diff --git a/.github/workflows/psalm.yml b/.github/workflows/psalm.yml new file mode 100644 index 0000000..373c3da --- /dev/null +++ b/.github/workflows/psalm.yml @@ -0,0 +1,63 @@ +# SPDX-FileCopyrightText: 2022-2024 Nextcloud GmbH and Nextcloud contributors +# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +# SPDX-License-Identifier: MIT + +name: Static analysis + +on: + workflow_call: + +permissions: + contents: read + +concurrency: + group: psalm-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +jobs: + static-analysis: + runs-on: ubuntu-latest + name: static-psalm-analysis + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - name: Get php version + id: versions + uses: nextcloud-libraries/nextcloud-version-matrix@cd0211ffcef1065e2020cd579e4843b8746e7a58 # v1.3.3 + + - name: Check minimum PHP version in psalm.xml + env: + PHP_MIN: ${{ steps.versions.outputs.php-min }} + run: grep "phpVersion=\"$PHP_MIN" psalm.xml + + - name: Set up php${{ steps.versions.outputs.php-available }} + uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2 + with: + php-version: ${{ steps.versions.outputs.php-available }} + extensions: bz2, ctype, curl, dom, fileinfo, gd, iconv, intl, json, libxml, mbstring, openssl, pcntl, posix, session, simplexml, xmlreader, xmlwriter, zip, zlib, sqlite, pdo_sqlite + coverage: none + ini-file: development + ini-values: disable_functions= + env: + GITHUB_TOKEN: ${{ github.token }} + + - name: Remove nextcloud/ocp + run: composer remove nextcloud/ocp --dev --no-scripts + + - name: Install composer dependencies + uses: ramsey/composer-install@65e4f84970763564f46a70b8a54b90d033b3bdda # 4.0.0 + + - name: Install supported nextcloud/ocp + env: + OCP_BRANCH: ${{ steps.versions.outputs.branches-max }} + run: >- + composer require --dev + "nextcloud/ocp:dev-$OCP_BRANCH" + --ignore-platform-reqs + --with-dependencies + + - name: Run Psalm + run: composer run psalm -- --threads=1 --monochrome --no-progress --output-format=github diff --git a/workflow-templates/psalm.properties.json b/workflow-templates/psalm.properties.json new file mode 100644 index 0000000..336c709 --- /dev/null +++ b/workflow-templates/psalm.properties.json @@ -0,0 +1,12 @@ +{ + "name": "Psalm static analysis", + "description": "Run Psalm static analysis with the PHP and Nextcloud versions supported by the app.", + "iconName": "octicon codescan-checkmark", + "categories": [ + "PHP" + ], + "filePatterns": [ + "^composer.json$", + "^psalm.xml$" + ] +} diff --git a/workflow-templates/psalm.properties.json.license b/workflow-templates/psalm.properties.json.license new file mode 100644 index 0000000..1ce4e0c --- /dev/null +++ b/workflow-templates/psalm.properties.json.license @@ -0,0 +1,2 @@ +SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +SPDX-License-Identifier: AGPL-3.0-or-later diff --git a/workflow-templates/psalm.yml b/workflow-templates/psalm.yml new file mode 100644 index 0000000..b7fa510 --- /dev/null +++ b/workflow-templates/psalm.yml @@ -0,0 +1,16 @@ +# SPDX-FileCopyrightText: 2026 LibreCode coop and contributors +# SPDX-License-Identifier: AGPL-3.0-or-later + +# This workflow is published through the LibreCode organization catalog. +# Implementation: LibreCodeCoop/github-workflows + +name: Static analysis + +on: pull_request + +permissions: + contents: read + +jobs: + psalm: + uses: LibreCodeCoop/github-workflows/.github/workflows/psalm.yml@bedd8421ad6c95914f10f0dc631333223d17c515