Skip to content

chore(deps): update dependency squizlabs/php_codesniffer to v4 - #69

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/squizlabs-php_codesniffer-4.x
Open

chore(deps): update dependency squizlabs/php_codesniffer to v4#69
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/squizlabs-php_codesniffer-4.x

Conversation

@renovate

@renovate renovate Bot commented Sep 15, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
squizlabs/php_codesniffer 3.13.64.0.4 age confidence

Release Notes

PHPCSStandards/PHP_CodeSniffer (squizlabs/php_codesniffer)

v4.0.4: - 2026-08-06

Compare Source

The 4.0.2 release, the 4.0.3 and the 4.0.4 release are 100% the same (aside from the version number), there was just a slight snafu in the release publication on GitHub (missing PHAR assets). Sorry for the confusion.

v4.0.2: - 2026-08-06

Compare Source

This is a security release and all users are advised to update their install(s) as soon as possible.
The security issue only affects users of the Gitblame, Hgblame or Svnblame report(s).

Added
  • Tokenizer support for the PHP 8.5 (void) cast. #​1325
    The T_VOID_CAST token has been added to the Tokens::CAST_TOKENS array.
  • suggest section to the composer.json file to inform users about the recommended iconv and pcntl PHP extensions. #​1388
Changed
  • Clarified that libxml is a required PHP extension. #​1409
  • Squiz.Scope.StaticThisUsage: the sniff will now also search for the use of $this in static closures. #​1377
  • The Generic.PHP.LowerCaseKeyword, Generic.WhiteSpace.LanguageConstructSpacing and Squiz.Functions.FunctionDeclarationArgumentSpacing sniffs no longer embed UTF-8 middot characters for spaces in error messages. #​1379, #​1389 Fixes Squiz/#​2652.
  • PSR2.ControlStructures.SwitchDeclaration: the error message for the use of colon + curly braces (WrongOpener*) has been made more informative. #​1358. Fixes #​1322.
  • The error messages for the following sniffs have been improved by exposing more data placeholders:
    • PEAR.Functions.FunctionDeclaration #​1445
      • The CloseBracketLine error message now exposes 1 data value (previously 0).
      • The EmptyLine error message now exposes 1 data value (previously 0).
      • The Indent error message now exposes 3 data values (previously 2).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Functions.MultiLineFunctionDeclaration sniffs.
    • PSR2.Classes.ClassDeclaration #​1446
      • The ExtendsLine and ImplementsLine error messages now expose 3 data values (previously 1).
      • The SpaceBeforeExtends and SpaceBeforeImplements error messages now expose 2 data values (previously 1).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration and Squiz.Classes.ClassDeclaration sniffs.
    • PSR2.ControlStructures.SwitchDeclaration #​1447
      • The defaultNotLower and caseNotLower error messages now expose 3 data values (previously 2).
      • The SpaceBeforeColonDEFAULT and SpaceBeforeColonCASE error messages now expose 1 data value (previously 0).
      • The BodyOnNextLineDEFAULT and BodyOnNextLineCASE error messages now expose 1 data value (previously 0).
      • The WrongOpenerdefault and WrongOpenercase error messages now expose 1 data value (previously 0).
    • Squiz.ControlStructures.SwitchDeclaration #​1449
      • The CaseNotLower and DefaultNotLower error messages now expose 3 data values (previously 2).
      • The CaseIndent and DefaultIndent error messages now expose 2 data values (previously 0).
      • The SpaceBeforeColonCase and SpaceBeforeColonDefault error messages now expose 1 data value (previously 0).
      • The BreakIndent error message now exposes 1 data value (previously 0).
      • The SpacingAfterCase and SpacingAfterDefault error messages now expose 1 data value (previously 0).
    • Squiz.Functions.FunctionDeclarationArgumentSpacing #​1452
      • The SpaceBeforeEquals error message now exposes 3 data values (previously 2).
      • The SpaceAfterEquals error message now exposes 3 data values (previously 2).
    • Squiz.Functions.MultiLineFunctionDeclaration #​1453
      • The FirstParamSpacing and UseFirstParamSpacing error messages now expose 1 data value (previously 0).
      • The OneParamPerLine and UseOneParamPerLine error messages now expose 1 data value (previously 0).
      • These changes also affect the same error codes for the PSR12.Classes.AnonClassDeclaration sniff.
    • If you have customised the error messages of these sniffs, please review your ruleset after upgrading.
    • Thanks to Zhang WenTao for these patches.
  • The following sniff(s) have received efficiency improvements:
    • PSR2.Classes.PropertyDeclaration
    • Thanks to Jonathan Champ for the patch.
  • The test suite is now more contributor friendly for contributors on MacOS. #​1437
  • Various housekeeping, including improvements to the tests and documentation.
Fixed
  • SECURITY FIX: Running PHP_CodeSniffer over untrusted files, for example, in a CI pipeline that scans pull requests, or on a developer machine reviewing third-party code, could result in attacker-controlled shell commands being executed when the Gitblame, Hgblame or Svnblame report(s) would process a file whose name contains shell metacharacters. #​1473
  • Fixed bug #​1320: Generic.Strings.UnnecessaryHeredoc: the fixer could incidentally change tab indentation to space indentation in select lines in the heredoc body.
  • Fixed bug #​1354: PSR12.Functions.ReturnTypeDeclaration: prevent an "Undefined array key" warning if the code under scan contains a parse error.
  • Fixed bug #​1357: Squiz.Scope.StaticThisUsage: false positive for usage of $this in non-static closures nested in OO methods.
  • Fixed bug #​1368: PEAR.Functions.FunctionDeclaration: the indentation for subsequent lines in multi-line block comments within a multi-line function signature, would be incorrectly determined, leading to false positives and resulting in a fixer conflict when running phpcbf.
    • This also fixes, by extension, the same issue in the Squiz.Functions.MultiLineFunctionDeclaration sniff.
  • Fixed bug #​1418: Tokenizer/PHP: tokenization of an inline else colon after an inline comment could fail and/or throw a "Trying to access array offset on null" warning.
  • Fixed bug #​1435: Generic.Formatting.MultipleStatementAlignment would get into a fixer conflict for multiple assignments within a single statement spanning multiple lines.
    • Same as when the statement would be single-line, alignment of subsequent assignment operators within the same multi-line statement will now be ignored.
    • Thanks to Sergei Morozov for the patch.
  • Fixed bug #​1451: Tokenizer/PHP: prevent an "Undefined array key" warning during live coding when a file ends on the name in a constant declaration.
  • Fixed bug #​1463: Squiz.Functions.FunctionDuplicateArgument: prevent an "Undefined array key" PHP warning when the sniff encounters a function declaration without parentheses (parse error / live coding).
Other
  • The GPG signature for the PHAR files has been rotated. The new fingerprint is: 5CB4F77.

New Contributors

The PHP_CodeSniffer project is happy to welcome the following new contributors:
@​bigdevlarry, @​Faze-up, @​jrchamp, @​lazerg, @​morozov, @​ntdiary, @​SAY-5

Statistics

Closed: 10 issues
Merged: 33 pull requests

Follow @​phpcs on Mastodon or @​PHP_CodeSniffer on X to stay informed.

Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!

v4.0.1: - 2025-11-10

Compare Source

This release includes all improvements and bugfixes from PHP_CodeSniffer 3.13.5.

Added
  • Runtime support for PHP 8.5. All known PHP 8.5 deprecation notices have been fixed.
    • Syntax support for new PHP 8.5 features will follow in a future release.
    • If you find any PHP 8.5 deprecation notices which were missed, please report them.
Changed
  • The Squiz.ControlStructures.SwitchDeclaration sniff will now flag a PHP close tag as a "wrong opener" and will auto-fix this by inserting a colon. #​1316
  • Various housekeeping, including improvements to the tests and documentation.
Fixed
  • 4.x regression #​1277: bring back whitespace tolerance in phpcs:ignore comma-separated rule reference lists.
    • Note: this bug did not affect phpcs:disable/phpcs:enable ignore annotations.
  • Fixed bug #​968: Generic.WhiteSpace.ScopeIndent was reporting false positives - and making incorrect fixes - for lines following a line containing an arrow function.
  • Fixed bug #​1216: Tokenizer/PHP: added more defensive coding to prevent PHP 8.5 "Using null as an array offset" deprecation notices.
  • Fixed bug #​1279: Tokenizer/PHP: on PHP < 8.0, an unclosed attribute (parse error) could end up removing some tokens from the token stream.
    • This could lead to false positives and false negative from sniffs, but could also lead to incorrect fixes being made mangling the file under scan.
  • Fixed bug #​1315: Squiz.ControlStructures.SwitchDeclaration: a number of the fixers would get into fixer conflicts with each other if the code under scan contained multiple statements on a line within a switch.
    • The sniff will now forbid - and auto-fix - multiple statements on one line for case/default and "case breaking" statements.
  • Fixed bug #​1316: Tokenizer/PHP: a PHP close tag after a switch case condition or after a default keyword, was not regarded as a "scope_opener" for the case/default body.
  • Fixed bug #​1316: PSR2.ControlStructures.SwitchDeclaration: the WrongOpener error is now also auto-fixable if the wrong opener is a PHP close tag.
  • Fixed bug #​1316: Squiz.PHP.NonExecutableCode would throw false positives when code within a switch control structure would move in and out of PHP.

New Contributors

The PHP_CodeSniffer project is happy to welcome the following new contributors:
@​andrewnicols, @​Soh1121

Statistics

Closed: 2 issues
Merged: 8 pull requests

Follow @​phpcs on Mastodon or @​PHP_CodeSniffer on X to stay informed.

Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!

v4.0.0: - 2025-09-16

Compare Source

This release contains breaking changes.

Upgrade guides for both ruleset maintainers/end-users, as well as for sniff developers and integrators, have been published to the Wiki.

You are strongly encouraged to read the upgrade guide applicable to your situation before upgrading.

This release includes all improvements and bugfixes from PHP_CodeSniffer 4.0.0-beta1, 4.0.0-RC1, 3.13.3 and 3.13.4.

Changed
  • Tokenizer/PHP: fully qualified exit/die/true/false/null will be tokenized as the keyword token and the token 'content' will include the leading backslash. #​1201
  • Wherever possible based on the PHP 7.2 minimum version, parameter types have been added to all methods. #​1237
  • The supported PHPUnit version constraints have been updated to ^8.4.0 || ^9.3.4 || ^10.5.32 || 11.3.3 - 11.5.28 || ^11.5.31. #​1247
    • External standards using the PHP_CodeSniffer native framework may need to update their own PHPUnit version constraints.
  • Various housekeeping, including improvements to the tests and documentation.
Fixed
  • Fixed bug #​1082: new exit codes weren't applied when running phpcbf on code provided via STDIN.
  • Fixed bug #​1172: // phpcs:set for inline array properties did not handle a single item array with the value true, false or null correctly.
  • Fixed bug #​1174: progress bar wasn't showing files as fixed when running phpcbf in parallel mode.
  • Fixed bug #​1226: PHP 8.5 "Using null as an array offset" deprecation notice.
Other
  • Please be aware that the master branch has been renamed to 3.x and the default branch has changed to the 4.x branch.
    • If you contribute to PHP_CodeSniffer, you will need to update your local git clone.
    • If you develop against PHP_CodeSniffer and run your tests against dev branches of PHPCS, you will need to update your workflows.

Statistics

Closed: 5 issues
Merged: 35 pull requests

Follow @​phpcs on Mastodon or @​PHP_CodeSniffer on X to stay informed.

Please consider funding the PHP_CodeSniffer project. If you already do so: thank you!


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file php Pull requests that update Php code labels Sep 15, 2025
@renovate

renovate Bot commented Sep 15, 2025

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: composer.lock
Command failed: composer update squizlabs/php_codesniffer:4.0.4 --with-dependencies --ignore-platform-req=ext-* --ignore-platform-req=lib-* --no-ansi --no-interaction --no-scripts --no-autoloader --no-plugins --minimal-changes
Loading composer repositories with package information
Updating dependencies
Your requirements could not be resolved to an installable set of packages.

  Problem 1
    - Root composer.json requires squizlabs/php_codesniffer 4.0.4 (exact version match: 4.0.4 or 4.0.4.0), found squizlabs/php_codesniffer[4.0.4] but these were not loaded, likely because it conflicts with another require.
  Problem 2
    - wp-coding-standards/wpcs is locked to version 3.4.1 and an update of this package was not requested.
    - wp-coding-standards/wpcs 3.4.1 requires squizlabs/php_codesniffer ^3.13.5 -> found squizlabs/php_codesniffer[3.13.5, 3.13.6] but it conflicts with your root composer.json require (4.0.4).
  Problem 3
    - dealerdirect/phpcodesniffer-composer-installer is locked to version v1.2.1 and an update of this package was not requested.
    - dealerdirect/phpcodesniffer-composer-installer v1.2.1 requires squizlabs/php_codesniffer ^3.1.0 || ^4.0 -> found squizlabs/php_codesniffer[3.1.0, ..., 3.13.6, 4.0.0, 4.0.1, 4.0.2, 4.0.4] but these were not loaded, likely because it conflicts with another require.

Use the option --with-all-dependencies (-W) to allow upgrades, downgrades and removals for packages currently locked to specific versions.

@renovate renovate Bot added dependencies Pull requests that update a dependency file php Pull requests that update Php code labels Sep 15, 2025
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch from 7ec920d to f0c3ad2 Compare October 1, 2025 22:24
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch 2 times, most recently from 4d08e16 to 4d809eb Compare November 10, 2025 19:58
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch from 4d809eb to a9feb25 Compare November 26, 2025 15:26
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch from a9feb25 to 302357e Compare December 3, 2025 16:07
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch from 302357e to a396005 Compare December 15, 2025 17:33
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch 2 times, most recently from 3828fdf to 5aecb37 Compare February 3, 2026 18:45
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch 2 times, most recently from eeeefb8 to d99d0e8 Compare March 12, 2026 00:58
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch from d99d0e8 to 00af3f2 Compare August 6, 2026 04:36
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch 3 times, most recently from ef12e5c to dadbd78 Compare August 20, 2026 22:22
@renovate
renovate Bot force-pushed the renovate/squizlabs-php_codesniffer-4.x branch from dadbd78 to ccf1e9f Compare August 21, 2026 08:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file php Pull requests that update Php code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants