Repository navigation
WEB-1194: Read releases from private repositories with a token (1.4.0) - #34
Merged
miguelcolmenares merged 4 commits intoSep 25, 2026
Merged
Conversation
- Type the array parameters and properties (array<string, mixed>) - Narrow the update_plugins transient and guard a failed version lookup in checkForUpdate and pluginInfo - Keep the original text when a Markdown regex fails, instead of passing null on - Drop the stream and filename defaults from the download request and handle a missing URL path in the temp file name - Remove the ignoreErrors pattern that no longer matched anything (WEB-1194)
- Add the token_constant option (default SILVER_GITHUB_TOKEN) and UpdaterConfig::getGithubToken(): a PHP constant first, then an environment variable, never the database - Send Authorization: Bearer to api.github.com only, never to another host - Use the asset API URL when a token exists and download in two steps: the first request carries the token and stops at the redirect, the second goes to the signed storage URL without it - Log a distinct message for 401, 403 and 404 with and without a token, and never log the token; failed lookups are not cached - Tests run on the real WordPress Test Suite with the pre_http_request filter, plus an opt-in live test against a private repository (WEB-1194)
- Add a Private Repositories README section (token setup, how it works, log messages, live test) and the token_constant option - Add the 1.4.0 CHANGELOG entry and a private repository example to the integration guide - Stop describing the updater as public-only in the README and the package description, and correct the requires_php default (WEB-1194)
- Add ci.yml: PHPCS, PHPStan and composer validate, PHPUnit on the real WordPress Test Suite (PHP 8.2, 8.3, 8.4) and standalone unit tests - Pass COMPOSER_AUTH to composer install in ci.yml and create-release.yml - Raise the PHPStan memory limit so composer phpstan does not crash
miguelcolmenares
force-pushed
the
feature/WEB-1194-updater-private-releases
branch
from
September 25, 2026 14:20
d468bc8 to
3f813e5
Compare
miguelcolmenares
deleted the
feature/WEB-1194-updater-private-releases
branch
September 25, 2026 14:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
wp-github-updatercan now read the releases of a private GitHub repository with a token, and keeps working anonymously for public ones. Phase 1 of WEB-1194 (making the SilverAssist plugin repositories private without breaking updates on the sites). Once this ships, the plugins bundle it, the sites get the token, and only then the repositories go private.Changes
token_constantoption (defaultSILVER_GITHUB_TOKEN) andUpdaterConfig::getGithubToken(): a PHP constant first, then an environment variable, trimmed,nullwhen empty. Never read from the database.Authorization: Beareris sent toapi.github.comonly, never to another host.redirection => 0), the second goes to the signed storage URL without the token. A redirect that is not https is refused.ignoreErrorspattern, socomposer checkpasses again (separate commit, no behaviour changes apart from two small hardenings listed in the CHANGELOG).token_constantoption, 1.4.0 CHANGELOG, integration guide example. The "public GitHub releases" wording is gone, and the READMErequires_phpdefault is corrected (8.2).Tests
Nothing from WordPress core is mocked in the new tests. They run on the real WordPress Test Suite (
WP_UnitTestCase) and intercept requests with WordPress' ownpre_http_requestfilter.tests/WordPress/UpdaterPrivateReleasesTest.php: 12 tests (headers, asset URL, redirect without the token, refused insecure redirect, 401/403/404 messages, token never logged, failures not cached).tests/Unit/UpdaterConfigTest.php: 7 tests for the token lookup (constant, environment, precedence, trimming).tests/WordPress/PrivateRepoLiveTest.php: opt-in, skipped unlessWPGU_LIVE_REPO,WPGU_LIVE_VERSIONandSILVER_GITHUB_TOKENare set.Verification
Notes
v1.4.0follows the merge.tests/wordpress-mocks.php. Migrating them to the real suite is a separate change.