Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
193 changes: 153 additions & 40 deletions .github/workflows/main.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
name: CI for TwoFactorAuthCustomerApp42
name: CI for TwoFactorAuthCustomerApp44

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

GITHUB_TOKEN を読み取り専用に制限してください。

permissions がないため、トークン権限がリポジトリ・組織の既定値に依存します。このCIに必要な権限を明示してください。GitHubも最小権限の明示を推奨しています。 (docs.github.com)

修正案
 name: CI for TwoFactorAuthCustomerApp44
 
+permissions:
+  contents: read
+
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
name: CI for TwoFactorAuthCustomerApp44
name: CI for TwoFactorAuthCustomerApp44
permissions:
contents: read
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 1-281: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block

(excessive-permissions)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/main.yml at line 1,
ワークフロー全体の権限設定としてpermissionsを追加し、GITHUB_TOKENを読み取り専用に制限してください。CIで必要な権限のみを明示し、それ以外の権限は付与しない構成にします。

Source: Linters/SAST tools

on:
push:
branches:
Expand All @@ -17,19 +17,15 @@ on:
jobs:
run-on-linux:
name: Run on Linux
runs-on: ubuntu-22.04
runs-on: ubuntu-24.04
strategy:
fail-fast: false
matrix:
eccube_version: [ '4.2','4.3' ]
php: [ '7.4', '8.0', '8.1','8.2', '8.3' ]
db: [ 'mysql', 'mysql8', 'pgsql' ]
plugin_code: [ 'TwoFactorAuthCustomerApp42' ]
eccube_version: [ '4.4' ]
php: [ '8.2', '8.3', '8.4', '8.5' ]
db: [ 'mysql8', 'pgsql' ]
plugin_code: [ 'TwoFactorAuthCustomerApp44' ]
include:
- db: mysql
database_url: mysql://root:password@127.0.0.1:3306/eccube_db
database_server_version: 5.7
database_charset: utf8mb4
- db: mysql8
database_url: mysql://root:password@127.0.0.1:3308/eccube_db
database_server_version: 8
Expand All @@ -38,24 +34,7 @@ jobs:
database_url: postgres://postgres:password@127.0.0.1:5432/eccube_db
database_server_version: 14
database_charset: utf8
exclude:
- eccube_version: 4.2
php: 8.2
- eccube_version: 4.2
php: 8.3
- eccube_version: 4.3
php: 7.4
- eccube_version: 4.3
php: 8.0
services:
mysql:
image: mysql:5.7
env:
MYSQL_ROOT_PASSWORD: password
MYSQL_DATABASE: ${{ matrix.dbname }}
ports:
- 3306:3306
options: --health-cmd="mysqladmin ping" --health-interval=10s --health-timeout=5s --health-retries=3
mysql8:
image: mysql:8
env:
Expand All @@ -81,7 +60,7 @@ jobs:
- 1025:1025
steps:
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@v4

- name: Setup PHP
uses: nanasess/setup-php@master
Expand All @@ -97,26 +76,29 @@ jobs:
- name: Checkout Base Plugin
uses: actions/checkout@v4
with:
repository: 'EC-CUBE/TwoFactorAuthCustomer42'
path: 'TwoFactorAuthCustomer42'
# 親プラグイン PR が公式 4.4 にマージされるまで、パッケージ名 twofactorauthcustomer44 が入っている
# KenTanaka/TwoFactorAuthCustomer の feat-4.4 を参照する。マージ後は EC-CUBE/TwoFactorAuthCustomer42@4.4 に戻す。
repository: 'KenTanaka/TwoFactorAuthCustomer'
ref: 'feat-4.4'
path: 'TwoFactorAuthCustomer44'

- name: Archive Base Plugin
working-directory: 'TwoFactorAuthCustomer42'
working-directory: 'TwoFactorAuthCustomer44'
run: |
tar cvzf ${GITHUB_WORKSPACE}/TwoFactorAuthCustomer42.tar.gz ./*
tar cvzf ${GITHUB_WORKSPACE}/TwoFactorAuthCustomer44.tar.gz ./*

- name: Setup mock-package-api
env:
PLUGIN_CODE: ${{ matrix.plugin_code }}
run: |
mkdir -p /tmp/repos
for f in ${PLUGIN_CODE} TwoFactorAuthCustomer42; do
for f in ${PLUGIN_CODE} TwoFactorAuthCustomer44; do
cp ${GITHUB_WORKSPACE}/${f}.tar.gz /tmp/repos/${f}.tgz
done
docker run --name package-api -d -v /tmp/repos:/repos -e MOCK_REPO_DIR=/repos -p 8080:8080 eccube/mock-package-api:composer2

- name: Checkout EC-CUBE
uses: actions/checkout@v2
uses: actions/checkout@v4
with:
repository: 'EC-CUBE/ec-cube'
ref: ${{ matrix.eccube_version }}
Expand All @@ -125,16 +107,18 @@ jobs:
- name: Get Composer Cache Directory
id: composer-cache
run: |
echo "::set-output name=dir::$(composer config cache-files-dir)"
- uses: actions/cache@v1
echo "dir=$(composer config cache-files-dir)" >> "$GITHUB_OUTPUT"
- uses: actions/cache@v4
with:
path: ${{ steps.composer-cache.outputs.dir }}
key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
restore-keys: |
${{ runner.os }}-composer-
- name: Install to composer
working-directory: 'ec-cube'
run: composer install --no-interaction -o --apcu-autoloader
# Symfony 7.4 の symfony/cache が ext-redis <6.1 と衝突するが、ランナーには
# 古い php-redis(5.3.7) が入っている。本プラグイン/本体テストは redis 未使用のため無視する。
run: composer install --no-interaction -o --apcu-autoloader --ignore-platform-req=ext-redis

- name: Setup EC-CUBE
env:
Expand All @@ -160,10 +144,33 @@ jobs:
ECCUBE_PACKAGE_API_URL: 'http://127.0.0.1:8080'
working-directory: 'ec-cube'
run: |
bin/console eccube:composer:require ec-cube/twofactorauthcustomer42
bin/console eccube:plugin:enable --code=TwoFactorAuthCustomer42
bin/console eccube:composer:require ec-cube/twofactorauthcustomerapp42
bin/console eccube:composer:require ec-cube/twofactorauthcustomer44
bin/console cache:clear --no-warmup
bin/console eccube:plugin:enable --code=TwoFactorAuthCustomer44
bin/console eccube:composer:require ec-cube/twofactorauthcustomerapp44
bin/console cache:clear --no-warmup
bin/console eccube:plugin:enable --code=${PLUGIN_CODE}
bin/console cache:clear --no-warmup

- name: Run PHPUnit
env:
APP_ENV: 'test'
APP_DEBUG: 0
DATABASE_URL: ${{ matrix.database_url }}
DATABASE_SERVER_VERSION: ${{ matrix.database_server_version }}
DATABASE_CHARSET: ${{ matrix.database_charset }}
PLUGIN_CODE: ${{ matrix.plugin_code }}
ECCUBE_PACKAGE_API_URL: 'http://127.0.0.1:8080'
working-directory: 'ec-cube'
run: |
# 有効化したプラグインのルーティングはコンテナのコンパイル時に確定する。
# phpunit プロセスでの遅延コンパイルに任せると DB/タイミングで有効プラグイン一覧を
# 取りこぼし RouteNotFound になることがあるため、クリーンなプロセスで warmup して確定させる。
bin/console cache:clear --no-warmup
bin/console cache:warmup
if [ -d "app/Plugin/${PLUGIN_CODE}/Tests" ]; then
./vendor/bin/phpunit -c app/Plugin/${PLUGIN_CODE}/phpunit.xml.dist app/Plugin/${PLUGIN_CODE}/Tests
fi
Comment on lines +171 to +173

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

テストディレクトリがない場合もCIを失敗させてください。

現在はプラグインの配置不備やテスト欠落が発生しても、PHPUnitを一度も実行せず成功します。

修正案
-          if [ -d "app/Plugin/${PLUGIN_CODE}/Tests" ]; then
-            ./vendor/bin/phpunit -c app/Plugin/${PLUGIN_CODE}/phpunit.xml.dist app/Plugin/${PLUGIN_CODE}/Tests
-          fi
+          test -d "app/Plugin/${PLUGIN_CODE}/Tests"
+          ./vendor/bin/phpunit -c app/Plugin/${PLUGIN_CODE}/phpunit.xml.dist app/Plugin/${PLUGIN_CODE}/Tests
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
if [ -d "app/Plugin/${PLUGIN_CODE}/Tests" ]; then
./vendor/bin/phpunit -c app/Plugin/${PLUGIN_CODE}/phpunit.xml.dist app/Plugin/${PLUGIN_CODE}/Tests
fi
test -d "app/Plugin/${PLUGIN_CODE}/Tests"
./vendor/bin/phpunit -c app/Plugin/${PLUGIN_CODE}/phpunit.xml.dist app/Plugin/${PLUGIN_CODE}/Tests
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/main.yml around lines 166 - 168, Update the plugin test
block in the workflow so a missing app/Plugin/${PLUGIN_CODE}/Tests directory
causes the CI job to fail instead of silently skipping PHPUnit. Keep PHPUnit
execution unchanged when the directory exists, and make the missing-directory
branch explicitly exit with a nonzero status.


- name: Disable Plugin
working-directory: 'ec-cube'
Expand All @@ -188,3 +195,109 @@ jobs:
ECCUBE_PACKAGE_API_URL: 'http://127.0.0.1:8080'
working-directory: 'ec-cube'
run: bin/console eccube:plugin:uninstall --code=${PLUGIN_CODE}

static-analysis:
name: Static Analysis
runs-on: ubuntu-24.04
# 静的解析は DB 種別に依存しないため、SQLite 1 構成で一度だけ実行する。
# (php-cs-fixer / rector は DB 不要だが、phpstan は objectManagerLoader が
# カーネルを起動し EccubeExtension が dtb_plugin を読むため本体+DBが必要)
env:
PLUGIN_CODE: TwoFactorAuthCustomerApp44
PARENT_PLUGIN_CODE: TwoFactorAuthCustomer44
APP_ENV: 'test'
APP_DEBUG: 0
DATABASE_URL: 'sqlite:///var/eccube.db'
DATABASE_SERVER_VERSION: 3
DATABASE_CHARSET: 'utf8'
ECCUBE_PACKAGE_API_URL: 'http://127.0.0.1:8080'
steps:
- name: Checkout
uses: actions/checkout@v4

- name: Setup PHP
uses: nanasess/setup-php@master
with:
php-version: '8.5'
Comment on lines +218 to +221

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔒 Security & Privacy | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# 固定候補のSHAを取得し、内容を監査してから workflow に設定する
gh api repos/nanasess/setup-php/commits/master --jq '.sha'

Repository: EC-CUBE/TwoFactorAuthCustomerApp42

Length of output: 213


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== workflow excerpt =="
sed -n '200,220p' .github/workflows/main.yml

echo
echo "== commit existence check =="
gh api repos/nanasess/setup-php/commits/3f36b116d024300a7df978629a2bad9afceb2be3 --jq '.sha'

Repository: EC-CUBE/TwoFactorAuthCustomerApp42

Length of output: 827


nanasess/setup-php を 3f36b116d024300a7df978629a2bad9afceb2be3 に固定してください。 master のままだと更新がそのまま CI に入ります。

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/main.yml around lines 210 - 213, Update the “Setup PHP”
workflow step to pin nanasess/setup-php to commit
3f36b116d024300a7df978629a2bad9afceb2be3 instead of tracking master.


- name: Archive Plugin
run: |
tar cvzf ${GITHUB_WORKSPACE}/${PLUGIN_CODE}.tar.gz ./*

- name: Checkout Base Plugin
uses: actions/checkout@v4
with:
# 親プラグイン PR が公式 4.4 にマージされるまで、パッケージ名 twofactorauthcustomer44 が入っている
# KenTanaka/TwoFactorAuthCustomer の feat-4.4 を参照する。マージ後は EC-CUBE/TwoFactorAuthCustomer42@4.4 に戻す。
repository: 'KenTanaka/TwoFactorAuthCustomer'
ref: 'feat-4.4'
path: 'TwoFactorAuthCustomer44'

- name: Archive Base Plugin
working-directory: 'TwoFactorAuthCustomer44'
run: |
tar cvzf ${GITHUB_WORKSPACE}/TwoFactorAuthCustomer44.tar.gz ./*

- name: Setup mock-package-api
run: |
mkdir -p /tmp/repos
for f in ${PLUGIN_CODE} ${PARENT_PLUGIN_CODE}; do
cp ${GITHUB_WORKSPACE}/${f}.tar.gz /tmp/repos/${f}.tgz
done
docker run --name package-api -d -v /tmp/repos:/repos -e MOCK_REPO_DIR=/repos -p 8080:8080 eccube/mock-package-api:composer2

- name: Checkout EC-CUBE
uses: actions/checkout@v4
with:
repository: 'EC-CUBE/ec-cube'
ref: '4.4'
path: 'ec-cube'

- name: Get Composer Cache Directory
id: composer-cache
run: |
echo "dir=$(composer config cache-files-dir)" >> "$GITHUB_OUTPUT"
- uses: actions/cache@v4
with:
path: ${{ steps.composer-cache.outputs.dir }}
key: ${{ runner.os }}-composer-${{ hashFiles('**/composer.lock') }}
restore-keys: |
${{ runner.os }}-composer-
- name: Install to composer
working-directory: 'ec-cube'
run: composer install --no-interaction -o --apcu-autoloader --ignore-platform-req=ext-redis

- name: Setup EC-CUBE
working-directory: 'ec-cube'
run: |
# DBAL 4 の SQLite は doctrine:database:create 非対応(getCreateDatabaseSQL が削除済み)。
# 本体 InstallerCommand と同様、SQLite ではファイル作成をスキップし schema:create で用意する。
if [[ "${DATABASE_URL}" != sqlite* ]]; then
bin/console doctrine:database:create
fi
bin/console doctrine:schema:create
bin/console eccube:fixtures:load
- name: Setup Plugin
working-directory: 'ec-cube'
run: |
bin/console eccube:composer:require ec-cube/twofactorauthcustomer44
bin/console cache:clear --no-warmup
bin/console eccube:plugin:enable --code=TwoFactorAuthCustomer44
bin/console eccube:composer:require ec-cube/twofactorauthcustomerapp44
bin/console cache:clear --no-warmup
bin/console eccube:plugin:enable --code=${PLUGIN_CODE}
bin/console cache:clear --no-warmup

- name: Run php-cs-fixer
working-directory: 'ec-cube'
run: ./vendor/bin/php-cs-fixer fix --config=app/Plugin/${PLUGIN_CODE}/Resource/.php-cs-fixer.dist.php --dry-run --diff

- name: Run Rector
working-directory: 'ec-cube'
run: ./vendor/bin/rector process --config=app/Plugin/${PLUGIN_CODE}/Resource/rector.php --dry-run

- name: Run PHPStan
working-directory: 'ec-cube'
run: |
bin/console cache:clear --no-warmup
./vendor/bin/phpstan analyse -c app/Plugin/${PLUGIN_CODE}/phpstan.neon.dist --no-progress
4 changes: 3 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,11 +8,13 @@ jobs:
runs-on: ubuntu-22.04
steps:
- name: Checkout
uses: actions/checkout@v3
uses: actions/checkout@v4
- name: Packaging
working-directory: ../
run: |
rm -rf $GITHUB_WORKSPACE/.github
# 開発・テスト用ファイルは配布パッケージに含めない
rm -f $GITHUB_WORKSPACE/Resource/rector.php "$GITHUB_WORKSPACE/Resource/.php-cs-fixer.dist.php"
find $GITHUB_WORKSPACE -name "dummy" -delete
find $GITHUB_WORKSPACE -name ".git*" -and ! -name ".gitkeep" -print0 | xargs -0 rm -rf
chmod -R o+w $GITHUB_WORKSPACE
Expand Down
Loading
Loading