v0.5.0
Added
- Signed releases. From this release on,
lockrot.phar.ascships next to the PHAR: a detached OpenPGP signature by the lockrot release key (39EC C3F6 4AE8 D06A 9A63 FD99 AB6F 7F52 AE51 3141, public half inlockrot-release-key.ascand onkeys.openpgp.org), together with a GitHub build-provenance attestation. The release workflow verifies its own signature against the committed public key before it publishes anything. Verify withgpg --verify lockrot.phar.asc lockrot.pharorgh attestation verify lockrot.phar --repo somework/lockrot;phive install somework/lockrot --trust-gpg-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141now works. The sha256 checksum andself-updateare unchanged:self-updatestill verifies the checksum only. See The standalone PHAR.
Fixed
- phpstan/phpstan is no longer
abandoned. A package is no longer flagged because an older release points at an archived repository. The repository asked about activity is the one the highest stable release names — itssource, else itssupport.source— then the lock entry's, and when none of those names one the package is judged without a repository-activity check (Packagist's ownabandonedflag still counts). phpstan/phpstan was reportedabandonedon every project that runs lockrot with a GitHub token: its recent releases carry nosource,support.sourcenames the live phpstan/phpstan-src, and three old releases point at a one-off build repository that has since been archived. Asupport.sourcein the shape Packagist fills in by default,<repository>/tree/<version>(or/src/<ref>on Bitbucket), is reduced to the repository first.
Full changelog: v0.4.0...v0.5.0