# This workflow is provided via the organization template repository # # https://github.com/nextcloud/.github # https://docs.github.com/en/actions/learn-github-actions/sharing-workflows-with-your-organization # # SPDX-FileCopyrightText: 2022-2024 Nextcloud GmbH and Nextcloud contributors # SPDX-License-Identifier: MIT name: Static analysis on: pull_request concurrency: group: psalm-${{ github.head_ref || github.run_id }} cancel-in-progress: true permissions: contents: read jobs: changes: runs-on: selfhosted permissions: contents: read pull-requests: read outputs: src: ${{ steps.changes.outputs.src}} steps: - uses: https://github.com/dorny/paths-filter@ceb8a2b8f2d89434be7ff52d3de7ec3738c5cc9d # v4.0.3 id: changes continue-on-error: true with: filters: | src: - '.github/workflows/**' - 'appinfo/**' - 'lib/**' - 'templates/**' - 'tests/**' - 'vendor/**' - 'vendor-bin/**' - '.php-cs-fixer.dist.php' - 'composer.json' - 'composer.lock' - 'psalm.xml' - '**.php' versions: runs-on: selfhosted needs: changes if: needs.changes.outputs.src != 'false' outputs: ocp-matrix: ${{ steps.versions.outputs.ocp-matrix }} php-min: ${{ steps.versions.outputs.php-min }} steps: - name: Checkout app uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Get version matrix id: versions uses: https://github.com/icewind1991/nextcloud-version-matrix@8a7bac6300b2f0f3100088b297995a229558ddba # v1.3.2 - name: Check enforcement of minimum PHP version ${{ steps.versions.outputs.php-min }} in psalm.xml run: grep 'phpVersion="${{ steps.versions.outputs.php-min }}' psalm.xml static-analysis: runs-on: selfhosted needs: [changes, versions] if: needs.changes.outputs.src != 'false' container: image: docker.io/setupphp/node:php-${{ needs.versions.outputs.php-min }}-bookworm strategy: # do not stop on another job's failure fail-fast: false matrix: ${{ fromJson(needs.versions.outputs.ocp-matrix) }} name: static-psalm-analysis ${{ matrix.ocp-version }} steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Restore composer binary uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 id: composer-bin-cache with: path: .ci-bin/composer key: composer-2-${{ runner.os }}-php-${{ needs.versions.outputs.php-min }}-bookworm - name: Install composer if: steps.composer-bin-cache.outputs.cache-hit != 'true' run: | mkdir -p .ci-bin curl -sS https://getcomposer.org/installer | php -- --install-dir=.ci-bin --filename=composer - name: Save composer binary if: steps.composer-bin-cache.outputs.cache-hit != 'true' uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: .ci-bin/composer key: ${{ steps.composer-bin-cache.outputs.cache-primary-key }} - name: Add composer to PATH run: | chmod +x .ci-bin/composer echo "$GITHUB_WORKSPACE/.ci-bin" >> "$GITHUB_PATH" - name: Restore composer vendor cache uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 id: vendor-cache with: path: | vendor vendor-bin/*/vendor key: ${{ runner.os }}-composer-vendor-${{ needs.versions.outputs.php-min }}-ocp-${{ matrix.ocp-version }}-${{ hashFiles('composer.lock', 'vendor-bin/*/composer.lock') }} restore-keys: | ${{ runner.os }}-composer-vendor-${{ needs.versions.outputs.php-min }}-ocp-${{ matrix.ocp-version }}- - name: Install dependencies if: steps.vendor-cache.outputs.cache-hit != 'true' env: OCP_VERSION: ${{ matrix.ocp-version }} run: | composer remove nextcloud/ocp --dev --no-scripts composer i --prefer-dist composer require --dev "nextcloud/ocp:$OCP_VERSION" --ignore-platform-reqs --with-dependencies - name: Save composer vendor cache if: steps.vendor-cache.outputs.cache-hit != 'true' uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 with: path: | vendor vendor-bin/*/vendor key: ${{ steps.vendor-cache.outputs.cache-primary-key }} - name: Run coding standards check run: composer run psalm -- --threads=1 --monochrome --no-progress --output-format=github summary: runs-on: selfhosted needs: [changes, static-analysis] if: always() name: static-psalm-analysis-summary steps: - name: Summary status run: if ${{ needs.changes.outputs.src != 'false' && needs.static-analysis.result != 'success' }}; then exit 1; fi