Skip to content

fix(plugin-checks): install WP-CLI from its release by name, checked against its SHA-512 - #23

Merged
soydiloreto merged 1 commit into
mainfrom
fix/wp-cli-pinned
Oct 2, 2026
Merged

soydiloreto merged 1 commit into
mainfrom
fix/wp-cli-pinned

Conversation

@soydiloreto

Copy link
Copy Markdown
Member

📝 What changes

The i18n and translations jobs of plugin-checks-wp.yml install WP-CLI themselves instead of through setup-php's tools: wp-cli. They download wp-cli-2.12.0.phar from wp-cli's v2.12.0 release and verify it against its SHA-512 before installing it as wp.

💡 Why

setup-php asks for a release asset named wp-cli.phar, which wp-cli's releases do not carry. On 2 October 2026 it answered 404, "Could not setup wp-cli", and both jobs failed in every plugin (DiluxOne/diluxone-offload-wordpress#48). The checksum matches the one wp-cli publishes in wp-cli/builds (wp-cli-release.phar.sha512).

🧪 How I tested it

  • actionlint on the workflow
  • The URL answers 200, and the downloaded file's SHA-512 equals wp-cli/builds' published value

🤖 AI-generated · Claude Opus 5.5 (Anthropic)

…against its SHA-512

setup-php's tools: wp-cli asks for a release asset named wp-cli.phar, which wp-cli's releases do not carry: it answered 404 on 2 October 2026 and the i18n and translations jobs failed in every plugin. Both jobs download wp-cli-2.12.0.phar and verify the SHA-512 wp-cli publishes in wp-cli/builds.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@dilux-bot dilux-bot Bot added risk:high Set by the Claude review complexity:low Set by the Claude review type:fix The kind of change, read from the diff by the Claude review labels Oct 2, 2026
@dilux-bot

dilux-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Claude review · risk high · complexity low · type fix

Replaces setup-php's tools: wp-cli (404 on the missing wp-cli.phar asset) with a pinned download of wp-cli-2.12.0.phar, verified with sha512sum -c before install, in both the i18n and translations jobs. The hash is 128 hex characters, and the download fails the step on an HTTP error (curl -f) or a checksum mismatch. The values are passed through env:, no secrets or untrusted text are involved, and no other wp-cli reference remains in the repo, so no docs are stale. The description matches the diff. I could not re-check the published SHA-512 against wp-cli/builds here (the PR says it was checked). Minor: the version, URL and hash are duplicated in two jobs, so a bump must change both, and no test guards that they stay in step.

  • minor .github/workflows/plugin-checks-wp.yml:241: WP-CLI version, URL and SHA-512 are copied in two jobs (also line 261); a bump can update one and miss the other. Consider a composite action or a script, or a check that the two copies match.

Policy floor: high (touches high-risk paths: .github/workflows/plugin-checks-wp.yml). Reviewed 05de466 (whole pull request; review 1 of 5 automatic). Author trusted for auto-merge: true.

🤖 AI review · claude-sonnet-5-5 (Anthropic) · $0.24, 5 turns

@soydiloreto
soydiloreto merged commit ec30178 into main Oct 2, 2026
7 checks passed
@soydiloreto
soydiloreto deleted the fix/wp-cli-pinned branch October 2, 2026 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

complexity:low Set by the Claude review risk:high Set by the Claude review type:fix The kind of change, read from the diff by the Claude review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant