Skip to content

CI: build free package safely for fork PRs - #4

Merged
bradvin merged 3 commits into
fooplugins:masterfrom
foo-bender:ci/free-only-fork-build
Aug 13, 2026
Merged

bradvin merged 3 commits into
fooplugins:masterfrom
foo-bender:ci/free-only-fork-build

Conversation

@foo-bender

@foo-bender foo-bender commented Aug 13, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • add an explicit free-only build/package mode for public pull-request CI that never requires or packages the private pro submodule
  • preserve the existing Pro-inclusive default/release build and fail clearly when pro is missing
  • keep build output visible and add regressions for free packaging, private-content exclusion, and full-build failure behavior
  • quote the MariaDB-reserved conversion column so the packaged plugin activates on current MariaDB
  • resolve existing Plugin Check errors narrowly in source without workflow-wide error suppression

Security boundary

This PR does not use pull_request_target, check out the private submodule, or expose private credentials to fork-controlled code. Free-mode coverage injects a synthetic private sentinel and verifies it is absent from both the generated translation catalog and ZIP archive.

Root cause

The public workflow checked out no submodules but ran the full package command, whose webpack, assets, localization, Composer, and ZIP stages expected pro. Both the PR branch and unchanged master reproduced the same missing-Pro failure.

Verification

TDD / local

  • RED: the free package command did not exist and the default missing-Pro failure was unclear
  • GREEN: npm run test:ci-package on Node 18.20.8: 3/3 passed
  • free ZIP created successfully with 0 pro/ entries and no synthetic private sentinel
  • full/default package succeeded locally with the private submodule initialized at the repository gitlink
  • npm run test:php: passed
  • npm run test:js: 20 files / 88 tests passed on supported Node 22
  • PHP syntax check: 235 files passed
  • git diff --check: passed
  • added-line static security scan: passed
  • independent full-diff reviews: passed with no security or logic findings

GitHub Actions

Authoritative run: https://github.com/fooplugins/fooconvert/actions/runs/31719483906

  • CI packaging regressions: passed
  • free build and ZIP: passed
  • archive extraction: passed
  • plugin activation on current MariaDB: passed
  • WordPress Plugin Check: passed
  • Socket Security Project Report: passed
  • Socket Security PR Alerts: passed

Scope

No versions, compatibility metadata, release artifacts, tags, deployments, production systems, private credentials, or WordPress.org SVN records were changed.

Notes

  • Existing PHP 8.5 Reflection setAccessible() deprecation notices remain non-blocking and were not introduced here.
  • Optional workflow hardening such as SHA-pinning Actions and least-privilege permissions is intentionally outside this focused fix.

@bradvin
bradvin merged commit f6dab2d into fooplugins:master Aug 13, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants