packagist psalm/plugin-laravel v3.16.4

2 hours ago

A patch release adding a header-injection sink for response headers.

Features

  • 🛡️ Report user-controlled response header values as TaintedHeader under --taint-analysis: the $headers argument of ResponseFactory::make() (direct, contract, and facade forms), the three-argument response() helper, and new Response() is now a header sink. The attachment exemption still applies only to the TaintedHtml content finding (#1575)
 $title = $request->input('team');
 return response()->make($csv, 200, [
     'Content-Disposition' => "attachment; filename=\"{$title}.csv\"",
 ]);
-// before: no issue
+// now: TaintedHeader: Detected tainted header
  • Recommend alies-dev/psalm-plugin-pest instead of psalm/plugin-phpunit in psalm-laravel init when the project requires pestphp/pest (#1596)

Fixes

  • Write the facade alias stub atomically, so overlapping Psalm runs on one project (IDE plus CLI, parallel CI steps) no longer read a truncated stub and fail with a parse error or a missing alias class (#1604)

Full Changelog: v3.16.3...v3.16.4

Don't miss a new plugin-laravel release

NewReleases is sending notifications on new releases.