Download the PHP package fromholdio/phpstan-non-nullable-sink-rules without Composer
On this page you can find all versions of the php package fromholdio/phpstan-non-nullable-sink-rules. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download fromholdio/phpstan-non-nullable-sink-rules
More information about fromholdio/phpstan-non-nullable-sink-rules
Files in fromholdio/phpstan-non-nullable-sink-rules
Package phpstan-non-nullable-sink-rules
Short Description PHPStan rules for values that are not proven safe at non-nullable PHP-owned sinks.
License BSD-3-Clause
Homepage https://github.com/fromholdio/phpstan-non-nullable-sink-rules
Informations about the package phpstan-non-nullable-sink-rules
PHPStan Non-Nullable Sink Rules
PHPStan rules for values that are not proven safe at non-nullable or narrowly typed PHP-owned sinks.
The guiding idea is intentionally narrow:
This package is useful for dynamic PHP codebases where enabling strict mixed checks globally would produce too much noise, but where certain PHP-owned operations should still require a proven-safe value.
Installation
Install the package as a dev dependency:
If your project uses phpstan/extension-installer, the extension is loaded automatically:
Composer 2.2+ may ask whether phpstan/extension-installer is allowed to run as a plugin. Answer yes if you want automatic PHPStan extension registration.
Without phpstan/extension-installer, include the extension manually in phpstan.neon:
Do not use both automatic installation and a manual include for this package in the same project; PHPStan will report that the extension file has been included more than once.
Local Path Usage
Before the package is published on Packagist, or when testing local changes in another project, add a Composer path repository:
Then run:
Rules
UnsafeValueForNonNullableSinkRule
Reports values used at known non-nullable or narrowly typed PHP-owned sinks when PHPStan cannot prove the value satisfies the sink requirement.
The rule currently emits these identifiers:
Array Key Sinks
Identifier:
This sink family covers values used as array keys:
The required key type is int|string. The rule reports keys that are not proven to satisfy that requirement, including mixed, nullable values, false, bool, float, array, and object.
Example:
PHPStan reports:
Internal Function Argument Sinks
Identifier:
This sink family covers calls to PHP built-in/internal functions where PHPStan knows the parameter contract and the argument is not proven compatible.
Example:
PHPStan reports:
The rule does not treat arbitrary userland functions as sinks solely because they receive mixed.
Scope Boundaries
This package models dangerous use-sites, not value sources.
It does not need special knowledge of where a value came from:
If one of those values reaches a supported sink and PHPStan cannot prove it is safe, the rule reports the sink.
The package intentionally does not include:
- WordPress-aware source modelling.
- Special handling for
filter_input(). - Hook-aware analysis for
do_action()orapply_filters(). - Project-specific severity or release policy.
Those decisions belong in consuming projects or higher-level workflows.
Development
Install dependencies:
Run tests:
Run PHPStan against the package:
Run Composer validation:
Requirements
- PHP
^8.1 - PHPStan
^2.1.39
License
BSD-3-Clause.