From 7295a2421f8e7971be2b5b55285e25f62d4922ac Mon Sep 17 00:00:00 2001 From: Miguel Colmenares Date: Fri, 25 Sep 2026 10:24:32 -0500 Subject: [PATCH] WEB-1194: Read the vcs repositories with git instead of the GitHub API (no-api) A lockless composer install cost about 100 GitHub API requests of the token's hourly quota, enough to exhaust it in a busy CI (Could not authenticate against github.com). no-api makes Composer read tags with git: zero API requests, same resolved versions. Applied to the development dependencies and the README snippet. --- CHANGELOG.md | 6 ++++++ README.md | 7 ++++++- composer.json | 2 +- 3 files changed, 13 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index edee553..cda324d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## [Unreleased] + +### Changed + +- The `vcs` repositories in `composer.json` (development dependencies) and in the README snippet now carry `"no-api": true`, so Composer reads tags with git instead of the GitHub API. A lockless install cost about 100 API requests of the token's hourly quota, enough to exhaust it in a busy CI. + ## [1.4.0] - 2026-09-25 ### Added diff --git a/README.md b/README.md index 57d368c..ab75d8a 100644 --- a/README.md +++ b/README.md @@ -41,7 +41,7 @@ authentication, so always configure a token. ```json { "repositories": [ - { "type": "vcs", "url": "https://github.com/SilverAssist/wp-github-updater" } + { "type": "vcs", "url": "https://github.com/SilverAssist/wp-github-updater", "no-api": true } ], "require": { "silverassist/wp-github-updater": "^1.3" @@ -57,6 +57,11 @@ authentication, so always configure a token. Never commit a token or an `auth.json`. Without a token, Composer hits GitHub's anonymous API limit (60 requests per hour per IP) and falls back to an SSH clone. + Keep `"no-api": true` on every `vcs` entry: it makes Composer read tags with git instead of + the GitHub API. Without it, one install without a lock file costs about 100 API requests of + the token's hourly quota (5,000, shared with the token owner's other API usage), which a busy + CI can exhaust. + 3. **Refresh the lock file** if your project commits `composer.lock`: run `composer update --lock` after adding `repositories`, so the lock file's `content-hash` matches `composer.json`. diff --git a/composer.json b/composer.json index 7000ae6..a2eb0d7 100644 --- a/composer.json +++ b/composer.json @@ -19,7 +19,7 @@ } ], "repositories": [ - { "type": "vcs", "url": "https://github.com/SilverAssist/coding-standards" } + { "type": "vcs", "url": "https://github.com/SilverAssist/coding-standards", "no-api": true } ], "require": { "php": ">=8.2"