Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: vimeo/psalm
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 6.17.1
Choose a base ref
...
head repository: vimeo/psalm
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 6.17.2
Choose a head ref
  • 13 commits
  • 9 files changed
  • 5 contributors

Commits on Feb 17, 2026

  1. Fix function manipulator

    danog committed Feb 17, 2026
    Configuration menu
    Copy the full SHA
    bdc2435 View commit details
    Browse the repository at this point in the history

Commits on Feb 19, 2026

  1. Configuration menu
    Copy the full SHA
    3e06069 View commit details
    Browse the repository at this point in the history

Commits on Aug 28, 2026

  1. Fix MissingOverrideAttribute false positive for private trait methods

    When a trait declares a private method and is used by both a parent class
    and a child class that re-declares the same method, Populator recorded the
    child's method as "overriding" the parent's copy of the trait method. PHP
    does not treat private methods as part of a class's externally visible API
    and does not allow #[Override] across such a boundary, so the false
    MissingOverrideAttribute forced users into invalid code that PHP itself
    refuses to run.
    
    Populator now checks the declaring method's visibility before recording it
    as overridden, skipping private methods the same way it already special-
    cases abstract ones a few lines above.
    
    Fixes #10982
    Eljees committed Aug 28, 2026
    Configuration menu
    Copy the full SHA
    b3e7eb0 View commit details
    Browse the repository at this point in the history
  2. Fix the override guard to read effective visibility, not the trait's own

    Cursor Bugbot flagged the new guard on Populator.php and it was right, so
    this closes the gap it found.
    
    `use T { f as public; }` does not rewrite the copied method's visibility.
    Psalm keeps the adaptation in `trait_visibility_map` on the class that
    applies it, and every consumer overlays it at read time (see
    MethodVisibilityAnalyzer, ClassAnalyzer, FunctionLikeAnalyzer). The guard
    read `$declaring_method_storage->visibility` instead, and the declaring
    class here is the trait itself -- so it still saw `private` for a method
    the parent exposes publicly.
    
    The map lives on `$parent_storage` (the using class), not on the declaring
    trait, so that is what the guard now consults, falling back to the stored
    visibility when there is no adaptation.
    
    Both directions were wrong before, and both are covered now:
    
    * `as public` / `as protected` on a private trait method: the child's
      re-declaration is a real override, and MissingOverrideAttribute must
      still fire. It did not -- a false negative introduced by the guard.
    * `as private` on a public trait method: the parent's method is not part
      of its visible API, so the child's method is not an override. This one
      still raised MissingOverrideAttribute -- the exact false positive this
      PR exists to remove, reached through the other adaptation.
    
    All three new cases were checked against the unpatched tree first: the two
    "promoted" cases fail without this change, the demoted case errors with
    `MissingOverrideAttribute - Method B::f should have the "Override"
    attribute`, and all three pass with it. The original
    traitPrivateMethodRedeclaredByChildIsNotAnOverride case is unaffected.
    
    OverrideTest 19/19, TraitTest 82/82, ClassTest 119/119, MethodSignatureTest
    147 (4 pre-existing skips). parallel-lint, phpcs and Psalm's own analysis of
    the changed file are all clean.
    Eljees committed Aug 28, 2026
    Configuration menu
    Copy the full SHA
    151d1e8 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    45a3901 View commit details
    Browse the repository at this point in the history

Commits on Sep 2, 2026

  1. Fix crash on first-class callables in taint analysis

    FunctionCallReturnTypeFetcher::taintReturnType() calls $stmt->getArgs() on the
    taint-propagation path without checking isFirstClassCallable(). PhpParser's
    CallLike::getArgs() opens with assert(!$this->isFirstClassCallable()), so under
    zend.assertions=1 (PHP's development default) analysing a first-class callable of any
    function with return_source_params aborts the whole run:
    
        $fn = strtolower(...);
        echo $fn("safe");
    
      AssertionError: assert(!$this->isFirstClassCallable())
      in PhpParser/Node/Expr/CallLike.php:32
      from FunctionCallReturnTypeFetcher.php:629
    
    The same file already guards this: line 83 returns early on isFirstClassCallable(), and
    line 668 guards the getArgs() at 674 with the same check. Line 629 was missed.
    
    A first-class callable has no argument list yet, so nothing downstream can propagate taint
    through arguments that do not exist; returning the node unchanged is the same thing the
    sibling path at 668 already does.
    
    Two regression tests added to TaintTest, covering a single-argument and a multi-argument
    taint-propagating function. Both fail on the unpatched tree with the assertion and pass
    with the fix.
    Portll committed Sep 2, 2026
    Configuration menu
    Copy the full SHA
    90d47db View commit details
    Browse the repository at this point in the history

Commits on Sep 12, 2026

  1. Fix inherited native static return types

    Fixes #6232.
    muglug committed Sep 12, 2026
    Configuration menu
    Copy the full SHA
    d48e9f8 View commit details
    Browse the repository at this point in the history

Commits on Sep 13, 2026

  1. Configuration menu
    Copy the full SHA
    7b5b3fb View commit details
    Browse the repository at this point in the history
  2. Merge pull request #11671 from vimeo/fix_function_manipulator

    Fix function manipulator
    danog authored Sep 13, 2026
    Configuration menu
    Copy the full SHA
    070403f View commit details
    Browse the repository at this point in the history

Commits on Sep 14, 2026

  1. Fix

    danog committed Sep 14, 2026
    Configuration menu
    Copy the full SHA
    325d295 View commit details
    Browse the repository at this point in the history

Commits on Sep 15, 2026

  1. Merge pull request #11932 from Portll/fix/first-class-callable-taint-…

    …getargs
    
    Fix crash on first-class callables in taint analysis
    danog authored Sep 15, 2026
    Configuration menu
    Copy the full SHA
    8876449 View commit details
    Browse the repository at this point in the history
  2. Merge pull request #11927 from danielmorell/6.x

    Update nikic/php-parser version to ^5.2.0
    danog authored Sep 15, 2026
    Configuration menu
    Copy the full SHA
    1398c45 View commit details
    Browse the repository at this point in the history
  3. Merge pull request #11926 from Eljees/fix/10982-private-trait-method-…

    …override-fp
    
    Fix MissingOverrideAttribute false positive for private trait methods
    danog authored Sep 15, 2026
    Configuration menu
    Copy the full SHA
    dd62554 View commit details
    Browse the repository at this point in the history
Loading