PHPDecide v1.3.0
PHPDecide v1.3.0 is the first enforcement-ready release.
This version turns recorded decisions into something CI can act on by mapping analyzer findings back to decision IDs, while keeping the decision files themselves as the source of truth.
What's New
- Added the new enforce command for decision-aware enforcement workflows.
- Supports three report inputs:
- generic JSON via --report
- native Semgrep JSON via --semgrep-report
- native PHPStan JSON via --phpstan-report
- Added --format json so CI jobs, bots, and follow-up tooling can consume a structured result.
- Violations are grouped by decision ID and the command exits non-zero when decision-linked violations are found.
- Matching is based on active decisions, scope resolution, and rules.forbid tokens, which gives teams a stable contract between analyzer rule IDs and architectural policy.
- Semgrep-backed enforcement for the DEC-0003 flow
- a second Semgrep example for template-boundary enforcement with DEC-0004
- a native PHPStan identifier-mapping example for DEC-0005
- checked-in fixtures that show both allowed and violating paths
- GitHub Actions examples that run enforcement, emit structured JSON, render PR comments, render annotations, and fail the job using the recorded enforcement result
- Enforcement report loading now normalizes UTF-8 BOM and UTF-16/UTF-32 encoded JSON files, which improves compatibility with shell-generated reports on Windows and in CI.
- Decision rules.forbid tokens now have an explicit operational role in enforcement mapping, making the analyzer-to-decision contract clearer for custom project rules.
Why It Matters
This release does not introduce a new static analyzer.
Instead, PHPDecide acts as the policy and mapping layer on top of tools you may already use.
If you are already using PHPDecide for decision memory and explanation, v1.3.0 adds the missing enforcement bridge:
- keep decisions in .decisions/
- run Semgrep, PHPStan, or another tool that can emit the expected JSON shape
- map findings back to architectural decisions
- use the JSON output in CI, job summaries, annotations, or PR-comment workflows
This release is aimed at teams that want architectural decisions to stay explainable and versioned, while also becoming enforceable in day-to-day delivery pipelines.
Configuration
Use the new enforcement workflow with one of these inputs:
- generic JSON: php ./bin/phpdecide enforce --report build/phpdecide-findings.json
- Semgrep JSON: php ./bin/phpdecide enforce --semgrep-report build/semgrep.json
- PHPStan JSON: php ./bin/phpdecide enforce --phpstan-report build/phpstan.json
For CI and automation, emit structured output with:
php ./bin/phpdecide enforce --report build/phpdecide-findings.json --format json
Decision-to-finding mapping relies on three pieces of configuration:
- active decisions in .decisions/
- scope that matches the finding path
- analyzer rule_id or PHPStan identifier values that match tokens listed in rules.forbid