github vimeo/psalm 7.0.0-rc2

latest release: 6.20.0
pre-release2 hours ago

What's Changed

Features

  • Support generic exception classes in @throws by @orcnd in #12090
  • Taint DNS answers, and the paths and URLs more builtins read, write and connect to by @danog in #12135
  • Taint the entries of $_SERVER and $_FILES the client sends by @danog in #12086
  • Add new taint kinds for query and path injection by @danog in #12097
  • Taint the messages of exceptions, and the exceptions a catch block gets by @danog in #12139
  • Taint what closures are called with and return through variables and callable parameters by @danog in #12147
  • Taint what builtin objects are given and give back, described by a dictionary by @danog in #12102
  • Taint what generators yield and what iterating over objects gives by @danog in #12096
  • Let a constructor's @return give the type of the object it constructs by @danog in #12179
  • Know that the string of a MongoDB ObjectId holds no input (#12127) by @danog in #12162
  • [6.x] Add generic stubs for the PHP 8.4 Dom\ API by @alies-dev in #12231

Fixes

  • Remove the taints a value's type cannot hold, at returns, sources and assignments by @danog in #12079
  • Report the taint flows a plugin connects to a sink from a node without location by @danog in #12082
  • [6.x] Resolve parent:: first-class callables of @method pseudo-methods by @alies-dev in #12148
  • [6.x] Fix: type aliases depend on declaration order by @alies-dev in #12149
  • Narrow an array key loosely equal to a non-numeric string to that string, since PHP 8 by @danog in #12153
  • Give array items written by reference the types the call or the foreach leaves in them by @danog in #12154
  • Keep the instances of @psalm-taint-specialize classes from changing, specialize the classes extending them, and calls on them by @danog in #12083
  • Check what a method with @psalm-self-out stores in $this against its self-out type by @danog in #12120
  • Charge the class purity templates constructors depend on at new by @danog in #12116
  • Convert an object to a string with the taints of what its __toString returns by @danog in #12127
  • Don't taint what an array held under a literal key assigned or unset since then by @danog in #12128
  • Fix the taint flows of builtins missed or wrong since #12084 by @danog in #12129
  • Forget what is known about superglobals after a call that may write globals by @danog in #12175
  • Forget static properties after a method call that may write globals but not properties by @danog in #12176
  • Don't taint a variable with what it held before an if/else that assigns it in every branch by @danog in #12143
  • Keep whether a value is fresh or global when a @var docblock replaces its type by @danog in #12178
  • Leave a specialized call through all call sites of an exit it reaches through shared state by @danog in #12141
  • Take no taint of an array element into a cast or a concatenation of the array by @danog in #12163
  • Narrow static properties after an early return when they were not in scope by @danog in #12180
  • Track taint through methods called on a new specialized instance by @danog in #12170
  • Reset $_SESSION after session_unset() by @TheNetherWatcher in #12087
  • Taint flows that reach a visited node with other open array assignments by @danog in #12094
  • Infer the type of what array_replace_recursive() returns by @danog in #12132
  • Check trait methods against the purity template bindings of the class using the trait by @danog in #12126
  • Check @psalm-self-out types like @return types, so conditional purity arguments outside their bound are reported by @danog in #12189
  • Declare what the SPL autoload functions do, and that class_implements() of a class name may autoload by @danog in #12192
  • Fix the TypeError calling a closure held in a variable, and a TaintTest case a merge broke by @danog in #12194
  • Remember the results of a pure class's methods like those of an immutable class's by @danog in #12193
  • Rename a duplicated TaintTest case, so that both run by @danog in #12198
  • Keep the baseline's code samples a list by @danog in #12197
  • Fix the self-analysis errors left by the taint merges by @danog in #12199
  • Fix Shepherd's taint resolution blowup: widen the flows reaching a node through many call entries by @danog in #12195
  • [6.x] Model nullsafe short-circuiting across the whole chain by @alies-dev in #12064
  • Write into the array what a foreach by reference's value variable holds in the loop, not before it by @danog in #12196
  • Fix a self-analysis error left on master by a baseline mismatch by @danog in #12207
  • Write the terminal report to STDOUT instead of echoing it, as it is not HTML output by @danog in #12200
  • Fix the self-analysis, unit test and stubs build failures from the 6.x merge by @danog in #12208
  • Make printf, vprintf, print_r, var_dump and var_export sinks of the same taint kinds as echo by @danog in #12210
  • Treat vfprintf, gzpassthru, highlight_file and printing highlight_string as io, like printf by @danog in #12211
  • Make writes to streams opened on php://output or php://stdout html sinks, as they are the response by @danog in #12209
  • Make debug_zval_dump a sink of the same taint kinds as echo, like var_dump by @danog in #12212
  • Add OutputStreamTaintAnalyzer to the preloader list and test has_quotes output stream sinks alone by @danog in #12220
  • Make implode() and join() fetch the values of the array in taint analysis by @danog in #12256
  • Keep the items a list surely has out of the items appended to it by @danog in #12266
  • Keep the literal items before an unpacked list out of the list's value type by @danog in #12267
  • Allow writing the properties of fresh objects in pure functions outside of classes by @danog in #12265
  • Charge write-props for writing an array element of a property of a call result by @danog in #12264
  • Charge write-props for writing another non-fresh instance of the same class by @danog in #12269
  • Remove the nosql taint from scalar, array-key and numeric values by @danog in #12274
  • Treat calls on $this of methods returning their receiver as $this in fluent chains by @danog in #12263
  • Require read-globals for debug_backtrace(), as the call stack it returns differs per call site by @danog in #12260
  • Treat the command-line options getopt() returns as a taint source of user input by @danog in #12246
  • Treat $argv, bound with global or read through $GLOBALS too, as a taint source of user input by @danog in #12245
  • Don't report what fprintf and vfprintf write to output streams only as numbers, as for printf by @danog in #12224
  • Don't report what printf and vprintf print only as numbers, as sprintf's return already isn't by @danog in #12213
  • Don't taint what vsprintf returns of values it formats only as numbers, as for sprintf by @danog in #12215
  • Don't taint the value a whole tainted array held under a literal key overwritten since then by @danog in #12273
  • Track taint through the bodies of trait methods, keyed by the class using the trait by @danog in #12272
  • Keep the items after an unpacked array of unknown length out of the known list slots by @danog in #12271

Docs

Internal changes

Other changes

  • Taint what objects read from their properties with what their parent classes set by @danog in #12137
  • Don't let the keys of an array hold a value assigned under a variable key by @danog in #12145
  • Fix LSP lookup of functions declared in included files by @M393 in #12080
  • Add an article explaining the purity model by @danog in #12182
  • Fix: Psalter crash on bodyless methods with a return type by @alies-dev in #12221
  • Fix: Psalter crash when analyzing a single directory by @alies-dev in #12222
  • Fix: dispatch AfterCodebasePopulated from Psalter and the language server by @alies-dev in #12235

New Contributors

Full Changelog: 7.0.0-rc1...7.0.0-rc2

Don't miss a new psalm release

NewReleases is sending notifications on new releases.