fix(plugin-checks): install WP-CLI from its release by name, checked against its SHA-512 - #23
Conversation
…against its SHA-512 setup-php's tools: wp-cli asks for a release asset named wp-cli.phar, which wp-cli's releases do not carry: it answered 404 on 2 October 2026 and the i18n and translations jobs failed in every plugin. Both jobs download wp-cli-2.12.0.phar and verify the SHA-512 wp-cli publishes in wp-cli/builds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude review · risk high · complexity low · type fixReplaces setup-php's
Policy floor: high (touches high-risk paths: .github/workflows/plugin-checks-wp.yml). Reviewed 05de466 (whole pull request; review 1 of 5 automatic). Author trusted for auto-merge: true. 🤖 AI review · claude-sonnet-5-5 (Anthropic) · $0.24, 5 turns |
📝 What changes
The i18n and translations jobs of
plugin-checks-wp.ymlinstall WP-CLI themselves instead of through setup-php'stools: wp-cli. They downloadwp-cli-2.12.0.pharfrom wp-cli's v2.12.0 release and verify it against its SHA-512 before installing it aswp.💡 Why
setup-php asks for a release asset named
wp-cli.phar, which wp-cli's releases do not carry. On 2 October 2026 it answered 404, "Could not setup wp-cli", and both jobs failed in every plugin (DiluxOne/diluxone-offload-wordpress#48). The checksum matches the one wp-cli publishes in wp-cli/builds (wp-cli-release.phar.sha512).🧪 How I tested it
🤖 AI-generated · Claude Opus 5.5 (Anthropic)