Repository navigation
Label the setup-php pin in ci.yml with its real tag - #1118
Merged
Mikola Lysenko (mikolalysenko) merged 1 commit intoOct 8, 2026
Merged
Conversation
Upstream moved setup-php's v2 tag past the pinned commit, so the Audit GitHub Actions check (zizmor ref-version-mismatch) now fails on every PR. The pinned hash is tag 2.37.2, which composer-compatibility already says; ci.yml now says the same. The action that runs is unchanged. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 8, 2026
Upstream moved setup-php's v2 tag past the pinned commit, so the Audit GitHub Actions check (zizmor ref-version-mismatch) now fails on every PR. The pinned hash is tag 2.37.2. Ported from #1118 so this PR's audit goes green before that lands. Assisted-by: Claude Code:claude-opus-5-5
Collaborator
Author
|
BugBot review Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit d4919bc. Configure here.
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 8, 2026
The Audit GitHub Actions check (zizmor ref-version-mismatch) fails because the ci.yml pin's comment says v2 while the pinned commit is tagged 2.37.2. Same one-line change as #1118; it no-ops once that lands. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 8, 2026
Upstream moved setup-php's v2 tag, so the "# v2" comment on the 2.37.2 commit pin now fails the Audit GitHub Actions check (ref-version-mismatch). Same change as #1118. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
added a commit
that referenced
this pull request
Oct 8, 2026
Upstream moved setup-php's `v2` tag to d52fc211, so the `# v2` comment on the f3e473d1 pin no longer matches. zizmor's ref-version-mismatch now fails the org-required "Audit GitHub Actions" check on every PR. f3e473d1 is tag 2.37.2, the label composer-compatibility.yml already uses. This is the same one-line change as #1118, carried here so this PR can merge; whichever lands first, the other merges cleanly. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
added a commit
that referenced
this pull request
Oct 8, 2026
The required 'Audit GHA Workflows' check (zizmor ref-version-mismatch) now fails on every head because the pinned setup-php hash no longer matches the moving v2 tag. Same one-line change as #1118, so it merges cleanly when that lands. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Collaborator
Author
|
Ready for review (burn-down agent).
Nothing specific flagged for the reviewer beyond the PR description. Generated by Claude Code |
github-merge-queue Bot
pushed a commit
that referenced
this pull request
Oct 8, 2026
* Let a group commit hold vendored artifact deletions until it lands A group commit can now defer the vendored artifact deletions a revert makes (GroupCommit::defer_removals): every per-unit revert removal goes through remove_tree_and_prune (cargo and golang now too, instead of their own remove_tree + prune copies) and the bun workspace tarball removal through remove_mirror, and both queue the deletion for after the commit when the open group asks for it. A rollback_to forgets the queued deletions and a dropped group never makes them, so a staged revert can be undone with its artifact intact. Also: - commit_unjournaled: the all-or-nothing replace without the crash journal, for runs that must write nothing under .socket/; - a journal that had to create .socket/vendor/ prunes it again; - group_commit::exists is public, for overlay-aware existence checks. Audit B03/B14 groundwork. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Share one takeover-reach predicate between the hosted engines The disk flow took over cargo, npm, golang, pypi and Gradle maven entries, while the in-memory engine refused only cargo, npm and golang, so a vendored PyPI package reached the Python rewriters in memory. Both now use hosted::takeover::in_reach (audit B15). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Make the vendored-to-hosted takeover staged and atomic scan/get --mode hosted reverted a vendored package's wiring on disk first and planned the hosted pin afterwards. When the rewriter then refused (a lock-level refusal, a missing berry checksum, unavailable wheel metadata, a Poetry 0.x lock, ...), the package was left unpatched in both modes, and only six hand-copied per-ecosystem pre-gates tried to predict those refusals. The dry run counted every takeover as redirected. The takeover now runs inside the run's group commit: - each vendored revert is staged in the overlay under a savepoint (a failing or drift-keeping revert is rolled back and refused); - the hosted rewrite reads the overlay, so it plans against the reverted project; - a staged purl the rewrite does not pin is retracted: the overlay goes back to its pre-revert state, the purl stays vendored byte for byte (redirect_takeover_kept_vendored, skipped with the cause), and the rest are staged and rewritten again; - the hosted pins and the vendored ledger are written into the same overlay and committed once (journaled); artifacts go after the commit. A dry run does the same and drops the overlay, so it reports the wet outcome. A hosted run without a takeover commits its files unjournaled, putting back the ones replaced if one fails. Deleted: the bun, berry (lock and dep), classic, vlt, Gradle, pypi platform-wheel and requirements pre-gates (9 copies of rewriter logic -> 0; the requirements reach check only explains a retraction now), the dry-run TakeoverPreview path in the engine, and the stranded-takeover reporting (redirect_takeover_unpatched), which can no longer happen. Audit B03, B14, B37 (takeover part). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Keep a staged Gradle takeover from deleting the vendored tree The staged vendored-to-hosted takeover runs the real revert inside a group commit and relies on the overlay plus deferred removals to undo it. The JVM revert deleted the tree files under .socket/vendor/gradle and .socket/vendor/maven2 directly, and wrote or deleted the owned .socket/gradle/.gitattributes, .socket/vendor/.gitattributes and the derived maven-metadata.xml files straight to disk. A dry run, or a takeover the hosted Gradle planner refused and retracted, therefore deleted the vendored jars while the restored wiring still named them. Capture the owned .gitattributes files and the derived metadata in the group overlay, and route the tree-file deletions through group_commit::defer_removal so they happen only after the commit. A new test stages the revert (with and without a sibling version sharing the metadata) and checks that dropping or rolling back the group leaves the project byte-identical and that committing lands the plain revert. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Put back direct hosted writes when the hosted commit fails commit_hosted_writes writes the files the group does not capture (the Gradle hosted index and script under .socket/gradle/) straight to disk before the commit. When writing a later file, saving the vendored ledger or the commit itself failed, the error said nothing was changed while those files stayed on disk. Record their previous bytes and put them back on every failure path except an interrupted journaled commit, which the next locked command finishes. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Check that dry-run takeovers leave the whole tree byte-identical Snapshot every project file, .socket/ and the vendored artifacts included, around the dry-run vendored-to-hosted takeover for pnpm, package-lock, vlt, golang and cargo (bun and the uv retract test already compare the artifact). Rewrite the stale CLI_CONTRACT Gradle paragraph that still described the deleted takeover_refusal pre-gate, and the real-Gradle refusal test's doc comment. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Make the yarn hosted preflights private to the redirect module The takeover pre-gates that called preflight_yarn_classic_hosted and preflight_yarn_berry_hosted from outside are gone. The classic one is now private and the berry one pub(crate) (upstream/npm.rs still uses it). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Skip the yarn berry risk warning when an offline mirror refused the pins With a yarn-offline-mirror configured the classic hosted rewriter refuses every entry, so nothing is pinned, yet it still warned that a berry install would drop the hosted pins (#907's warning counted the refused entries as pinned). The staged takeover reports a retracted purl's first rewrite warning as its cause, so a vendored classic project with a mirror was skipped as redirect_yarn_classic_berry_ migration_risk and the real refusal, redirect_yarn_classic_offline_ mirror, was never reported (in_process_vendor's classic_vendored_to_hosted_takeover_refuses_with_offline_mirror failed once main's #917 landed beside the staged takeover). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Keep a yarn berry takeover vendored when the project gates refuse it #657 (merged on main) made the hosted and vendored modes refuse a mixed root package.json, and gated the vendored-to-hosted takeover before its revert. The staged takeover dropped that pre-gate and let the hosted rewriter judge the reverted project, but the berry revert re-renders package.json in its majority line ending, so a mixed manifest passed the rewriter's check after the revert and the takeover went ahead (in_process_vendor berry_takeovers_refuse_before_reverting_the_old_mode failed after the merge). Judge the berry project gates once per staging pass, on the pre-revert overlay, through the rewriter's own preflight_yarn_berry_hosted (the shared berry_gates set, no copied logic). A refused yarn-berry entry is skipped with the gate's code, followed by redirect_takeover_kept_vendored. preflight_yarn_berry_hosted is public again for this caller. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Keep landed-pin advisories and scope suffixes out of takeover skip reasons When a staged takeover is retracted and no rewriter warning names the package, explain() fell back to the rewrite's first warning as the lock-level cause. That warning can be a success advisory from a pin that did land (redirect_npm_allow_remote, redirect_pnpm_trust_lockfile, redirect_yarn_classic_berry_migration_risk), so the skipped purl and redirect_takeover_kept_vendored reported the wrong code. Skip those advisories when picking the fallback; with nothing else left the reason is NOT_PINNED. names_package accepted `/` as a left boundary unconditionally, so an unscoped name like `node` matched inside `@types/node` and a retracted takeover could inherit another package's warning. A `/` now counts as a boundary only after a path segment, not after an `@scope`. Co-Authored-By: Claude <noreply@anthropic.com> * Label the setup-php pin in ci.yml with its real tag The required 'Audit GHA Workflows' check (zizmor ref-version-mismatch) now fails on every head because the pinned setup-php hash no longer matches the moving v2 tag. Same one-line change as #1118, so it merges cleanly when that lands. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Tanmay Singla (Tanmay182003)
approved these changes
Oct 8, 2026
Mikola Lysenko (mikolalysenko)
deleted the
agent/ci-setup-php-version-comment
branch
October 8, 2026 16:51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
What fails
Since about 07:59Z,
Audit GitHub Actions(zizmor) fails withref-version-mismatchat.github/workflows/ci.yml(the composer job'sshivammathur/setup-php@f3e473d… # v2). Example: https://github.com/SocketDev/socket-patch/actions/runs/37746834064/job/113210208768 on #1009.The same line passed on main at 06:14Z (829d0af). Nothing in this repo changed in between. Upstream moved the
v2tag:Fix
Change the version comment to
# 2.37.2, the tag that the pinned hash actually is.composer-compatibility.ymlalready says this for the same hash. The action that runs stays the same, and nothing else changes.Every open PR will hit this audit failure until it merges main with this change. #1009 carries the same one-line port so it can go green now.
🤖 Generated with Claude Code
https://claude.ai/code/session_01NfrapG9DFf76Fy96mocdRS
Note
Low Risk
Comment-only workflow change; no runtime or toolchain behavior changes.
Overview
Updates the inline version comment on the pinned
shivammathur/setup-phpstep inci.ymlfrom# v2to# 2.37.2, matching the commit the SHA resolves to (andcomposer-compatibility.yml).The action ref is unchanged; this only satisfies zizmor’s
ref-version-mismatchcheck after upstream moved thev2tag away from that pin.Reviewed by Cursor Bugbot for commit d4919bc. Configure here.
Generated by Claude Code