[BUGFIX] Return processed paths from plugin config - #19
Merged
Merged
Conversation
PHPStan reports a possibly invalid array key type for the package name read from a fixture package `composer.json`, which is `mixed` at that point. The name is now verified to be a string before it is used to look up a version from the repository options. A non-string name fails package loading later on anyway, so behaviour does not change.
`Config::processFixtureExtensionPaths()` computed the processed path list, but returned the unprocessed input. `paths()`, `get()` and `all()` therefore handed out the configured keys as written in `composer.json`, regardless of the passed flag. The default mode, which should return absolute paths, was completely broken and a trailing slash reached the `fixture-path` repository url. The processed list is returned now. Relative mode normalizes the configured path using the composer filesystem utility, the same way the absolute mode already did. An empty result is kept as the current directory, and selections of different notations of the same path are merged instead of being dropped. Additionally: * `realpath()` normalizes before checking for an empty path, so `./` resolves to the base dir instead of reading an offset of an empty string. * `isRelativePathsFlag()` checks the flag bit with `!== 0`, which does not depend on the constant value. * An unused config instance left over in `handleRootPackageExtraConfig()` is removed. Resolves: #18
`phpunit/phpunit` was pinned to 9.6.22, which is affected by CVE-2026-24765 (PKSA-z3gr-8qht-p93v). Composer blocks packages with known security advisories by default in recent versions, which lets dependency installation fail in CI for PHP 8.1 and newer. The constraint is raised to `^9.6.33`, the first 9.6 release that is not affected, still supporting PHP 7.4.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Config::processFixtureExtensionPaths()computed the processed pathlist, but returned the unprocessed input. The default (absolute) mode
of
paths(),get()andall()was broken completely and a trailingslash reached the
fixture-pathrepository url.The processed list is returned now. Relative mode normalizes paths the
same way the absolute mode does, keeps an empty result as the current
directory and merges selections of different notations of the same
path. Test cases cover both flags.
Two
[TASK]commits keep CI green:FixturePathRepository, whichPHPStan reports with current dependencies.
phpunit/phpunitfrom the pinned 9.6.22 to^9.6.33. Thepinned version is affected by CVE-2026-24765 and recent Composer
versions refuse to install it, failing CI for PHP 8.1 and newer.
Resolves: #18