github vimeo/psalm 7.0.0-beta23

4 hours ago

What's Changed

Features

  • Exclude impure destructors from unused variable detection by @danog in #11981
  • Emit issues on php <8.5 if overridden method uses self instead of static by @danog in #11985
  • [6.x] Support parameter-conditional types in @self-out / @this-out by @alies-dev in #11964
  • Report string increments as deprecated since PHP 8.5, suggest str_increment() by @danog in #11993
  • [6.x] Support @param-closure-this docblock tag by @alies-dev in #11853
  • [6.x] Allow #[\Override] on properties (PHP 8.5) by @alies-dev in #11891
  • [6.x] Support PHP 8.5 clone-with-properties by @alies-dev in #11893
  • [6.x] Accept string pseudo-type intersections in docblocks by @alies-dev in #11823
  • [6.x] extract IdeDetector, auto-detect IDE when none specified by @alies-dev in #11802
  • [7.x] Add --init-ci command to generate GitHub Actions workflow by @alies-dev in #11748
  • [6.x] Accept --no-progress in psalm-refactor by @alies-dev in #11995
  • Add support for PHP 8.4 asymmetric property visibility by @danog in #11988
  • Capability-based purity and purity templates (Hack coeffects for Psalm) by @danog in #11984
  • Enforce #[\NoDiscard] on every analysed PHP version by @danog in #12007
  • Report native symbols used below the PHP version that introduced them by @danog in #12006
  • Load genuinely-new native classes on every PHP version, tagged with @SInCE by @danog in #12008
  • Respect PHP version guards when reporting unavailable native symbols by @danog in #12010
  • Date native functions and methods by the versioned callmaps by @danog in #12009
  • [6.x] Report string increments as deprecated since PHP 8.5 (backport) by @alies-dev in #12062
  • Report taint issues as security issues by @danog in #12068
  • Specialize taints of calls to inferred-pure functions by @danog in #12048

Fixes

  • fix: false-positive NullableReturnStatement when a nullsafe property fetch is compared to a non-nullable value by @yuriy-sorokin in #11982
  • [6.x] Resolve transitive @mixin chains (depth >= 2) by @alies-dev in #11868
  • [6.x] Keep the template argument of a constructed generic object at a call site by @alies-dev in #11991
  • [6.x] Fix parallel scan crash on PHP-native intersection types by @alies-dev in #11841
  • fix: shallow-scan extraFiles also for language server by @susnux in #11919
  • [6.x] Check set visibility for clone() withProperties keys by @alies-dev in #11999
  • [6.x] Resolve self/static template args against implementing class before bound check by @alies-dev in #11833
  • Fix ClassMustBeFinal final insertion for #11460 by @HenkPoley in #11855
  • Fix builtin class string instantiation by @HenkPoley in #11860
  • Fix invalid SARIF region for issues reported at line 0 by @eyupcanakman in #11903
  • [6.x] Resolve method templates for polymorphic array callables by @alies-dev in #11815
  • Do not resolve the _ purity of closure types as a class name by @danog in #12014
  • Let a purity template fit wherever its bound does by @danog in #12023
  • Keep polyfills of newer native functions out of the global functions on cached runs by @danog in #12025
  • Infer the purity of arrow functions by @danog in #12018
  • Do not crash when a closure unsets a variable it captured by reference by @danog in #12022
  • Do not crash when a callable object narrowed from a callable is called by @danog in #12021
  • Do not crash on multibyte string literal arguments on PHP 8.5 by @danog in #12020
  • Do not report calls of mutation-free methods given impure closures as unused by @danog in #12017
  • [6.x] Allow asymmetric visibility on static properties in PHP 8.5 by @alies-dev in #12035
  • [6.x] Fix: ReflectionClass template became invariant on PHP 8.4 by @alies-dev in #12036
  • Fix crash on static property fetch via builtin class string by @HenkPoley in #12038
  • Check $class::$prop reads and assignments when the class is a variable by @HenkPoley in #12040
  • Type calls of the callable templates a function-like inherits its purity from by @danog in #12016
  • Fix missing new $c checks when the class string has a leading backslash by @HenkPoley in #12039
  • Bind the purity wildcard at any depth of a parameter, and close its gaps by @danog in #12034
  • Let closures carry the purity templates of the scopes they are nested in by @danog in #12027
  • Compare the purity templates of overriding methods by their bounds by @danog in #12015
  • Fix master CI after merging 6.x by @danog in #12047
  • [6.x] Fix implode() inferring non-empty-string for possibly empty elements (backport) by @alies-dev in #12054
  • [6.x] Fix: respect ERROR_LEVEL for plugin-defined issues (backport) by @alies-dev in #12060
  • [6.x] Fix InvalidCast when casting a type variable to string (backport) by @alies-dev in #12055
  • [6.x] Fix crash on multibyte literal haystack on PHP 8.5 (backport) by @alies-dev in #12053
  • [6.x] Support parenthesized union types in @method parameters (backport) by @alies-dev in #12057

Docs

Internal changes

  • Merge 6.x into master by @danog in #12011
  • Merge 6.x into master by @danog in #12028
  • Give Psalm's own closure-calling helpers the _ purity by @danog in #12043
  • Annotate FunctionPurityTemplateReplacer::enterNode(), drop stale baseline entries by @danog in #12045
  • Print the purity of closures and callables as Closure[pure] and callable[impure] by @danog in #12042
  • [6.x] Allow plugin issues to specify custom documentation URLs (backport) by @alies-dev in #12061

Other changes

  • [6.x] Throw TypeParseTreeException for an incomplete conditional type by @alies-dev in #11962
  • Don't infer non-empty-string for implode() of possibly-empty elements by @anyingiit in #11990
  • [7.x] Use auto-detected thread count in CI environments by @alies-dev in #11771
  • [6.x] Add TKeyedArray::make() factory to 6.x for cross-version plugin compatibility by @alies-dev in #11810
  • [6.x] Quiet CLI output when running under an AI agent by @alies-dev in #11812
  • Bump mheap/github-action-required-labels from 5.5.2 to 5.6.0 by @dependabot[bot] in #11907
  • Bump actions/cache from 5.0.5 to 6.1.0 by @dependabot[bot] in #11896
  • Bump docker/setup-buildx-action from 4.1.0 to 4.2.0 by @dependabot[bot] in #11902
  • Bump docker/setup-buildx-action from 4.2.0 to 4.4.1 by @dependabot[bot] in #12005
  • Bump fkirc/skip-duplicate-actions from 5.3.1 to 5.3.2 by @dependabot[bot] in #12004
  • Bump actions/checkout from 6.0.2 to 7.0.1 by @dependabot[bot] in #12003
  • [6.x] Propagate throws from pseudo-method dispatch by @alies-dev in #11843
  • Fix for coding standard issue in commit ca15124 by @HenkPoley in #11856
  • Bump actions/cache from 5.0.5 to 6.1.0 by @dependabot[bot] in #12002
  • [7.x] Taint: report every flow into a shared sink exactly once by @alies-dev in #12037
  • [PoC] Taint: keep late flows through @psalm-taint-specialize calls (per-entry body summaries) by @alies-dev in #12041

New Contributors

Full Changelog: 7.0.0-beta22...7.0.0-beta23

Don't miss a new psalm release

NewReleases is sending notifications on new releases.