• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

bleedingdeacons / unity / 31078712148
96%

Build:
DEFAULT BRANCH: main
Ran 06 Aug 2026 06:51AM UTC
Jobs 1
Files 8
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

06 Aug 2026 06:51AM UTC coverage: 94.079%. Remained the same
31078712148

push

github

web-flow
ci: gate on composer audit (#49)

CI gates on syntax, build, PHPUnit, PHPCS and PHPStan, but nothing checked
dependencies against known security advisories. A vulnerable package could be
introduced, or an advisory published against one already pinned, and no
workflow in the suite would say a word.

One step, placed in the gates block before install:

    composer audit --locked --abandoned=report

--locked reads composer.lock directly, so it needs no vendor/ and fails in
seconds. Nothing is added to require-dev; Composer ships the command and the
runner already has composer:v2. The suite is clean today — this exits 0 in all
17 — so it goes in as a gate rather than landing advisory and being promoted
later, the same way PHPCS was.

Dev dependencies are audited too. The first attempt scoped the gate to --no-dev,
with a separate advisory step covering dev, so that an advisory published
against phpunit or php_codesniffer could not block every PR in the suite at
once. That does not work here, and CI is what proved it:

  - Production requirements across these plugins amount to psr/container and a
    couple of ext-*, so with --no-dev the audit set is empty in 9 of the 17.
  - Composer 2.10 (what the runner installs) treats an empty set as an error —
    "No installed packages found" — even when --locked is passed. Composer 2.9
    prints "No packages - skipping audit" and exits 0, so a local pre-flight
    across all 17 came back green and CI still failed 9 of them.
  - In the 8 where it did run, it audited exactly one package.

So the scoped gate protected almost nothing while failing more than half the
suite. Auditing the whole lock audits something real. The accepted cost is that
an advisory published against a dev tool will block PRs in every repo at once;
that is a legitimate failure with a legitimate fix, and it is visible rather
than silent.

--abandoned=report pins today's behaviour. The default becomes "fail" in
Composer 3, which would turn an unm... (continued)

143 of 152 relevant lines covered (94.08%)

3.09 hits per line

Jobs
ID Job ID Ran Files Coverage
1 31078712148.1 06 Aug 2026 06:51AM UTC 8
94.08
GitHub Action Run
Source Files on build 31078712148
  • Tree
  • List 8
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #31078712148
  • 64ab23c4 on github
  • Prev Build on main (#31052714303)
  • Next Build on main (#31079741363)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc