PluginBench
Skill
Pass
Audit score 90

laravel-verification

affaan-m/ecc

Comprehensive verification loop for Laravel projects: env checks, linting, static analysis, tests, security scans, and deployment readiness.

What is laravel-verification?

A structured multi-phase verification pipeline for Laravel projects that runs environment checks, code quality analysis, tests with coverage, security audits, database migrations, and deployment readiness checks. Use this before pull requests, after major changes, and pre-deployment to catch issues early.

  • Validates environment configuration and PHP/Composer versions
  • Runs code linting (Pint) and static analysis (PHPStan/Psalm)
  • Executes tests with optional coverage reporting via Xdebug
  • Audits dependencies for security vulnerabilities with composer audit
  • Previews database migrations and validates migration status
  • Caches configuration, routes, and views for production optimization

How to install laravel-verification

npx skills add null --skill laravel-verification
Prerequisites
  • Laravel project with Composer dependencies installed
  • PHP CLI and Composer available in the environment
  • Code quality tools installed: Pint (linting), PHPStan or Psalm (static analysis)
  • Test suite configured with PHPUnit or Pest
  • Optional: Xdebug for coverage reporting, Horizon for queue monitoring
Claude Code
Cursor
Windsurf
Cline

How to use laravel-verification

  1. 1.Run Phase 1 environment checks: verify PHP, Composer, and Laravel versions, plus .env configuration
  2. 2.Run Phase 1.5 Composer validation and autoload optimization
  3. 3.Run Phase 2 linting and static analysis with Pint and PHPStan/Psalm
  4. 4.Run Phase 3 tests with php artisan test, optionally with coverage
  5. 5.Run Phase 4 security audit with composer audit
  6. 6.Run Phase 5 migration preview and status checks
  7. 7.Run Phase 6 cache warmup and optimization commands
  8. 8.Run Phase 7 queue and scheduler verification

Use cases

Good for
  • Pre-pull-request verification to ensure code quality and test coverage
  • Post-dependency-upgrade validation to catch breaking changes and security issues
  • Pre-deployment checks for staging or production environments
  • CI/CD pipeline integration with full linting, testing, and security scanning
  • Queue and scheduler health verification before release
Who it's for
  • Laravel developers preparing code for review or deployment
  • DevOps engineers setting up CI/CD pipelines for Laravel applications
  • Teams requiring comprehensive pre-deployment verification
  • Projects with strict code quality and security standards

laravel-verification FAQ

Can I run just a subset of phases?

Yes. The minimal flow includes environment checks, linting, static analysis, tests, security audit, migration preview, and queue checks. Customize based on your needs, but always run Phase 1 first.

How do I enable test coverage reporting?

Set XDEBUG_MODE=coverage and run php artisan test --coverage. Requires Xdebug installed and configured.

What should I do if a migration fails the --pretend check?

Review the migration file for syntax errors or unsafe operations. Ensure down() methods are reversible and follow the Y_m_d_His_* naming convention. Test locally before deploying.

Can I use this in CI/CD pipelines?

Yes. The CI-style pipeline example shows a complete sequence suitable for GitHub Actions, GitLab CI, or similar platforms.

What if my project uses Psalm instead of PHPStan?

Replace vendor/bin/phpstan analyse with vendor/bin/psalm in Phase 2. Both tools perform static analysis; use whichever your project is configured for.

Full instructions (SKILL.md)

Source of truth, from affaan-m/ecc.


name: laravel-verification description: "Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness." metadata: origin: ECC

Laravel Verification Loop

Run before PRs, after major changes, and pre-deploy.

When to Use

  • Before opening a pull request for a Laravel project
  • After major refactors or dependency upgrades
  • Pre-deployment verification for staging or production
  • Running full lint -> test -> security -> deploy readiness pipeline

How It Works

  • Run phases sequentially from environment checks through deployment readiness so each layer builds on the last.
  • Environment and Composer checks gate everything else; stop immediately if they fail.
  • Linting/static analysis should be clean before running full tests and coverage.
  • Security and migration reviews happen after tests so you verify behavior before data or release steps.
  • Build/deploy readiness and queue/scheduler checks are final gates; any failure blocks release.

Phase 1: Environment Checks

php -v
composer --version
php artisan --version
  • Verify .env is present and required keys exist
  • Confirm APP_DEBUG=false for production environments
  • Confirm APP_ENV matches the target deployment (production, staging)

If using Laravel Sail locally:

./vendor/bin/sail php -v
./vendor/bin/sail artisan --version

Phase 1.5: Composer and Autoload

composer validate
composer dump-autoload -o

Phase 2: Linting and Static Analysis

vendor/bin/pint --test
vendor/bin/phpstan analyse

If your project uses Psalm instead of PHPStan:

vendor/bin/psalm

Phase 3: Tests and Coverage

php artisan test

Coverage (CI):

XDEBUG_MODE=coverage php artisan test --coverage

CI example (format -> static analysis -> tests):

vendor/bin/pint --test
vendor/bin/phpstan analyse
XDEBUG_MODE=coverage php artisan test --coverage

Phase 4: Security and Dependency Checks

composer audit

Phase 5: Database and Migrations

php artisan migrate --pretend
php artisan migrate:status
  • Review destructive migrations carefully
  • Ensure migration filenames follow Y_m_d_His_* (e.g., 2025_03_14_154210_create_orders_table.php) and describe the change clearly
  • Ensure rollbacks are possible
  • Verify down() methods and avoid irreversible data loss without explicit backups

Phase 6: Build and Deployment Readiness

php artisan optimize:clear
php artisan config:cache
php artisan route:cache
php artisan view:cache
  • Ensure cache warmups succeed in production configuration
  • Verify queue workers and scheduler are configured
  • Confirm storage/ and bootstrap/cache/ are writable in the target environment

Phase 7: Queue and Scheduler Checks

php artisan schedule:list
php artisan queue:failed

If Horizon is used:

php artisan horizon:status

If queue:monitor is available, use it to check backlog without processing jobs:

php artisan queue:monitor default --max=100

Active verification (staging only): dispatch a no-op job to a dedicated queue and run a single worker to process it (ensure a non-sync queue connection is configured).

php artisan tinker --execute="dispatch((new App\\Jobs\\QueueHealthcheck())->onQueue('healthcheck'))"
php artisan queue:work --once --queue=healthcheck

Verify the job produced the expected side effect (log entry, healthcheck table row, or metric).

Only run this on non-production environments where processing a test job is safe.

Examples

Minimal flow:

php -v
composer --version
php artisan --version
composer validate
vendor/bin/pint --test
vendor/bin/phpstan analyse
php artisan test
composer audit
php artisan migrate --pretend
php artisan config:cache
php artisan queue:failed

CI-style pipeline:

composer validate
composer dump-autoload -o
vendor/bin/pint --test
vendor/bin/phpstan analyse
XDEBUG_MODE=coverage php artisan test --coverage
composer audit
php artisan migrate --pretend
php artisan optimize:clear
php artisan config:cache
php artisan route:cache
php artisan view:cache
php artisan schedule:list