Skip to content

Fixes PHP-CS-Fixer workflow #9110

Merged
Sesquipedalian merged 2 commits intoSimpleMachines:release-3.0from
Sesquipedalian:3.0/contint-php-cs-fixer
Feb 13, 2026
Merged

Fixes PHP-CS-Fixer workflow #9110
Sesquipedalian merged 2 commits intoSimpleMachines:release-3.0from
Sesquipedalian:3.0/contint-php-cs-fixer

Conversation

@Sesquipedalian
Copy link
Member

No description provided.

@Sesquipedalian Sesquipedalian force-pushed the 3.0/contint-php-cs-fixer branch 9 times, most recently from 1b06967 to cb37df4 Compare February 13, 2026 07:56
Signed-off-by: Jon Stovell <jonstovell@gmail.com>
@Sesquipedalian Sesquipedalian force-pushed the 3.0/contint-php-cs-fixer branch 4 times, most recently from 5d4416c to e69b39e Compare February 13, 2026 08:14
@Sesquipedalian Sesquipedalian marked this pull request as draft February 13, 2026 08:14
@Sesquipedalian Sesquipedalian force-pushed the 3.0/contint-php-cs-fixer branch 13 times, most recently from 064a1bc to 263074b Compare February 13, 2026 09:01
Signed-off-by: Jon Stovell <jonstovell@gmail.com>
@Sesquipedalian Sesquipedalian force-pushed the 3.0/contint-php-cs-fixer branch from 263074b to 1011d89 Compare February 13, 2026 09:03
@Sesquipedalian Sesquipedalian marked this pull request as ready for review February 13, 2026 09:10
@Sesquipedalian Sesquipedalian changed the title Different method to run PHP-CS-Fixer in continuous integration script Fixes PHP-CS-Fixer workflow Feb 13, 2026
@Sesquipedalian Sesquipedalian merged commit 079f425 into SimpleMachines:release-3.0 Feb 13, 2026
8 checks passed
@Sesquipedalian Sesquipedalian deleted the 3.0/contint-php-cs-fixer branch February 13, 2026 09:11
@jdarwood007
Copy link
Member

@Sesquipedalian
I had migrated away from tj-actions because of the security issue that occurred: GHSA-mrrh-fwg8-r2c3

In reality, we have ways to do the same thing without adding a dependency.

Also, this is why we don't use tag ids when referencing dependencies in our CI, but rather the commit hash. Because as the security issue above, the tag was overwritten, allowing the vulnerability.

@Sesquipedalian
Copy link
Member Author

I'll try reverting that part of the change and test whether it still works.

@Sesquipedalian
Copy link
Member Author

It did not work. That shell code did not do the job it needed to.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants