From 11703c20e4d3ece2d2bd6335d9302a4ffdd350ad Mon Sep 17 00:00:00 2001 From: Manoj Hortulanus Date: Tue, 13 Jan 2026 15:47:02 +0100 Subject: [PATCH 01/11] Add user management --- .../7_add_deleted_add_to_users_tabe.php.stub | 26 +++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 database/migrations/7_add_deleted_add_to_users_tabe.php.stub diff --git a/database/migrations/7_add_deleted_add_to_users_tabe.php.stub b/database/migrations/7_add_deleted_add_to_users_tabe.php.stub new file mode 100644 index 0000000..9d8318e --- /dev/null +++ b/database/migrations/7_add_deleted_add_to_users_tabe.php.stub @@ -0,0 +1,26 @@ +getTable(), 'deleted_at')) { + $table->softDeletes(); + } + }); + } + + public function down(): void + { + Schema::table(config('users.eloquent.user.table', 'users'), function (Blueprint $table) { + if(Schema::hasColumn($table->getTable(), 'deleted_at')) { + $table->dropSoftDeletes(); + } + }); + } +}; From 90987af28709da6ae2712ef4b46b047c87fcdc5e Mon Sep 17 00:00:00 2001 From: Mathieu Date: Fri, 30 Jan 2026 13:04:28 +0100 Subject: [PATCH 02/11] Remove matrix in github workflows --- .github/workflows/run-tests.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/run-tests.yml b/.github/workflows/run-tests.yml index c878d51..e2b9b50 100644 --- a/.github/workflows/run-tests.yml +++ b/.github/workflows/run-tests.yml @@ -16,10 +16,10 @@ jobs: strategy: fail-fast: true matrix: - os: [ubuntu-latest, windows-latest] + os: [ubuntu-latest] php: [8.3, 8.2] laravel: [11.*, 10.*] - stability: [prefer-lowest, prefer-stable] + stability: [prefer-stable] include: - laravel: 11.* testbench: 9.* From 6e2093d2a8584439298c03ec556cdeb59b2d6e06 Mon Sep 17 00:00:00 2001 From: Bas van Dinther Date: Thu, 19 Feb 2026 11:00:23 +0100 Subject: [PATCH 03/11] perf: queue user login/logout recording to avoid slow DNS lookups (#83) The gethostbyaddr() call was blocking the login/logout response, causing delays of 1-30+ seconds depending on network conditions. Now the recording is dispatched to a queue job, so the user gets an instant response while the DNS lookup happens in the background. Co-authored-by: Claude Opus 4.5 --- src/Jobs/RecordUserLogin.php | 45 +++++++++++++++++++++++++ src/Listeners/Auth/HandleUserLogin.php | 26 +++++++------- src/Listeners/Auth/HandleUserLogout.php | 30 +++++++++-------- 3 files changed, 73 insertions(+), 28 deletions(-) create mode 100644 src/Jobs/RecordUserLogin.php diff --git a/src/Jobs/RecordUserLogin.php b/src/Jobs/RecordUserLogin.php new file mode 100644 index 0000000..5111aa0 --- /dev/null +++ b/src/Jobs/RecordUserLogin.php @@ -0,0 +1,45 @@ +|null $inputs + */ + public function __construct( + public int $userId, + public string $type, + public ?string $url, + public ?string $referrer, + public ?array $inputs, + public ?string $userAgent, + public ?string $ipAddress, + ) {} + + public function handle(): void + { + $userModel = config('users.eloquent.user.model'); + $user = $userModel::find($this->userId); + + if (! $user) { + return; + } + + $user->logins()->create([ + 'user_id' => $this->userId, + 'type' => $this->type, + 'url' => $this->url, + 'referrer' => $this->referrer, + 'inputs' => $this->inputs ? json_encode($this->inputs) : null, + 'user_agent' => $this->userAgent, + 'ip_address' => $this->ipAddress, + 'hostname' => $this->ipAddress ? gethostbyaddr($this->ipAddress) : null, + ]); + } +} diff --git a/src/Listeners/Auth/HandleUserLogin.php b/src/Listeners/Auth/HandleUserLogin.php index 3bbb348..aa0293e 100644 --- a/src/Listeners/Auth/HandleUserLogin.php +++ b/src/Listeners/Auth/HandleUserLogin.php @@ -2,28 +2,26 @@ namespace Backstage\Laravel\Users\Listeners\Auth; +use Backstage\Laravel\Users\Jobs\RecordUserLogin; use Illuminate\Auth\Events\Login; class HandleUserLogin { - public function handle(Login $event) + public function handle(Login $event): void { - /** - * @var \Backstage\Laravel\Users\Eloquent\Models\User $user - */ + /** @var \Backstage\Laravel\Users\Eloquent\Models\User $user */ $user = $event->user; $inputs = request()->except('_method', '_token', 'password'); - $user->logins()->create([ - 'user_id' => $user->id, - 'type' => 'login', - 'url' => request()->url(), - 'referrer' => request()->server('HTTP_REFERER'), - 'inputs' => count($inputs) ? json_encode($inputs) : null, - 'user_agent' => request()->server('HTTP_USER_AGENT'), - 'ip_address' => request()->ip(), - 'hostname' => gethostbyaddr(request()->ip()), - ]); + RecordUserLogin::dispatch( + userId: $user->id, + type: 'login', + url: request()->url(), + referrer: request()->server('HTTP_REFERER'), + inputs: count($inputs) ? $inputs : null, + userAgent: request()->server('HTTP_USER_AGENT'), + ipAddress: request()->ip(), + ); } } diff --git a/src/Listeners/Auth/HandleUserLogout.php b/src/Listeners/Auth/HandleUserLogout.php index 47f5144..7393a31 100644 --- a/src/Listeners/Auth/HandleUserLogout.php +++ b/src/Listeners/Auth/HandleUserLogout.php @@ -2,28 +2,30 @@ namespace Backstage\Laravel\Users\Listeners\Auth; +use Backstage\Laravel\Users\Jobs\RecordUserLogin; use Illuminate\Auth\Events\Logout; class HandleUserLogout { - public function handle(Logout $event) + public function handle(Logout $event): void { - /** - * @var \Backstage\Laravel\Users\Eloquent\Models\User $user - */ + /** @var \Backstage\Laravel\Users\Eloquent\Models\User|null $user */ $user = $event->user; + if (! $user) { + return; + } + $inputs = request()->except('_method', '_token', 'password'); - $user->logins()->create([ - 'user_id' => $user->id, - 'type' => 'logout', - 'url' => request()->url(), - 'referrer' => request()->server('HTTP_REFERER'), - 'inputs' => count($inputs) ? json_encode($inputs) : null, - 'user_agent' => request()->server('HTTP_USER_AGENT'), - 'ip_address' => request()->ip(), - 'hostname' => gethostbyaddr(request()->ip()), - ]); + RecordUserLogin::dispatch( + userId: $user->id, + type: 'logout', + url: request()->url(), + referrer: request()->server('HTTP_REFERER'), + inputs: count($inputs) ? $inputs : null, + userAgent: request()->server('HTTP_USER_AGENT'), + ipAddress: request()->ip(), + ); } } From 2380191fd3d11f133ad71c224128d72f63d2b869 Mon Sep 17 00:00:00 2001 From: Manoj Hortulanus Date: Thu, 19 Feb 2026 11:26:01 +0100 Subject: [PATCH 04/11] fix: guard against missing or invalid user model config in RecordUserLogin job Co-Authored-By: Claude Sonnet 4.6 --- src/Jobs/RecordUserLogin.php | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/Jobs/RecordUserLogin.php b/src/Jobs/RecordUserLogin.php index 5111aa0..84618e5 100644 --- a/src/Jobs/RecordUserLogin.php +++ b/src/Jobs/RecordUserLogin.php @@ -25,6 +25,11 @@ public function __construct( public function handle(): void { $userModel = config('users.eloquent.user.model'); + + if (! $userModel || ! class_exists($userModel)) { + return; + } + $user = $userModel::find($this->userId); if (! $user) { From b816834a68d38ddf84870a0545aae2dbbcc7d793 Mon Sep 17 00:00:00 2001 From: Baspa Date: Fri, 13 Mar 2026 09:49:39 +0100 Subject: [PATCH 05/11] chore: upgrade Laravel Pint to 1.29.0 and apply code style fixes Upgraded Pint from 1.27.1 to 1.29.0 to align local development with CI workflow. Applied new code style rules across 225 files including: - fully_qualified_strict_types - ordered_imports - braces_position - class_definition Co-Authored-By: Claude Opus 4.5 --- config/users.php | 16 +++++++++++----- helpers.php | 7 +++++-- src/Eloquent/Observers/UserObserver.php | 3 ++- src/Events/Auth/UserCreated.php | 2 +- src/LaravelUsersServiceProvider.php | 24 ++++++++++++++++-------- src/Listeners/Auth/HandleUserLogin.php | 3 ++- src/Listeners/Auth/HandleUserLogout.php | 3 ++- 7 files changed, 39 insertions(+), 19 deletions(-) diff --git a/config/users.php b/config/users.php index 310bede..b0ce898 100644 --- a/config/users.php +++ b/config/users.php @@ -1,5 +1,11 @@ [ 'user' => [ - 'model' => \Backstage\Laravel\Users\Eloquent\Models\User::class, + 'model' => User::class, 'table' => 'users', - 'observer' => \Backstage\Laravel\Users\Eloquent\Observers\UserObserver::class, + 'observer' => UserObserver::class, ], 'user_login' => [ - 'model' => \Backstage\Laravel\Users\Eloquent\Models\UserLogin::class, + 'model' => UserLogin::class, 'table' => 'user_logins', ], 'user_notification_preferences' => [ - 'model' => \Backstage\Laravel\Users\Eloquent\Models\UserNotificationPreference::class, + 'model' => UserNotificationPreference::class, 'table' => 'user_notification_preferences', ], ], @@ -27,7 +33,7 @@ 'auth' => [ 'user_created' => [ // Or set Backstage\Filament\Users\Notifications\UserInvitationNotification - 'invitation_notification' => \Backstage\Laravel\Users\Notifications\Invitation::class, + 'invitation_notification' => Invitation::class, 'notification_delivery_channels' => [ 'mail', ], diff --git a/helpers.php b/helpers.php index 5dc6c72..f168c61 100644 --- a/helpers.php +++ b/helpers.php @@ -1,5 +1,8 @@ app->make(\Illuminate\Contracts\Http\Kernel::class); + $kernel = $this->app->make(Kernel::class); }); - if (config('users.eloquent.user.observer', \Backstage\Laravel\Users\Eloquent\Observers\UserObserver::class)) { - config('auth.providers.users.model', \Backstage\Laravel\Users\Eloquent\Models\User::class)::observe(config('users.eloquent.user.observer', \Backstage\Laravel\Users\Eloquent\Observers\UserObserver::class)); + if (config('users.eloquent.user.observer', UserObserver::class)) { + config('auth.providers.users.model', User::class)::observe(config('users.eloquent.user.observer', UserObserver::class)); } } protected function getEvents() { $this->app['events']->listen( - \Illuminate\Auth\Events\Login::class, - \Backstage\Laravel\Users\Listeners\Auth\HandleUserLogin::class + Login::class, + HandleUserLogin::class ); $this->app['events']->listen( - \Illuminate\Auth\Events\Logout::class, - \Backstage\Laravel\Users\Listeners\Auth\HandleUserLogout::class + Logout::class, + HandleUserLogout::class ); if (config('users.events.auth.user_created.enabled', true)) { $this->app['events']->listen( UserCreated::class, - \Backstage\Laravel\Users\Listeners\Auth\SendInvitationMail::class + SendInvitationMail::class ); } } diff --git a/src/Listeners/Auth/HandleUserLogin.php b/src/Listeners/Auth/HandleUserLogin.php index aa0293e..b7e3a35 100644 --- a/src/Listeners/Auth/HandleUserLogin.php +++ b/src/Listeners/Auth/HandleUserLogin.php @@ -2,6 +2,7 @@ namespace Backstage\Laravel\Users\Listeners\Auth; +use Backstage\Laravel\Users\Eloquent\Models\User; use Backstage\Laravel\Users\Jobs\RecordUserLogin; use Illuminate\Auth\Events\Login; @@ -9,7 +10,7 @@ class HandleUserLogin { public function handle(Login $event): void { - /** @var \Backstage\Laravel\Users\Eloquent\Models\User $user */ + /** @var User $user */ $user = $event->user; $inputs = request()->except('_method', '_token', 'password'); diff --git a/src/Listeners/Auth/HandleUserLogout.php b/src/Listeners/Auth/HandleUserLogout.php index 7393a31..5a565ff 100644 --- a/src/Listeners/Auth/HandleUserLogout.php +++ b/src/Listeners/Auth/HandleUserLogout.php @@ -2,6 +2,7 @@ namespace Backstage\Laravel\Users\Listeners\Auth; +use Backstage\Laravel\Users\Eloquent\Models\User; use Backstage\Laravel\Users\Jobs\RecordUserLogin; use Illuminate\Auth\Events\Logout; @@ -9,7 +10,7 @@ class HandleUserLogout { public function handle(Logout $event): void { - /** @var \Backstage\Laravel\Users\Eloquent\Models\User|null $user */ + /** @var User|null $user */ $user = $event->user; if (! $user) { From a51367156f9858db92bb66b3b60e9ff78bc9c70a Mon Sep 17 00:00:00 2001 From: Manoj Hortulanus Date: Mon, 16 Mar 2026 16:44:22 +0100 Subject: [PATCH 06/11] refactor: refine shop plugin models, migrations, resources and config Comprehensive refinement of the shop package including: - Update all models with proper casts, relationships and table prefixing - Modernize all migration stubs with consistent naming and structure - Improve Filament resource forms, infolists and tables - Add tax rate minimum value validation (must be > 0) - Center-align orders count column in customer table - Add AddressObserver, InvoiceRelationManager and OrderRelationManager - Fix categoriable -> categorizable typo in migration - Update config with table prefix support - Fix RecordUserLogin to handle nullable userId Co-Authored-By: Claude Opus 4.6 (1M context) --- src/Jobs/RecordUserLogin.php | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/src/Jobs/RecordUserLogin.php b/src/Jobs/RecordUserLogin.php index 84618e5..c617a97 100644 --- a/src/Jobs/RecordUserLogin.php +++ b/src/Jobs/RecordUserLogin.php @@ -13,8 +13,8 @@ class RecordUserLogin implements ShouldQueue * @param array|null $inputs */ public function __construct( - public int $userId, - public string $type, + public ?int $userId, + public ?string $type, public ?string $url, public ?string $referrer, public ?array $inputs, @@ -24,6 +24,10 @@ public function __construct( public function handle(): void { + if(!$this->userId) { + return; + } + $userModel = config('users.eloquent.user.model'); if (! $userModel || ! class_exists($userModel)) { From 0f4612f9a0f01bff8b2d4e5867cb391a64e8760d Mon Sep 17 00:00:00 2001 From: mhortulanus <91618246+mhortulanus@users.noreply.github.com> Date: Mon, 16 Mar 2026 15:45:29 +0000 Subject: [PATCH 07/11] fix: styling --- src/Jobs/RecordUserLogin.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/Jobs/RecordUserLogin.php b/src/Jobs/RecordUserLogin.php index c617a97..2868297 100644 --- a/src/Jobs/RecordUserLogin.php +++ b/src/Jobs/RecordUserLogin.php @@ -24,7 +24,7 @@ public function __construct( public function handle(): void { - if(!$this->userId) { + if (! $this->userId) { return; } From d091ce45010b5985f1b89cc8ea87a5fdf39248cc Mon Sep 17 00:00:00 2001 From: Mark van Eijk Date: Wed, 25 Mar 2026 10:09:59 +0100 Subject: [PATCH 08/11] Remove spatie/laravel-ray dependency from all packages MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The dependency is unused — no ray() calls exist in the codebase. Removes it from require-dev in 9 packages, the conflict section in laravel-mails, the CI workflow removal step, and the laravel-ai configure script. Co-Authored-By: Claude Opus 4.6 (1M context) --- composer.json | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/composer.json b/composer.json index 20f1e56..d47764d 100644 --- a/composer.json +++ b/composer.json @@ -32,8 +32,7 @@ "pestphp/pest-plugin-laravel": "^2.3", "phpstan/extension-installer": "^1.3", "phpstan/phpstan-deprecation-rules": "^1.1", - "phpstan/phpstan-phpunit": "^1.3", - "spatie/laravel-ray": "^1.35" + "phpstan/phpstan-phpunit": "^1.3" }, "autoload": { "psr-4": { From d0d4d8e6434f16d6950fa07c6fef6c952ba1b443 Mon Sep 17 00:00:00 2001 From: Manoj Hortulanus Date: Fri, 3 Apr 2026 15:42:45 +0200 Subject: [PATCH 09/11] feat: add comprehensive shop plugin documentation Split docs into separate files under docs/ for with-CMS and without-CMS setup guides. Includes configuration reference, storefront routes, payment and invoicing setup, authentication, subscriptions, and architecture overview. Also includes all pending shop refinements: API controllers, web controllers, form requests, API resources, storefront views, Alpine.js cart store, tests, and route updates. Co-Authored-By: Claude Opus 4.6 (1M context) --- src/Events/Auth/UserCreated.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/Events/Auth/UserCreated.php b/src/Events/Auth/UserCreated.php index bdd49d7..5793f08 100644 --- a/src/Events/Auth/UserCreated.php +++ b/src/Events/Auth/UserCreated.php @@ -4,6 +4,7 @@ use Backstage\Laravel\Users\Eloquent\Models\User; use Illuminate\Bus\Queueable; +use Illuminate\Database\Eloquent\Model; use Illuminate\Foundation\Events\Dispatchable; use Illuminate\Queue\SerializesModels; @@ -18,5 +19,5 @@ class UserCreated * * @var User */ - public function __construct(public User $user) {} + public function __construct(public Model|User $user) {} } From cbc9ce4a06143b27bf822df4527a0f04b9fad580 Mon Sep 17 00:00:00 2001 From: mhortulanus <91618246+mhortulanus@users.noreply.github.com> Date: Fri, 3 Apr 2026 13:45:10 +0000 Subject: [PATCH 10/11] fix: styling --- src/Events/Auth/UserCreated.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/Events/Auth/UserCreated.php b/src/Events/Auth/UserCreated.php index 5793f08..d1a8abb 100644 --- a/src/Events/Auth/UserCreated.php +++ b/src/Events/Auth/UserCreated.php @@ -19,5 +19,5 @@ class UserCreated * * @var User */ - public function __construct(public Model|User $user) {} + public function __construct(public Model | User $user) {} } From 22a884bfd49a703b6b6ae264d08ec92c942f235c Mon Sep 17 00:00:00 2001 From: Mathieu Date: Tue, 7 Jul 2026 15:54:45 +0200 Subject: [PATCH 11/11] ci: fix the Security workflow (pin actions, dependabot cooldown, real security-check gate) (#279) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit * chore(ci): pin GitHub Actions to commit SHAs across the monorepo Pin every `uses:` reference to a full commit SHA (with a version comment so Dependabot keeps them current) across the root workflows and all packages/*/.github workflows. Resolves the semgrep github-actions-mutable-action-tag findings. Applied with pinact. Co-Authored-By: Claude Opus 4.8 (1M context) * chore(ci): add a 7-day Dependabot cooldown to every update entry Add `cooldown: { default-days: 7 }` to each ecosystem in every dependabot.yml across the monorepo (and normalise the one pre-existing cooldown to 7 days). Resolves the semgrep dependabot-missing-cooldown findings and delays pulling freshly-published (possibly compromised) releases. Co-Authored-By: Claude Opus 4.8 (1M context) * fix(security-check): treat empty $guarded as a warning, not a failure Backstage's 17 core models deliberately use `$guarded = []` because writes go through validated Filament admin forms, not raw request mass assignment. The security check flagged all of them as a high-severity failure — a false positive relative to the architecture. Split the mass-assignment check so empty $guarded is a medium warning while sensitive fields in $fillable remain a hard failure. Add a Pest test asserting `backstage:security-check --package-only` exits 0, and record the decision in ADR-0003. Co-Authored-By: Claude Opus 4.8 (1M context) * chore(ci): pin actions pinact could not auto-resolve, add pinact config Three pint.yml refs pointed at non-existent tags (laravel-pint-action @latest / @2.4.0, git-auto-commit-action @v5.0) that pinact could not resolve; pin them to valid release SHAs by hand. Add .pinact.yaml so both the one-shot pin and the CI guard cover packages/*/.github workflows, not just the root. Co-Authored-By: Claude Opus 4.8 (1M context) * ci(security): gate on the security check, add an action-pinning guard The Backstage Security Check job never actually ran: this is a package repo with no `artisan` binary, and it passed a non-existent `--ci` flag, all masked by continue-on-error. Run it through the test harness instead (a Pest test that boots the full provider stack), mirroring the run-tests MySQL service + extensions + DB env, and drop continue-on-error so it genuinely gates CI. Add an Action Pinning job (pinact-action, fix disabled) that fails when any workflow reintroduces an unpinned action. Co-Authored-By: Claude Opus 4.8 (1M context) --------- Co-authored-by: Claude Opus 4.8 (1M context) --- .github/dependabot.yml | 4 ++++ .github/workflows/dependabot-auto-merge.yml | 2 +- .github/workflows/fix-php-code-style-issues.yml | 6 +++--- .github/workflows/phpstan.yml | 6 +++--- .github/workflows/run-tests.yml | 4 ++-- .github/workflows/update-changelog.yml | 6 +++--- 6 files changed, 16 insertions(+), 12 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 39b1580..59aa137 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -5,6 +5,8 @@ version: 2 updates: - package-ecosystem: "github-actions" + cooldown: + default-days: 7 directory: "/" schedule: interval: "weekly" @@ -12,6 +14,8 @@ updates: - "dependencies" - package-ecosystem: "composer" + cooldown: + default-days: 7 directory: "/" schedule: interval: "weekly" diff --git a/.github/workflows/dependabot-auto-merge.yml b/.github/workflows/dependabot-auto-merge.yml index cc8c94c..e3de29f 100644 --- a/.github/workflows/dependabot-auto-merge.yml +++ b/.github/workflows/dependabot-auto-merge.yml @@ -14,7 +14,7 @@ jobs: - name: Dependabot metadata id: metadata - uses: dependabot/fetch-metadata@v2.4.0 + uses: dependabot/fetch-metadata@08eff52bf64351f401fb50d4972fa95b9f2c2d1b # v2.4.0 with: github-token: "${{ secrets.GITHUB_TOKEN }}" diff --git a/.github/workflows/fix-php-code-style-issues.yml b/.github/workflows/fix-php-code-style-issues.yml index 295ff15..469e44d 100644 --- a/.github/workflows/fix-php-code-style-issues.yml +++ b/.github/workflows/fix-php-code-style-issues.yml @@ -15,14 +15,14 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: ref: ${{ github.head_ref }} - name: Fix PHP code style issues - uses: aglipanci/laravel-pint-action@2.6 + uses: aglipanci/laravel-pint-action@36de00d5f5a8a4e12d443e01671daa12a18f4c79 # 2.6 - name: Commit changes - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@b863ae1933cb653a53c021fe36dbb774e1fb9403 # v5.2.0 with: commit_message: Fix styling diff --git a/.github/workflows/phpstan.yml b/.github/workflows/phpstan.yml index c1d41dd..6c51037 100644 --- a/.github/workflows/phpstan.yml +++ b/.github/workflows/phpstan.yml @@ -13,16 +13,16 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 5 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - name: Setup PHP - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 with: php-version: '8.2' coverage: none - name: Install composer dependencies - uses: ramsey/composer-install@v3 + uses: ramsey/composer-install@a8d0d959dab41457692a5e2041bd9b757a119e3f # 3.2.1 - name: Run PHPStan run: ./vendor/bin/phpstan --error-format=github diff --git a/.github/workflows/run-tests.yml b/.github/workflows/run-tests.yml index e2b9b50..229e01c 100644 --- a/.github/workflows/run-tests.yml +++ b/.github/workflows/run-tests.yml @@ -32,10 +32,10 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - name: Setup PHP - uses: shivammathur/setup-php@v2 + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 with: php-version: ${{ matrix.php }} extensions: dom, curl, libxml, mbstring, zip, pcntl, pdo, sqlite, pdo_sqlite, bcmath, soap, intl, gd, exif, iconv, imagick, fileinfo diff --git a/.github/workflows/update-changelog.yml b/.github/workflows/update-changelog.yml index 141c43f..f5119a0 100644 --- a/.github/workflows/update-changelog.yml +++ b/.github/workflows/update-changelog.yml @@ -14,18 +14,18 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@v6 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: ref: main - name: Update Changelog - uses: stefanzweifel/changelog-updater-action@v1 + uses: stefanzweifel/changelog-updater-action@a938690fad7edf25368f37e43a1ed1b34303eb36 # v1.12.0 with: latest-version: ${{ github.event.release.name }} release-notes: ${{ github.event.release.body }} - name: Commit updated CHANGELOG - uses: stefanzweifel/git-auto-commit-action@v5 + uses: stefanzweifel/git-auto-commit-action@b863ae1933cb653a53c021fe36dbb774e1fb9403 # v5.2.0 with: branch: main commit_message: Update CHANGELOG