From b4cba52c64837cd3440c87204afb32de67db4abc Mon Sep 17 00:00:00 2001 From: Mikola Lysenko Date: Wed, 7 Oct 2026 21:54:41 -0400 Subject: [PATCH 1/2] Run the macOS Composer 2.10.3 cell on PHP 8.4 Since 2026-10-07 23:51Z every Composer compatibility run has failed its macOS 2.10.3 / PHP 8.5 cell in "Setup PHP": setup-php 2.37.2 cannot install PHP 8.5 from Homebrew now that PHP 8.6 has shipped ("php: command not found", "Could not setup PHP 8.5"). This keeps main red on every push. Run that cell on PHP 8.4, which Composer 2.10.3 supports. Ubuntu and Windows keep the 2.10.3 / PHP 8.5 cell, so 8.5 is still covered. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/composer-compatibility.yml | 5 ++++- docs/testing/composer-compatibility.md | 2 +- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/composer-compatibility.yml b/.github/workflows/composer-compatibility.yml index 4741fef4c..e3c47834f 100644 --- a/.github/workflows/composer-compatibility.yml +++ b/.github/workflows/composer-compatibility.yml @@ -180,7 +180,10 @@ jobs: include: - {os: macos-latest, composer: '1.10.28', php: '8.1', sha256: 0915af36eb01e3f0e16cd309adff7051832b9ef014e38371756804b20425cd5a} - {os: macos-latest, composer: '2.2.30', php: '8.3', sha256: 8c2b4478b64f8f7cdf1574838fdb0033b29049ca821dad452db7a3dcfcdbffc2} - - {os: macos-latest, composer: '2.10.3', php: '8.5', sha256: 7a2d379d5b8ffdaa028580ef26494c36d2feef4b178d3dd1473a4dbc5e17c8d6} + # PHP 8.4 on macOS: setup-php 2.37.2 cannot install 8.5 from Homebrew + # since PHP 8.6 shipped (every run from 2026-10-07 23:51Z failed in + # "Setup PHP"). Ubuntu and Windows keep the 2.10.3 / 8.5 cell. + - {os: macos-latest, composer: '2.10.3', php: '8.4', sha256: 7a2d379d5b8ffdaa028580ef26494c36d2feef4b178d3dd1473a4dbc5e17c8d6} runs-on: ${{ matrix.os }} timeout-minutes: 60 steps: *native-steps diff --git a/docs/testing/composer-compatibility.md b/docs/testing/composer-compatibility.md index 9347d8e7b..afaa6f30d 100644 --- a/docs/testing/composer-compatibility.md +++ b/docs/testing/composer-compatibility.md @@ -43,7 +43,7 @@ vendored (`e2e_vendor_composer_build`) and hosted | --- | --- | | Ubuntu | 1.10.28 (8.1), 2.0.14 (8.0), 2.1.14 (8.1), 2.2.30 (8.1, 8.3), 2.5.8 (8.2), 2.8.12 (8.4), 2.9.8 (8.4), 2.10.3 (8.5) | | Windows | 1.10.28 (8.1), 2.2.30 (8.3), 2.9.8 (8.4), 2.10.3 (8.5) | -| macOS | 1.10.28 (8.1), 2.2.30 (8.3), 2.10.3 (8.5) | +| macOS | 1.10.28 (8.1), 2.2.30 (8.3), 2.10.3 (8.4) | | Docker (Debian 12, PHP 8.2) | 2.2.30, 2.10.3 (`docker_e2e_vendor_composer`) | The capstones pin psr/log 3.0.2 (PHP ≥ 8.0) and, for the `v`-tagged cells, From e74ec7d1095eb51256d266000abcc7fefc737175 Mon Sep 17 00:00:00 2001 From: Mikola Lysenko Date: Thu, 8 Oct 2026 05:41:19 -0400 Subject: [PATCH 2/2] Label ci.yml's setup-php pin with its exact tag The upstream v2 tag moved off f3e473d1, so zizmor's ref-version-mismatch audit now fails every merge group that touches workflows. f3e473d1 is 2.37.2, the label composer-compatibility.yml already uses. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f4f8067ea..cce660612 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1397,7 +1397,7 @@ jobs: # The composer capstones shell out to a real composer; `composer:` # pins the release line (1, 2.2 LTS, 2) so the composer.lock grammar # the edits assert stays stable across runners. - uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2 + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 with: php-version: '8.2' tools: composer:${{ matrix.composer }}