Skip to content

Update root-composer - #27

Open
renovate[bot] wants to merge 1 commit into
2.xfrom
renovate/root-composer
Open

Update root-composer#27
renovate[bot] wants to merge 1 commit into
2.xfrom
renovate/root-composer

Conversation

@renovate

@renovate renovate Bot commented Mar 23, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
dealerdirect/phpcodesniffer-composer-installer (source) 1.2.01.2.1 age confidence
slevomat/coding-standard 8.28.08.31.1 age confidence
squizlabs/php_codesniffer 4.0.14.0.4 age confidence

Release Notes

PHPCSStandards/composer-installer (dealerdirect/phpcodesniffer-composer-installer)

v1.2.1

Compare Source

Changed
  • Various housekeeping, including improvements to CI.
Fixed
  • Fix potential error when running composer install with an open_basedir restriction in effect. Thanks [@​srebb] ! #​271, #​272
slevomat/coding-standard (slevomat/coding-standard)

v8.31.1

Compare Source

🐛 Fixes

  • SlevomatCodingStandard.Classes.ParentCall: Fixed false positive for parent calls after =>
  • SlevomatCodingStandard.Classes.ParentCall: Fixed false positive for @parent::
  • SlevomatCodingStandard.Classes.ReadonlyClass: Do not mark abstract class as readonly despite all promoted and body-property are mark as readonly (thanks to @​kamil-zacek)

v8.31.0

Compare Source

🔧 Improvements

  • SlevomatCodingStandard.Classes.ReadonlyClass: New options allowNonFinalClasses and ignoreTraits (thanks to @​kamil-zacek)
  • SlevomatCodingStandard.Functions.ArrowFunctionDeclaration: New options disallowReturnTypeHint (thanks to @​simPod)

v8.30.1

Compare Source

🐛 Fixes

  • SlevomatCodingStandard.Classes.ReadonlyClass: Do not require mark readonly class when class extends from another class (thanks o @​kamil-zacek)

v8.30.0

Compare Source

🔧 Improvements

  • SlevomatCodingStandard.Classes.ReadonlyClass: For check to readonly class / promoted properties (thanks to @​kamil-zacek)
  • SlevomatCodingStandard.Namespaces.ReferenceUsedNamesOnly: New options namespacesAllowedToUsePartially and namespacesRequiredToUsePartially (thanks to @​Toflar)

🐛 Fixes

  • Fix (Disallow|Require)TrailingComma sniffs to handle null parenthesis pointers (thanks to @​HonzaCZ)

v8.29.0

Compare Source

🔧 Improvements

  • SlevomatCodingStandard.TypeHints.DNFTypeHintFormat: New option enableForDocComments (thanks to @​alleknalle)

🐛 Fixes

  • SlevomatCodingStandard.Namespaces.FullyQualifiedClassNameInAnnotation: Option ignoredAnnotationNames now works for ConstFetchNode (thanks to @​vojmani)

v8.28.1

Compare Source

🐛 Fixes

  • SlevomatCodingStandard.ControlStructures.NewWithoutParentheses: Fix to allow empty parentheses when followed by member access operators for PHP 8.4+ chaining
  • SlevomatCodingStandard.Namespaces.ReferenceUsedNamesOnly: Use existing alias (thanks to @​Khartir)
  • Fixed undefined array key in ReferencedNameHelper when processing fully-qualified names in strings (thanks to @​AlexSkrypnyk)
PHPCSStandards/PHP_CodeSniffer (squizlabs/php_codesniffer)

v4.0.4: - 2026-08-06

Compare Source

The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same (aside from the version number), there was just a slight snafu in the release publication on GitHub (missing PHAR assets). Sorry for the confusion.

v4.0.2: - 2026-08-06

Compare Source

This is a security release and all users are advised to update their install(s) as soon as possible.
The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).

Added
  • Tokenizer support for the PHP 8.5 (void) cast. #​1325
    The T_VOID_CAST token has been added to the Tokens::CAST_TOKENS array.
  • suggest section to the composer.json file to inform users about the recommended iconv and pcntl PHP extensions. #​1388
Changed
  • Clarified that libxml is a required PHP extension. #​1409
  • Squiz.Scope.StaticThisUsage: the sniff will now also search for the use of $this in static closures. #​1377
  • The Generic.PHP.LowerCaseKeyword, Generic.WhiteSpace.LanguageConstructSpacing and Squiz.Functions.FunctionDeclarationArgumentSpacing sniffs no longer embed UTF-8 middot characters for spaces in error messages. #​1379, #​1389 Fixes Squiz/#​2652.
  • PSR2.ControlStructures.SwitchDeclaration: the error message for the use of colon + curly braces (WrongOpener*) has been made more informative. #​1358. Fixes #​1322.
  • The error messages for the following sniffs have been improved by exposing more data placeholders:
    • PEAR.Functions.FunctionDeclaration #​1445
      • The CloseBracketLine error message now exposes 1 data value (previously 0).
      • The EmptyLine error message now exposes 1 data value (previously 0).
      • The Indent error message now exposes 3 data values (previously 2).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Functions.MultiLineFunctionDeclaration sniffs.
    • PSR2.Classes.ClassDeclaration #​1446
      • The ExtendsLine and ImplementsLine error messages now expose 3 data values (previously 1).
      • The SpaceBeforeExtends and SpaceBeforeImplements error messages now expose 2 data values (previously 1).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Classes.ClassDeclaration sniffs.
    • PSR2.ControlStructures.SwitchDeclaration #​1447
      • The defaultNotLower and caseNotLower error messages now expose 3 data values (previously 2).
      • The SpaceBeforeColonDEFAULT and SpaceBeforeColonCASE error messages now expose 1 data value (previously 0).
      • The BodyOnNextLineDEFAULT and BodyOnNextLineCASE error messages now expose 1 data value (previously 0).
      • The WrongOpenerdefault and WrongOpenercase error messages now expose 1 data value (previously 0).
    • Squiz.ControlStructures.SwitchDeclaration #​1449
      • The CaseNotLower and DefaultNotLower error messages now expose 3 data values (previously 2).
      • The CaseIndent and DefaultIndent error messages now expose 2 data values (previously 0).
      • The SpaceBeforeColonCase and SpaceBeforeColonDefault error messages now expose 1 data value (previously 0).
      • The BreakIndent error message now exposes 1 data value (previously 0).
      • The SpacingAfterCase and SpacingAfterDefault error messages now expose 1 data value (previously 0).
    • Squiz.Functions.FunctionDeclarationArgumentSpacing #​1452
      • The SpaceBeforeEquals error message now exposes 3 data values (previously 2).
      • The SpaceAfterEquals error message now exposes 3 data values (previously 2).
    • Squiz.Functions.MultiLineFunctionDeclaration #​1453
      • The FirstParamSpacing and UseFirstParamSpacing error messages now expose 1 data value (previously 0).
      • The OneParamPerLine and UseOneParamPerLine error messages now expose 1 data value (previously 0).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration sniff.
    • If you have customised the error messages of these sniffs, please review your ruleset after upgrading.
    • Thanks to Zhang WenTao for these patches.
  • The following sniff(s) have received efficiency improvements:
    • PSR2.Classes.PropertyDeclaration
    • Thanks to Jonathan Champ for the patch.
  • The test suite is now more contributor friendly for contributors on MacOS. #​1437
  • Various housekeeping, including improvements to the tests and documentation.
Fixed
  • SECURITY FIX: Running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the Gitblame, Hgblame or Svnblame report(s) would process a file whose name contains shell metacharacters. #​1473
  • Fixed bug #​1320: Generic.Strings.UnnecessaryHeredoc: the fixer could incidentally change tab indentation to space indentation in select lines in the heredoc body.
  • Fixed bug #​1354: PSR12.Functions.ReturnTypeDeclaration: prevent an "Undefined array key" warning if the code under scan contains a parse error.
  • Fixed bug #​1357: Squiz.Scope.StaticThisUsage: false positive for usage of $this in non-static closures nested in OO methods.
  • Fixed bug #​1368: PEAR.Functions.FunctionDeclaration: the indentation for subsequent lines in multi-line block comments within a multi-line function signature, would be incorrectly determined, leading to false positives and resulting in a fixer conflict when running phpcbf.
    • This also fixes, by extension, the same issue in the Squiz.Functions.MultiLineFunctionDeclaration sniff.
  • Fixed bug #​1418: Tokenizer/PHP: tokenization of an inline else colon after an inline comment could fail and/or throw a "Trying to access array offset on null" warning.
  • Fixed bug #​1435: Generic.Formatting.MultipleStatementAlignment would get into a fixer conflict for multiple assignments within a single statement spanning multiple lines.
    • Same as when the statement would be single-line, alignment of subsequent assignment operators within the same multi-line statement will now be ignored.
    • Thanks to Sergei Morozov for the patch.
  • Fixed bug #​1451: Tokenizer/PHP: prevent an "Undefined array key" warning during live coding when a file ends on the name in a constant declaration.
  • Fixed bug #​1463: Squiz.Functions.FunctionDuplicateArgument: prevent an "Undefined array key" PHP warning when the sniff encounters a function declaration without parentheses (parse error / live coding).
Other
  • The GPG signature for the PHAR files has been rotated. The new fingerprint is: 5CB4F77.

New Contributors

The PHP_CodeSniffer project is happy to welcome the following new contributors:
@​bigdevlarry, @​Faze-up, @​jrchamp, @​lazerg, @​morozov, @​ntdiary, @​SAY-5

Statistics

Closed: 10 issues
Merged: 33 pull requests

Follow @​phpcs on Mastodon or @​PHP_CodeSniffer on X to stay informed.

Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update dependency slevomat/coding-standard to v8.28.1 Update root-composer May 6, 2026
@renovate
renovate Bot force-pushed the renovate/root-composer branch from 04f5f6a to f44dc8c Compare May 18, 2026 18:44
@renovate
renovate Bot force-pushed the renovate/root-composer branch 2 times, most recently from c74649c to 65f4a57 Compare June 27, 2026 18:44
@renovate
renovate Bot force-pushed the renovate/root-composer branch from 65f4a57 to c07f341 Compare July 21, 2026 19:10
@renovate
renovate Bot force-pushed the renovate/root-composer branch 3 times, most recently from 1ca918c to 1e4a855 Compare August 6, 2026 06:00
@renovate
renovate Bot force-pushed the renovate/root-composer branch from 1e4a855 to 0b06074 Compare August 11, 2026 23:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants