Skip to content

WEB-1194: Read the vcs repositories with git instead of the GitHub API - #35

Merged
miguelcolmenares merged 1 commit into
mainfrom
feature/WEB-1194-vcs-no-api
Sep 25, 2026
Merged

miguelcolmenares merged 1 commit into
mainfrom
feature/WEB-1194-vcs-no-api

Conversation

@miguelcolmenares

Copy link
Copy Markdown
Member

Why

The CI of the plugin PRs failed with Could not authenticate against github.com. Root cause: a lockless composer install through vcs repositories spends about 100 GitHub API requests (measured: 102 with a cold cache, 30 with a warm one). A pull request with ~15 jobs is ~1,500 requests, and the quota (5,000 per hour) belongs to the token's owner, so it was exhausted (remaining: 0) and Composer fell back to a prompt that cannot run in CI.

What

  • composer.json: "no-api": true on the vcs entries of the development dependencies. Composer then reads tags with git instead of the API.
  • README snippet and CHANGELOG ([Unreleased]): same option, with the reason.

Verification

  • Cold-cache install of a plugin with the five vcs entries: 0 API requests, same versions (coding-standards v1.0.1, wp-coding-standards v1.1.7, wp-github-updater v1.4.0, wp-plugin-kernel v1.0.1, wp-settings-hub v1.2.2).
  • Private repository (probe): with the token and git isolated from local credentials it installs with 0 requests; without the token it fails clearly.
  • The lock now records the plain https source URL instead of the SSH one.

Docs and configuration only, no release needed.

…I (no-api)

A lockless composer install cost about 100 GitHub API requests of the token's
hourly quota, enough to exhaust it in a busy CI (Could not authenticate against
github.com). no-api makes Composer read tags with git: zero API requests, same
resolved versions. Applied to the development dependencies and the README snippet.
@miguelcolmenares
miguelcolmenares merged commit e712596 into main Sep 25, 2026
9 checks passed
@miguelcolmenares
miguelcolmenares deleted the feature/WEB-1194-vcs-no-api branch September 25, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant