Skip to content

Filenames in HTML report are not escaped#1212

Closed
edorian wants to merge 1 commit into
sebastianbergmann:mainfrom
edorian:escape-html
Closed

Filenames in HTML report are not escaped#1212
edorian wants to merge 1 commit into
sebastianbergmann:mainfrom
edorian:escape-html

Conversation

@edorian
Copy link
Copy Markdown
Contributor

@edorian edorian commented Jun 1, 2026

Hi,

I've recently been playing around with oddly named files as part of a testing project, and while using the code coverage report, I’ve noticed that they sometimes break the layout.

The fix feels somewhat minimal, so hopefully this is the right place and a sensible change.

@codecov
Copy link
Copy Markdown

codecov Bot commented Jun 1, 2026

Codecov Report

❌ Patch coverage is 85.00000% with 3 lines in your changes missing coverage. Please review.
✅ Project coverage is 83.05%. Comparing base (9b96bf1) to head (1feb606).
✅ All tests successful. No failed tests found.

Files with missing lines Patch % Lines
src/Report/Html/Renderer/Directory.php 75.00% 3 Missing ⚠️
Additional details and impacted files
@@             Coverage Diff              @@
##               main    #1212      +/-   ##
============================================
+ Coverage     82.83%   83.05%   +0.21%     
- Complexity     1574     1575       +1     
============================================
  Files           113      113              
  Lines          5326     5329       +3     
============================================
+ Hits           4412     4426      +14     
+ Misses          914      903      -11     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@sebastianbergmann sebastianbergmann self-assigned this Jun 1, 2026
@sebastianbergmann sebastianbergmann changed the title Escape filenames in HTML output Filenames in HTML report are not escaped Jun 1, 2026
sebastianbergmann added a commit that referenced this pull request Jun 1, 2026
sebastianbergmann added a commit that referenced this pull request Jun 1, 2026
* 14.1:
  Update tools
  Backport #1212
  Update dependency phpstan/phpstan to ^2.2.1
  Update dependency phpunit/phpunit to ^12.5.28
  Update dependency tomasvotruba/type-coverage to ^2.2.1
  Update dependency phpstan/phpstan to ^2.1.56
  Update dependency sebastian/environment to ^8.1.2
  Update dependency phpunit/phpunit to ^12.5.27
  Update dependency phpunit/phpunit to ^12.5.26
  Update dependency sebastian/environment to ^8.1.1
  Update dependency sebastian/lines-of-code to ^4.0.1
  Update github-actions
  Update dependency phpstan/phpstan to ^2.1.55
  Update codecov/codecov-action digest to e79a696
@sebastianbergmann
Copy link
Copy Markdown
Owner

sebastianbergmann commented Jun 1, 2026

I backported the changes that apply to 12.5 to 12.5 and cherry-picked your changes into 14.1 from where I merged them to main. Thank you!

sebastianbergmann added a commit that referenced this pull request Jun 1, 2026
Route class, trait, function, and method names in the per-file HTML report through htmlspecialchars(), consistent with the filename escaping added in #1212. These names originate from PHP-Parser identifiers and cannot contain HTML metacharacters today, so this is defense-in-depth that keeps the renderer's escaping uniform.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants