This is a security release and all users are advised to update their install(s) as soon as possible.
The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).
Added
- Tokenizer support for the PHP 8.5
(void)cast. #1325
TheT_VOID_CASTtoken has been added to theTokens::CAST_TOKENSarray. suggestsection to thecomposer.jsonfile to inform users about the recommendediconvandpcntlPHP extensions. #1388- Thanks to Rodrigo Primo for the patch.
Changed
- Clarified that
libxmlis a required PHP extension. #1409 - Squiz.Scope.StaticThisUsage: the sniff will now also search for the use of
$thisin static closures. #1377 - The Generic.PHP.LowerCaseKeyword, Generic.WhiteSpace.LanguageConstructSpacing and Squiz.Functions.FunctionDeclarationArgumentSpacing sniffs no longer embed UTF-8 middot characters for spaces in error messages. #1379, #1389 Fixes Squiz/#2652.
- Thanks to Rodrigo Primo for the patches.
- PSR2.ControlStructures.SwitchDeclaration: the error message for the use of colon + curly braces (
WrongOpener*) has been made more informative. #1358. Fixes #1322.- Thanks to Sule-Balogun Olanrewaju for the patch.
- The error messages for the following sniffs have been improved by exposing more data placeholders:
PEAR.Functions.FunctionDeclaration#1445- The
CloseBracketLineerror message now exposes 1 data value (previously 0). - The
EmptyLineerror message now exposes 1 data value (previously 0). - The
Indenterror message now exposes 3 data values (previously 2). - These changes also affect the same error codes for the
PSR12.Classes.AnonClassDeclarationandSquiz.Functions.MultiLineFunctionDeclarationsniffs.
- The
PSR2.Classes.ClassDeclaration#1446- The
ExtendsLineandImplementsLineerror messages now expose 3 data values (previously 1). - The
SpaceBeforeExtendsandSpaceBeforeImplementserror messages now expose 2 data values (previously 1). - These changes also affect the same error codes for the
PSR12.Classes.AnonClassDeclarationandSquiz.Classes.ClassDeclarationsniffs.
- The
PSR2.ControlStructures.SwitchDeclaration#1447- The
defaultNotLowerandcaseNotLowererror messages now expose 3 data values (previously 2). - The
SpaceBeforeColonDEFAULTandSpaceBeforeColonCASEerror messages now expose 1 data value (previously 0). - The
BodyOnNextLineDEFAULTandBodyOnNextLineCASEerror messages now expose 1 data value (previously 0). - The
WrongOpenerdefaultandWrongOpenercaseerror messages now expose 1 data value (previously 0).
- The
Squiz.ControlStructures.SwitchDeclaration#1449- The
CaseNotLowerandDefaultNotLowererror messages now expose 3 data values (previously 2). - The
CaseIndentandDefaultIndenterror messages now expose 2 data values (previously 0). - The
SpaceBeforeColonCaseandSpaceBeforeColonDefaulterror messages now expose 1 data value (previously 0). - The
BreakIndenterror message now exposes 1 data value (previously 0). - The
SpacingAfterCaseandSpacingAfterDefaulterror messages now expose 1 data value (previously 0).
- The
Squiz.Functions.FunctionDeclarationArgumentSpacing#1452- The
SpaceBeforeEqualserror message now exposes 3 data values (previously 2). - The
SpaceAfterEqualserror message now exposes 3 data values (previously 2).
- The
Squiz.Functions.MultiLineFunctionDeclaration#1453- The
FirstParamSpacingandUseFirstParamSpacingerror messages now expose 1 data value (previously 0). - The
OneParamPerLineandUseOneParamPerLineerror messages now expose 1 data value (previously 0). - These changes also affect the same error codes for the
PSR12.Classes.AnonClassDeclarationsniff.
- The
- If you have customised the error messages of these sniffs, please review your ruleset after upgrading.
- Thanks to Zhang WenTao for these patches.
- The following sniff(s) have received efficiency improvements:
- PSR2.Classes.PropertyDeclaration
- Thanks to Jonathan Champ for the patch.
- The test suite is now more contributor friendly for contributors on MacOS. #1437
- Thanks to Sergei Morozov for the patch.
- Various housekeeping, including improvements to the tests and documentation.
- Thanks to Dan Wallis, Rodrigo Primo, Sergei Morozov and Juliette Reinders Folmer for their contributions.
Fixed
- SECURITY FIX: Running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the
Gitblame,HgblameorSvnblamereport(s) would process a file whose name contains shell metacharacters. #1473- Users using the default
Fullreport, or any of the other non-*blame reports, are not affected. - For more details, see the security advisory.
- Thanks go to Faze-up and Volker Dusch for responsibly disclosing the vulnerability.
- Additionally, thanks go to Volker Dusch, Rodrigo Primo, Dan Wallis and Juliette Reinders Folmer for creating and testing the fix.
- Users using the default
- Fixed bug #1320: Generic.Strings.UnnecessaryHeredoc: the fixer could incidentally change tab indentation to space indentation in select lines in the heredoc body.
- Fixed bug #1354: PSR12.Functions.ReturnTypeDeclaration: prevent an "Undefined array key" warning if the code under scan contains a parse error.
- Thanks to Dan Wallis for the patch.
- Fixed bug #1357: Squiz.Scope.StaticThisUsage: false positive for usage of
$thisin non-static closures nested in OO methods. - Fixed bug #1368: PEAR.Functions.FunctionDeclaration: the indentation for subsequent lines in multi-line block comments within a multi-line function signature, would be incorrectly determined, leading to false positives and resulting in a fixer conflict when running
phpcbf.- This also fixes, by extension, the same issue in the
Squiz.Functions.MultiLineFunctionDeclarationsniff.
- This also fixes, by extension, the same issue in the
- Fixed bug #1418: Tokenizer/PHP: tokenization of an inline else colon after an inline comment could fail and/or throw a "Trying to access array offset on null" warning.
- Thanks to Lazizbek Ergashev for the patch.
- Fixed bug #1435: Generic.Formatting.MultipleStatementAlignment would get into a fixer conflict for multiple assignments within a single statement spanning multiple lines.
- Same as when the statement would be single-line, alignment of subsequent assignment operators within the same multi-line statement will now be ignored.
- Thanks to Sergei Morozov for the patch.
- Fixed bug #1451: Tokenizer/PHP: prevent an "Undefined array key" warning during live coding when a file ends on the name in a constant declaration.
- Thanks to Lazizbek Ergashev and Sai Asish Y for the patch.
- Fixed bug #1463: Squiz.Functions.FunctionDuplicateArgument: prevent an "Undefined array key" PHP warning when the sniff encounters a function declaration without parentheses (parse error / live coding).
- Thanks to Rodrigo Primo for the patch.
Other
- The GPG signature for the PHAR files has been rotated. The new fingerprint is: 5CB4F778BF9BC4FB67AE511D96E91A992CF22FF4.
New Contributors
The PHP_CodeSniffer project is happy to welcome the following new contributors:
@bigdevlarry, @Faze-up, @jrchamp, @lazerg, @morozov, @ntdiary, @SAY-5
Statistics
Closed: 10 issues
Merged: 33 pull requests
Follow @phpcs on Mastodon or @PHP_CodeSniffer on X to stay informed.
Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!