Add php-tuf/composer-integration to core dependencies and governance β€” for experimental Automatic Updates & Project Browser modules

Created on 26 June 2023, 12 months ago
Updated 6 December 2023, 6 months ago

Problem/Motivation

This is a similar issue as πŸ“Œ Add php-tuf/composer-stager to core dependencies and governance β€” for experimental Automatic Updates & Project Browser modules Needs work but for the https://github.com/php-tuf/composer-integration library.

TODO: this issue summary needs to provide more details, like πŸ“Œ Add php-tuf/composer-stager to core dependencies and governance β€” for experimental Automatic Updates & Project Browser modules Needs work does.

How to test

Use https://github.com/php-tuf/drupal-project. (See the instructions on that page.)

It sets up a regular Drupal project, with Drush, and using PHP-TUF protection for packages on the staging server of packages.drupal.org. This means you can only install a subset of all the packages available for Drupal -- the top 150 modules/themes -- but it's enough to build a basic site and test.

Remaining tasks

Committing this is likely blocked on πŸ“Œ Add php-tuf/php-tuf to core governance β€” for experimental Automatic Updates & Project Browser modules Needs work which is itself blocked on 🌱 Security review of secure signing components for package manager Active , but code reviews and other required tasks can be happening in parallel in the meantime.

πŸ“Œ Task
Status

Needs work

Version

11.0 πŸ”₯

Component
BaseΒ  β†’

Last updated about 7 hours ago

Created by

πŸ‡ΊπŸ‡ΈUnited States effulgentsia

Live updates comments and jobs are added and updated live.
  • Needs framework manager review

    It is used to alert the framework manager core committer(s) that an issue significantly impacts (or has the potential to impact) multiple subsystems or represents a significant change or addition in architecture or public APIs, and their signoff is needed (see the governance policy draft for more information). If an issue significantly impacts only one subsystem, use Needs subsystem maintainer review instead, and make sure the issue component is set to the correct subsystem.

  • Needs release manager review

    It is used to alert the release manager core committer(s) that an issue significantly affects the overall technical debt or release timeline of Drupal, and their signoff is needed. See the governance policy draft for more information.

  • Needs issue summary update

    Issue summaries save everyone time if they are kept up-to-date. See Update issue summary task instructions.

Sign in to follow issues

Comments & Activities

Production build 0.69.0 2024