Skip to content

Switch Plugin Check CI to official plugin-check-action - #294

Merged
davidperezgar merged 4 commits into
trunkfrom
feature/plugin-check-action
Sep 7, 2026
Merged

davidperezgar merged 4 commits into
trunkfrom
feature/plugin-check-action

Conversation

@davidperezgar

@davidperezgar davidperezgar commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Swap the manual wp-cli/SQLite Plugin Check bootstrap in .github/workflows/plugin-check.yml for the official WordPress/plugin-check-action@v1, which handles the wp-env/WordPress setup itself.
  • Configure error-severity: 7 and warning-severity: 8 thresholds.
  • Keep exclude-directories: vendor,node_modules,tests and the existing trigger/concurrency rules unchanged.

Test plan

  • Confirm the Plugin Check workflow run passes on this PR
  • Confirm results are gated at error severity 7 / warning severity 8 as expected

Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com

Open WordPress Playground Preview

Replace the manual wp-cli/SQLite bootstrap with WordPress/plugin-check-action@v1,
which handles the wp-env/WordPress setup itself. Gate results with
error-severity=7 and warning-severity=8 thresholds.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@github-actions

github-actions Bot commented Sep 6, 2026 •

Copy link
Copy Markdown

✅ WordPress Plugin Check Report

✅ Status: Passed

📊 Report

All checks passed! No errors or warnings found.


🤖 Generated by WordPress Plugin Check Action • Learn more about Plugin Check

davidperezgar and others added 3 commits September 6, 2026 14:05
The first Plugin Check run flagged 9 dev-only files/dirs already stripped
from the distributed plugin via .distignore (.github, bin/, .npmrc,
.phpcs.xml.dist, phpstan.neon.dist, phpunit.xml.dist, .gitignore,
.distignore, AGENTS.md, CLAUDE.md) as hidden_files/application_detected/
unexpected_markdown_file errors and warnings. Exclude them from the scan
via exclude-directories/exclude-files.

Also add .pcpignore, ready for when Plugin Check ships its opt-in
--use-pcpignore flag (WordPress/plugin-check#1459, PR #1460), so local
and WP-CLI scans can skip the same non-distributed paths without
per-invocation flags.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- register_setting() now sanitizes formscrm_slack_webhook_url (esc_url_raw)
  and formscrm_error_notification_email (sanitize_email) instead of
  accepting raw input.
- Bump readme.txt "Tested up to" to 7.1 (current WP release).
- Exclude .pcpignore itself from the scan and .distignore, since it's a
  dev-only file like .gitignore.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
sanitize_email() strips commas, which would break the documented
comma-separated multi-recipient feature (readme.txt "you can add
multiple emails separated by commas", consumed as-is by wp_mail() in
helpers-functions.php). Sanitize and validate each address separately
instead, dropping invalid ones, and keep the list joined by commas.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@davidperezgar
davidperezgar merged commit 0c3d968 into trunk Sep 7, 2026
8 checks passed
@davidperezgar
davidperezgar deleted the feature/plugin-check-action branch September 7, 2026 06:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant