Skip to content

WEB-1194: Install SilverAssist packages from GitHub and ship the private-repo updater (1.3.1) - #53

Merged
miguelcolmenares merged 2 commits into
mainfrom
feature/WEB-1194-private-composer-vcs
Sep 25, 2026
Merged

miguelcolmenares merged 2 commits into
mainfrom
feature/WEB-1194-private-composer-vcs

Conversation

@miguelcolmenares

@miguelcolmenares miguelcolmenares commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Summary

Part of WEB-1194 (make the SilverAssist repositories private without breaking updates or builds). This PR moves the plugin's Composer resolution to GitHub vcs repositories, picks up the private-repository support of wp-github-updater 1.4.0 and gets the CI ready for authenticated installs. It is prepared as a release: 1.3.1.

Changes Made

  • composer.json: vcs repositories (with "no-api": true: Composer reads tags with git instead of the GitHub API, which otherwise costs ~100 requests of the token's hourly quota per install and exhausted it in CI) for wp-github-updater, wp-plugin-kernel, wp-settings-hub, coding-standards and wp-coding-standards (Composer only reads repositories from the root package, so transitive packages must be listed too). wp-github-updater constraint ^1.3 to ^1.4.
  • Workflows: every step that runs composer install, update or outdated gets COMPOSER_AUTH from the repository secret, and calls to reusable workflows pass secrets: inherit.
  • README: section "Composer authentication (private packages)".
  • Version and CHANGELOG: 1.3.1 (plugin header and version constant).

Not in this PR

  • dependabot.yml registries: they need a Dependabot-scoped secret first, and referencing a missing one would break the Dependabot runs while the repositories are still public. Tracked separately in the ticket.
  • The Copilot agent workflow (copilot-setup-steps.yml) reads COMPOSER_AUTH from the copilot environment secrets, if any; the repository secret may not be visible there.

Type of Change

  • 🔧 Refactoring (build and CI configuration)
  • 📝 Documentation

Testing

  • All workflow steps that run Composer were checked programmatically (parsed YAML: every one sets COMPOSER_AUTH, every reusable call passes secrets).
  • Ran the pre-PR consistency review, applied its findings (stale version tables, README placement).
  • CI of this PR: resolves wp-github-updater ^1.4 from the GitHub vcs repository and runs the plugin suite on the real WordPress test suite.

Release

After the merge, push the signed tag v1.3.1. Base branch: main.

Checklist

  • Self-review completed
  • Documentation updated
  • No token or auth.json committed

…ate-repo updater (1.3.1)

- Declare vcs repositories for the five SilverAssist packages in composer.json
- Require wp-github-updater ^1.4 (reads private releases with SILVER_GITHUB_TOKEN)
- Pass COMPOSER_AUTH to every composer install and secrets: inherit to reusable workflows
- README section on Composer authentication, CHANGELOG and version bump to 1.3.1
…I (no-api)

A lockless composer install cost about 100 GitHub API requests of the token's
hourly quota, enough to exhaust it in a busy CI (Could not authenticate against
github.com). no-api makes Composer read tags with git: zero API requests, same
resolved versions.
@miguelcolmenares
miguelcolmenares merged commit 755de78 into main Sep 25, 2026
16 checks passed
@miguelcolmenares
miguelcolmenares deleted the feature/WEB-1194-private-composer-vcs branch September 25, 2026 17:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant