Skip to content

Tighten GitHub Actions / Drop Laravel 11 Support - #42

Merged
ultrono merged 5 commits into
masterfrom
ultrono-patch-9
Jun 20, 2026
Merged

ultrono merged 5 commits into
masterfrom
ultrono-patch-9

Conversation

@ultrono

@ultrono ultrono commented Jun 20, 2026 •

Copy link
Copy Markdown
Contributor

Add three new steps to the GitHub Actions workflow:

  • Composer validation — checks composer.json is well-formed and strict
  • PHP lint — runs a syntax check across all files in src/
  • Dependency audit — flags any installed packages with known vulnerabilities

These are cheap, fast checks that catch real problems early:

  • A malformed composer.json or syntax error will now fail the build immediately, before wasting time installing dependencies or running the full test suite
  • The security audit means vulnerabilities in dependencies are caught automatically on every push, rather than discovered later in production

All three steps use built-in PHP/Composer tooling — no new dependencies required.

The validate and lint steps run after PHP is set up via shivammathur/setup-php, so they use the correct matrix PHP version rather than the runner default.

Due to composer audit output and the fact Laravel 11 is now officially EOL (see https://laravel.com/docs/13.x/releases#support-policy), this PR also drops Laravel 11 support.

ultrono added 5 commits June 20, 2026 15:32
Update Laravel versions because the composer audit command found 3 security vulnerability advisories affecting 1 package:

- GHSA-crmm-hgp2-wgrp   
- GHSA-5vg9-5847-vvmq    
- GHSA-5vg9-5847-vvmq
Do not run actions under Laravel 11. Laravel 11 is now EOF, see https://laravel.com/docs/13.x/releases#support-policy
Support Laravel 12 and up
@ultrono ultrono changed the title Tighten GitHub Actions Tighten GitHub Actions / Drop Laravel 11 Support Jun 20, 2026
@ultrono
ultrono merged commit 127cb02 into master Jun 20, 2026
28 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant