test: add Pest v1 security test infrastructure - #14
Conversation
Add source-scan tests verifying security patterns (prepared statements, output escaping, auth guards, PHP 7.4 compatibility) remain in place across refactors. Tests run with Pest v1 (PHP 7.3+) and stub the Cacti framework so plugins can be tested in isolation. Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |
There was a problem hiding this comment.
Pull request overview
Adds a Pest v1-based security testing scaffold for the quicktree plugin, aiming to validate plugin structure, enforce safer DB helper usage, and prevent accidental adoption of PHP 8+ syntax while also introducing basic repository automation config.
Changes:
- Introduce Pest bootstrap/config plus initial security-focused tests (setup.php structure, prepared-statement usage scan, PHP 7.4 syntax checks).
- Add
composer.jsondev dependency on Pest to run the new tests. - Add GitHub automation configs (CodeQL workflow, Dependabot configuration).
Reviewed changes
Copilot reviewed 8 out of 8 changed files in this pull request and generated 6 comments.
Show a summary per file
| File | Description |
|---|---|
tests/Security/SetupStructureTest.php |
Validates presence of required setup.php hooks and version array keys. |
tests/Security/PreparedStatementConsistencyTest.php |
Scans plugin source for raw db_* calls to prevent regressions to unprepared queries. |
tests/Security/Php74CompatibilityTest.php |
Scans for common PHP 8.0+ syntax/API usage to enforce PHP 7.4 compatibility. |
tests/Pest.php |
Pest entrypoint that loads the test bootstrap. |
tests/bootstrap.php |
Stubs core Cacti framework functions/constants so plugin code can load in isolation. |
composer.json |
Adds Pest v1 as a dev dependency and test bootstrap autoloading. |
.github/workflows/codeql.yml |
Introduces a CodeQL workflow (currently configured for JS/TS). |
.github/dependabot.yml |
Introduces Dependabot updates for npm and GitHub Actions. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
…dabot - Throw RuntimeException when realpath/file_get_contents fails (previously silent continue hid unscanned files) - Fix Dependabot ecosystem from npm to composer - Remove committed .omc session artifacts, add .omc/ to .gitignore Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
|
Converted to draft to serialize the stack in this repo. Blocked by #10; will un-draft after that merges to avoid cross-PR merge conflicts. |
Signed-off-by: Thomas Vincent <thomasvincent@gmail.com>
Summary
Test plan
composer install && vendor/bin/pestpasses