Skip to content

Bump silverassist/wp-github-updater from 1.3.1 to 1.4.0 - #28

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/silverassist/wp-github-updater-1.4.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/composer/silverassist/wp-github-updater-1.4.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps silverassist/wp-github-updater from 1.3.1 to 1.4.0.

Release notes

Sourced from silverassist/wp-github-updater's releases.

WP GitHub Updater v1.4.0

What's New in v1.4.0

Added

  • Private repositories. The updater reads the releases of a private GitHub repository with a token. The token_constant option (default SILVER_GITHUB_TOKEN) names a PHP constant or environment variable, and UpdaterConfig::getGithubToken() returns it, trimmed, or null. It is never read from the database.
  • The token is sent as Authorization: Bearer to api.github.com only. A private asset is downloaded through its API URL in two steps: the first request carries the token and stops at GitHub's redirect, the second goes to the signed storage URL without the token. A redirect that is not https is refused.
  • Failed requests log a distinct message for 401, 403 and 404, with and without a token, naming the constant to check. The token is never logged, and a failed version lookup is not cached.
  • Tests on the real WordPress Test Suite that intercept requests with the pre_http_request filter, and an opt-in live test against a private repository (WPGU_LIVE_REPO, WPGU_LIVE_VERSION, SILVER_GITHUB_TOKEN).
  • ci.yml runs on every pull request and push to main: PHPCS, PHPStan and composer validate --strict, the full PHPUnit suite on the real WordPress Test Suite (PHP 8.2, 8.3 and 8.4), and the unit and integration suites without WordPress. Until now the tests only ran when a release tag was pushed.

Fixed

  • composer phpstan crashed on the default 128 MB PHP memory limit. It now runs with --memory-limit=512M.
  • 29 PHPStan level 8 errors, and an ignoreErrors pattern that no longer matched, so composer check passes again.
  • download_link in the plugin information is empty, instead of a broken URL, when the version lookup fails.
  • pluginInfo() and checkForUpdate() no longer raise a warning on a missing slug or a transient that is not an object.
  • The Markdown to HTML conversion keeps the original text when a regular expression fails, instead of dropping it.

Changed

  • Documentation, class descriptions and the package description no longer say "public GitHub releases".
  • ci.yml and create-release.yml pass the COMPOSER_AUTH secret to composer install, because the SilverAssist development dependencies are resolved from GitHub.

Documentation

  • The README listed 8.3 as the default of requires_php, the code defaults to 8.2.

📦 Package Information

  • Package Name: wp-github-updater
  • Version: 1.4.0
  • Namespace: SilverAssist\WpGithubUpdater
  • License: PolyForm Noncommercial 1.0.0
  • PHP Version: 8.2+
  • WordPress Version: 6.0+

🚀 Installation via Composer

Declare the repository as a Composer vcs repository first (see README).

composer require silverassist/wp-github-updater:^1.4.0

📋 Basic Usage

use SilverAssist\WpGithubUpdater\UpdaterConfig;
use SilverAssist\WpGithubUpdater\Updater;
// Configure the updater
$config = new UpdaterConfig(FILE, 'owner/repository', [
</tr></table>

... (truncated)

Changelog

Sourced from silverassist/wp-github-updater's changelog.

[1.4.0] - 2026-09-25

Added

  • Private repositories. The updater reads the releases of a private GitHub repository with a token. The token_constant option (default SILVER_GITHUB_TOKEN) names a PHP constant or environment variable, and UpdaterConfig::getGithubToken() returns it, trimmed, or null. It is never read from the database.
  • The token is sent as Authorization: Bearer to api.github.com only. A private asset is downloaded through its API URL in two steps: the first request carries the token and stops at GitHub's redirect, the second goes to the signed storage URL without the token. A redirect that is not https is refused.
  • Failed requests log a distinct message for 401, 403 and 404, with and without a token, naming the constant to check. The token is never logged, and a failed version lookup is not cached.
  • Tests on the real WordPress Test Suite that intercept requests with the pre_http_request filter, and an opt-in live test against a private repository (WPGU_LIVE_REPO, WPGU_LIVE_VERSION, SILVER_GITHUB_TOKEN).
  • ci.yml runs on every pull request and push to main: PHPCS, PHPStan and composer validate --strict, the full PHPUnit suite on the real WordPress Test Suite (PHP 8.2, 8.3 and 8.4), and the unit and integration suites without WordPress. Until now the tests only ran when a release tag was pushed.

Fixed

  • composer phpstan crashed on the default 128 MB PHP memory limit. It now runs with --memory-limit=512M.
  • 29 PHPStan level 8 errors, and an ignoreErrors pattern that no longer matched, so composer check passes again.
  • download_link in the plugin information is empty, instead of a broken URL, when the version lookup fails.
  • pluginInfo() and checkForUpdate() no longer raise a warning on a missing slug or a transient that is not an object.
  • The Markdown to HTML conversion keeps the original text when a regular expression fails, instead of dropping it.

Changed

  • Documentation, class descriptions and the package description no longer say "public GitHub releases".
  • ci.yml and create-release.yml pass the COMPOSER_AUTH secret to composer install, because the SilverAssist development dependencies are resolved from GitHub.

Documentation

  • The README listed 8.3 as the default of requires_php, the code defaults to 8.2.

[1.3.2] - 2026-09-25

Changed

  • Declared vcs repositories for the SilverAssist development dependencies (coding-standards), so contributors and CI resolve them from GitHub instead of Packagist.org.

Documentation

  • Documented installing this package through a Composer vcs repository with a GitHub token, instead of Packagist.org (README, "Installing via Composer").
  • Release notes and the Copilot instructions no longer point at Packagist as the distribution channel.
Commits
  • e8f250a WEB-1194: Read releases from private repositories with a token (1.4.0) (#34)
  • 5d6cb20 WEB-1194: Add Composer vcs repositories and install docs (#33)
  • a9b96a5 chore: strip AI attribution trailers from commit messages automatically
  • 5ed0619 chore(deps): bump softprops/action-gh-release (#32)
  • 032b8c7 chore: Remove hardcoded version field from composer.json (#31)
  • 12ad374 Adopt silverassist/coding-standards for PHPCS (#30)
  • 03efe7d chore(deps): bump actions/checkout in the github-actions-updates group (#29)
  • 8e2768c chore(deps): bump softprops/action-gh-release (#28)
  • b0a2604 chore(deps): bump dependabot/fetch-metadata from 2 to 3 (#26)
  • ec2a77a chore(deps): bump actions/cache from 5 to 6 (#27)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [silverassist/wp-github-updater](https://github.com/SilverAssist/wp-github-updater) from 1.3.1 to 1.4.0.
- [Release notes](https://github.com/SilverAssist/wp-github-updater/releases)
- [Changelog](https://github.com/SilverAssist/wp-github-updater/blob/main/CHANGELOG.md)
- [Commits](SilverAssist/wp-github-updater@v1.3.1...v1.4.0)

---
updated-dependencies:
- dependency-name: silverassist/wp-github-updater
  dependency-version: 1.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file php Pull requests that update php code labels Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants