Skip to content

feat: check modules installed by Composer for updates - #439

Merged
ogorzalka merged 5 commits into
developfrom
feat/module-versions
Oct 8, 2026
Merged

ogorzalka merged 5 commits into
developfrom
feat/module-versions

Conversation

@ogorzalka

Copy link
Copy Markdown
Member

Step 6 of the modules specification. Stacked on #438 (itself on #437): retarget to develop once they are merged.

What changes

  • VersionSource contract (latest(), releaseUrl()), with ComposerRepositorySource ({url}/p2/{package}.json: Packagist, Private Packagist, Satis — highest stable version, not the first entry) and GitHubSource (latest release, else highest tag, optional token). VersionSources picks one from the root composer.json: a composer repository serving the package (its only), a GitHub vcs repository named after it, else Packagist.
  • PackageVersionChecker (Application layer): current(), cachedLatest() (never fetches), refresh() (fetches, transient pollora_latest_{sha1(package)}, 12 h, 1 h negative cache), isUpdateAvailable() (a dev-*/*-dev build never is).
  • ModuleVersions: a module whose real path is a Composer package's install path carries its version; local modules have none — no value, no check, no request (decision of 8 October).
  • Shown in: the Version column of Plugins › Modules ("1.3.0 · 1.4.0 available", release link, composer update vendor/package), a Site Health test "Pollora modules are up to date", pollora:status / --json (version, latest per module), and pollora:module:outdated (--json), which refreshes on demand.
  • Fetching: a daily WP-Cron event pollora_refresh_module_versions (scheduled from admin_init) — never during a front-end request.
  • The framework's own check (PackagistVersionChecker, VersionComparator) is left as it is: it works and has its tests; moving it onto ComposerRepositorySource can come later.

Verification

  • Pest: sources (p2 metadata, GitHub release/tags with token, source selection), cache and negative cache, dev builds, ModuleVersions with a real installed package's install path vs a local module, the Site Health test, the command, the Version cell.
  • pollora-test (linked to this branch, then restored): the view has the Version column, pollora:module:outdated says no module is installed by Composer, the daily event is scheduled (then removed).
  • Not done: the spec's "fixture module installed from a local Composer repository" check — it needs a change to pollora-test's composer.json/composer.lock, which hold uncommitted work. To do on a scratch project before the release.

Full suite 1954 passed; PHPStan, Rector, Pint, type coverage clean.

Step 6 of the modules specification: VersionSource (Composer repositories, GitHub), PackageVersionChecker with per-package cache, ModuleVersions matched by install path, the Version column, a Site Health test, pollora:module:outdated, a daily WP-Cron refresh and versions in pollora:status.
@ogorzalka
ogorzalka changed the base branch from feat/modules-admin to develop October 8, 2026 09:46
# Conflicts:
#	src/Modules/Infrastructure/Providers/ModuleServiceProvider.php
@ogorzalka
ogorzalka merged commit 1544d00 into develop Oct 8, 2026
11 checks passed
@ogorzalka
ogorzalka deleted the feat/module-versions branch October 8, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant