Skip to content

feat: centralize Psalm static analysis - #24

Merged
vitormattos merged 4 commits into
mainfrom
feat/reusable-psalm
Sep 20, 2026
Merged

vitormattos merged 4 commits into
mainfrom
feat/reusable-psalm

Conversation

@vitormattos

Copy link
Copy Markdown
Member

Summary

Continue #15 by centralizing the Psalm static-analysis workflow behind a reusable workflow with a thin catalog caller.

The caller is pinned to immutable commit bedd8421ad6c95914f10f0dc631333223d17c515.

Upstream alignment

This follows the current Nextcloud workflow rather than the older copy in LibreCodeCoop/extract:

  • checkout v7.0.1;
  • nextcloud-libraries/nextcloud-version-matrix v1.3.3;
  • setup-php 2.37.2;
  • cached Composer installation via ramsey/composer-install;
  • removal of the old roave/security-advisories:dev-latest step.

The Roave step was deliberately removed upstream in nextcloud/.github#712 because this dependency-blocking pattern is no longer needed with Composer 2.9. Dependency-security policy remains a separate concern from static analysis.

Security / maintainability

  • third-party actions remain pinned to full SHAs;
  • values derived from workflow outputs are passed into shell through environment variables rather than direct template interpolation;
  • the consumer owns only the pull-request event;
  • the catalog uses a GitHub Octicon instead of copying Psalm branding assets.

After merge, the workflow can be validated in LibreCodeCoop/extract.

@vitormattos
vitormattos merged commit 1d431a6 into main Sep 20, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant