PHPStan v0.12.99 releases: PHP Static Analysis Tool
PHPStan focuses on finding errors in your code without actually running it. It catches whole classes of bugs even before you write tests for the code. It moves PHP closer to compiled languages in the sense that the correctness of each line of the code can be checked before you run the actual line.
What it currently checks for?
- Existence of classes used in instanceof, catch, typehints and other language constructs. PHP does not check this and just stays instead, rendering the surrounded code unused.
- Existence and accessibility of called methods and functions. It also checks the number of passed arguments.
- Whether a method returns the same type it declares to return.
- Existence and visibility of accessed properties. It will also point out if a different type from the declared one is assigned to the property.
- The correct number of parameters passed to sprintf/printf calls based on format strings.
- Existence of variables while respecting scopes of branches and loops.
- Useless casting like (string) ‘foo’ and strict comparisons (=== and !==) with different types as operands which always result in false.
PHPStan is fast…
It manages to check the whole codebase in a single pass. It doesn’t need to go through the code multiple times. And it only needs to go through the code you wish to analyze, e.g. the code you have written. It doesn’t need to parse and analyze 3rd party dependencies. Instead, it uses reflection to find out useful information about somebody else’s code your codebase uses.
PHPStan is able to check our codebase (6000 files, 600k LOCs) in around a minute. And it checks itself under a second.
CompoundTypeHelperis deprecated (phpstan/phpstan-src@fff85f3)
- Add support for multiple wildcards in const type annotations (#658), #5534,thanks @Seldaek!
Bleeding edge 🔪
MissingReturnRule– make the error non-ignorable for native typehints (phpstan/phpstan-src@9ecefd5)
- Check callable parameter types for
array_filter()calls, #5609, #5356, #1954
VariableCertaintyInIssetRuledoes (phpstan/phpstan-src@9689fbd), #970
- Check that function with
@throws voiddoes not have an explicit throw point (phpstan/phpstan-src@8b3382a)
If you want to see the shape of things to come and adopt bleeding edge features early, you can include this config file in your project’s
includes: - vendor/phpstan/phpstan/conf/bleedingEdge.neon
Of course, there are no backwards compatibility guarantees when you include this file. The behaviour and reported errors can change in minor versions with this file included. Learn more
- Fix false-positive when merging unions with plus operator (#657), #5584, thanks @staabm!
checkExplicitMixed– replace mixed type recursively (phpstan/phpstan-src@b4f81db), #5218
BaselineNeonErrorFormatter: Sort errors by normalized relative path (#536), #5085, thanks @dktapps!
- Enter assignment of property fetch’s var when in null coalesce operator (phpstan/phpstan-src@7ddfa17), #3283
- Pass-by-ref argument type passed to callable should be mixed after calling the callable (phpstan/phpstan-src@109bf99), #5615, #5428, #2191
StubSourceLocatorFactory– always use PHP 8 parser for PhpStorm stubs (phpstan/phpstan-src@731ce1d)
- support unary-minus on
IntegerRangeType(#669), thanks @staabm!
array_map– understand call with multiple arrays (phpstan/phpstan-src@3e0ecec), #5039
numeric-strings can produce array of float|int (phpstan/phpstan-src@3b6f0bf)
Function signature fixes 🤖
- Fix parameter definition for
Grpc\ChannelCredentials::createSsl(#665), thanks @howyi!
SimpleXMLElementstub more specific (#666), thanks @devbanana!
Copyright (c) 2016 Ondřej Mirtes