grep -q "ABSPATH" "$file"; then
echo "✅ ${file}: Has ABSPATH check"
else
echo "⚠️ ${file}: Consider adding ABSPATH check"
fi
done
# Check for wp_enqueue_style/script
if grep -rq "wp_enqueue_style\|wp_enqueue_script" inc/ functions.php; then
echo "✅ Uses proper asset enqueueing"
else
echo "⚠️ Should use wp_enqueue_style/wp_enqueue_script"
fi
# Check for esc_ functions
if grep -rq "esc_html\|esc_attr\|esc_url\|wp_kses" . --include="*.php" | grep -v vendor; then
echo "✅ Uses escaping functions"
else
echo "⚠️ Should use escaping functions (esc_html, esc_attr, etc.)"
fi
echo ""
echo "Common issues check completed!"
- name: Validate JSON files
run: |
echo "Validating JSON files..."
for file in $(find . -name "*.json" -not -path "./vendor/*" -not -path "./node_modules/*"); do
if python3 -m json.tool "$file" > /dev/null 2>&1; then
echo "✅ Valid: ${file}"
else
echo "❌ Invalid JSON: ${file}"
exit 1
fi
done
echo ""
echo "JSON validation passed!"
summary:
name: Standards Summary
runs-on: ubuntu-latest
timeout-minutes: 15
needs: [phpcs, phpstan, php-compatibility, wp-compatibility, theme-check]
if: always()
steps:
- name: Check results
run: |
echo "## PHP/WordPress Standards Results" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
if [ "${{ needs.phpcs.result }}" == "success" ]; then
echo "✅ **PHPCS**: Passed" >> $GITHUB_STEP_SUMMARY
else
echo "❌ **PHPCS**: Failed" >> $GITHUB_STEP_SUMMARY
fi
if [ "${{ needs.phpstan.result }}" == "success" ]; then
echo "✅ **PHPStan**: Passed" >> $GITHUB_STEP_SUMMARY
else
echo "❌ **PHPStan**: Failed" >> $GITHUB_STEP_SUMMARY
fi
if [ "${{ needs.php-compatibility.result }}" == "success" ]; then
echo "✅ **PHP Compatibility**: Passed" >> $GITHUB_STEP_SUMMARY
else
echo "❌ **PHP Compatibility**: Failed" >> $GITHUB_STEP_SUMMARY
fi
if [ "${{ needs.wp-compatibility.result }}" == "success" ]; then
echo "✅ **WordPress Compatibility**: Passed" >> $GITHUB_STEP_SUMMARY
else
echo "❌ **WordPress Compatibility**: Failed" >> $GITHUB_STEP_SUMMARY
fi
if [ "${{ needs.theme-check.result }}" == "success" ]; then
echo "✅ **Theme Check**: Passed" >> $GITHUB_STEP_SUMMARY
else
echo "❌ **Theme Check**: Failed" >> $GITHUB_STEP_SUMMARY
fi