-
Notifications
You must be signed in to change notification settings - Fork 500
Add PHPStan static analysis (level 5) with a baseline and CI job #1089
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
whyisjake
wants to merge
7
commits into
WordPress:develop
Choose a base branch
from
whyisjake:try/phpstan
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
7 commits
Select commit
Hold shift + click to select a range
9f55a62
Add PHPStan configuration at level 5 for the src directory
whyisjake 2249e3c
PHPStan: fix four type findings and baseline the remainder
whyisjake e753e78
CI: run PHPStan in the CS workflow
whyisjake 4375c5f
PHPStan: drop the baseline, analyse all code, list ignores explicitly
whyisjake 1581dbe
PHPStan: fix reported type issues in the library
whyisjake 377aa34
PHPStan: fix reported issues in the test suite
whyisjake aa66761
PHPStan: silence the PSR-0 deprecation during analysis; cover float t…
whyisjake File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,14 @@ | ||
| <?php | ||
| /** | ||
| * Bootstrap file for PHPStan. | ||
| * | ||
| * The Composer autoloader registers the autoloader for the deprecated PSR-0 `Requests_*` class | ||
| * names (see library/Deprecated.php). When PHPStan reflects on those class names, which the | ||
| * autoloader tests reference, that autoloader triggers an E_USER_DEPRECATED notice, which PHPStan | ||
| * reports as an internal error. The constant below is the documented way to silence the notice and | ||
| * only affects the analysis run. | ||
| */ | ||
|
|
||
| if (defined('REQUESTS_SILENCE_PSR0_DEPRECATIONS') === false) { | ||
| define('REQUESTS_SILENCE_PSR0_DEPRECATIONS', true); | ||
| } |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,164 @@ | ||
| parameters: | ||
| level: 5 | ||
| bootstrapFiles: | ||
| - phpstan-bootstrap.php | ||
| - tests/bootstrap.php | ||
| paths: | ||
| - build/ghpages | ||
| - examples | ||
| - library | ||
| - src | ||
| - tests | ||
| excludePaths: | ||
| analyse: | ||
| - build/ghpages/vendor (?) | ||
| # Externally maintained file (based on the SimplePie IRI class), not held to this project's standards. | ||
| - src/Iri.php | ||
| treatPhpDocTypesAsCertain: false | ||
|
|
||
| ignoreErrors: | ||
| # The library supports PHP 5.6+, where cURL handles are resources. PHPStan analyses against the | ||
| # PHP 8 stubs, in which curl_close() only accepts a CurlHandle object and the resource type can | ||
| # never occur. | ||
| - | ||
| identifier: argument.type | ||
| message: '#function curl_close expects CurlHandle, resource given#' | ||
| path: src/Transport/Curl.php | ||
| - | ||
| identifier: argument.type | ||
| message: '#function curl_close expects CurlHandle, resource given#' | ||
| path: tests/Utility/InputValidator/IsCurlHandleTest.php | ||
| - | ||
| identifier: property.unusedType | ||
| message: '#is never assigned resource#' | ||
| path: src/Transport/Curl.php | ||
| - | ||
| identifier: property.unusedType | ||
| message: '#is never assigned resource#' | ||
| path: tests/Utility/InputValidator/IsCurlHandleTest.php | ||
|
|
||
| # OPENSSL_TLSEXT_SERVER_NAME is only defined when OpenSSL is compiled with SNI support; the guard | ||
| # is needed on older PHP builds even though it is always true on the PHP version running PHPStan. | ||
| - | ||
| identifier: booleanAnd.rightAlwaysTrue | ||
| path: src/Transport/Fsockopen.php | ||
|
|
||
| # PHPStan's stub for spl_autoload_register() declares the callback as returning void. PHP ignores | ||
| # the return value, and the Requests autoloaders return bool to report whether a class was loaded. | ||
| - | ||
| identifier: argument.type | ||
| message: '#function spl_autoload_register expects#' | ||
| path: src/Autoload.php | ||
| - | ||
| identifier: argument.type | ||
| message: '#function spl_autoload_register expects#' | ||
| path: tests/bootstrap.php | ||
|
|
||
| # REQUESTS_SILENCE_PSR0_DEPRECATIONS is defined by the integrator before the library loads. PHPStan | ||
| # resolves it from the define() call in library/Requests.php and treats it as always true. | ||
| - | ||
| identifier: notIdentical.alwaysFalse | ||
| message: '#REQUESTS_SILENCE_PSR0_DEPRECATIONS|between true and true#' | ||
| path: src/Autoload.php | ||
| - | ||
| identifier: notIdentical.alwaysFalse | ||
| message: '#between true and true#' | ||
| path: library/Requests.php | ||
|
|
||
| # The `cookies` option accepts false per the documentation, but set_defaults() replaces false with an | ||
| # empty Jar via the empty() check above, so the guard can never see false. Kept as-is pending a | ||
| # decision on whether `cookies => false` should disable cookie handling. | ||
| - | ||
| identifier: notIdentical.alwaysTrue | ||
| path: src/Requests.php | ||
|
|
||
| # The REQUESTS_TEST_SERVER_*_AVAILABLE constants are defined by tests/bootstrap.php from the environment; | ||
| # PHPStan sees the values the bootstrap produced on this machine and treats the checks as constant. | ||
| - | ||
| identifier: booleanAnd.alwaysFalse | ||
| path: tests/TestCase.php | ||
| - | ||
| identifier: identical.alwaysFalse | ||
| path: tests/TestCase.php | ||
| - | ||
| identifier: booleanAnd.rightAlwaysFalse | ||
| path: tests/Proxy/Http/HttpTest.php | ||
| - | ||
| identifier: booleanNot.alwaysTrue | ||
| path: tests/Proxy/Http/HttpTest.php | ||
|
|
||
| # PHPUnit version shim: setMethods() exists on PHPUnit < 10 and addMethods() on PHPUnit >= 8. | ||
| # PHPStan only sees the installed PHPUnit version. | ||
| - | ||
| identifier: function.alreadyNarrowedType | ||
| path: tests/TestCase.php | ||
| - | ||
| identifier: method.notFound | ||
| message: '#setMethods\(\)#' | ||
| path: tests/TestCase.php | ||
|
|
||
| # Tests which deliberately pass invalid input to verify the exception thrown or the resulting behaviour. | ||
| - | ||
| identifier: argument.type | ||
| path: tests/Cookie/ParseTest.php | ||
| - | ||
| identifier: argument.type | ||
| path: tests/Hooks/RegisterTest.php | ||
| - | ||
| identifier: argument.type | ||
| path: tests/Proxy/Http/HttpTest.php | ||
| - | ||
| identifier: argument.type | ||
| path: tests/Utility/FilteredIterator/SerializationTest.php | ||
| - | ||
| identifier: array.invalidKey | ||
| path: tests/Utility/CaseInsensitiveDictionary/* | ||
| - | ||
| identifier: offsetAssign.dimType | ||
| path: tests/* | ||
| - | ||
| identifier: offsetAssign.valueType | ||
| path: tests/Response/Headers/* | ||
| - | ||
| identifier: assign.propertyType | ||
| message: '#Iri::\$host#' | ||
| path: tests/Iri/IriTest.php | ||
|
|
||
| # Tests of magic property access (__get/__set/__isset) on properties which intentionally do not exist. | ||
| - | ||
| identifier: property.notFound | ||
| path: tests/Iri/IriTest.php | ||
| - | ||
| identifier: property.notFound | ||
| path: tests/Session/MagicPropertyAccessTest.php | ||
|
|
||
| # Session exposes request options as magic properties through __get()/__set(). | ||
| - | ||
| identifier: property.notFound | ||
| message: '#Session::\$useragent#' | ||
| path: examples/session.php | ||
|
|
||
| # The example uses a placeholder path the reader is expected to replace. | ||
| - | ||
| identifier: requireOnce.fileNotFound | ||
| path: examples/preload-aliases.php | ||
|
|
||
| # Assertions on values PHPStan can prove at analysis time. They document the test environment | ||
| # (extension availability, constant definitions) rather than exercise logic. | ||
| - | ||
| identifier: method.alreadyNarrowedType | ||
| path: tests/* | ||
|
|
||
| # Tests disabled at the top with markTestSkipped() while their body is kept for reference | ||
| # (see issues #966 and #1077). | ||
| - | ||
| identifier: deadCode.unreachable | ||
| path: tests/Transport/BaseTestCase.php | ||
|
|
||
| # Minimal ArrayAccess fixture used only to satisfy type checks; it is never read from. | ||
| - | ||
| identifier: property.onlyWritten | ||
| path: tests/Fixtures/ArrayAccessibleObject.php | ||
| - | ||
| identifier: return.missing | ||
| path: tests/Fixtures/ArrayAccessibleObject.php |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This file needs to be listed in the
.gitattributesexport-ignores.Along the same lines,
phpstan.neon(local override) needs to be added to.gitignore.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added
phpstan.neon.dist(and the newphpstan-bootstrap.php) to the export-ignore list, andphpstan.neonto .gitignore.