fix: resolve all WordPress Plugin Check errors #28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| lint-js: | |
| name: Lint JS & CSS | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: '24' | |
| cache: 'npm' | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Lint JavaScript | |
| run: npm run lint:js | |
| - name: Lint CSS | |
| run: npm run lint:css | |
| - name: Audit npm dependencies | |
| # All npm packages are devDependencies (build tooling only — nothing ships | |
| # to WordPress). Audit only production deps to avoid false positives from | |
| # build tools like @wordpress/scripts that can't be patched without a | |
| # breaking downgrade. | |
| run: npm audit --audit-level=high --omit=dev | |
| lint-php: | |
| name: Lint PHP | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up PHP | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: '8.2' | |
| tools: composer | |
| coverage: none | |
| - name: Install Composer dependencies | |
| run: composer install --prefer-dist --no-progress | |
| - name: Run PHP_CodeSniffer | |
| run: composer lint | |
| - name: Audit Composer dependencies | |
| run: composer audit | |
| phpstan: | |
| name: PHPStan Static Analysis | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up PHP | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: '8.2' | |
| tools: composer | |
| coverage: none | |
| - name: Install Composer dependencies | |
| run: composer install --prefer-dist --no-progress | |
| - name: Run PHPStan | |
| run: php -d memory_limit=1G vendor/bin/phpstan analyse --no-progress | |
| test-php: | |
| name: PHP Tests (PHP ${{ matrix.php }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| php: ['8.2', '8.3'] | |
| services: | |
| mysql: | |
| image: mysql:8.0 | |
| env: | |
| MYSQL_ROOT_PASSWORD: root | |
| MYSQL_DATABASE: wordpress_test | |
| ports: | |
| - 3306:3306 | |
| options: >- | |
| --health-cmd="mysqladmin ping --silent" | |
| --health-interval=10s | |
| --health-timeout=5s | |
| --health-retries=5 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up PHP ${{ matrix.php }} | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: ${{ matrix.php }} | |
| extensions: mysqli, openssl | |
| tools: composer | |
| coverage: xdebug | |
| - name: Install Composer dependencies | |
| run: composer install --prefer-dist --no-progress | |
| - name: Install WordPress test suite | |
| run: | | |
| bash bin/install-wp-tests.sh wordpress_test root root 127.0.0.1 latest | |
| - name: Run PHPUnit with coverage | |
| run: composer test -- --coverage-clover coverage.xml | |
| - name: Upload coverage to Codecov | |
| if: matrix.php == '8.2' | |
| uses: codecov/codecov-action@v5 | |
| with: | |
| files: coverage.xml | |
| flags: phpunit | |
| fail_ci_if_error: false | |
| plugin-check: | |
| name: WordPress Plugin Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Set up PHP | |
| uses: shivammathur/setup-php@v2 | |
| with: | |
| php-version: '8.2' | |
| tools: composer | |
| coverage: none | |
| - name: Install Composer dependencies (production only) | |
| run: composer install --prefer-dist --no-progress --no-dev --optimize-autoloader | |
| - name: Build clean distribution directory | |
| # Mirrors what bin/build-zip.sh does: copy only production files so | |
| # dev tooling (bin/, tests/, .github/, .eslintrc.js, etc.) is absent | |
| # when plugin-check runs — those files must not be in a WP.org zip. | |
| run: | | |
| mkdir -p /tmp/plugin-dist/dispatch | |
| rsync -r --exclude-from=.distignore . /tmp/plugin-dist/dispatch/ | |
| - name: WordPress Plugin Check | |
| uses: wordpress/plugin-check-action@v1 | |
| with: | |
| build-dir: '/tmp/plugin-dist/dispatch' | |
| # plugin_readme — readme.txt is for wordpress.org listing, not runtime. | |
| # plugin_review_phpcs — covered by the dedicated lint-php job. | |
| # plugin_updater — false positive: the update hooks inject updates for | |
| # Telex-managed blocks/themes into WP's native update UI, not for | |
| # self-updating this plugin outside wordpress.org. | |
| exclude-checks: 'plugin_readme,plugin_review_phpcs,plugin_updater' |