Skip to content

Harden CI: Artifactory OIDC, fork-aware workflows, composer.lock - #253

Merged
MichaelGHSeg merged 10 commits into
masterfrom
ci/harden-build-publish
Sep 28, 2026
Merged

MichaelGHSeg merged 10 commits into
masterfrom
ci/harden-build-publish

Conversation

@MichaelGHSeg

Copy link
Copy Markdown
Contributor

Summary

  • Add Artifactory OIDC composite action — exchanges GitHub OIDC token for short-lived Artifactory access token, configures Composer to resolve through `virtual-php-thirdparty`
  • Add `ci.yml` — replaces `tests.yml`, fork-aware runner selection, PHP 8.1–8.4 matrix, `composer install --no-scripts`, SHA-pinned actions
  • Update `e2e-tests.yml` — remove `E2E_TESTS_TOKEN` (sdk-e2e-tests going public), fork-aware
  • Commit `composer.lock` (removed from `.gitignore`)

Notes

  • No deploy workflow needed — Packagist publishes automatically from git tags
  • Old `tests.yml` can be deleted once `ci.yml` is validated

Test plan

  • CI runs on this PR
  • Artifactory OIDC exchange succeeds on same-repo CI
  • Before merging: set `ARTIFACTORY_URL` repository variable

- Add Artifactory OIDC composite action (configures Composer to use virtual-php-thirdparty)
- Add ci.yml: fork-aware, PHP 8.1-8.4 matrix, --no-scripts, SHA-pinned actions
- Update e2e-tests.yml: remove E2E_TESTS_TOKEN, fork-aware
- Commit composer.lock (removed from .gitignore)
Comment thread .github/workflows/ci.yml Outdated
Comment thread .github/workflows/ci.yml Outdated
didiergarcia
didiergarcia previously approved these changes Jul 10, 2026
Rewrite composite action to use single-script pattern matching
analytics-python: audience=${ARTIFACTORY_URL}, provider_name=
github-actions-segmentio, and add JWT claim logging for debugging.
The pinned SHAs for setup-ruby/setup-php/codecov/release-gem did not exist
upstream, so the org's sha_pinning_required check could never resolve them.
Repinned to the commits the v1/v2/v5 tags actually point at.
The org Actions policy admits GitHub-owned actions only, so
shivammathur/setup-php could never resolve and every workflow referencing it
failed at startup with no check reported. The runner image ships exactly one
PHP, so CI can only prove that one.

PHP_MATRIX/PHP_PRIMARY hold the version list in one place and feed all three
matrix jobs, so restoring breadth is a one-line change once LIBRARIES-3169
settles how other versions get installed. The local setup-php action verifies
the runtime rather than installing it, and fails loudly on a version the image
lacks so a widened matrix cannot silently test the wrong runtime.

cs2pr and codecov upload go with it — both came from blocked actions. The
PHPCS report and clover.xml are kept as build artifacts instead.
Bare ubuntu-latest never gets picked up on same-repo PRs here, so the job sat
queued and held the whole workflow behind it.
The lock had doctrine/instantiator 2.1.0, which requires PHP ^8.4, so it was
installable only on 8.4 — every other leg of the matrix would have failed had
CI ever started. Nothing else in the lock needs above 8.1.

config.platform.php makes resolution independent of whoever regenerates the
lock, and 8.1 keeps it installable across the full intended 8.1-8.4 matrix
rather than just the version CI currently runs. It constrains this project's
own resolution only; consumers still resolve against their own runtime.
Replaces the repo-local copy with the shared first-party action, pinned. Each
SDK had its own drifting copy of the same exchange; the shared one covers every
ecosystem we use, so fixes land once instead of six times.
@MichaelGHSeg
MichaelGHSeg merged commit fe32646 into master Sep 28, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants