Skip to content

v0.5.0

Choose a tag to compare

@github-actions github-actions released this 17 Sep 06:53
· 280 commits to main since this release

Added

  • Signed releases. From this release on, lockrot.phar.asc ships next to the PHAR: a detached OpenPGP signature by the lockrot release key (39EC C3F6 4AE8 D06A 9A63 FD99 AB6F 7F52 AE51 3141, public half in lockrot-release-key.asc and on keys.openpgp.org), together with a GitHub build-provenance attestation. The release workflow verifies its own signature against the committed public key before it publishes anything. Verify with gpg --verify lockrot.phar.asc lockrot.phar or gh attestation verify lockrot.phar --repo somework/lockrot; phive install somework/lockrot --trust-gpg-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141 now works. The sha256 checksum and self-update are unchanged: self-update still verifies the checksum only. See The standalone PHAR.

Fixed

  • phpstan/phpstan is no longer abandoned. A package is no longer flagged because an older release points at an archived repository. The repository asked about activity is the one the highest stable release names — its source, else its support.source — then the lock entry's, and when none of those names one the package is judged without a repository-activity check (Packagist's own abandoned flag still counts). phpstan/phpstan was reported abandoned on every project that runs lockrot with a GitHub token: its recent releases carry no source, support.source names the live phpstan/phpstan-src, and three old releases point at a one-off build repository that has since been archived. A support.source in the shape Packagist fills in by default, <repository>/tree/<version> (or /src/<ref> on Bitbucket), is reduced to the repository first.

Full changelog: v0.4.0...v0.5.0