1 Commits
Author SHA1 Message Date
renovate-bot 6a7ca9695b chore(deps): update symfony packages to v7.4.15 2026-07-29 12:02:32 +00:00
6 changed files with 57 additions and 210 deletions
+11
View File
@@ -70,6 +70,17 @@ jobs:
username: ${{ gitea.actor }} username: ${{ gitea.actor }}
password: ${{ secrets.REGISTRY_TOKEN }} password: ${{ secrets.REGISTRY_TOKEN }}
# Build a single-arch image locally so Trivy can inspect it before the real push.
- name: Build local image for scanning
uses: docker/build-push-action@v5
with:
context: .
target: final
platforms: linux/amd64
load: true
tags: scan-target:${{ inputs.tag }}
cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ gitea.repository }}:buildcache
- name: Build and push - name: Build and push
uses: docker/build-push-action@v5 uses: docker/build-push-action@v5
with: with:
-62
View File
@@ -1,62 +0,0 @@
# Cuts a release: moves CHANGELOG.md's [Unreleased] section under a new
# version heading, commits it to main, then creates and pushes the version tag.
# Trigger manually via workflow_dispatch, entering the semver to release.
# The pushed tag can then be built with docker-publish.yml.
name: Create Release Tag
on:
workflow_dispatch:
inputs:
version:
description: "Version to release (semver, e.g. 1.2.3)"
required: true
type: string
jobs:
tag:
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
token: ${{ secrets.GITHUB_TOKEN }}
- name: Validate version and Unreleased section
run: |
if ! [[ "${{ inputs.version }}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "Error: '${{ inputs.version }}' is not a valid semver (e.g. 1.2.3)."
exit 1
fi
if git rev-parse "refs/tags/${{ inputs.version }}" >/dev/null 2>&1; then
echo "Error: tag '${{ inputs.version }}' already exists."
exit 1
fi
awk '/^## \[Unreleased\]/{f=1;next}/^## \[/{f=0}f' CHANGELOG.md > /tmp/unreleased.md
if ! grep -q '[^[:space:]]' /tmp/unreleased.md; then
echo "Error: CHANGELOG.md's [Unreleased] section is empty — nothing to release."
exit 1
fi
- name: Move Unreleased entries under the new version heading
run: |
today=$(date +%Y-%m-%d)
awk -v ver="${{ inputs.version }}" -v date="$today" '
/^## \[Unreleased\]/ { print; print ""; print "## [" ver "] - " date; next }
{ print }
' CHANGELOG.md > /tmp/CHANGELOG.md
mv /tmp/CHANGELOG.md CHANGELOG.md
- name: Commit and tag
run: |
git config user.name "gitea-actions"
git config user.email "actions@noreply.git.arthurerlich.de"
git add CHANGELOG.md
git commit -m "chore(release): ${{ inputs.version }}"
git tag "${{ inputs.version }}"
git push origin HEAD:main
git push origin "${{ inputs.version }}"
-78
View File
@@ -1,78 +0,0 @@
name: Tests
on:
push:
branches: [main]
pull_request:
branches: [main]
env:
REGISTRY: git.arthurerlich.de
jobs:
build-dev:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to Gitea registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ gitea.actor }}
password: ${{ secrets.REGISTRY_TOKEN }}
- name: Build dev image (PHP 8.4 + composer deps)
uses: docker/build-push-action@v5
with:
context: .
file: Dockerfile.dev
target: dev
load: true
tags: graph-dev:ci
cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ gitea.repository }}:buildcache-dev
cache-to: type=registry,ref=${{ env.REGISTRY }}/${{ gitea.repository }}:buildcache-dev,mode=max
- name: Run tests in dev image
run: |
cid=$(docker create graph-dev:ci sh -c "
composer install --no-interaction &&
vendor/bin/phpunit --testdox &&
composer phpstan
")
docker cp . "$cid":/app
rc=0
docker start -a "$cid" || rc=$?
docker rm "$cid" > /dev/null
exit $rc
build-prod:
needs: build-dev
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to Gitea registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ gitea.actor }}
password: ${{ secrets.REGISTRY_TOKEN }}
- name: Build prod image (final target)
uses: docker/build-push-action@v5
with:
context: .
file: Dockerfile
target: final
push: false
cache-from: type=registry,ref=${{ env.REGISTRY }}/${{ gitea.repository }}:buildcache-prod
cache-to: type=registry,ref=${{ env.REGISTRY }}/${{ gitea.repository }}:buildcache-prod,mode=max
-4
View File
@@ -7,10 +7,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## [Unreleased] ## [Unreleased]
### Fixed
- Removed a leftover `composer dump-env prod` call in the prod Docker build stage — the command doesn't exist in this project's Composer setup and broke every image build
## [0.2.0] - 2026-07-12 ## [0.2.0] - 2026-07-12
### Added ### Added
-17
View File
@@ -138,29 +138,12 @@ Workflow files live in [.gitea/workflows/](.gitea/workflows/). This project uses
- Secrets are set under Repository → Settings → Secrets → Actions - Secrets are set under Repository → Settings → Secrets → Actions
- The registry hostname must be derived from `gitea.server_url` (strip the protocol prefix) - The registry hostname must be derived from `gitea.server_url` (strip the protocol prefix)
- Triggers use standard `on:` syntax; `tags: '*.*.*'` matches semver pushes without a `v` prefix - Triggers use standard `on:` syntax; `tags: '*.*.*'` matches semver pushes without a `v` prefix
- Do not use `cache-from/cache-to: type=gha` — on this instance's act_runner (v2.0.0), the internal GitHub Actions-cache-compatible proxy is not reachable from job containers (`dial tcp <ip>:<port>: i/o timeout`), a known act_runner docker-executor networking limitation, not a workflow bug. Use `type=registry` instead (push cache blobs to `${{ env.REGISTRY }}/<repo>:buildcache*` — see both `test.yml` and `docker-publish.yml`); it requires a registry login step even for jobs that don't push the final image.
**Current workflows:** **Current workflows:**
| File | Trigger | Purpose | | File | Trigger | Purpose |
| -------------------- | ---------------- | --------------------------------------------------------- | | -------------------- | ---------------- | --------------------------------------------------------- |
| `docker-publish.yml` | Push tag `*.*.*` | Build & push multi-arch image to Gitea container registry | | `docker-publish.yml` | Push tag `*.*.*` | Build & push multi-arch image to Gitea container registry |
| `test.yml` | Push/PR to `main`| Build dev+prod images, run PHPUnit and PHPStan |
### Release testing with `act`
Before tagging a release (anything that would trigger `docker-publish.yml`), run `test.yml` locally with [`act`](https://github.com/nektos/act) to catch pipeline failures before pushing. `test.yml` uses plain GitHub Actions syntax (no `gitea.*` contexts), so it runs under `act` unmodified.
```bash
act -j test \
-P ubuntu-latest=catthehacker/ubuntu:act-latest \
--artifact-server-path /tmp/act-artifacts
```
- `-P ubuntu-latest=catthehacker/ubuntu:act-latest` — default act runner image lacks a Docker CLI, which the `test` job needs for its nested `docker run` steps
- `--artifact-server-path` — required for the `upload-artifact`/`download-artifact` steps to work; without it they silently no-op
**If `act` is not installed:** warn the user it's missing and how to install it (`sudo pacman -S act`, or see the repo above) — do not install it yourself or force the check. `docker-publish.yml` is out of scope for `act` (it needs real `gitea.*` context and a live registry secret); don't try to run it locally.
## Docker ## Docker
Generated
+46 -49
View File
@@ -313,16 +313,16 @@
}, },
{ {
"name": "symfony/cache", "name": "symfony/cache",
"version": "v7.4.14", "version": "v7.4.15",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/symfony/cache.git", "url": "https://github.com/symfony/cache.git",
"reference": "9adfcb2a7fc3924473b09f5a0b058dcc2cc7be9a" "reference": "c1e7abe8e8c9b315d6d8b86446ffd9cf73679303"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/symfony/cache/zipball/9adfcb2a7fc3924473b09f5a0b058dcc2cc7be9a", "url": "https://api.github.com/repos/symfony/cache/zipball/c1e7abe8e8c9b315d6d8b86446ffd9cf73679303",
"reference": "9adfcb2a7fc3924473b09f5a0b058dcc2cc7be9a", "reference": "c1e7abe8e8c9b315d6d8b86446ffd9cf73679303",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -393,7 +393,7 @@
"psr6" "psr6"
], ],
"support": { "support": {
"source": "https://github.com/symfony/cache/tree/v7.4.14" "source": "https://github.com/symfony/cache/tree/v7.4.15"
}, },
"funding": [ "funding": [
{ {
@@ -413,7 +413,7 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2026-06-17T14:44:48+00:00" "time": "2026-07-29T04:03:42+00:00"
}, },
{ {
"name": "symfony/cache-contracts", "name": "symfony/cache-contracts",
@@ -576,16 +576,16 @@
}, },
{ {
"name": "symfony/console", "name": "symfony/console",
"version": "v7.4.14", "version": "v7.4.15",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/symfony/console.git", "url": "https://github.com/symfony/console.git",
"reference": "92f58bc4bf97a92ed1b9f367f0cd44f20bde0e87" "reference": "088ec6fe0ef6819cbc301174093b6bfa4ad26930"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/symfony/console/zipball/92f58bc4bf97a92ed1b9f367f0cd44f20bde0e87", "url": "https://api.github.com/repos/symfony/console/zipball/088ec6fe0ef6819cbc301174093b6bfa4ad26930",
"reference": "92f58bc4bf97a92ed1b9f367f0cd44f20bde0e87", "reference": "088ec6fe0ef6819cbc301174093b6bfa4ad26930",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -650,7 +650,7 @@
"terminal" "terminal"
], ],
"support": { "support": {
"source": "https://github.com/symfony/console/tree/v7.4.14" "source": "https://github.com/symfony/console/tree/v7.4.15"
}, },
"funding": [ "funding": [
{ {
@@ -670,43 +670,40 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2026-06-16T11:50:14+00:00" "time": "2026-07-27T13:51:00+00:00"
}, },
{ {
"name": "symfony/dependency-injection", "name": "symfony/dependency-injection",
"version": "v7.4.14", "version": "v8.0.15",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/symfony/dependency-injection.git", "url": "https://github.com/symfony/dependency-injection.git",
"reference": "2c8c64a33e2e6911579e1ff79a8e06c27d48d402" "reference": "c5c30601e3efaf6b9a2ec286883acf9183c024a4"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/symfony/dependency-injection/zipball/2c8c64a33e2e6911579e1ff79a8e06c27d48d402", "url": "https://api.github.com/repos/symfony/dependency-injection/zipball/c5c30601e3efaf6b9a2ec286883acf9183c024a4",
"reference": "2c8c64a33e2e6911579e1ff79a8e06c27d48d402", "reference": "c5c30601e3efaf6b9a2ec286883acf9183c024a4",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
"php": ">=8.2", "php": ">=8.4",
"psr/container": "^1.1|^2.0", "psr/container": "^1.1|^2.0",
"symfony/deprecation-contracts": "^2.5|^3", "symfony/deprecation-contracts": "^2.5|^3",
"symfony/service-contracts": "^3.6", "symfony/service-contracts": "^3.6",
"symfony/var-exporter": "^6.4.20|^7.2.5|^8.0" "symfony/var-exporter": "^7.4|^8.0"
}, },
"conflict": { "conflict": {
"ext-psr": "<1.1|>=2", "ext-psr": "<1.1|>=2"
"symfony/config": "<6.4",
"symfony/finder": "<6.4",
"symfony/yaml": "<6.4"
}, },
"provide": { "provide": {
"psr/container-implementation": "1.1|2.0", "psr/container-implementation": "1.1|2.0",
"symfony/service-implementation": "1.1|2.0|3.0" "symfony/service-implementation": "1.1|2.0|3.0"
}, },
"require-dev": { "require-dev": {
"symfony/config": "^6.4|^7.0|^8.0", "symfony/config": "^7.4|^8.0",
"symfony/expression-language": "^6.4|^7.0|^8.0", "symfony/expression-language": "^7.4|^8.0",
"symfony/yaml": "^6.4|^7.0|^8.0" "symfony/yaml": "^7.4|^8.0"
}, },
"type": "library", "type": "library",
"autoload": { "autoload": {
@@ -734,7 +731,7 @@
"description": "Allows you to standardize and centralize the way objects are constructed in your application", "description": "Allows you to standardize and centralize the way objects are constructed in your application",
"homepage": "https://symfony.com", "homepage": "https://symfony.com",
"support": { "support": {
"source": "https://github.com/symfony/dependency-injection/tree/v7.4.14" "source": "https://github.com/symfony/dependency-injection/tree/v8.0.15"
}, },
"funding": [ "funding": [
{ {
@@ -754,7 +751,7 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2026-06-24T07:41:05+00:00" "time": "2026-07-22T15:20:43+00:00"
}, },
{ {
"name": "symfony/deprecation-contracts", "name": "symfony/deprecation-contracts",
@@ -1214,16 +1211,16 @@
}, },
{ {
"name": "symfony/framework-bundle", "name": "symfony/framework-bundle",
"version": "v7.4.14", "version": "v7.4.15",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/symfony/framework-bundle.git", "url": "https://github.com/symfony/framework-bundle.git",
"reference": "4d11fd50d0a3d2c43b400154ad7ec35b84ea3e5b" "reference": "a430728797dda13ec60add8afd18e3fea50f5e93"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/symfony/framework-bundle/zipball/4d11fd50d0a3d2c43b400154ad7ec35b84ea3e5b", "url": "https://api.github.com/repos/symfony/framework-bundle/zipball/a430728797dda13ec60add8afd18e3fea50f5e93",
"reference": "4d11fd50d0a3d2c43b400154ad7ec35b84ea3e5b", "reference": "a430728797dda13ec60add8afd18e3fea50f5e93",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -1232,7 +1229,7 @@
"php": ">=8.2", "php": ">=8.2",
"symfony/cache": "^6.4.12|^7.0|^8.0", "symfony/cache": "^6.4.12|^7.0|^8.0",
"symfony/config": "^7.4.4|^8.0.4", "symfony/config": "^7.4.4|^8.0.4",
"symfony/dependency-injection": "^7.4.4|^8.0.4", "symfony/dependency-injection": "^7.4.15|~8.0.15|^8.1.2",
"symfony/deprecation-contracts": "^2.5|^3", "symfony/deprecation-contracts": "^2.5|^3",
"symfony/error-handler": "^7.3|^8.0", "symfony/error-handler": "^7.3|^8.0",
"symfony/event-dispatcher": "^6.4|^7.0|^8.0", "symfony/event-dispatcher": "^6.4|^7.0|^8.0",
@@ -1251,7 +1248,7 @@
"symfony/asset": "<6.4", "symfony/asset": "<6.4",
"symfony/asset-mapper": "<6.4", "symfony/asset-mapper": "<6.4",
"symfony/clock": "<6.4", "symfony/clock": "<6.4",
"symfony/console": "<6.4", "symfony/console": "<6.4.43|>=7.0,<7.4.15|>=8.0,<8.0.15",
"symfony/dom-crawler": "<6.4", "symfony/dom-crawler": "<6.4",
"symfony/dotenv": "<6.4", "symfony/dotenv": "<6.4",
"symfony/form": "<7.4", "symfony/form": "<7.4",
@@ -1285,7 +1282,7 @@
"symfony/asset-mapper": "^6.4|^7.0|^8.0", "symfony/asset-mapper": "^6.4|^7.0|^8.0",
"symfony/browser-kit": "^6.4|^7.0|^8.0", "symfony/browser-kit": "^6.4|^7.0|^8.0",
"symfony/clock": "^6.4|^7.0|^8.0", "symfony/clock": "^6.4|^7.0|^8.0",
"symfony/console": "^6.4|^7.0|^8.0", "symfony/console": "^6.4.43|^7.4.15|^8.0.15",
"symfony/css-selector": "^6.4|^7.0|^8.0", "symfony/css-selector": "^6.4|^7.0|^8.0",
"symfony/dom-crawler": "^6.4|^7.0|^8.0", "symfony/dom-crawler": "^6.4|^7.0|^8.0",
"symfony/dotenv": "^6.4|^7.0|^8.0", "symfony/dotenv": "^6.4|^7.0|^8.0",
@@ -1320,7 +1317,7 @@
"symfony/webhook": "^7.4|^8.0", "symfony/webhook": "^7.4|^8.0",
"symfony/workflow": "^7.4|^8.0", "symfony/workflow": "^7.4|^8.0",
"symfony/yaml": "^7.3|^8.0", "symfony/yaml": "^7.3|^8.0",
"twig/twig": "^3.12" "twig/twig": "^3.12|^4.0"
}, },
"type": "symfony-bundle", "type": "symfony-bundle",
"autoload": { "autoload": {
@@ -1348,7 +1345,7 @@
"description": "Provides a tight integration between Symfony components and the Symfony full-stack framework", "description": "Provides a tight integration between Symfony components and the Symfony full-stack framework",
"homepage": "https://symfony.com", "homepage": "https://symfony.com",
"support": { "support": {
"source": "https://github.com/symfony/framework-bundle/tree/v7.4.14" "source": "https://github.com/symfony/framework-bundle/tree/v7.4.15"
}, },
"funding": [ "funding": [
{ {
@@ -1368,20 +1365,20 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2026-06-27T08:31:38+00:00" "time": "2026-07-26T12:33:49+00:00"
}, },
{ {
"name": "symfony/http-client", "name": "symfony/http-client",
"version": "v7.4.14", "version": "v7.4.15",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/symfony/http-client.git", "url": "https://github.com/symfony/http-client.git",
"reference": "f6bc6b5a54ff5afac4725cacec9bf2f52eb15920" "reference": "817bb83ef06717f67ab72a3f03e3b63fbe138de1"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/symfony/http-client/zipball/f6bc6b5a54ff5afac4725cacec9bf2f52eb15920", "url": "https://api.github.com/repos/symfony/http-client/zipball/817bb83ef06717f67ab72a3f03e3b63fbe138de1",
"reference": "f6bc6b5a54ff5afac4725cacec9bf2f52eb15920", "reference": "817bb83ef06717f67ab72a3f03e3b63fbe138de1",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -1449,7 +1446,7 @@
"http" "http"
], ],
"support": { "support": {
"source": "https://github.com/symfony/http-client/tree/v7.4.14" "source": "https://github.com/symfony/http-client/tree/v7.4.15"
}, },
"funding": [ "funding": [
{ {
@@ -1469,7 +1466,7 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2026-06-16T11:50:14+00:00" "time": "2026-07-29T07:12:33+00:00"
}, },
{ {
"name": "symfony/http-client-contracts", "name": "symfony/http-client-contracts",
@@ -3009,16 +3006,16 @@
}, },
{ {
"name": "symfony/yaml", "name": "symfony/yaml",
"version": "v7.4.14", "version": "v7.4.15",
"source": { "source": {
"type": "git", "type": "git",
"url": "https://github.com/symfony/yaml.git", "url": "https://github.com/symfony/yaml.git",
"reference": "f8f328665ace2370d1e10645b807ba1646dc7dcc" "reference": "e101850ded5d2c0d44bf32abb8996404afec2dec"
}, },
"dist": { "dist": {
"type": "zip", "type": "zip",
"url": "https://api.github.com/repos/symfony/yaml/zipball/f8f328665ace2370d1e10645b807ba1646dc7dcc", "url": "https://api.github.com/repos/symfony/yaml/zipball/e101850ded5d2c0d44bf32abb8996404afec2dec",
"reference": "f8f328665ace2370d1e10645b807ba1646dc7dcc", "reference": "e101850ded5d2c0d44bf32abb8996404afec2dec",
"shasum": "" "shasum": ""
}, },
"require": { "require": {
@@ -3061,7 +3058,7 @@
"description": "Loads and dumps YAML files", "description": "Loads and dumps YAML files",
"homepage": "https://symfony.com", "homepage": "https://symfony.com",
"support": { "support": {
"source": "https://github.com/symfony/yaml/tree/v7.4.14" "source": "https://github.com/symfony/yaml/tree/v7.4.15"
}, },
"funding": [ "funding": [
{ {
@@ -3081,7 +3078,7 @@
"type": "tidelift" "type": "tidelift"
} }
], ],
"time": "2026-06-08T20:24:16+00:00" "time": "2026-07-21T15:13:06+00:00"
} }
], ],
"packages-dev": [ "packages-dev": [