Repository navigation
v0.1.0
First public release.
Added
- 178 PHP inspections in 12 groups (probable bugs, performance, security,
control flow, code style, unused code, PHPUnit, language-level migration
5.3 → 8.5, …), 108 of them with quick-fixes. Rules follow the target PHP
version. Rule IDs are compatible with Php Inspections (EA Extended), so
existing@noinspectioncomments keep working;@custos-ignoreworks
too. See the rule reference. - CLI:
analyse(text, json, checkstyle, github and sarif output;
--fail-on; baselines for legacy code),fix(--dry-run,--diff,
parallel),rules,explain,lsp,version. - Language server: diagnostics, quick-fixes, fix-all, "suppress for this
statement" code action, and a background project index kept current
through file watching. Setup guides for Neovim, Helix, VS Code, PhpStorm,
Sublime Text and Emacs. - Configuration through an optional
custos.json(paths, rules and their
options, baseline); the PHP target falls back tocomposer.json. - Own PHP 5.3–8.5 parser (lossless, error tolerant) and semantic layer: a
symbol index with embedded JetBrains phpstorm-stubs, type inference with
narrowing, and PHPDoc support (generics and@template, type aliases,
array shapes, conditional return types,@param-out, phpstan/psalm
assertions). - Distribution: release archives for Linux, macOS and Windows (amd64,
arm64), a Homebrew cask (brew install janalis/tap/custos) and a Composer
package (composer require --dev janalis/custos) whose launcher downloads
the checksum-verified binary. - Documentation site: https://janalis.github.io/custos/ (user guide, one
page per rule with examples and quick-fix results, contributor guide).
Security
- Hostile input cannot crash, hang or exhaust the analyser: nesting depth,
file size (10 MB), syntax errors and findings per file are capped, PHPDoc
types are parsed in linear time, and known quadratic paths were removed. - Only regular files are read, with size caps;
pathsandbaselinemust
stay inside the project;custos fixnever writes through symlinks; the
language server rejects malformed or oversized messages.
Notes
- custos is a clean-room implementation and intentionally differs from
upstream where upstream behaviour is wrong (false positives, fixes that
change semantics or produce invalid PHP).