Repository navigation
WEB-1194: Install SilverAssist packages from GitHub and ship the private-repo updater (1.3.1) - #53
Merged
Conversation
…ate-repo updater (1.3.1) - Declare vcs repositories for the five SilverAssist packages in composer.json - Require wp-github-updater ^1.4 (reads private releases with SILVER_GITHUB_TOKEN) - Pass COMPOSER_AUTH to every composer install and secrets: inherit to reusable workflows - README section on Composer authentication, CHANGELOG and version bump to 1.3.1
…I (no-api) A lockless composer install cost about 100 GitHub API requests of the token's hourly quota, enough to exhaust it in a busy CI (Could not authenticate against github.com). no-api makes Composer read tags with git: zero API requests, same resolved versions.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Part of WEB-1194 (make the SilverAssist repositories private without breaking updates or builds). This PR moves the plugin's Composer resolution to GitHub
vcsrepositories, picks up the private-repository support ofwp-github-updater1.4.0 and gets the CI ready for authenticated installs. It is prepared as a release: 1.3.1.Changes Made
composer.json:vcsrepositories (with"no-api": true: Composer reads tags with git instead of the GitHub API, which otherwise costs ~100 requests of the token's hourly quota per install and exhausted it in CI) forwp-github-updater,wp-plugin-kernel,wp-settings-hub,coding-standardsandwp-coding-standards(Composer only readsrepositoriesfrom the root package, so transitive packages must be listed too).wp-github-updaterconstraint^1.3to^1.4.composer install,updateoroutdatedgetsCOMPOSER_AUTHfrom the repository secret, and calls to reusable workflows passsecrets: inherit.Not in this PR
dependabot.ymlregistries: they need a Dependabot-scoped secret first, and referencing a missing one would break the Dependabot runs while the repositories are still public. Tracked separately in the ticket.copilot-setup-steps.yml) readsCOMPOSER_AUTHfrom thecopilotenvironment secrets, if any; the repository secret may not be visible there.Type of Change
Testing
COMPOSER_AUTH, every reusable call passes secrets).wp-github-updater ^1.4from the GitHubvcsrepository and runs the plugin suite on the real WordPress test suite.Release
After the merge, push the signed tag
v1.3.1. Base branch:main.Checklist