GitLab CI

Back to the README

The package ships the jobs, so a project includes them instead of pasting them:

include:
  - project: 'FestiCore/php_festi_codingstandard'
    ref: '1.3.0'
    file: '/ci/static-analysis.gitlab-ci.yml'

variables:
  FESTI_RUNNER_TAG: "php8.1"   # required
Job Blocks a merge request? Runs on Does
festi:phpcs:changed yes merge requests festi-phpcs-diff: errors in the code the branch changed, complexity only where the branch raised it
festi:phpcs:full no the default branch phpcs over the whole tree, to keep the backlog visible
festi:phan yes merge requests and the default branch Phan with the project's .phan/config.php
festi:phpmd no merge requests and the default branch class size and coupling over the whole tree

Three things to get right

Set FESTI_RUNNER_TAG. Every runner on gitlab.varteq.com is tagged. A job whose tag no runner serves is never picked up: it sits pending and fails as stuck_pending_no_matching_runners, which looks like a hung pipeline rather than a failed check. Set the variable once; do not override tags per job.

Name a ref that exists. Tags on this project carry no v prefix (1.3.0, not v1.3.0). An include: with a ref that does not exist fails when the pipeline is created, so no job runs at all.

Give the project read access to FestiCore/php_festi_codingstandard, or the include cannot be fetched.

Variables

Variable Default Meaning
FESTI_RUNNER_TAG php8.1 Tag of the runner that takes the jobs.
FESTI_PHPCS_PATHS ./ What phpcs looks at.
FESTI_PHPCS_IGNORE vendor/**,public/**,**/themes/**,.phan/** phpcs ignore patterns.
FESTI_PHPCS_STANDARD Festi Set to phpcs.xml when the project has its own ruleset.
FESTI_PHAN_CONFIG .phan/config.php The project's Phan configuration.
FESTI_PHPMD_PATHS ./ What PHPMD measures.
FESTI_PHPMD_EXCLUDE vendor/*,tests/* PHPMD exclude patterns.
FESTI_PHPMD_RULESET the shipped phpmd/ruleset.xml Set to phpmd.xml when the project has its own ruleset.

The jobs set GIT_DEPTH: 0, because the changed-lines job needs the merge base and GitLab clones shallow by default.

Fitting the jobs into a pipeline

The jobs use the test stage. Override it per job when the pipeline has none:

festi:phpcs:changed:
  stage: analysis

To run the whole toolchain as one job instead, call festi-quality yourself. --strict makes it fail on an issue, --only chooses the tools:

quality:changed:
  stage: test
  tags: ["php8.1"]
  variables:
    GIT_DEPTH: 0
  script:
    - composer install --no-interaction --prefer-dist --no-progress
    - vendor/bin/festi-quality --diff --strict --list --only=phpcs,phpmd,phan
  rules:
    - if: $CI_PIPELINE_SOURCE == "merge_request_event"

Note the difference from festi:phpcs:changed: this also gates on PHPMD's class measures and on Phan, and under --strict a warning fails the job too.

SonarQube

The scan is the project's own job; this package only reads its result. A minimal one:

sonar:
  stage: test
  image:
    name: sonarsource/sonar-scanner-cli:11
    entrypoint: [""]
  variables:
    GIT_DEPTH: 0
  script:
    - sonar-scanner

It reads sonar-project.properties from the project root and its token from the SONAR_TOKEN CI variable. Do not pass the token on the command line.