Skip to content

Release: merge development into beta - #45

Open
github-actions[bot] wants to merge 382 commits into
betafrom
development
Open

Release: merge development into beta#45
github-actions[bot] wants to merge 382 commits into
betafrom
development

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated PR to sync development changes to beta for beta release.

Merging this PR will trigger the beta release workflow.

Reminder: Add a major, minor, or patch label to this PR to control the version bump. Default is patch.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit 796c4ee
Branch 45/merge
Event pull_request
Generated 2026-03-19 19:05 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/23312024709

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit 452ede8
Branch 45/merge
Event pull_request
Generated 2026-03-19 21:37 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/23318045149

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit 1652e7f
Branch 45/merge
Event pull_request
Generated 2026-03-23 21:38 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/23461372774

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented Apr 9, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report

Repository ConductionNL/nldesign
Commit acbb095
Branch 45/merge
Event pull_request
Generated 2026-04-09 09:48 UTC
Workflow Run https://github.com/ConductionNL/nldesign/actions/runs/24183659733

Summary

Group Result
PHP Quality PASS
Vue Quality PASS
Security PASS
License PASS
PHPUnit PASS
Newman SKIP
Playwright SKIP

PHP Quality

Tool Result
lint PASS
phpcs PASS
phpmd PASS
psalm PASS
phpstan PASS
phpmetrics PASS

Vue Quality

Tool Result
eslint PASS
stylelint PASS

Security

Ecosystem Result
composer PASS
npm PASS

License Compliance

Ecosystem Result
composer PASS
npm PASS

composer dependencies (100 total)

Metric Count
Approved (allowlist) 100
Approved (override) 0
Denied 0

npm dependencies (7 total)

Metric Count
Approved (allowlist) 5
Approved (override) 2
Denied 0

PHPUnit Tests

PHP Nextcloud Result
Overall PASS

Code coverage: 0% (0 / 24 statements)

Integration Tests (Newman)

Newman integration tests were not enabled for this run.

E2E Tests (Playwright)

Playwright E2E tests were not enabled for this run.


Generated automatically by the Quality workflow.

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented May 1, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e0b6c18

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-01 11:51 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 33bfd61

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-07 20:51 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented May 7, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e5323e2

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-07 21:25 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 13c6474

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-12 22:09 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ b568281

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-12 22:29 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 6622f07

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-13 09:26 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 9aca552

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-17 07:45 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ f546205

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 18:09 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 772217c

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 18:54 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ b606ba3

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 19:16 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ b935b19

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 20:47 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 8ccab3a

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 20:59 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 7cc0b80

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-18 21:17 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 6caa0b5

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 02:56 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ ec8228b

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 03:08 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 6d9de7e

Check PHP Vue Security License Tests
lint ⏭️
phpcs ⏭️
phpmd ⏭️
psalm ⏭️
phpstan ⏭️
phpmetrics ⏭️
eslint ⏭️
stylelint ⏭️
composer ⏭️ ⏭️
npm ⏭️ ⏭️
PHPUnit
Newman
Playwright

Quality workflow — 2026-05-19 05:05 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 9d39dfa

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 05:07 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ d0a0f90

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-19 05:21 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e4f5c54

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 05:24 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 0d0d51a

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 07:42 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ fd9e665

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 08:13 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ c4f612c

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 08:23 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e222d87

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit
Newman ⏭️
Playwright ⏭️

Coverage: 0% (0/24 statements)


Quality workflow — 2026-05-19 08:35 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ f369153

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer ✅ 100/100
npm ✅ 7/7
PHPUnit ⏭️
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-21 20:32 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 503fc89

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer
npm ✅ 7/7
PHPUnit ⏭️
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-22 07:13 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 84a13c0

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
composer
npm ✅ 7/7
PHPUnit ⏭️
Newman ⏭️
Playwright ⏭️

Quality workflow — 2026-05-23 07:26 UTC

Download the full PDF report from the workflow artifacts.

…failing CI (#223)

v1.0.1 is `f4d9756` (2026-08-03) and predates three gate fixes, so every
Hydra Gates run this repo has ever made executed a script in which 16
gates reported PASS when their helper never ran (ConductionNL/.github#147),
gate-33 had no axe report to read and never said so (#148), and gates 6
and 7 reported PASS on an empty scope (#149). The tick was identical
either way, which is why nothing in this repo's history shows it.

That pin is now also RED, and the mechanism is worth writing down.
quality.yml is referenced `@main` while this package is PINNED, so the
two can desync. #164 flipped `hydra-gates-require-full-coverage` to
default true in the shared workflow, and that flag requires a gate to
DECLARE itself not-applicable. v1.0.1 contains ZERO `_skip` calls; v1.3.0
has 36. v1.0.1 has no vocabulary to declare, so every absent prerequisite
became "DID NOT RUN" and failed the job — for gates the repo has no
subject matter for.

Measured on this branch, diff-scoped against origin/development exactly
as CI scopes it, in a private mount namespace with a private tmpfs (the
runner's ~50 /tmp/hydra-gate-*.log paths are shared state and two
concurrent runs corrupt each other's counts, .github#158 item 6):

  v1.0.1  exit 98  FAIL — "GATES THAT DID NOT RUN: 24 33"
  v1.3.0  exit 0   PASS — those gates named NOT APPLICABLE, with reasons

Independently confirmed end-to-end: doriath#160 changed this one line and
nothing else, and its Hydra Gates job went failure -> success.

v1.3.0 is `f7eaf2a` = .github@main at the time it was cut.

Refs ConductionNL/.github#159
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 19b796d

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-05 18:51 UTC

Download the full PDF report from the workflow artifacts.

#225)

Pre-existing CI failure, unrelated to the licence sweep: `test:l10n` was red on
`development` before this branch existed. js/admin.js:2829 calls
t('nldesign', 'Saved. Reload to see the change.') in the custom-CSS save
handler, but the key was never added to l10n/en.json, so the string shipped
untranslated in every locale.

Verified pre-existing by running the check against a pristine `origin/development`
tree: it fails there identically, and this branch touches neither js/admin.js
nor l10n/.

- l10n/en.json: added the key (key === English source).
- l10n/<36 locales>.json: backfilled via the repo's own
  `check-l10n-completeness.js --write`, which is what keeps that second check
  green once en.json gains a key.
- l10n/nl.json: translated properly rather than left as an English placeholder,
  matching the phrasing of the neighbouring "Herlaad de pagina om ..." strings.

test:l10n FAIL -> OK; test:l10n:completeness OK -> OK (209 keys, 36 locales).
* chore(license): normalise licence declarations to EUPL-1.2

The app is licensed EUPL-1.2 — composer.json, appinfo/info.xml and the
bundled LICENSE all say so — but package.json and seven source/config
files still carried AGPL-3.0-or-later SPDX headers left over from the
Nextcloud app template. A licence header is a legal claim, so a repo
that states two different licences about itself is a real defect, not a
lint nit.

Changed:
- package.json + package-lock.json root entry: AGPL-3.0-or-later -> EUPL-1.2
- SPDX-License-Identifier headers on 7 files: css/show-menu-labels.css,
  js/lib/tokenTransforms.js, vitest.config.js, tests/e2e/visual/_visual-helpers.ts,
  tests/integration/run-newman.sh, tests/vitest/tokenTransforms.spec.js,
  tests/vitest/lasuiteBridgeRadiusScale.spec.js

Deliberately NOT changed (third-party — not ours to relicense):
- scripts/sources/lasuite-deployed-cunningham-tokens.css (MIT, verbatim
  vendored from suitenumerique/docs; header says do NOT hand-edit)
- LICENSES/Etalab-2.0.txt, MARIANNE-LICENCE.md, AGREEMENT-MARIANNE.md and
  css/systems/lasuite/fonts/marianne/ (French State Etalab-2.0 licence
  governing the bundled Marianne font)
- tests/Unit/MarianneFontTest.php — 'Etalab-2.0' there is a test assertion
  string, not a licence declaration on the file
- the AGPL entries in package-lock.json for @nextcloud/* packages — those
  are upstream's own licences

Header-only change; no behaviour touched. PHPUnit 556 tests OK before and
after (PHP 8.4), vitest 81 passed before and after, hydra gate-28
license-triangle PASS before and after.

* fix(l10n): register the missing "Saved. Reload to see the change." key

Pre-existing CI failure, unrelated to the licence sweep: `test:l10n` was red on
`development` before this branch existed. js/admin.js:2829 calls
t('nldesign', 'Saved. Reload to see the change.') in the custom-CSS save
handler, but the key was never added to l10n/en.json, so the string shipped
untranslated in every locale.

Verified pre-existing by running the check against a pristine `origin/development`
tree: it fails there identically, and this branch touches neither js/admin.js
nor l10n/.

- l10n/en.json: added the key (key === English source).
- l10n/<36 locales>.json: backfilled via the repo's own
  `check-l10n-completeness.js --write`, which is what keeps that second check
  green once en.json gains a key.
- l10n/nl.json: translated properly rather than left as an English placeholder,
  matching the phrasing of the neighbouring "Herlaad de pagina om ..." strings.

test:l10n FAIL -> OK; test:l10n:completeness OK -> OK (209 keys, 36 locales).

* Revert "fix(l10n): register the missing "Saved. Reload to see the change." key"

This reverts commit 6268a18.
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 66ba9de

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-05 19:14 UTC

Download the full PDF report from the workflow artifacts.

Follow-up to #224. The docs site's 'Open Source' feature card told every
visitor the app is 'AGPL-3.0 licensed', while composer.json, package.json,
appinfo/info.xml, the bundled LICENSE and every source header say EUPL-1.2.

This is the most public licence claim the app makes — it is the landing page
of the documentation site — and my sweep in #224 missed it because I grepped
for SPDX identifiers and @license tags, not for prose.

No behaviour change; one string in a Docusaurus feature card.
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ dfb37aa

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-05 19:44 UTC

Download the full PDF report from the workflow artifacts.

…o its own ruleset (#220)

* fix(phpmd): scope the lib/Migration UnusedFormalParameter exclusion to its own ruleset

The nested <exclude-pattern> inside the UnusedFormalParameter <rule> was inert:
PHPMD 2.15 honours exclude-patterns only as direct children of <ruleset>, so
lib/Migration was scanned by the very rule the pattern was written to spare.

Hoisting the pattern to the top level of phpmd.xml would have worked but is
applied at file-collection time, dropping lib/Migration from EVERY rule and
silently swallowing real complexity, StaticAccess and method-length findings.

UnusedFormalParameter now lives alone in phpmd-unusedparams.xml with a
top-level */Migration/* exclude, and the phpmd composer script runs both legs
keeping the worst exit code.

* fix(phpmd): narrow the exclude-pattern to */lib/Migration/*

*/Migration/* matches any directory segment named Migration, so it would also
exempt ordinary classes under lib/Service/Migration/ and similar, which have no
interface-mandated signature and must stay analysed. Measured on openconnector,
that broader form hides a genuine UnusedFormalParameter finding in
lib/Service/Migration/. Only the app's own lib/Migration/ holds IMigrationStep
implementations, so only that directory is exempted.

Re-verified after the change: the lib/Migration probe is still excluded, the
non-UnusedFormalParameter Migration probe is still reported by leg 1, and the
retired-finding counts are unchanged.
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 3ab8c62

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-05 21:08 UTC

Download the full PDF report from the workflow artifacts.

…ne (#229)

The standing 'Release: merge development into beta' PR has head_ref
'development', so its pull_request run rendered the same concurrency group as a
push to development. cancel-in-progress killed the push run, which is the only
carrier of the push-only jobs (Coverage Baseline Check, SBOM, Features
Extract). Those jobs report 'skipped' on the surviving PR run, which renders
like a pass, so the gate never produced a verdict.

Suffixes -push on the group for main/development pushes only; feature-branch
dedup is unchanged. No gate weakened: no waiver, baseline, threshold or
continue-on-error.

Same fix as openconnector#1158.
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ ed3416a

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 05:40 UTC

Download the full PDF report from the workflow artifacts.

…kflow needs

The Hydra Gates job fails with a message that says outright it is not about this
repository:

  hydra-gates-ref <old> does not contain: scripts/lib/check_spec_anchors.py
  scripts/lib/check_form_labels.py scripts/lib/check_license_triangle.py

The reusable workflow floats on @main and calls those scripts BY PATH inside the
PINNED package, so a pin older than the scripts cannot run the gates that
implement them. A pinned ref is a silent expiry date on every upstream change,
and the failure reports on the pin while saying nothing about the code.

v1.5.0 is the first tag containing all of them, verified by reading each path at
that tag rather than assuming the newest tag has everything.

Swept across the fleet: 11 of 13 repos were pinned below v1.5.0 and every one of
them was failing this way.
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ a50edff

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 06:32 UTC

Download the full PDF report from the workflow artifacts.

rubenvdlinde and others added 2 commits August 6, 2026 09:31
…#231)

.coverage-baseline was read as a floor by the phpunit guard and as an exact
target by the push-side staleness check. Together they demand equality with a
checked-in constant, which against a moving base branch is not satisfiable:
closing "stale" means committing the value the tree will measure after the PR
lands. Measured on openregister — committed 58.93, development advanced
16030->16038 tests, merge result measured 58.88, guard reported a 0.05% drop.

coverage-guard.php gains --against=<clover.xml>, naming a report measured at
the merge base. When present it is the only floor; the committed constant is
reported but not enforced. Both numbers then come from one driver in one job,
so the xdebug/pcov statement-counting difference cancels rather than being
baked in, and the merge base cannot go stale.

Ratios are compared as exact integer cross-products, not rounded percentages:
at two decimals a one-statement regression read as "unchanged" and exited 0.
An empty or zero-statement report is now a hard error rather than 0%, which as
the merge-base side would set the floor to zero and pass every drop.

Verified on real CI clover artifacts: a genuine 1.44% drop fails, an unchanged
tree passes, and adding untested code fails while adding tested code passes.
Both sides had found the SAME defect in the lasuite parity table and fixed it
opposite ways. Resolved toward the repair, in both hunks.

`header app name` row — development DELETED it, correctly observing that
`#header .header-appname` exists only in Nextcloud's PUBLIC layout, so the row
could never pass at THEMING_URL and blew a 15s waitForSelector every run. That
diagnosis is right about the OLD selector. This side had already replaced it:
NC34 renders the current app's name through `.app-menu__current-app-name`,
which does exist here and is measured live. Kept the repaired row and carried
development's public-layout finding across as a comment, because repairing a
check keeps the coverage deleting it loses — a parity table that quietly stops
asserting is the failure mode this suite exists to prevent.

Theme re-render — development reloaded and waited on `networkidle`; this side
navigates and waits on `domcontentloaded`. Same intent, but Nextcloud polls in
the background so the network never goes idle and the wait burns the test
budget. `networkidle` is what the e2e-networkidle gate exists to catch.

Also converted the one remaining `networkidle` in this file, which every other
wait here had already moved away from — it would have been the only one left
tripping that gate.
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 91f053c

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 07:41 UTC

Download the full PDF report from the workflow artifacts.

@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 7d5ef46

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 08:06 UTC

Download the full PDF report from the workflow artifacts.

* chore(ci): move hydra-gates-ref v1.3.0 -> v1.4.0

A pinned `hydra-gates-ref` is a silent expiry date on every upstream fix:
this repo cannot receive a gate-package change until this line moves.

v1.4.0 is the latest tag and the first one that carries
`hydra-gates/scripts/axe-run.cjs` (verified absent at v1.3.0), so it is
also the first that has ConductionNL/.github#168 axe DOM scoping and
ConductionNL/.github#165 gate-46 fix.

`enable-axe` is deliberately NOT enabled in this commit. Ordering matters:
the ref lands first, enabling axe is a separate decision.

* chore(ci): stop pinning hydra-gates — track the package at @main

Removes the `hydra-gates-ref` input from the `quality.yml` caller. The
shared workflow already defaults it to `main`, and this repo consumes
`quality.yml` itself at `@main`, so dropping the override makes both
sides move together: a gate-package fix lands here without a commit here.

A pin is a silent expiry date on every upstream fix, and we have paid for
that twice already:

  - .github#159 — 22 repos sat on v1.0.1, which predated the gate fixes.
    16 gates were dead fleet-wide and every single one reported PASS. A
    gate that never runs emits a tick identical to one that did, so
    nothing in any repo's history showed it.

  - .github#173 — the shared side flipped a default at @main while the
    package stayed pinned per caller. Old runners lacked the coverage
    accounting the new default assumed, so they went red on gates they
    had no subject matter for.

Removing the pin closes both shapes at once. Rolling back is a revert on
ConductionNL/.github main, which reaches the whole fleet in one commit;
holding this one repo still is still possible by setting the input
explicitly, with a reason.

`enable-hydra-gates: true` is unchanged. `enable-axe` remains unset.
The comment block that justified the pin is replaced with a short note
saying why there is no pin.

---------

Co-authored-by: Conduction Release Bot <release-bot@conduction.nl>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 4c713cd

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 08:40 UTC

Download the full PDF report from the workflow artifacts.

…owser (#228)

#218 unmapped `--border-radius-large` so cards keep Nextcloud's 8px
container radius while controls keep La Suite's 4px. That was verified by
measuring a live page, but nothing held it.

The existing unit spec asserts the bridge's SOURCE — that the container
token is not force-mapped. That is a text assertion about a stylesheet.
It cannot say what a browser computes once the cascade, the `!important`s
and the `body[data-themes]` selector have had their say, which is exactly
where the original bug lived. It is also where a first attempt at
measuring the fix went wrong: a plain `body` override loses to
`body[data-themes]` and reports "the fix does nothing".

So this loads the real defaults/bridge/element-overrides into Chromium
with `data-themes` set as the shell sets it, and reads getComputedStyle.
No Nextcloud instance — the stylesheets plus a synthetic DOM are the
whole system under test, which also means the spec cannot be broken by
whatever happens to be deployed on a shared instance.

Four assertions: containers are 8px, controls (button, input, modal) are
4px, the two are genuinely DIFFERENT — stated directly, since the defect
was a flattened hierarchy rather than a wrong number — and a fixture
guard reading a token only the bridge sets, because if bridge.css failed
to load every other assertion would pass for the wrong reason on the NC
defaults alone.

Verified both ways: 4 pass as merged, and reintroducing the container
mapping fails exactly the two that should.

Co-authored-by: Conduction Release Bot <release-bot@conduction.nl>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 91ca71a

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 09:28 UTC

Download the full PDF report from the workflow artifacts.

Comment on lines +32 to +36
uses: ConductionNL/.github/.github/workflows/release-beta.yml@main
with:
app-name: nldesign
channel: dev
secrets: inherit
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ e9148fb

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 11:33 UTC

Download the full PDF report from the workflow artifacts.

…ommand injection) (#236)

quality / Security (composer) is red on every PR here as of today:

    Advisory ID: PKSA-rdkp-vv9z-mjkg
    CVE: CVE-2026-67434  —  OS Command injection
    Affected versions: <3.13.6|>=4.0.0,<4.0.2
    Reported at: 2026-08-05T23:53:11+00:00

The advisory was published YESTERDAY and roave/security-advisories installs
as dev-latest each run, so the same lockfile was clean on 2026-08-05 and is
vulnerable on 2026-08-06 with no commit in between. The last green run is
evidence of when it ran, not that the lockfile is safe.

composer.json's existing constraint already permits the fixed version, so
this is a lockfile move only: 1 update, 0 installs, 0 removals. Verified the
diff touches exactly two lines, both the version string, and no other file.

Part of a fleet sweep — 13 of 16 repos checked were on the affected 3.13.5.

Co-authored-by: Conduction Release Bot <release-bot@conduction.nl>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 80a6b5b

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 12:08 UTC

Download the full PDF report from the workflow artifacts.

#237)

OS command injection in PHP_CodeSniffer, GHSA-hmqg-cxww-wqhq, reported
2026-08-05. Affected: <3.13.6 | >=4.0.0,<4.0.2. This repo was on 3.13.5.

All 16 repos checked across the fleet are on 3.13.5 and equally affected. The
advisory is live in the audit DB, so this repo's Security (composer) gate is
failing until this lands.

Verified
- composer audit --locked: 'No security vulnerability advisories found' (was 1).
- vendor/bin/phpcs --version -> 3.13.6.
- composer phpcs: rc=0.
- Positive control: a deliberately non-conforming file under lib/ made phpcs
  exit 2 with 13 findings, so the green above is a real pass and not a checker
  that no-ops. Probe removed; only composer.lock is modified.

Co-authored-by: Conduction Release Bot <release-bot@conduction.nl>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ 9260408

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 12:44 UTC

Download the full PDF report from the workflow artifacts.

…t the app root (#238)

`quality / Integration Tests (Newman)` has been red on development with 14
assertion failures, all in "4. Custom token sets (upload/list/export/delete)".
Every upload returned 400, including the one asserting 200, and the follow-on
assertions then failed on `undefined` because there was no response body to
read.

None of it was an API bug. The three multipart fixtures were declared as

    "src": "tests/integration/fixtures/newman-valid.css"

— a path relative to the APP ROOT. The shared workflow runs

    cd server/apps/<app>/tests/integration
    newman run "$collection" ...

so newman's working directory IS tests/integration, and it looked for
tests/integration/tests/integration/fixtures/... . The file was never
attached, the request arrived with no upload, and CustomTokenSetController::
readUpload() correctly answered `No file uploaded.` with 400. The endpoint was
doing exactly the right thing; the collection was lying about where its
fixtures live.

The cascade is worth naming: ONE unresolvable path produced 14 failures
spread across six named test cases (409-on-collision, 422-on-bad-selector,
422-on-malformed-json, listing, export, delete), because each subsequent case
depends on the set the first one was supposed to create. Reading the failure
list bottom-up suggests a broken feature; there is a single missing file.

Verified by running newman against a dead port, so only file resolution is
exercised:

    before   'unable to load data for "…/fixtures/newman-bad-selector.css", no such file'
             'unable to load data for "…/fixtures/newman-malformed.tokens.json", no such file'
             'unable to load data for "…/fixtures/newman-valid.css", no such file'
    after    (no file-resolution errors at all)

and by checking each rewritten path resolves from the CI working directory.

Fixing the collection rather than adding `--working-dir` to the shared
workflow: the workflow's contract is already "cwd is the collection
directory", and a fixture path relative to its own collection is what every
other consumer of that contract would expect.

Co-authored-by: Conduction Release Bot <release-bot@conduction.nl>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Quality Report — ConductionNL/nldesign @ caad8a6

Check PHP Vue Security License Tests
lint
phpcs
phpmd
psalm
phpstan
phpmetrics
eslint
stylelint
build
check-manifest
test-l10n
composer ✅ 100/100
npm ✅ 2/2
PHPUnit
Newman
Playwright
Hydra gates

Quality workflow — 2026-08-06 13:33 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants