Skip to content

chore(deps): sync fork with upstream 2.0.0 [SQZLY-14423] - #6

Merged
aalwash merged 23 commits into
masterfrom
chore/sync-upstream-2.0.0
Sep 22, 2026
Merged

aalwash merged 23 commits into
masterfrom
chore/sync-upstream-2.0.0

Conversation

@aalwash

@aalwash aalwash commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Refs: SQZLY-14423

Summary

  • Merges cloudflare/cloudflare-php master (2.0.0) into the fork, bringing psr/http-message: ^1.0 || ^2.0 so consumers are no longer pinned to PSR-7 v1.
  • Reduces the fork to upstream + src/Endpoints/WorkersRoute.php, its only local addition — Guzzle 7, the PHP 8.1/8.2 bumps, the InvalidArgumentException import and the linter fixes have all since landed upstream.
  • Only breaking change in 2.0.0 is the PHP floor (7.2.5 → 8.1); consumers already require 8.3. Upstream suite passes (156 tests, 994 assertions), php-cs-fixer and phpmd clean.

🤖 Generated with Claude Code


Note

Medium Risk
Major-version dependency and PHP floor changes can break downstream consumers; new cache purge behavior only applies when $includeEnvironments is true.

Overview
This PR brings in cloudflare-php 2.0.0: the minimum PHP version is now 8.1, committed composer.lock is removed, and psr/http-message accepts v1 or v2 so installs are not stuck on PSR-7 v1.

Runtime tweaks include explicit nullable types in Guzzle::__construct() and Zones::cachePurge() (PHP 8.4), plus optional $includeEnvironments on cachePurgeEverything / cachePurge to purge cache via zone environment endpoints when enabled. Minor style fixes land in WorkersRoute.

CI and dev tooling are refreshed: lint runs on PHP 8.3 only; tests run on PHP 8.1–8.4 with a prefer-lowest matrix; Semgrep is added; Makefile / phpmd.xml / .php-cs-fixer.php replace older lint setup. Tests are updated for stricter PHPUnit mocking (adapter mocks with constructor args, FQCNs, renamed data providers).

Reviewed by Cursor Bugbot for commit e8438b5. Configure here.

PululuK and others added 22 commits May 30, 2022 03:17
Convert four implicit-nullable parameters to explicit nullable types:
- Adapter\Guzzle::__construct $baseURI
- Endpoints\Zones::cachePurge $files, $tags, $hosts

PHP 8.4 emits E_DEPRECATED for implicit nullables; PHP 9.0 will make them
fatal. Public method contracts are unchanged \xE2\x80\x94 the parameters were
already accepting null at runtime; this just declares it explicitly.

Refs: cloudflare#277
…lable

Fix PHP 8.4 implicit-nullable deprecations (cloudflare#277)
Add `composer require cloudflare/sdk` in how to install doc
- Upgrade actions/checkout and actions/cache from v2 to v4 (v2 is dead)
- Upgrade php-actions/composer from v5 to v6, drop Composer 1
- Remove PHP 7.3/7.4/8.0 from test matrix (minimum is now 8.1)
- Rename .php_cs to .php-cs-fixer.php (required by php-cs-fixer v3)
- Replace PhpCsFixer\Config::create() with new Config() (removed in v3)
- Update Makefile to reference new config filename
- Fix composer.json PHP constraint from >=7.3 to >=8.1
- Remove --no-suggest flag (removed in Composer 2)
- Fix cache key to hash composer.json instead of removed composer.lock
The --prefer-stable flag is only valid for composer update, not install.
Composer 2 enforces this strictly unlike Composer 1.
PHPMD MissingImport rule requires explicit use statements instead of
fully-qualified class names.
- Add phpmd.xml ruleset excluding MissingImport and StaticAccess rules
  (100+ pre-existing violations across test files, not worth fixing in
  bulk for an unmaintained codebase)
- Update Makefile to use the ruleset file instead of inline rule list
- Remove unused $authMock variables in DNSAnalyticsTest
ubuntu-20.04 runner image was removed by GitHub, causing jobs to queue
indefinitely.
fix: update CI workflows, linter config, and PHP version constraint
- Remove Travis CI badge (service shut down in 2021)
- Update title to drop PHP 7 reference
- Add PHP 8.1+ requirement section
- Add maintenance status note
- Fix API docs link to developers.cloudflare.com
- Remove dead Knowledge Base link
- Add CHANGELOG.md covering all 2.0.0 changes
…ngelog

docs: update README and add CHANGELOG for 2.0.0
Takes upstream's tree wholesale and re-applies src/Endpoints/WorkersRoute.php,
the fork's only local addition. Everything else the fork carried has since
landed upstream: Guzzle 7, PHP 8.1/8.2 requirements, the InvalidArgumentException
import and the linter fixes.

Brings in psr/http-message ^1.0 || ^2.0, which unpins PSR-7 for consumers.
Upstream's .php-cs-fixer.php config is stricter than the one the fork
carried. Whitespace only: if($script) -> if ($script).

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit e8438b5. Configure here.

uses: php-actions/composer@v5
uses: php-actions/composer@v6
env:
COMPOSER_PREFER_LOWEST: ${{ matrix.lowest }}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prefer-lowest CI installs incompatible PHPUnit

Low Severity

The new test matrix sets COMPOSER_PREFER_LOWEST while phpunit/phpunit is constrained to ^9.0. Prefer-lowest resolves PHPUnit 9.0, which does not define assertObjectHasProperty (added in 9.6.11) that the suite already calls, so the lowest=1 jobs fail.

Additional Locations (1)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit e8438b5. Configure here.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 0abb510 — the constraint bug is real, though the symptom isn't quite what's described here.

The lowest=1 jobs weren't failing — they were passing without testing anything. Composer only honours COMPOSER_PREFER_LOWEST on update; this workflow ran install, so the variable was inert and those four jobs silently re-resolved the highest versions, duplicating the lowest=0 jobs:

$ COMPOSER_PREFER_LOWEST=1 composer install
$ composer show phpunit/phpunit
versions : * 9.6.36     # highest, not lowest

So the matrix was reporting green for work it never did. The constraint problem was sitting behind that, latent — with prefer-lowest genuinely applied, ^9.0 resolves 9.3.0 and the suite errors 28 times on assertObjectHasProperty(), exactly as described.

The fix needed both halves: correcting only the constraint would have left the matrix still inert, and correcting only the workflow would have turned the PR red.

One correction worth flagging: ^9.6 is not a sufficient floor. assertObjectHasProperty() landed in 9.6.11, so prefer-lowest on ^9.6 resolves 9.6.0 and still fails. Measured both:

constraint prefer-lowest resolves result
^9.6 9.6.0 28 errors
^9.6.11 9.6.11 OK (156 tests, 994 assertions)

Landed as command: install → update and ^9.0 → ^9.6.11. Both arms now pass and genuinely differ — the lowest arm installs psr/http-message 1.1 and the highest 2.0, so this PR's ^1.0 || ^2.0 change is actually exercised across PHP 8.1–8.4 rather than merely asserted.

The test matrix set COMPOSER_PREFER_LOWEST, but composer only honours that
variable on 'update' -- the workflow ran 'install', so the lowest=1 jobs
silently resolved the highest versions and just duplicated the lowest=0 jobs.

Switching the command to 'update' makes those jobs test what they claim.
That exposes the constraint they were meant to catch: the suite calls
assertObjectHasProperty(), added in PHPUnit 9.6.11, while require-dev allowed
^9.0 -- prefer-lowest resolves 9.3.0 and 28 tests error out. ^9.6 is not
enough either, since 9.6.0 predates the method.

Both arms now pass, and the lowest arm covers psr/http-message 1.0 while the
highest covers 2.0, so the ^1.0 || ^2.0 constraint is actually exercised.
@aalwash
aalwash merged commit 92312cc into master Sep 22, 2026
10 checks passed
@aalwash
aalwash deleted the chore/sync-upstream-2.0.0 branch September 22, 2026 10:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants