Skip to content

Label the setup-php pin in ci.yml with its real tag - #1118

Merged
Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
agent/ci-setup-php-version-comment
Oct 8, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
agent/ci-setup-php-version-comment

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

What fails

Since about 07:59Z, Audit GitHub Actions (zizmor) fails with ref-version-mismatch at .github/workflows/ci.yml (the composer job's shivammathur/setup-php@f3e473d… # v2). Example: https://github.com/SocketDev/socket-patch/actions/runs/37746834064/job/113210208768 on #1009.

The same line passed on main at 06:14Z (829d0af). Nothing in this repo changed in between. Upstream moved the v2 tag:

$ git ls-remote https://github.com/shivammathur/setup-php refs/tags/v2 refs/tags/2.37.2
f3e473d116dcccaddc5834248c87452386958240  refs/tags/2.37.2
d52fc211a0436f8839a587b3b5b8efddab4744ea  refs/tags/v2   (-> eb7c497…)

Fix

Change the version comment to # 2.37.2, the tag that the pinned hash actually is. composer-compatibility.yml already says this for the same hash. The action that runs stays the same, and nothing else changes.

Every open PR will hit this audit failure until it merges main with this change. #1009 carries the same one-line port so it can go green now.

🤖 Generated with Claude Code

https://claude.ai/code/session_01NfrapG9DFf76Fy96mocdRS


Note

Low Risk
Comment-only workflow change; no runtime or toolchain behavior changes.

Overview
Updates the inline version comment on the pinned shivammathur/setup-php step in ci.yml from # v2 to # 2.37.2, matching the commit the SHA resolves to (and composer-compatibility.yml).

The action ref is unchanged; this only satisfies zizmor’s ref-version-mismatch check after upstream moved the v2 tag away from that pin.

Reviewed by Cursor Bugbot for commit d4919bc. Configure here.


Generated by Claude Code

Upstream moved setup-php's v2 tag past the pinned commit, so the
Audit GitHub Actions check (zizmor ref-version-mismatch) now fails on
every PR. The pinned hash is tag 2.37.2, which composer-compatibility
already says; ci.yml now says the same. The action that runs is
unchanged.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 8, 2026
Upstream moved setup-php's v2 tag past the pinned commit, so the
Audit GitHub Actions check (zizmor ref-version-mismatch) now fails on
every PR. The pinned hash is tag 2.37.2. Ported from #1118 so this
PR's audit goes green before that lands.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit d4919bc. Configure here.

Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 8, 2026
The Audit GitHub Actions check (zizmor ref-version-mismatch) fails
because the ci.yml pin's comment says v2 while the pinned commit is
tagged 2.37.2. Same one-line change as #1118; it no-ops once that
lands.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 8, 2026
Upstream moved setup-php's v2 tag, so the "# v2" comment on the
2.37.2 commit pin now fails the Audit GitHub Actions check
(ref-version-mismatch). Same change as #1118.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) added a commit that referenced this pull request Oct 8, 2026
Upstream moved setup-php's `v2` tag to d52fc211, so the `# v2` comment on
the f3e473d1 pin no longer matches. zizmor's ref-version-mismatch now
fails the org-required "Audit GitHub Actions" check on every PR. f3e473d1
is tag 2.37.2, the label composer-compatibility.yml already uses. This is
the same one-line change as #1118, carried here so this PR can merge;
whichever lands first, the other merges cleanly.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 8, 2026
zizmor's ref-version-mismatch audit fails every PR on main's ci.yml
because the setup-php hash pin is labelled `# v2`. Same one-line
change as #1118, ported so this PR's audit goes green; it no-ops when
#1118 lands.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) added a commit that referenced this pull request Oct 8, 2026
The required 'Audit GHA Workflows' check (zizmor ref-version-mismatch)
now fails on every head because the pinned setup-php hash no longer
matches the moving v2 tag. Same one-line change as #1118, so it merges
cleanly when that lands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 8, 2026
Ports #1118's one-line fix: zizmor's ref-version-mismatch audit
fails every new PR head on main's `# v2` label for this pin. No-op
once #1118 lands.

Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko) pushed a commit that referenced this pull request Oct 8, 2026
Ported from #1118. The upstream v2 tag moved off the pinned commit,
so zizmor's ref-version-mismatch audit fails every PR on main. The
pin itself is unchanged; only its comment now names 2.37.2. This
no-ops once #1118 lands.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 8, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Ready for review (burn-down agent).

  • Head: d4919bcc0dd3360a45d9df4d1fc9a3d78a5cb10c
  • CI: 297/297 check runs green (success/skipped/neutral) on this head, mergeable, no conflicts.
  • Bugbot: reviewed this head (Cursor Bugbot check: success), no unresolved review threads.
  • Changelog: untouched.

Nothing specific flagged for the reviewer beyond the PR description.


Generated by Claude Code

github-merge-queue Bot pushed a commit that referenced this pull request Oct 8, 2026
* Let a group commit hold vendored artifact deletions until it lands

A group commit can now defer the vendored artifact deletions a revert
makes (GroupCommit::defer_removals): every per-unit revert removal goes
through remove_tree_and_prune (cargo and golang now too, instead of their
own remove_tree + prune copies) and the bun workspace tarball removal
through remove_mirror, and both queue the deletion for after the commit
when the open group asks for it. A rollback_to forgets the queued
deletions and a dropped group never makes them, so a staged revert can be
undone with its artifact intact.

Also:
- commit_unjournaled: the all-or-nothing replace without the crash
  journal, for runs that must write nothing under .socket/;
- a journal that had to create .socket/vendor/ prunes it again;
- group_commit::exists is public, for overlay-aware existence checks.

Audit B03/B14 groundwork.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Share one takeover-reach predicate between the hosted engines

The disk flow took over cargo, npm, golang, pypi and Gradle maven
entries, while the in-memory engine refused only cargo, npm and golang,
so a vendored PyPI package reached the Python rewriters in memory. Both
now use hosted::takeover::in_reach (audit B15).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Make the vendored-to-hosted takeover staged and atomic

scan/get --mode hosted reverted a vendored package's wiring on disk
first and planned the hosted pin afterwards. When the rewriter then
refused (a lock-level refusal, a missing berry checksum, unavailable
wheel metadata, a Poetry 0.x lock, ...), the package was left unpatched
in both modes, and only six hand-copied per-ecosystem pre-gates tried to
predict those refusals. The dry run counted every takeover as redirected.

The takeover now runs inside the run's group commit:
- each vendored revert is staged in the overlay under a savepoint (a
  failing or drift-keeping revert is rolled back and refused);
- the hosted rewrite reads the overlay, so it plans against the
  reverted project;
- a staged purl the rewrite does not pin is retracted: the overlay goes
  back to its pre-revert state, the purl stays vendored byte for byte
  (redirect_takeover_kept_vendored, skipped with the cause), and the
  rest are staged and rewritten again;
- the hosted pins and the vendored ledger are written into the same
  overlay and committed once (journaled); artifacts go after the commit.
A dry run does the same and drops the overlay, so it reports the wet
outcome. A hosted run without a takeover commits its files unjournaled,
putting back the ones replaced if one fails.

Deleted: the bun, berry (lock and dep), classic, vlt, Gradle, pypi
platform-wheel and requirements pre-gates (9 copies of rewriter logic ->
0; the requirements reach check only explains a retraction now), the
dry-run TakeoverPreview path in the engine, and the stranded-takeover
reporting (redirect_takeover_unpatched), which can no longer happen.

Audit B03, B14, B37 (takeover part).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Keep a staged Gradle takeover from deleting the vendored tree

The staged vendored-to-hosted takeover runs the real revert inside a
group commit and relies on the overlay plus deferred removals to undo
it. The JVM revert deleted the tree files under .socket/vendor/gradle
and .socket/vendor/maven2 directly, and wrote or deleted the owned
.socket/gradle/.gitattributes, .socket/vendor/.gitattributes and the
derived maven-metadata.xml files straight to disk. A dry run, or a
takeover the hosted Gradle planner refused and retracted, therefore
deleted the vendored jars while the restored wiring still named them.

Capture the owned .gitattributes files and the derived metadata in the
group overlay, and route the tree-file deletions through
group_commit::defer_removal so they happen only after the commit. A
new test stages the revert (with and without a sibling version sharing
the metadata) and checks that dropping or rolling back the group leaves
the project byte-identical and that committing lands the plain revert.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Put back direct hosted writes when the hosted commit fails

commit_hosted_writes writes the files the group does not capture (the
Gradle hosted index and script under .socket/gradle/) straight to disk
before the commit. When writing a later file, saving the vendored
ledger or the commit itself failed, the error said nothing was changed
while those files stayed on disk. Record their previous bytes and put
them back on every failure path except an interrupted journaled
commit, which the next locked command finishes.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Check that dry-run takeovers leave the whole tree byte-identical

Snapshot every project file, .socket/ and the vendored artifacts
included, around the dry-run vendored-to-hosted takeover for pnpm,
package-lock, vlt, golang and cargo (bun and the uv retract test
already compare the artifact). Rewrite the stale CLI_CONTRACT Gradle
paragraph that still described the deleted takeover_refusal pre-gate,
and the real-Gradle refusal test's doc comment.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Make the yarn hosted preflights private to the redirect module

The takeover pre-gates that called preflight_yarn_classic_hosted and
preflight_yarn_berry_hosted from outside are gone. The classic one is
now private and the berry one pub(crate) (upstream/npm.rs still uses
it).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Skip the yarn berry risk warning when an offline mirror refused the pins

With a yarn-offline-mirror configured the classic hosted rewriter
refuses every entry, so nothing is pinned, yet it still warned that a
berry install would drop the hosted pins (#907's warning counted the
refused entries as pinned). The staged takeover reports a retracted
purl's first rewrite warning as its cause, so a vendored classic
project with a mirror was skipped as redirect_yarn_classic_berry_
migration_risk and the real refusal, redirect_yarn_classic_offline_
mirror, was never reported (in_process_vendor's
classic_vendored_to_hosted_takeover_refuses_with_offline_mirror failed
once main's #917 landed beside the staged takeover).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Keep a yarn berry takeover vendored when the project gates refuse it

#657 (merged on main) made the hosted and vendored modes refuse a mixed
root package.json, and gated the vendored-to-hosted takeover before its
revert. The staged takeover dropped that pre-gate and let the hosted
rewriter judge the reverted project, but the berry revert re-renders
package.json in its majority line ending, so a mixed manifest passed
the rewriter's check after the revert and the takeover went ahead
(in_process_vendor berry_takeovers_refuse_before_reverting_the_old_mode
failed after the merge).

Judge the berry project gates once per staging pass, on the pre-revert
overlay, through the rewriter's own preflight_yarn_berry_hosted (the
shared berry_gates set, no copied logic). A refused yarn-berry entry is
skipped with the gate's code, followed by redirect_takeover_kept_vendored.
preflight_yarn_berry_hosted is public again for this caller.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Keep landed-pin advisories and scope suffixes out of takeover skip reasons

When a staged takeover is retracted and no rewriter warning names the
package, explain() fell back to the rewrite's first warning as the
lock-level cause. That warning can be a success advisory from a pin that
did land (redirect_npm_allow_remote, redirect_pnpm_trust_lockfile,
redirect_yarn_classic_berry_migration_risk), so the skipped purl and
redirect_takeover_kept_vendored reported the wrong code. Skip those
advisories when picking the fallback; with nothing else left the reason
is NOT_PINNED.

names_package accepted `/` as a left boundary unconditionally, so an
unscoped name like `node` matched inside `@types/node` and a retracted
takeover could inherit another package's warning. A `/` now counts as a
boundary only after a path segment, not after an `@scope`.

Co-Authored-By: Claude <noreply@anthropic.com>

* Label the setup-php pin in ci.yml with its real tag

The required 'Audit GHA Workflows' check (zizmor ref-version-mismatch)
now fails on every head because the pinned setup-php hash no longer
matches the moving v2 tag. Same one-line change as #1118, so it merges
cleanly when that lands.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit 30a45b3 Oct 8, 2026
297 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/ci-setup-php-version-comment branch October 8, 2026 16:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants