Download the PHP package fromholdio/phpstan-non-nullable-sink-rules without Composer

On this page you can find all versions of the php package fromholdio/phpstan-non-nullable-sink-rules. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package phpstan-non-nullable-sink-rules

PHPStan Non-Nullable Sink Rules

PHPStan rules for values that are not proven safe at non-nullable or narrowly typed PHP-owned sinks.

The guiding idea is intentionally narrow:

This package is useful for dynamic PHP codebases where enabling strict mixed checks globally would produce too much noise, but where certain PHP-owned operations should still require a proven-safe value.

Installation

Install the package as a dev dependency:

If your project uses phpstan/extension-installer, the extension is loaded automatically:

Composer 2.2+ may ask whether phpstan/extension-installer is allowed to run as a plugin. Answer yes if you want automatic PHPStan extension registration.

Without phpstan/extension-installer, include the extension manually in phpstan.neon:

Do not use both automatic installation and a manual include for this package in the same project; PHPStan will report that the extension file has been included more than once.

Local Path Usage

Before the package is published on Packagist, or when testing local changes in another project, add a Composer path repository:

Then run:

Rules

UnsafeValueForNonNullableSinkRule

Reports values used at known non-nullable or narrowly typed PHP-owned sinks when PHPStan cannot prove the value satisfies the sink requirement.

The rule currently emits these identifiers:

Array Key Sinks

Identifier:

This sink family covers values used as array keys:

The required key type is int|string. The rule reports keys that are not proven to satisfy that requirement, including mixed, nullable values, false, bool, float, array, and object.

Example:

PHPStan reports:

Internal Function Argument Sinks

Identifier:

This sink family covers calls to PHP built-in/internal functions where PHPStan knows the parameter contract and the argument is not proven compatible.

Example:

PHPStan reports:

The rule does not treat arbitrary userland functions as sinks solely because they receive mixed.

Scope Boundaries

This package models dangerous use-sites, not value sources.

It does not need special knowledge of where a value came from:

If one of those values reaches a supported sink and PHPStan cannot prove it is safe, the rule reports the sink.

The package intentionally does not include:

Those decisions belong in consuming projects or higher-level workflows.

Development

Install dependencies:

Run tests:

Run PHPStan against the package:

Run Composer validation:

Requirements

License

BSD-3-Clause.


All versions of phpstan-non-nullable-sink-rules with dependencies

PHP Build Version
Package Version
Requires php Version ^8.1
phpstan/phpstan Version ^2.1.39
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package fromholdio/phpstan-non-nullable-sink-rules contains the following files

Loading the files please wait ...