chore: harmonize CI workflow, templates, and test structure - #29
Conversation
Part of the fleet-wide plugin_* harmonization effort (2nd repo after
plugin_analytics).
- Stop logging the MySQL root password in CI output (cat ~/.my.cnf ->
chmod 600), same fix just applied to plugin_analytics per Copilot review.
- Harden MySQL bootstrap: quoted --defaults-file, grants added for both
'cactiuser'@'localhost' and 'cactiuser'@'127.0.0.1'.
- Switch the PHP syntax-check step to the vendor-excluding, null-delimited
find/xargs pattern used in plugin_audit.
- No CodeQL workflow added: this repo has no JavaScript/Python/Ruby content
(PHP + Shell only per repo language stats), so there is nothing for
CodeQL to scan.
- Consolidate tests/Security/Php74CompatibilityTest.php AND
tests/Security/Php82CompatibilityTest.php (this repo had both) into a
single tests/Security/PhpCompatibilityTest.php, now checking for PHP
8.3/8.4-only syntax only (this plugin's floor is PHP 8.2 per the CI
matrix), replacing the now-moot PHP 7.4-vs-8.0 checks.
- Remove tests/TestCase.php and its require in tests/bootstrap-unit.php: no
test in this plugin actually uses `uses(TestCase::class)` (verified via an
org-wide code search); it was unused boilerplate.
- Add .github/ISSUE_TEMPLATE/{bug_report,feature_request}.md and
.github/PULL_REQUEST_TEMPLATE.md, styled after Cacti/cacti's own templates
(this repo previously had none).
- Document CI/dependency baselines in copilot-instructions.md: no plugin-local
composer.json/composer.lock or phpstan/php-cs-fixer config (use Cacti's),
and prefer cacti_count()/cacti_sizeof() over count()/sizeof().
Everything else (pinned Actions, "Restore vendor ownership for Pest" step,
no Configure Apache step, the bespoke "Wait for background apcupsd poller"
step, the log-failure gate) was already in place in this repo and used as
the template for the rest of the fleet.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The consolidated PhpCompatibilityTest currently has gaps/bugs in its guards (missing checks and attribute matching) that weaken the stated PHP 8.2-compatibility guarantee.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 4
Open (5)
Guard against realpath failure before constructing the iterator · New Recognize fully qualified Override attributes · New Recognize qualified and parameterized Deprecated attributes · New Restore checks for PHP 8.3/8.4 compatibility constructs · New Include the relative path in resolution error messages · New
What changed in this PR
This PR continues the fleet-wide harmonization of plugin_* repositories by aligning CI workflow behavior, test structure, and GitHub templates with the shared conventions used across the Cacti plugin ecosystem.
Changes:
- Hardened GitHub Actions MySQL bootstrap (avoid logging credentials, safer
--defaults-fileusage, grants for bothlocalhostand127.0.0.1). - Consolidated PHP compatibility/security tests by replacing per-version compatibility test files with a single recursive
PhpCompatibilityTest. - Added standard GitHub issue/PR templates and updated repo Copilot guidance to document CI/dependency baselines.
| File | Description |
|---|---|
.github/workflows/plugin-ci-workflow.yml |
CI hardening: avoids password logging, improves MySQL bootstrap, and updates PHP syntax checking to a vendor-excluding `find |
tests/Security/PhpCompatibilityTest.php |
New consolidated compatibility test scanning all production PHP files for PHP 8.3/8.4-only constructs. |
tests/Security/Php82CompatibilityTest.php |
Removed in favor of the consolidated compatibility test. |
tests/Security/Php74CompatibilityTest.php |
Removed (plugin floor is PHP 8.2 per CI matrix). |
tests/bootstrap-unit.php |
Removes dead TestCase.php bootstrap include. |
tests/TestCase.php |
Deleted unused PHPUnit base class. |
.github/PULL_REQUEST_TEMPLATE.md |
Adds a standard PR template. |
.github/ISSUE_TEMPLATE/bug_report.md |
Adds a standard bug report template. |
.github/ISSUE_TEMPLATE/feature_request.md |
Adds a standard feature request template. |
.github/copilot-instructions.md |
Documents CI/dependency baselines and preferred conventions for generated changes. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Document the locales/build_gettext.sh + cacti.pot workflow in copilot-instructions.md (Weblate owns per-language .po/.mo sync). - Add a CI step that regenerates cacti.pot and fails if it is stale, ignoring the POT-Creation-Date timestamp. - Mark locales/build_gettext.sh executable. - Bump the CI MariaDB service image floor to 11.8 (from mariadb:10.6 / mysql:8.0).
- mariadb:11.8 no longer ships mysqladmin; use mariadb-admin for the service container healthcheck. - Run chmod/build_gettext.sh with sudo in the i18n verification step, since locales/ is owned by www-data by the time it runs.
Ran the real locales/build_gettext.sh (xgettext/msgmerge/msgfmt) to refresh the translation template against current source. Per the i18n workflow documented in copilot-instructions.md, only the regenerated cacti.pot is committed here; Weblate owns syncing the per-language .po/.mo files from it.
…ibilityTest Matches the project's PSR coding standard (short array syntax, single quotes for non-interpolated strings) that php-cs-fixer enforces in CI.
`find` without `sort` returns filesystem/readdir-order results, which can differ between machines (e.g. a local regen vs. a GitHub Actions runner), producing a spurious reordering diff in cacti.pot even when no strings actually changed. Pipe through `sort` and regenerate cacti.pot with the now-deterministic order.
- tests/Security/PhpCompatibilityTest.php: fixed the #[Override]/#[Deprecated] attribute regexes to also match the fully qualified (`#[\Override]`, `#[\Deprecated]`) form, added a realpath() false-guard for the plugin root, included the relative file path in both RuntimeException messages, added typed-class-constant and dynamic-class-constant-fetch checks (PHP 8.3), and restored each()/create_function() removed-in-PHP-8.0 guards that the consolidation had dropped. Also excludes include/vendor/ (not just vendor/) from the recursive source scan. - .github/workflows/plugin-ci-workflow.yml: the "Create MySQL Config" step's root password is now masked via `::add-mask::` before it's echoed into ~/.my.cnf, so it no longer appears in plaintext in the Actions log (chmod 600 alone only protected the file after creation, not the command's own echoed source in the log).
|
This PR's |
The each()-removed-in-PHP-8.0 check matched jQuery's $.each(/.each( calls too, which have nothing to do with the removed PHP global function. Exclude any each( preceded by . or > via a negative lookbehind.


Description
Second repo in the fleet-wide
plugin_*CI/template/test-structureharmonization effort (see plugin_analytics#8 for the first). This repo was
actually used as the reference template for the composer-install/poller
pattern, so most of it was already compliant — the diff here is smaller.
Changes
plugin_analyticsafter Copilot review flagged it there —cat ~/.my.cnfprinted the root password into the Actions log; replaced with
chmod 600.--defaults-file, grants added forboth
'cactiuser'@'localhost'and'cactiuser'@'127.0.0.1'(previouslylocalhost-only).
find/xargspattern fromplugin_audit.content (PHP + Shell only), so there's nothing for CodeQL to scan.
tests/Security/Php74CompatibilityTest.phpandtests/Security/Php82CompatibilityTest.phpside by side. Merged into asingle
tests/Security/PhpCompatibilityTest.phpchecking only for PHP8.3/8.4-only syntax (this plugin's floor is PHP 8.2 per the CI matrix).
tests/TestCase.php: not referenced by anyuses(TestCase::class)call in this plugin's actual tests. Removed thenow-dead
require_oncefor it intests/bootstrap-unit.phptoo..github/ISSUE_TEMPLATE/bug_report.md,feature_request.md, and.github/PULL_REQUEST_TEMPLATE.md, styled after Cacti/cacti's own templates.plugin-local
composer.json/composer.lock/phpstan/php-cs-fixerconfig;prefer
cacti_count()/cacti_sizeof()).Everything else (pinned Actions, the "Restore vendor ownership for Pest"
step, no Configure Apache step, the bespoke "Wait for background apcupsd
poller" step, the log-failure gate) was already in place here and used as
the template for the rest of the fleet.
Related Issue
N/A — internal fleet harmonization, not tracked against a specific issue.
How Has This Been Tested?
(
powershell-yaml) before pushing.Plugin Integration Tests) will run automatically on this PR.Types of changes
Checklist
out across
plugin_*repos.