Skip to content

ci: let composer audit pass over the abandoned symplify contracts - #358

Merged
ogorzalka merged 1 commit into
developfrom
ci/audit-ignore-abandoned-symplify
Sep 29, 2026
Merged

ogorzalka merged 1 commit into
developfrom
ci/audit-ignore-abandoned-symplify

Conversation

@ogorzalka

Copy link
Copy Markdown
Member

Code Quality fails on every PR (#356, #357) at composer audit: symplify/rule-doc-generator-contracts is now abandoned on Packagist, with no replacement. It comes from driftingly/rector-laravel (dev only), whose latest version, 2.6.2, still requires it.

config.audit.ignore-abandoned lists this one package only: any other abandoned package, and every security advisory, still fail the job. Not reproducible locally: composer audit reads the abandoned flag stored at install time, so only a fresh install (as in CI) sees it — this PR's own Code Quality run is the check.

To remove once rector-laravel drops the dependency.

driftingly/rector-laravel (dev only, 2.6.2 is the latest) requires
symplify/rule-doc-generator-contracts, now marked abandoned on Packagist with
no replacement. composer audit fails on abandoned packages, so Code Quality
failed on every pull request. Only this package is ignored: any other
abandoned package, and every security advisory, still fail the job.
@ogorzalka
ogorzalka merged commit bc94702 into develop Sep 29, 2026
11 checks passed
@ogorzalka
ogorzalka deleted the ci/audit-ignore-abandoned-symplify branch September 29, 2026 14:06
@ogorzalka ogorzalka mentioned this pull request Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant