Skip to content

Conversation

@samdark
Copy link
Member

@samdark samdark commented Dec 25, 2025

Q A
Is bugfix?
New feature?
Breaks BC?
Fixed issues -

Copilot AI review requested due to automatic review settings December 25, 2025 20:55
@codecov
Copy link

codecov bot commented Dec 25, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 76.96%. Comparing base (07cc123) to head (9af4a41).
⚠️ Report is 3 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff            @@
##             master     #423   +/-   ##
=========================================
  Coverage     76.96%   76.96%           
  Complexity       29       29           
=========================================
  Files            11       11           
  Lines           178      178           
=========================================
  Hits            137      137           
  Misses           41       41           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR attempts to upgrade the Docker base image from PHP 8.2 to PHP 8.5 for the FrankenPHP-based application. However, this change is problematic as PHP 8.5 has not been released yet.

Key Change:

  • Updates the base Docker image from dunglas/frankenphp:1-php8.2-bookworm to dunglas/frankenphp:1-php8.5-bookworm

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

FROM composer/composer:2-bin AS composer

FROM dunglas/frankenphp:1-php8.2-bookworm AS base
FROM dunglas/frankenphp:1-php8.5-bookworm AS base
Copy link

Copilot AI Dec 25, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The base image dunglas/frankenphp:1-php8.5-bookworm is referenced only by a mutable tag, which makes the build dependent on whatever image is pushed to that tag in the future. If the upstream registry or image owner is compromised, an attacker could publish a malicious image under the same tag and your builds would consume it without any Dockerfile changes. To reduce supply chain risk, pin this dependency to an immutable image digest and, if possible, verify its provenance in your build pipeline.

Copilot uses AI. Check for mistakes.
Copy link
Member

@vjik vjik left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why? Minimal PHP version for template is 8.2.

@samdark
Copy link
Member Author

samdark commented Dec 26, 2025

Mainly because of initial installation using composer from Docker https://yiisoft.github.io/docs/guide/start/creating-project.html

docker run --rm -it -v "$(pwd):/app" composer/composer create-project yiisoft/app your_project
sudo chown -R $(id -u):$(id -g) your_project

In this case composer has PHP 8.5 inside so it creates the app with dependencies targeted for 8.5.

@samdark
Copy link
Member Author

samdark commented Dec 26, 2025

composer/composer#12691

@samdark
Copy link
Member Author

samdark commented Dec 26, 2025

Solved with additional make composer update in the guide for now.

@samdark samdark closed this Dec 26, 2025
@samdark samdark deleted the php85 branch December 26, 2025 18:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants