PHPStan v0.12.90 releases: PHP Static Analysis Tool
PHPStan focuses on finding errors in your code without actually running it. It catches whole classes of bugs even before you write tests for the code. It moves PHP closer to compiled languages in the sense that the correctness of each line of the code can be checked before you run the actual line.
What it currently checks for?
- Existence of classes used in instanceof, catch, typehints and other language constructs. PHP does not check this and just stays instead, rendering the surrounded code unused.
- Existence and accessibility of called methods and functions. It also checks the number of passed arguments.
- Whether a method returns the same type it declares to return.
- Existence and visibility of accessed properties. It will also point out if a different type from the declared one is assigned to the property.
- The correct number of parameters passed to sprintf/printf calls based on format strings.
- Existence of variables while respecting scopes of branches and loops.
- Useless casting like (string) ‘foo’ and strict comparisons (=== and !==) with different types as operands which always result in false.
PHPStan is fast…
It manages to check the whole codebase in a single pass. It doesn’t need to go through the code multiple times. And it only needs to go through the code you wish to analyze, e.g. the code you have written. It doesn’t need to parse and analyze 3rd party dependencies. Instead, it uses reflection to find out useful information about somebody else’s code your codebase uses.
PHPStan is able to check our codebase (6000 files, 600k LOCs) in around a minute. And it checks itself under a second.
- Allow empty array shape (phpstan/phpstan-src@d36852a), #5159
- ClassReflection: option to make
getTraits()recursive (#557), thanks @IAmRGroot!
- Update BetterReflection with some performance optimizations (phpstan/phpstan-src@dce3c85)
Bleeding edge 🔪
If you want to see the shape of things to come and adopt bleeding edge features early, you can include this config file in your project’s
includes: - vendor/phpstan/phpstan/conf/bleedingEdge.neon
Of course, there are no backwards compatibility guarantees when you include this file. The behaviour and reported errors can change in minor versions with this file included. Learn more
- Revert “InstalledVersions.php no longer needs to be whitelisted” (phpstan/phpstan-src@b902c38), #5157
- Fix evaluating match arm conditions (phpstan/phpstan-src@7acf7ca), #5161
neverreturn type in PHPDoc wins over native type (phpstan/phpstan-src@2c976fb), #5089
ClosureTypetypeOnly description is just
- NonexistentOffsetInArrayDimFetchCheck – be less strict about
- ClosureType and CallableType – infer template types from callable parameters properly (phpstan/phpstan-src@efa6aa6, phpstan/phpstan-src@01f99c1), #3158
Function signature fixes 🤖
Copyright (c) 2016 Ondřej Mirtes