packagist psalm/plugin-laravel v4.16.4

latest release: v3.16.4
3 hours ago

v4.16.4 moves the Psalm 7 floor to 7.0.0-beta22, adds a header-injection sink for response headers, and fixes facade and Pipeline inference gaps.

Requirements

  • Require vimeo/psalm ^7.0.0-beta22 and psalm/psalm-plugin-api ^0.2.0. Psalm 7.0.0-beta21 renamed the internal taint node factory, so older betas no longer work with this release (#1455, #1456, #1587)

Features

  • 🛡️ Report user-controlled response header values as TaintedHeader: the $headers argument of ResponseFactory::make() (direct, contract, and facade forms), the three-argument response() helper, and new Response() is now a header sink. The attachment exemption still applies only to the TaintedHtml content finding (#1575)
 $title = $request->input('team');
 return response()->make($csv, 200, [
     'Content-Disposition' => "attachment; filename=\"{$title}.csv\"",
 ]);
-// before: no issue
+// now: TaintedHeader: Detected tainted header
  • Recommend alies-dev/psalm-plugin-pest instead of psalm/plugin-phpunit in psalm-laravel init when the project requires pestphp/pest (#1596)

Fixes

  • Narrow App::environment() to bool when called with environment names and to string without arguments, instead of the facade's unconditional string|bool (#1453)
 $isProd = App::environment(['production', 'staging']);
-// string|bool
+// bool
  • Accept object pipes in Pipeline::through() and Pipeline::pipe(), matching Laravel's Pipeline::carry() (#1590)
 $pipeline->through(new AuthenticateMiddleware());
-// InvalidArgument: Argument 1 of Pipeline::through expects array<Closure|callable|string>|Closure|callable|string, but AuthenticateMiddleware provided
+// accepted, returns Pipeline&static
  • Write the facade alias stub atomically, so overlapping Psalm runs on one project (IDE plus CLI, parallel CI steps) no longer read a truncated stub and fail with a parse error or a missing alias class (#1604)

Full Changelog: v4.16.1...v4.16.4

Don't miss a new plugin-laravel release

NewReleases is sending notifications on new releases.