diff --git a/.github/workflows/cs.yml b/.github/workflows/cs.yml index 9b88a057..fd6b61be 100644 --- a/.github/workflows/cs.yml +++ b/.github/workflows/cs.yml @@ -26,15 +26,6 @@ jobs: tools: cs2pr coverage: none - # PHPCS does not need PHPUnit, and the PHPUnit versions pinned in composer.json - # are all blocked by a security advisory, which fails the install. Removing the - # requirement lets the Polyfills pull a PHPUnit version which is not blocked. - # The Composer command will exit with error code 2 as the package is not removed, - # so ignore "failure" of this step. - - name: Remove the PHPUnit requirement - continue-on-error: true - run: composer remove --dev phpunit/phpunit --no-update --no-interaction || true - # Install dependencies and handle caching in one go. # @link https://github.com/marketplace/actions/install-php-dependencies-with-composer - name: Install Composer dependencies diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 3fe093ea..af09d59f 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -145,15 +145,6 @@ jobs: continue-on-error: true run: composer remove --dev phpunit/phpunit --no-update --no-interaction || true - # WP < 5.9 predates the Polyfills bootstrap in Core, so those builds need PHPUnit 5 - 7. - # Those lines are end of life and have no release outside CVE-2026-24765, which Composer - # blocks by default, so the install fails before the tests can run. Allow that one - # advisory for these builds only. WP 5.9 and up drop the requirement above and resolve - # a PHPUnit release the advisory does not cover. - - name: Allow the end of life PHPUnit which older WP needs - if: ${{ steps.composer_toggle.outputs.TYPE == '2' || steps.composer_toggle.outputs.TYPE == '3' }} - run: composer config --json policy.advisories.ignore-id '["PKSA-z3gr-8qht-p93v"]' - # Install dependencies and handle caching in one go. # @link https://github.com/marketplace/actions/install-php-dependencies-with-composer - name: Install Composer dependencies - normal diff --git a/composer.json b/composer.json index 7b4f5fc7..ea73f782 100644 --- a/composer.json +++ b/composer.json @@ -28,6 +28,13 @@ "dealerdirect/phpcodesniffer-composer-installer": true }, "process-timeout": 900, - "lock": false + "lock": false, + "policy": { + "advisories": { + "ignore-id": { + "PKSA-z3gr-8qht-p93v": "Concerns .phpt test files, which this plugin does not use. WordPress below 5.9 needs PHPUnit 5 to 7, and every release in that range carries it." + } + } + } } }