[web-downloads] main: Handle PHP SBOM sidecars during archiving

From: Date: Sun, 26 Jul 2026 12:51:48 +0000
Subject: [web-downloads] main: Handle PHP SBOM sidecars during archiving
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-33893@lists.php.net to get a copy of this message
Author: Shivam Mathur (shivammathur) Date: 2026-07-12T19:58:26+05:30 Commit: https://github.com/php/web-downloads/commit/e02e5403aed2243a72ffb3e89dc1f53a1e352d39 Raw diff: https://github.com/php/web-downloads/commit/e02e5403aed2243a72ffb3e89dc1f53a1e352d39.diff Handle PHP SBOM sidecars during archiving Changed paths: M src/Console/Command/PhpCommand.php M tests/Console/Command/PhpCommandTest.php Diff: diff --git a/src/Console/Command/PhpCommand.php b/src/Console/Command/PhpCommand.php index f2a7415..8d1c975 100644 --- a/src/Console/Command/PhpCommand.php +++ b/src/Console/Command/PhpCommand.php @@ -166,9 +166,16 @@ private function copyBuildsToArchive(string $directory, string $version): void foreach ($files as $file) { $fileVersion = $this->getFileVersion($file); if ($fileVersion) { - copy($directory . '/' . basename($file), $directory . '/archives/' . basename($file)); + copy($file, $directory . '/archives/' . basename($file)); + $sidecars = glob($file . '.*.json') ?: []; + foreach ($sidecars as $sidecar) { + copy($sidecar, $directory . '/archives/' . basename($sidecar)); + } if (version_compare($fileVersion, $version) < 0) { unlink($file); + foreach ($sidecars as $sidecar) { + unlink($sidecar); + } } } } diff --git a/tests/Console/Command/PhpCommandTest.php b/tests/Console/Command/PhpCommandTest.php index 62a0e9e..1beb4f9 100644 --- a/tests/Console/Command/PhpCommandTest.php +++ b/tests/Console/Command/PhpCommandTest.php @@ -48,6 +48,9 @@ public static function buildsProvider(): array return [ [[ 'php-8.4.1-Win32-vs17-x64.zip', + 'php-8.4.1-Win32-vs17-x64.zip.cdx.json', + 'php-8.4.1-Win32-vs17-x64.zip.spdx.json', + 'php-8.4.1-Win32-vs17-x64.zip.openvex.json', 'php-8.4.1-Win32-vs17-x86.zip', 'php-8.4.1-nts-Win32-vs17-x64.zip', 'php-8.4.1-nts-Win32-vs17-x86.zip', @@ -63,6 +66,8 @@ public static function buildsProvider(): array 'php-test-pack-8.4.1.zip', ]],[[ 'php-8.4.0-dev-Win32-vs17-x64.zip', + 'php-8.4.0-dev-Win32-vs17-x64.zip.cdx.json', + 'php-8.4.0-dev-Win32-vs17-x64.zip.spdx.json', 'php-8.4.0-dev-Win32-vs17-x86.zip', 'php-8.4.0-dev-nts-Win32-vs17-x64.zip', 'php-8.4.0-dev-nts-Win32-vs17-x86.zip', @@ -86,10 +91,14 @@ private function stageBuilds(array $phpZips, $zipPath): void if ($zip->open($zipPath, ZipArchive::CREATE) === TRUE) { foreach ($phpZips as $zipFileName) { $zipFilePath = $this->buildsDirectory . '/php/' . $zipFileName; - $innerZip = new ZipArchive(); - if ($innerZip->open($zipFilePath, ZipArchive::CREATE) === TRUE) { - $innerZip->addFromString("test_file.php", "<?php echo 'Hello, world!'; ?>"); - $innerZip->close(); + if (str_ends_with($zipFileName, '.json')) { + file_put_contents($zipFilePath, '{}'); + } else { + $innerZip = new ZipArchive(); + if ($innerZip->open($zipFilePath, ZipArchive::CREATE) === TRUE) { + $innerZip->addFromString("test_file.php", "<?php echo 'Hello, world!'; ?>"); + $innerZip->close(); + } } $zip->addFile($zipFilePath, $zipFileName); } @@ -112,8 +121,15 @@ public function testCommandHandlesSuccessfulExecution(array $phpZips): void $this->assertEquals(0, $result, "Command should return success."); - $expectedDestination = $this->baseDirectory . '/releases'; + $expectedDestination = $this->baseDirectory . (str_contains($phpZips[0], '-dev-') ? '/qa' : '/releases'); $this->assertDirectoryExists($expectedDestination, "Destination directory should exist."); + foreach (array_filter($phpZips, static fn (string $file): bool => str_ends_with($file, '.json')) as $sidecar) { + $this->assertFileExists($expectedDestination . '/' . $sidecar); + $this->assertFileExists($expectedDestination . '/archives/' . $sidecar); + } + $this->assertStringNotContainsString('.json', file_get_contents($expectedDestination . '/sha256sum.txt')); + $this->assertStringNotContainsString('.json', file_get_contents($expectedDestination . '/sha1sum.txt')); + $this->assertStringNotContainsString('.json', file_get_contents($expectedDestination . '/releases.json')); } public function testCommandHandlerWithMissingTestPackZip(): void

« previous php.webmaster (#33893) next »