v4.16.4 moves the Psalm 7 floor to 7.0.0-beta22, adds a header-injection sink for response headers, and fixes facade and Pipeline inference gaps.
Requirements
- Require
vimeo/psalm^7.0.0-beta22andpsalm/psalm-plugin-api^0.2.0. Psalm7.0.0-beta21renamed the internal taint node factory, so older betas no longer work with this release (#1455, #1456, #1587)
Features
- 🛡️ Report user-controlled response header values as
TaintedHeader: the$headersargument ofResponseFactory::make()(direct, contract, and facade forms), the three-argumentresponse()helper, andnew Response()is now aheadersink. The attachment exemption still applies only to theTaintedHtmlcontent finding (#1575)
$title = $request->input('team');
return response()->make($csv, 200, [
'Content-Disposition' => "attachment; filename=\"{$title}.csv\"",
]);
-// before: no issue
+// now: TaintedHeader: Detected tainted header- Recommend
alies-dev/psalm-plugin-pestinstead ofpsalm/plugin-phpunitinpsalm-laravel initwhen the project requirespestphp/pest(#1596)
Fixes
- Narrow
App::environment()toboolwhen called with environment names and tostringwithout arguments, instead of the facade's unconditionalstring|bool(#1453)
$isProd = App::environment(['production', 'staging']);
-// string|bool
+// bool- Accept object pipes in
Pipeline::through()andPipeline::pipe(), matching Laravel'sPipeline::carry()(#1590)
$pipeline->through(new AuthenticateMiddleware());
-// InvalidArgument: Argument 1 of Pipeline::through expects array<Closure|callable|string>|Closure|callable|string, but AuthenticateMiddleware provided
+// accepted, returns Pipeline&static- Write the facade alias stub atomically, so overlapping Psalm runs on one project (IDE plus CLI, parallel CI steps) no longer read a truncated stub and fail with a parse error or a missing alias class (#1604)
Full Changelog: v4.16.1...v4.16.4