Skip to content

EE-282: Let the Symfony 3 and 4 jobs install with current Composer - #11

Merged
mSprunskas merged 2 commits into
paysera:masterfrom
vinayak-iyer-paysera:EE-282-ci-workflow
Sep 25, 2026
Merged

mSprunskas merged 2 commits into
paysera:masterfrom
vinayak-iyer-paysera:EE-282-ci-workflow

Conversation

@vinayak-iyer-paysera

@vinayak-iyer-paysera vinayak-iyer-paysera commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

This adds one step to the workflow and changes nothing else. It is split out of #10 so that it can be merged first.
The Symfony 7 jobs stay in #10, because they need its composer.json change.

Why

Composer 2.9 and later refuse to install a package release that has a published security advisory. The last Symfony
3.4 and 4.4 releases of several components the tests install have one, and so do the Symfony 6.0 releases PHP 8.0
installs and the PHPUnit 6.5 release PHP 7.2 installs. On master, 18 of the workflow's 36 jobs therefore fail at
install.

Changes

  • .github/workflows/ci.yml: a step that runs composer config policy.advisories.block false before the install, on
    every job except PHP 7.0 and 7.1. The setting exists from Composer 2.10, which setup-php installs on PHP 7.2 and
    later; PHP 7.0 and 7.1 get Composer 2.2, which does not block advisories and does not know the setting. It only
    affects the test install.

Test plan

  • All 36 jobs run locally on master with the workflow's own steps and this one: 36 of 36 green, 13 tests each.
  • Without the step, 18 of the 36 fail at install on master: every Symfony 3 and 4 job from PHP 7.2 up, PHP 7.2
    with Symfony 5, and PHP 8.0 with Symfony 6.
  • The workflow's run on GitHub.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mSprunskas
mSprunskas merged commit f7bd830 into paysera:master Sep 25, 2026
@vinayak-iyer-paysera vinayak-iyer-paysera mentioned this pull request Sep 25, 2026
7 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants