Skip to content

Fix CI on 2.x - #1112

Merged
dereuromark merged 1 commit into
2.xfrom
ci-fix-2.x
Oct 7, 2026
Merged

dereuromark merged 1 commit into
2.xfrom
ci-fix-2.x

Conversation

@dereuromark

Copy link
Copy Markdown
Member

CI on 2.x is red independent of what a PR changes, see #1110.

Composer 2.9 blocks versions with known security advisories. For Cake 4 the remaining candidates all pull a laminas-diactoros release that needs PHP 8.0+, so composer update fails on the PHP 7.2/7.4/8.0 jobs and in the static analysis job. The workflow now sets COMPOSER_NO_SECURITY_BLOCKING.

Also in here:

  • windows-2019 is gone, the job never started. Moved to windows-2022.
  • set-output replaced with GITHUB_OUTPUT.
  • actions/cache v3 to v4.

Composer 2.9 blocks dependency versions with known security advisories.
For cakephp/cakephp 4.x that leaves only releases whose
laminas-diactoros requirement needs PHP 8.0+, so nothing was
installable on the PHP 7.2 and 7.4 jobs or in the static analysis job.
Disable the blocking for CI, the suite still has to run on those
versions.

Also move off the removed windows-2019 image, the deprecated
set-output command and actions/cache v3.
@dereuromark dereuromark added this to the 2.x (CakePHP 4) milestone Oct 7, 2026
@dereuromark dereuromark added the github_actions Pull requests that update GitHub Actions code label Oct 7, 2026
@dereuromark
dereuromark merged commit 9f36595 into 2.x Oct 7, 2026
11 checks passed
@dereuromark
dereuromark deleted the ci-fix-2.x branch October 7, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant