diff --git a/.github/copilot-instructions.md b/.github/copilot-instructions.md index 2df6464..a6b1c91 100644 --- a/.github/copilot-instructions.md +++ b/.github/copilot-instructions.md @@ -33,7 +33,7 @@ This is a **reusable Composer package** that provides WordPress plugin update fu - **WordPress 6.0+**: WordPress update system integration via hooks and filters - **PSR-4 Autoloading**: Namespace-based class loading for better organization - **GitHub API v3**: REST API integration for release management -- **Composer Package**: Distributed via Packagist as `silverassist/wp-github-updater` +- **Composer Package**: Installed from GitHub through a Composer `vcs` repository (with a GitHub token) as `silverassist/wp-github-updater`, not from Packagist.org ## 🔒 PHPUnit Version Policy - CRITICAL @@ -210,7 +210,7 @@ define('WP_TEMP_DIR', ABSPATH . 'wp-content/temp'); - **Version Bumping**: Update version in composer.json and CHANGELOG.md - **Git Tagging**: Create semantic version tags (v1.0.0, v1.1.0, etc.) - **Documentation**: Update README and integration examples -- **Packagist**: Automatic distribution via Packagist on tag push +- **Composer**: Consumers resolve the new tag directly from GitHub through a `vcs` repository; no Packagist step ### Core Structure diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index c30e340..23574be 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -171,6 +171,8 @@ jobs: - **WordPress Version**: 6.0+ ## 🚀 Installation via Composer + Declare the repository as a Composer \`vcs\` repository first (see [README](README.md#installing-via-composer-private-repository)). + \`\`\`bash composer require silverassist/wp-github-updater:^$VERSION \`\`\` @@ -246,6 +248,8 @@ jobs: - Composer package definition (\`composer.json\`) ## Installation via Composer + Declare the repository as a Composer \`vcs\` repository first (see [README](README.md#installing-via-composer-private-repository)). + \`\`\`bash composer require silverassist/wp-github-updater:^$VERSION \`\`\` @@ -291,7 +295,7 @@ jobs: - **Issues**: [GitHub Issues](https://github.com/SilverAssist/wp-github-updater/issues) ## Distribution - - **Packagist**: https://packagist.org/packages/silverassist/wp-github-updater + - **Composer**: installed from this repository through a \`vcs\` repository, see [README](README.md#installing-via-composer-private-repository) - **GitHub Releases**: https://github.com/SilverAssist/wp-github-updater/releases EOF diff --git a/CHANGELOG.md b/CHANGELOG.md index dc194c7..59b19ed 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,16 @@ # Changelog +## [1.3.2] - 2026-09-25 + +### Changed + +- Declared `vcs` repositories for the SilverAssist development dependencies (`coding-standards`), so contributors and CI resolve them from GitHub instead of Packagist.org. + +### Documentation + +- Documented installing this package through a Composer `vcs` repository with a GitHub token, instead of Packagist.org (README, "Installing via Composer"). +- Release notes and the Copilot instructions no longer point at Packagist as the distribution channel. + ## [1.3.1] - 2026-03-02 ### Fixed diff --git a/README.md b/README.md index 3c39533..0b40d64 100644 --- a/README.md +++ b/README.md @@ -27,6 +27,49 @@ Install via Composer in your WordPress plugin: composer require silverassist/wp-github-updater ``` +## Installing via Composer (private repository) + +SilverAssist packages are installed from their GitHub repositories with a Composer +`vcs` repository, not from Packagist.org. Those repositories can require +authentication, so always configure a token. + +1. **Declare the repository** in your project's root `composer.json`. Composer only + reads `repositories` from the root package, so every SilverAssist package your + project needs must be listed there, including transitive ones: + + ```json + { + "repositories": [ + { "type": "vcs", "url": "https://github.com/SilverAssist/wp-github-updater" } + ], + "require": { + "silverassist/wp-github-updater": "^1.3" + } + } + ``` + +2. **Authenticate** with a GitHub token that can read the repository: + - Locally: `composer config --global github-oauth.github.com ` + - CI: set `COMPOSER_AUTH='{"github-oauth":{"github.com":""}}'` from a secret + (a GitHub Actions secret or a Bitbucket variable). + + Never commit a token or an `auth.json`. Without a token, Composer hits GitHub's + anonymous API limit (60 requests per hour per IP) and falls back to an SSH clone. + +3. **Refresh the lock file** if your project commits `composer.lock`: run + `composer update --lock` after adding `repositories`, so the lock file's + `content-hash` matches `composer.json`. + +This repository's own `composer.json` declares `vcs` repositories for its SilverAssist development dependencies (`coding-standards`), so contributors and CI need the same token. + +### Troubleshooting + +| Symptom | Cause | +|---------|-------| +| `Failed to clone the git@github.com:SilverAssist/wp-github-updater.git repository, try running in interactive mode...` followed by `Permission denied (publickey)` | The token is missing or has no access to the repository. | +| `remote: Invalid username or token` | The token is invalid or expired. | +| `it could not be found in any version` | The `vcs` entry is missing from the root `composer.json`. | + ## Quick Start ### Basic Usage diff --git a/composer.json b/composer.json index 07b22e8..9bc0f0f 100644 --- a/composer.json +++ b/composer.json @@ -18,6 +18,9 @@ "homepage": "https://silverassist.com" } ], + "repositories": [ + { "type": "vcs", "url": "https://github.com/SilverAssist/coding-standards" } + ], "require": { "php": ">=8.2" },