From 95c5f6a1f17bc30f8b8943edc3ba65bc1e1fb7aa Mon Sep 17 00:00:00 2001 From: Jeremy Massel <1123407+jkmassel@users.noreply.github.com> Date: Tue, 8 Sep 2026 10:30:58 -0600 Subject: [PATCH] build: pin the wp-env WordPress core and plugin versions MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `.wp-env.json` pointed at `latest.zip` and unversioned plugin zips, so every CI run installed whatever shipped that day. A third-party release could therefore turn every open PR red without a line of code changing, and did: a Jetpack release began bundling `@wordpress/ui` 0.21, whose ThemeProvider shim reads `window.wp.theme` at module-evaluation time and throws when it is missing, so no Jetpack block registered and the third-party block E2E tests failed on every branch predating #614. Pin all three to the versions CI is passing with today. The trade is a manual bump — nothing watches these, since Dependabot does not read `.wp-env.json` — in exchange for an upgrade being a reviewable change with an attributable failure rather than a surprise on an unrelated PR. --- .wp-env.json | 6 +++--- docs/code/local-wordpress.md | 24 ++++++++++++++++++++++++ 2 files changed, 27 insertions(+), 3 deletions(-) diff --git a/.wp-env.json b/.wp-env.json index 0dc65da8d..37694f149 100644 --- a/.wp-env.json +++ b/.wp-env.json @@ -1,8 +1,8 @@ { - "core": "https://wordpress.org/latest.zip", + "core": "https://wordpress.org/wordpress-7.1.zip", "plugins": [ - "https://downloads.wordpress.org/plugin/gutenberg.zip", - "https://downloads.wordpress.org/plugin/jetpack.zip" + "https://downloads.wordpress.org/plugin/gutenberg.23.9.1.zip", + "https://downloads.wordpress.org/plugin/jetpack.16.1.3.zip" ], "mappings": { "wp-content/mu-plugins": "./wp-env/mu-plugins" diff --git a/docs/code/local-wordpress.md b/docs/code/local-wordpress.md index 6b9665c83..716a12c3e 100644 --- a/docs/code/local-wordpress.md +++ b/docs/code/local-wordpress.md @@ -47,6 +47,30 @@ The `.wp-env.json` file at the project root configures the environment: - A **CORS mu-plugin** (`wp-env/mu-plugins/gutenbergkit-cors.php`) adds CORS headers to REST API responses, allowing requests from the Vite dev server, preview server, and native WebViews. - **WP_DEBUG** and **WP_DEBUG_LOG** are enabled for development. +WordPress core and both plugins are **pinned to explicit versions**. wp-env +downloads whatever the URL resolves to, so unpinned URLs mean every CI run +installs whatever shipped that day — and a third-party release can turn every +open PR red without a line of code changing. That has happened: a Jetpack +release began requiring `window.wp.theme`, and until #614 exposed it, no +Jetpack block registered and the third-party block E2E tests failed on every +branch that predated the fix. + +Pinning trades that for a manual bump. Nothing watches these versions — +Dependabot does not read `.wp-env.json` — so raise them deliberately, in their +own PR, where a failure is attributable to the upgrade rather than to whatever +else is in flight: + +```json +"core": "https://wordpress.org/wordpress-.zip", +"plugins": [ + "https://downloads.wordpress.org/plugin/gutenberg..zip", + "https://downloads.wordpress.org/plugin/jetpack..zip" +] +``` + +Bumping requires `make wp-env-start RESET=1`, since an existing environment +keeps the version it was created with. + ### Credential Provisioning The `bin/wp-env-setup.sh` script runs automatically after `wp-env start`: