Skip to content

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 08 Oct 16:53
· 64 commits to main since this release

First public release.

Added

  • 178 PHP inspections in 12 groups (probable bugs, performance, security,
    control flow, code style, unused code, PHPUnit, language-level migration
    5.3 → 8.5, …), 108 of them with quick-fixes. Rules follow the target PHP
    version. Rule IDs are compatible with Php Inspections (EA Extended), so
    existing @noinspection comments keep working; @custos-ignore works
    too. See the rule reference.
  • CLI: analyse (text, json, checkstyle, github and sarif output;
    --fail-on; baselines for legacy code), fix (--dry-run, --diff,
    parallel), rules, explain, lsp, version.
  • Language server: diagnostics, quick-fixes, fix-all, "suppress for this
    statement" code action, and a background project index kept current
    through file watching. Setup guides for Neovim, Helix, VS Code, PhpStorm,
    Sublime Text and Emacs.
  • Configuration through an optional custos.json (paths, rules and their
    options, baseline); the PHP target falls back to composer.json.
  • Own PHP 5.3–8.5 parser (lossless, error tolerant) and semantic layer: a
    symbol index with embedded JetBrains phpstorm-stubs, type inference with
    narrowing, and PHPDoc support (generics and @template, type aliases,
    array shapes, conditional return types, @param-out, phpstan/psalm
    assertions).
  • Distribution: release archives for Linux, macOS and Windows (amd64,
    arm64), a Homebrew cask (brew install janalis/tap/custos) and a Composer
    package (composer require --dev janalis/custos) whose launcher downloads
    the checksum-verified binary.
  • Documentation site: https://janalis.github.io/custos/ (user guide, one
    page per rule with examples and quick-fix results, contributor guide).

Security

  • Hostile input cannot crash, hang or exhaust the analyser: nesting depth,
    file size (10 MB), syntax errors and findings per file are capped, PHPDoc
    types are parsed in linear time, and known quadratic paths were removed.
  • Only regular files are read, with size caps; paths and baseline must
    stay inside the project; custos fix never writes through symlinks; the
    language server rejects malformed or oversized messages.

Notes

  • custos is a clean-room implementation and intentionally differs from
    upstream where upstream behaviour is wrong (false positives, fixes that
    change semantics or produce invalid PHP).