Commit Graph
50 Commits
Author SHA1 Message Date
Divarion_D 5e061dd0b6 ci: move referenced issues to "Review & Deploy" instead of closing
Add a push-to-main workflow that parses issue references in the
pushed commit messages and moves each referenced issue's card on the
org Projects v2 board (Vateron-Media/projects/5) to the
"Review & Deploy" status column, without closing the issue.

Reuses the existing ADD_TO_PROJECT_PAT secret.
2026-08-15 17:31:06 +03:00
Divarion_D 7f3812e165 chore(build): move phpstan / php-cs-fixer config out of the repo root
Relocate the dev-tooling config into build/ so the project root only holds
source and first-class project files:
- phpstan.dist.neon        -> build/phpstan.dist.neon
- phpstan-baseline.neon    -> build/phpstan-baseline.neon
- .php-cs-fixer.dist.php    -> build/.php-cs-fixer.dist.php
- .php-cs-fixer.cache       -> build/ (regenerated there; gitignored)

Because neon/CS-Fixer resolve relative paths against the config file's own
directory, the internal references are re-anchored one level up (src/ ->
../src/, tools/ -> ../tools/, Finder in(__DIR__.'/../src'); the baseline's
path: entries likewise). The Makefile now points PHPStan at the config with
-c build/phpstan.dist.neon (it previously relied on root auto-discovery),
generates the baseline into build/, and passes --config=build/... to CS-Fixer;
the CS-Fixer cache is pinned to build/ via setCacheFile and re-gitignored.

No behaviour change. Verified: make phpstan (No errors), make cs (0 fixable),
make gates. CI runs through these make targets, so it is covered.
2026-08-09 19:37:11 +03:00
DanilandGitHub a34361c2ee Merge branch 'main' into dependabot/github_actions/actions/checkout-7 2026-08-09 16:02:50 +03:00
dependabot[bot]andGitHub c0e5cde892 ci: bump actions/upload-pages-artifact from 3 to 5
Bumps [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) from 3 to 5.
- [Release notes](https://github.com/actions/upload-pages-artifact/releases)
- [Commits](https://github.com/actions/upload-pages-artifact/compare/v3...v5)

---
updated-dependencies:
- dependency-name: actions/upload-pages-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-09 12:59:54 +00:00
dependabot[bot]andGitHub e1040752dc ci: bump actions/checkout from 4 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-09 12:59:48 +00:00
dependabot[bot]andGitHub 26adb0bfad ci: bump actions/configure-pages from 5 to 6
Bumps [actions/configure-pages](https://github.com/actions/configure-pages) from 5 to 6.
- [Release notes](https://github.com/actions/configure-pages/releases)
- [Commits](https://github.com/actions/configure-pages/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/configure-pages
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-09 12:45:50 +00:00
dependabot[bot]andGitHub 60d07a243e ci: bump actions/deploy-pages from 4 to 5
Bumps [actions/deploy-pages](https://github.com/actions/deploy-pages) from 4 to 5.
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](https://github.com/actions/deploy-pages/compare/v4...v5)

---
updated-dependencies:
- dependency-name: actions/deploy-pages
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-09 10:04:23 +00:00
Divarion_D 904ea4859c Update Github CI 2026-08-07 21:39:59 +03:00
Divarion_D ad8894844a ci(pages): add path-filtered Pages deploy workflow for docs/ 2026-08-07 21:34:32 +03:00
Divarion_D b83cb86fbb ci: run CI once per change (scope push to main, add concurrency) 2026-08-06 21:31:46 +03:00
dependabot[bot]andGitHub 7a09a11d84 ci: bump actions/add-to-project from 1.0.2 to 2.0.0
Bumps [actions/add-to-project](https://github.com/actions/add-to-project) from 1.0.2 to 2.0.0.
- [Release notes](https://github.com/actions/add-to-project/releases)
- [Commits](https://github.com/actions/add-to-project/compare/v1.0.2...v2.0.0)

---
updated-dependencies:
- dependency-name: actions/add-to-project
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-02 10:04:12 +00:00
Divarion-D 23009b3e6c Add workflow automation 2026-07-28 22:16:23 +03:00
Divarion-D 12195c9e70 feat(workflow): add workflow_dispatch inputs for release notifications 2026-07-10 20:15:49 +03:00
Divarion-D 8d39f90902 chore(tools): remove php_syntax_check.sh — covered by PHPStan/CS/PHPUnit
`php -l` syntax checking is redundant with the real linters/validators (PHPStan
  parses the code, PHP-CS-Fixer and the PHPUnit bootstrap also fail on parse
  errors). Remove the script and every reference to it:

  - Makefile: drop the `syntax_check` target and its .PHONY entry.
  - CI (ci.yml): drop the dedicated `lint` (PHP Syntax Check) job.
  - Release workflows (build-release, build_pre-release): drop the "Check syntax"
    step from the Quality Gate (PHPUnit remains).
  - CONTRIBUTING.md: replace the syntax-check pre-commit guidance with the real
    checks (make dev-tools / phpstan / cs / gates / phpunit).
  - updates_checklist (en/ru): replace `make syntax_check` with the quality-check
    suite and drop the stale "Security scan" snippet that referenced the removed
    script and a non-existent tools/run_scan.sh (Semgrep runs automatically in CI).
2026-06-26 19:00:10 +03:00
Divarion-D 0ea025c7b5 chore: remove unused filter option from checkout step in build workflows 2026-06-26 17:11:10 +03:00
Divarion-D 7634c0fc75 chore: migrate workflows to support pre-release assets 2026-06-26 11:50:10 +03:00
Divarion-D baf6c8e231 build: ship a production-only vendor; install dev tools via Composer
Switch from "commit vendor with dev deps + strip at release" to the standard
application model: the committed src/vendor/ is PRODUCTION-ONLY, and dev tooling
(PHPStan, PHP-CS-Fixer + ~37 transitive deps) is installed on demand with
"composer install".

- Regenerate the committed src/vendor/ via "composer install --no-dev"
  (34 MB -> ~0.5 MB; only the Composer autoloader + gemorroj/m3u-parser +
  chrisyue/php-m3u8 remain). This also stops PHPStan\PharAutoloader registering
  in production.
- Commit src/composer.lock (un-ignored) — this is an application, so the lock is
  committed to make "composer install" reproducible across dev/CI.
- Revert the release-time strip step (Makefile hooks + tools/build/
  strip-dev-vendor.sh) — no longer needed; the archive ships the prod vendor as-is.
- CI: the phpstan and code-style jobs now run "composer install --working-dir=src"
  (with tools: composer) to obtain the dev tools before running.
- New gate tools/ci/check-vendor-prod-only.sh (+ make check-vendor-prod-only,
  wired into "make gates"): asserts no require-dev package from composer.lock is
  committed under src/vendor/ — guards against accidentally committing a
  dev-bloated vendor. Inspects git-tracked files, so it is correct even in a CI
  job that already ran "composer install".
- Fix verify-lb-archive.sh: LB legitimately ships most of Cli/Commands and
  Cli/CronJobs (edge commands + certbot/cache/cleanup crons), so flag only the
  genuinely privileged dirs + the specific install/root files, not the whole dirs.
- .gitignore / composer.json notes updated.

Verified before pruning: PHPStan no errors, PHPUnit 303, cs + gates green. After
pruning: PHPUnit 303 (prod-only vendor), all three gates green. Local dev tools
restored afterwards with "composer install" (not committed).
2026-06-25 21:51:13 +03:00
Divarion-D fd35f00c4d fix(views): import migrated classes at top of 5 admin view templates
enigma, episode, episodes, process_monitor and stream_view referenced migrated
classes (UserRepository, BouquetService, StreamRepository, RequestManager,
SettingsManager, ...) by short name with either no `use` or a `use` placed
*below* the first usage. PHP imports outside the top scope are positional, so the
short name resolved to a now-nonexistent global class — a runtime fatal on those
admin pages (php -l passes; not covered by PHPStan/PHPUnit). The migration's
automated `use` insertion missed them due to the interleaved HTML / short-tag
(<? , <?=) structure, and the later php-cs-fixer pass stripped some as 'unused'
because it could not see usage inside short-tag blocks.

- Consolidate every needed `use XcVm\...;` into a single top-of-file PHP block.
- Exclude Public/Views and Modules/*/views from php-cs-fixer (no_unused_imports
  is unreliable on short-tag templates); their import correctness is enforced by
  the new check_procedural_use gate instead.

Verified: php -l (short_open_tag=1) clean; PHPStan no errors; PHPUnit green.
2026-06-25 20:57:37 +03:00
Divarion-D 1a0ad5667a chore(cs): add PHP-CS-Fixer (import/namespace hygiene only)
Add friendsofphp/php-cs-fixer as a committed Composer dev dependency (src/vendor/,
same model as PHPStan — no composer install on deploy).

- .php-cs-fixer.dist.php: deliberately NARROW ruleset — no_unused_imports,
  ordered_imports, no_leading_import_slash, single_line_after_imports,
  blank_line_after_namespace, no_extra_blank_lines[use]. NO @PSR12 / indentation
  rules: the codebase is tab-indented legacy and a full reformat would be
  unreviewable. Indent forced to tabs, LF endings. Excludes vendor, the bundled
  Modules/tmdb/lib, tmp/, backups/.
- Makefile: 'make cs' (dry-run, fails on diff — CI) and 'make cs-fix' (apply).
- CI: new 'Code Style (PHP-CS-Fixer)' job running 'make cs' on PHP 8.3.
- .gitignore: ignore .php-cs-fixer.cache.
2026-06-25 20:24:34 +03:00
Divarion-D db9b8ea7fc chore(deps): migrate M3uParser to Composer (gemorroj/m3u-parser 6.0.1)
- add gemorroj/m3u-parser 6.0.1 to committed vendor/ (PHP >=8.0.2;
  upstream 6.1.0 requires PHP 8.2, incompatible with the 8.1 target)
- remove vendored Core/Parsing/M3uParser snapshot and manual bootstraps
- autoload \M3uParser\ from committed vendor/ instead of a path mapping
- stop tracking composer.lock (already gitignored); CI now audits the
  committed vendor/composer/installed.json without --locked
2026-06-25 19:36:18 +03:00
Divarion-D 7572b9b4d0 chore(ci): enhance Composer audit step to skip when no packages are found 2026-06-25 18:47:24 +03:00
Divarion-D 64e37eb05e chore(ci): update Composer audit command to use --locked option 2026-06-24 22:28:39 +03:00
Divarion-D 7e5732cdcb chore(psr4): phase 0 — Composer PSR-4 autoloader foundation
Introduce a committed Composer PSR-4 autoloader without changing class
resolution behavior, as the foundation for the incremental PSR-4 migration.

- src/composer.json: PSR-4 (XcVm\ -> ./, M3uParser\, Chrisyue\PhpM3u8\),
  platform php 8.1.33 (deploy runtime), optimize-autoloader/classmap-authoritative
  false (live path resolution, no class-map cache). autoload.files left empty:
  global functions are still loaded by existing require glue; moving them is
  deferred until that glue is removed.
- src/vendor/ + src/composer.lock: committed (deploy path has no Composer);
  generated with 'composer update' from src/. Regenerate with dump-autoload.
- src/bootstrap.php, tests/bootstrap.php: require vendor/autoload.php first,
  then the legacy autoload.php.
- src/autoload.php: drop the igbinary disk cache (enableFileCache/saveCache/
  shutdown handler/root-chown + bottom call); register at the END of the SPL
  queue (prepend=false) so Composer wins for XcVm\* and only still-global
  classes fall through to the in-memory scanner.
- Makefile: add vendor to LB_DIRS so load-balancer archives ship the loader.
- phpstan.dist.neon: exclude src/vendor/* from analysis.
- .gitignore: document that src/vendor/ is intentionally tracked.
- ci.yml: add composer-audit job (no-op until real require deps exist).

Verified: php -l clean; Composer first / XC_Autoloader last in the SPL stack;
tmp/cache/autoload_map no longer written; PHPUnit 292/292; PHPStan no errors.
2026-06-24 19:07:37 +03:00
Divarion-D 93da607626 ci(phpstan): add static-analysis job with frozen baseline
- .github/workflows/ci.yml: new `phpstan` job (PHP 8.3, no Composer) running
  `make phpstan` on every push/PR.
- phpstan.dist.neon: include phpstan-baseline.neon so the gate is green on the
  ~446 pre-existing (mostly false-positive/cosmetic) findings and fails only on
  NEW issues. Shrink the baseline over time via `make phpstan-baseline`.
2026-06-23 22:05:42 +03:00
DanilandGitHub 413dec24d2 Merge pull request #124 from Vateron-Media/dependabot/github_actions/softprops/action-gh-release-3
ci: bump softprops/action-gh-release from 2 to 3
2026-06-21 22:30:48 +03:00
Divarion-D e474500978 ci: enhance Semgrep security scan with baseline commit resolution 2026-06-21 22:30:09 +03:00
DanilandGitHub 881c9b9ffb Merge pull request #123 from Vateron-Media/dependabot/github_actions/actions/checkout-7
ci: bump actions/checkout from 6 to 7
2026-06-21 22:28:41 +03:00
dependabot[bot]andGitHub 38f1be67bb ci: bump actions/upload-artifact from 4 to 7
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-21 19:17:51 +00:00
dependabot[bot]andGitHub 7cb361d692 ci: bump softprops/action-gh-release from 2 to 3
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 2 to 3.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](https://github.com/softprops/action-gh-release/compare/v2...v3)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: '3'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-21 19:17:49 +00:00
dependabot[bot]andGitHub 9dff052fbd ci: bump actions/checkout from 6 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-21 19:17:46 +00:00
Divarion-D 484a758ca0 chore: add Git LFS tracking, CODEOWNERS, SECURITY.md, and CI workflows 2026-06-21 22:11:49 +03:00
Divarion-D 44d312a997 feat(security-scan): add gate job to control scan execution based on commit count 2026-04-21 14:57:02 +03:00
Divarion-D d9bbd6c35b build: unify install and update into a single archive
Replace separate install/update build targets with a single archive that
serves both purposes. The update script (src/update) now extracts to a
temp directory, removes excluded dirs (binaries, config, user data), and
copies remaining files over the live installation.

Changes:
- Remove main_update, lb_update, lb_update_copy_files,
  main_update_copy_files Makefile targets and UPDATE_EXCLUDE_DIRS var
- Move exclude dirs list into src/update (Python) where filtering
  actually happens at runtime
- Rewrite doUpdate() to use tempdir extraction with try/finally cleanup
- Make delete_files_list/lb_delete_files_list gracefully skip when
  LAST_TAG is empty (warn instead of error)
- Simplify CI workflows: one make command per variant instead of
  conditional install + update steps
- Add ARCHITECTURE.md §5.5 documenting update flow
- Update en/ru docs: update-system.md, updates_checklist.md
- Update makefile-build.instructions.md with new targets
2026-04-12 17:38:35 +03:00
Divarion-D 3bbb0865ff feat(workflows): enhance release notifier with inputs for tag and release names 2026-03-17 21:32:55 +03:00
Divarion-D 2478ba612a fix(build): update git diff commands to exclude renames 2026-03-17 21:21:20 +03:00
Divarion-D 006584ffac chore: update actions/checkout to v6 in build and pre-release workflows 2026-03-15 19:32:14 +03:00
Divarion-D cb8e49f238 chore: remove duplicate files entry in release asset upload step 2026-03-15 19:25:52 +03:00
Divarion-D e483098447 chore: enhance workflows to support manual dispatch and dynamic tag resolution 2026-03-15 19:21:21 +03:00
Divarion-D a263a30187 chore: update pre-release workflow to build assets and remove manual inputs 2026-03-15 18:49:20 +03:00
Divarion-D 327c8dc161 ci: automate release asset builds via GitHub Actions 2026-03-15 18:45:19 +03:00
Divarion-D 518993bb66 ci: extract PHP syntax check into reusable script
- Add tools/php_syntax_check.sh (supports full scan + single-file mode)
- CI workflow now calls the shared script
- All 6 agents updated to reference the script
- CONTRIBUTING.md: add Pre-Commit Checks section
- Exclude src/bin/* (third-party stubs) from lint
2026-03-15 13:49:18 +03:00
Divarion-D e4e0fb7eb7 ci: upgrade actions to Node.js 24-compatible versions
- actions/checkout@v4 -> @v5 (Node 24 since v5.0.0)
- github/codeql-action/upload-sarif@v3 -> @v4
- softprops/action-gh-release@v1 -> @v2
- shivammathur/setup-php@v2 stays (no v3 released yet)
2026-03-15 12:41:13 +03:00
Divarion-D 1369b8fd20 ci: add security scan workflow with PHP syntax check and Semgrep
New GitHub Actions workflow that runs on push/PR to main and weekly:

1. PHP Syntax Check: validates all src/*.php files with php -l
2. Semgrep Security Scan: runs php, security-audit, command-injection,
   sql-injection, and xss rule packs against src/

SARIF results are uploaded to GitHub Code Scanning.
2026-03-15 12:28:34 +03:00
Divarion-D 279a10b4c5 Update Top Contributors 2025-12-03 21:50:32 +03:00
Divarion-D b4dbecebf3 Added auto editing of Top Contributors 2025-12-03 21:42:41 +03:00
Divarion-D cd637c9dde Fixed workflow 2025-12-03 18:26:27 +03:00
DanilandGitHub c09125d9c3 Added suport pre-release in Github Action 2025-11-20 19:46:16 +03:00
DanilandGitHub 9854fca0af Create build_pre-release.yml 2025-11-19 22:30:15 +03:00
Divarion-D cce768e39f Update release notifier 2025-09-30 19:38:07 +03:00
Divarion-D a214ef4754 add issue templates and add release notifier 2025-07-10 20:48:38 +03:00