Repository navigation
Rework Renovate config, drop third-party extension installer, tidy CI - #467
Merged
Merged
Conversation
- Remove dependabot.yml; Renovate already manages GitHub Actions and the two were opening competing PRs - Group non-major action updates with a 7 day release age (replaces the Dependabot cooldown) - Drop rebaseWhen so the default applies (fewer redundant multi-arch runs) - Remove no-op rules (enabled: true, dependencyDashboardApproval: false) - Scope separateMinorPatch to composer/composer - Pin 2.2 to patch releases with allowedVersions - Merge the two identical custom managers, anchor/escape the path pattern, accept -RC versions - Add a PR note for a new Composer major on latest - Don't propose PHP major base image bumps for 1.10 and 2.2 - Add helpers:pinGitHubActionDigests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both extensions are bundled with php-src, so the base image can build them itself. This drops the third-party docker-php-extension-installer download (and its manually maintained sha512). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- zizmor only triggered on .github/**.yml, so the .yaml build workflows and composite action were never scanned; rename to zizmor.yaml and match both extensions - Pass the metadata-action labels to build-push-action (they were computed but unused) - Rewrite manifest creation with arrays instead of unquoted command substitution / variable printf formats (SC2046, SC2059) - Document the $/ self-repository action reference Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Replace implicit word-splitting with explicit arrays (mapfile/read -a) and stop excluding the script from the ShellCheck workflow. Generated output is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The same loop was repeated for the full and binary-only images in all three build workflows. Move it to .github/actions/create-manifest-list and call it via the $/ self-repository reference, which works without a checkout in the merge job. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
🔵 Needs a closer look
The new registry-publishing composite action cannot execute in pull-request CI and will first be exercised after merging.
0 open findings
What changed in this PR
Modernizes dependency automation, simplifies PHP extension builds, and consolidates multi-platform image publishing workflows.
Changes:
- Reworks Renovate configuration and removes Dependabot.
- Builds bundled PHP extensions directly and improves shell tooling.
- Consolidates manifest publishing into a composite action and updates CI metadata/security coverage.
| File | Description |
|---|---|
README.md |
Documents the Renovate-driven release flow. |
latest/Dockerfile |
Builds bundled bz2 and zip extensions directly. |
2.2/Dockerfile |
Builds bundled bz2 and zip extensions directly. |
1.10/Dockerfile |
Builds bundled bz2 and zip extensions directly. |
generate-stackbrew-library.sh |
Replaces implicit word splitting with arrays. |
.github/workflows/zizmor.yaml |
Extends scanning to YAML files. |
.github/workflows/shellcheck.yaml |
ShellChecks every shell script safely. |
.github/workflows/latest.yaml |
Adds labels and uses shared manifest creation. |
.github/workflows/2.2.yaml |
Adds labels and uses shared manifest creation. |
.github/workflows/1.10.yaml |
Adds labels and uses shared manifest creation. |
.github/renovate.json |
Refines dependency grouping and version policies. |
.github/dependabot.yml |
Removes competing dependency automation. |
.github/actions/create-manifest-list/action.yaml |
Introduces shared multi-platform manifest publishing. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Repository maintenance, split into one commit per area so each can be reviewed (or reverted) on its own.
Commits
Rework Renovate config and drop Dependabot
dependabot.yml: Renovate already manages GitHub Actions and the two were opening competing PRs (e.g.8bc612cvsa737876). Dependabot security alerts are a repo setting and are unaffected.minimumReleaseAge(replaces the Dependabot cooldown); each action PR otherwise triggers 3 workflows × 8 platformsrebaseWhen: behind-base-branch(defaultauto) to avoid redundant multi-arch rebuildsenabled: true,dependencyDashboardApproval: false)separateMinorPatchtocomposer/composerallowedVersions: "<2.3.0"rule-RCversionslatest/(stackbrew aliases, LTS directory)helpers:pinGitHubActionDigestsValidated with
renovate-config-validator --strict.Build bz2 and zip with docker-php-ext-install
Both extensions are bundled with php-src, so the base image can build them itself. This removes the third-party
docker-php-extension-installerdownload and its manually maintained sha512. Verified locally (amd64) for all three images:php -midentical to before, ZipArchive/bzip2 round-trip works, images ~11MB smaller. Other platforms are exercised by this PR's CI.Fix zizmor coverage and tidy build workflows
.github/**.yml, so the.yamlbuild workflows and composite action were never scanned; rename tozizmor.yamland match both extensionslabelsto build-push-action (they were computed but unused)$/self-repository action referenceDescribe the Renovate-driven release flow in README
Make generate-stackbrew-library.sh ShellCheck-clean
Explicit arrays instead of implicit word-splitting; no longer excluded from the ShellCheck workflow. Generated output verified byte-identical.
Extract manifest list creation into a composite action
The loop was duplicated for full/bin images in all three workflows; it now lives in
.github/actions/create-manifest-list(dry-run verified to produce the sameimagetoolscommands).Note
The
mergejob only runs onmain, so the composite action is first exercised on the first push after merging. Worth watching that run (or triggering viaworkflow_dispatch).🤖 Generated with Claude Code