-
-
Notifications
You must be signed in to change notification settings - Fork 0
Comparing changes
Open a pull request
base repository: backstagephp/laravel-users
base: main
head repository: backstagephp/laravel-users
compare: 5.x
- 13 commits
- 15 files changed
- 6 contributors
Commits on Jan 13, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 11703c2 - Browse repository at this point
Copy the full SHA 11703c2View commit details
Commits on Jan 30, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 90987af - Browse repository at this point
Copy the full SHA 90987afView commit details
Commits on Feb 13, 2026
-
Configuration menu - View commit details
-
Copy full SHA for d1fd8fe - Browse repository at this point
Copy the full SHA d1fd8feView commit details
Commits on Feb 19, 2026
-
perf: queue user login/logout recording to avoid slow DNS lookups (#83)
The gethostbyaddr() call was blocking the login/logout response, causing delays of 1-30+ seconds depending on network conditions. Now the recording is dispatched to a queue job, so the user gets an instant response while the DNS lookup happens in the background. Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for 6e2093d - Browse repository at this point
Copy the full SHA 6e2093dView commit details -
fix: guard against missing or invalid user model config in RecordUser…
…Login job Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for 2380191 - Browse repository at this point
Copy the full SHA 2380191View commit details
Commits on Mar 13, 2026
-
chore: upgrade Laravel Pint to 1.29.0 and apply code style fixes
Upgraded Pint from 1.27.1 to 1.29.0 to align local development with CI workflow. Applied new code style rules across 225 files including: - fully_qualified_strict_types - ordered_imports - braces_position - class_definition Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for b816834 - Browse repository at this point
Copy the full SHA b816834View commit details
Commits on Mar 16, 2026
-
refactor: refine shop plugin models, migrations, resources and config
Comprehensive refinement of the shop package including: - Update all models with proper casts, relationships and table prefixing - Modernize all migration stubs with consistent naming and structure - Improve Filament resource forms, infolists and tables - Add tax rate minimum value validation (must be > 0) - Center-align orders count column in customer table - Add AddressObserver, InvoiceRelationManager and OrderRelationManager - Fix categoriable -> categorizable typo in migration - Update config with table prefix support - Fix RecordUserLogin to handle nullable userId Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for a513671 - Browse repository at this point
Copy the full SHA a513671View commit details -
Configuration menu - View commit details
-
Copy full SHA for 0f4612f - Browse repository at this point
Copy the full SHA 0f4612fView commit details
Commits on Mar 25, 2026
-
Remove spatie/laravel-ray dependency from all packages
The dependency is unused — no ray() calls exist in the codebase. Removes it from require-dev in 9 packages, the conflict section in laravel-mails, the CI workflow removal step, and the laravel-ai configure script. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for d091ce4 - Browse repository at this point
Copy the full SHA d091ce4View commit details
Commits on Mar 30, 2026
-
Configuration menu - View commit details
-
Copy full SHA for d20ba89 - Browse repository at this point
Copy the full SHA d20ba89View commit details
Commits on Apr 3, 2026
-
feat: add comprehensive shop plugin documentation
Split docs into separate files under docs/ for with-CMS and without-CMS setup guides. Includes configuration reference, storefront routes, payment and invoicing setup, authentication, subscriptions, and architecture overview. Also includes all pending shop refinements: API controllers, web controllers, form requests, API resources, storefront views, Alpine.js cart store, tests, and route updates. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Configuration menu - View commit details
-
Copy full SHA for d0d4d8e - Browse repository at this point
Copy the full SHA d0d4d8eView commit details -
Configuration menu - View commit details
-
Copy full SHA for cbc9ce4 - Browse repository at this point
Copy the full SHA cbc9ce4View commit details
Commits on Jul 7, 2026
-
ci: fix the Security workflow (pin actions, dependabot cooldown, real…
… security-check gate) (#279) * chore(ci): pin GitHub Actions to commit SHAs across the monorepo Pin every `uses:` reference to a full commit SHA (with a version comment so Dependabot keeps them current) across the root workflows and all packages/*/.github workflows. Resolves the semgrep github-actions-mutable-action-tag findings. Applied with pinact. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(ci): add a 7-day Dependabot cooldown to every update entry Add `cooldown: { default-days: 7 }` to each ecosystem in every dependabot.yml across the monorepo (and normalise the one pre-existing cooldown to 7 days). Resolves the semgrep dependabot-missing-cooldown findings and delays pulling freshly-published (possibly compromised) releases. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(security-check): treat empty $guarded as a warning, not a failure Backstage's 17 core models deliberately use `$guarded = []` because writes go through validated Filament admin forms, not raw request mass assignment. The security check flagged all of them as a high-severity failure — a false positive relative to the architecture. Split the mass-assignment check so empty $guarded is a medium warning while sensitive fields in $fillable remain a hard failure. Add a Pest test asserting `backstage:security-check --package-only` exits 0, and record the decision in ADR-0003. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * chore(ci): pin actions pinact could not auto-resolve, add pinact config Three pint.yml refs pointed at non-existent tags (laravel-pint-action @latest / @2.4.0, git-auto-commit-action @v5.0) that pinact could not resolve; pin them to valid release SHAs by hand. Add .pinact.yaml so both the one-shot pin and the CI guard cover packages/*/.github workflows, not just the root. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * ci(security): gate on the security check, add an action-pinning guard The Backstage Security Check job never actually ran: this is a package repo with no `artisan` binary, and it passed a non-existent `--ci` flag, all masked by continue-on-error. Run it through the test harness instead (a Pest test that boots the full provider stack), mirroring the run-tests MySQL service + extensions + DB env, and drop continue-on-error so it genuinely gates CI. Add an Action Pinning job (pinact-action, fix disabled) that fails when any workflow reintroduces an unpinned action. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>Configuration menu - View commit details
-
Copy full SHA for 22a884b - Browse repository at this point
Copy the full SHA 22a884bView commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff main...5.x