Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
f7902b2
tests: configure PHPStan
justlevine Oct 22, 2024
805199c
chore: update config
justlevine Oct 27, 2024
5aad07a
tests: exclude `wp-include/blocks` from PHPStan analysis
justlevine Oct 30, 2024
cc24e27
chore: remove `-v` flag from `analyse` composer command
justlevine Nov 4, 2024
c2da5b6
tests: regenerate PHPStan baselines after rebase
justlevine Nov 4, 2024
8fd0517
tests: exclude additional external libraries to match phpcs.xml.dist
justlevine Nov 4, 2024
cdc3c6d
tmp: bump PHPStan to 2.x
justlevine Feb 1, 2025
9bb36a4
chore: regenerate PHPStan Baselines after rebase
justlevine Feb 21, 2025
6744b39
tests: suppress errors when string is used as `callable`
justlevine Feb 21, 2025
64d5311
chore: regenerate PHPStan Baselines after rebase
justlevine Apr 12, 2025
3746454
chore: regenerate PHPStan baselines after rebase
justlevine May 9, 2025
da39d35
dev: revert PHPStan to v1.x
justlevine May 23, 2025
52375af
ci: add GH workflow for PHPStan
justlevine May 23, 2025
004f70a
chore: regenerate PHPStan baselines after rebase
justlevine May 23, 2025
44c3beb
ci: use verbose PHPStan debugging
justlevine May 23, 2025
8a3775f
chore: regenerate PHPStan baselines after rebase
justlevine May 31, 2025
6589ce9
tests: define PHPStan `dynamicConstantNames`
justlevine May 31, 2025
c2acb6e
tests: Ignore `missingType.return` PHPStan error until `: void` types…
justlevine May 31, 2025
44a62c0
chore: regenerate PHPStan baselines
justlevine May 31, 2025
0e2d031
tests: set PHPStan `treatPhpDocTypesAsCertain` to false
justlevine May 31, 2025
d949a94
chore: regenerate PHPStan baselines
justlevine May 31, 2025
c92201e
chore: regenerate PHPStan baselines
justlevine Jun 1, 2025
d6d59a0
tests: Don't stan deprecated `wp-tinymce.php`
justlevine Jun 10, 2025
3a7f4d4
chore: regenerate PHPStan baselines
justlevine Jun 10, 2025
06f7f92
PHPStan: define additional dynamic constants
justlevine Jun 11, 2025
9ca376e
PHPStan: additional dynamicConstantNames
justlevine Jun 18, 2025
50169b6
chore: regenerate PHPStan baselines
justlevine Jun 18, 2025
fb61258
chore: regenerate PHPStan baselines
justlevine Jun 23, 2025
174afe0
PHPStan: limit memory usage when running `composer analyse`
justlevine Jun 28, 2025
c8645e8
chore: regenerate PHPStan baselines
justlevine Jun 28, 2025
fe5882a
tests: bump PHPStan to v2.x
justlevine Jul 8, 2025
5f43db2
chore: regenerate PHPStan baselines
justlevine Jul 8, 2025
0840486
chore: regenerate baselines
justlevine Jul 11, 2025
8a152d3
Remove some testing on < 7.4.
johnbillion Jul 12, 2025
9125d57
chore: use tabs for `.neon` and update annotation tenses
justlevine Jul 14, 2025
94fca70
PHPStan: restore and baseline inner function smells.
justlevine Jul 14, 2025
87e966a
ci: rename job + fix version targeting
justlevine Jul 14, 2025
1c9cfb9
PHPStan: clarify `dynamicConstantNames`
justlevine Jul 14, 2025
c43413f
chore: regenerate baselines
justlevine Jul 19, 2025
7e71c2f
chore: fix mixed tabs/spaces
justlevine Jul 19, 2025
0069fc5
chore: fix typo in phpstan.neon
justlevine Jul 25, 2025
d5a10d2
chore: regenerate baselines
justlevine Jul 25, 2025
f6af340
chore: bump phpstan to minimum 2.1.19 (bugfix)
justlevine Jul 26, 2025
46d4e72
phpstan: regenerate baselines
justlevine Jul 26, 2025
760d701
phpstan: regenerate baselines after rebase
justlevine Aug 16, 2025
9680162
phpstan: regenerate baselines after rebase
justlevine Oct 24, 2025
2839f28
phpstan: bump max PHP version to check to 80500
justlevine Oct 24, 2025
a4ee081
phpstan: remove unnecessary `WP_CONTENT_DIR` from bootstrap
justlevine Oct 24, 2025
6e2aa00
phpstan: ignore `wp-includes.user`
justlevine Oct 24, 2025
020f347
phpstan: update excludePaths
justlevine Oct 24, 2025
9f09845
phpstan: regenerate baselines
justlevine Oct 24, 2025
86c9442
tests: phpstan level 0
justlevine Oct 25, 2025
e50b2dc
Merge branch 'tests/phpstan/level-0' into feat/phpstan
justlevine Oct 25, 2025
8ea09de
chore: post-merge cleanup
justlevine Oct 25, 2025
0308f9e
tests: phpstan level 0
justlevine Nov 7, 2025
5ccfa1c
Merge branch 'tests/phpstan/level-0' into feat/phpstan
justlevine Nov 7, 2025
79b737b
chore: regenerate baselines
justlevine Nov 7, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
100 changes: 100 additions & 0 deletions .github/workflows/php-static-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,100 @@
name: PHPStan Static Analysis

on:
# PHPStan testing was introduced in @todo.
push:
branches:
- trunk
- '6.9'
- '[7-9].[0-9]'
tags:
- '6.9'
- '6.9.[0-9]+'
- '[7-9].[0-9]'
- '[7-9]+.[0-9].[0-9]+'
pull_request:
branches:
- trunk
- '6.9'
- '[7-9].[0-9]'
paths:
# This workflow only scans PHP files.
- '**.php'
# These files configure Composer. Changes could affect the outcome.
- 'composer.*'
# These files configure PHPStan. Changes could affect the outcome.
- 'phpstan.neon.dist'
- 'tests/phpstan/base.neon'
# Confirm any changes to relevant workflow files.
- '.github/workflows/php-static-analysis.yml'
- '.github/workflows/reusable-php-static-analysis.yml'
workflow_dispatch:

# Cancels all previous workflow runs for pull requests that have not completed.
concurrency:
# The concurrency group contains the workflow name and the branch name for pull requests
# or the commit hash for any other events.
group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.head_ref || github.sha }}
cancel-in-progress: true

# Disable permissions for all available scopes by default.
# Any needed permissions should be configured at the job level.
permissions: {}

jobs:
# Runs PHPStan Static Analysis.
phpstan:
name: PHP coding standards
uses: ./.github/workflows/reusable-php-static-analysis.yml
permissions:
contents: read
if: ${{ github.repository == 'WordPress/wordpress-develop' || ( github.event_name == 'pull_request' && github.actor != 'dependabot[bot]' ) }}

slack-notifications:
name: Slack Notifications
uses: ./.github/workflows/slack-notifications.yml
permissions:
actions: read
contents: read
needs: [ phpstan ]
if: ${{ github.repository == 'WordPress/wordpress-develop' && github.event_name != 'pull_request' && always() }}
with:
calling_status: ${{ contains( needs.*.result, 'cancelled' ) && 'cancelled' || contains( needs.*.result, 'failure' ) && 'failure' || 'success' }}
secrets:
SLACK_GHA_SUCCESS_WEBHOOK: ${{ secrets.SLACK_GHA_SUCCESS_WEBHOOK }}
SLACK_GHA_CANCELLED_WEBHOOK: ${{ secrets.SLACK_GHA_CANCELLED_WEBHOOK }}
SLACK_GHA_FIXED_WEBHOOK: ${{ secrets.SLACK_GHA_FIXED_WEBHOOK }}
SLACK_GHA_FAILURE_WEBHOOK: ${{ secrets.SLACK_GHA_FAILURE_WEBHOOK }}

failed-workflow:
name: Failed workflow tasks
runs-on: ubuntu-24.04
permissions:
actions: write
needs: [ slack-notifications ]
if: |
always() &&
github.repository == 'WordPress/wordpress-develop' &&
github.event_name != 'pull_request' &&
github.run_attempt < 2 &&
(
contains( needs.*.result, 'cancelled' ) ||
contains( needs.*.result, 'failure' )
)

steps:
- name: Dispatch workflow run
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
with:
retries: 2
retry-exempt-status-codes: 418
script: |
github.rest.actions.createWorkflowDispatch({
owner: context.repo.owner,
repo: context.repo.repo,
workflow_id: 'failed-workflow.yml',
ref: 'trunk',
inputs: {
run_id: `${context.runId}`,
}
});
95 changes: 95 additions & 0 deletions .github/workflows/reusable-php-static-analysis.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,95 @@
##
# A reusable workflow that runs PHP Static Analysis tests.
##
name: PHP Static Analysis

on:
workflow_call:
inputs:
php-version:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The php tests just uses php as this variable name while phpcompatability and this new one use php-version. I think we should make all of these consistent.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this something to be addressed in this PR, and if so in which direction?

(regular PHPCS also uses php-version https://github.com/justlevine/wordpress-develop/blob/7391ed6aadf101ca4e6e3c82fe841cbade4358ee/.github/workflows/reusable-coding-standards-php.yml#L9 )

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's something that should be addressed before this PR and then this PR may need to be updated. I'll raise a slack discussion.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

description: 'The PHP version to use.'
required: false
type: 'string'
default: 'latest'
Copy link
Author

@justlevine justlevine Jul 8, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm thinking this is why CI fails despite passing locally - I've baselined on v8.3.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think it's better to leave out a default since this could cause issues in the future. For example, once 9.0 is the latest PHP, versions of WP that don't support it shouldn't have that as the default. Better to be explicit about the version.

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Agreed, but what version do we use:

  • latest official PHP release,
  • latest non-beta-compatibility PHP version,
  • the lowest compatible version,
  • something else?


# Disable permissions for all available scopes by default.
# Any needed permissions should be configured at the job level.
permissions: {}

jobs:
# Runs PHP static analysis tests.
#
# Violations are reported inline with annotations.
#
# Performs the following steps:
# - Checks out the repository.
# - Sets up PHP.
# - Logs debug information.
# - Installs Composer dependencies.
# - Configures caching for PHP static analysis scans.
# - Make Composer packages available globally.
# - Runs PHPStan static analysis (with Pull Request annotations).
# - Saves the PHPStan result cache.
# - Ensures version-controlled files are not modified or deleted.
phpstan:
name: Run PHP static analysis
runs-on: ubuntu-24.04
permissions:
contents: read
timeout-minutes: 20

steps:
- name: Checkout repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
show-progress: ${{ runner.debug == '1' && 'true' || 'false' }}
persist-credentials: false

- name: Set up PHP
uses: shivammathur/setup-php@9e72090525849c5e82e596468b86eb55e9cc5401 # v2.32.0
with:
php-version: ${{ inputs.php-version }}
coverage: none
tools: cs2pr

- name: Log debug information
run: |
composer --version

# This date is used to ensure that the Composer cache is cleared at least once every week.
# http://man7.org/linux/man-pages/man1/date.1.html
- name: "Get last Monday's date"
id: get-date
run: echo "date=$(/bin/date -u --date='last Mon' "+%F")" >> "$GITHUB_OUTPUT"

# Since Composer dependencies are installed using `composer update` and no lock file is in version control,
# passing a custom cache suffix ensures that the cache is flushed at least once per week.
- name: Install Composer dependencies
uses: ramsey/composer-install@a2636af0004d1c0499ffca16ac0b4cc94df70565 # v3.1.0
with:
custom-cache-suffix: ${{ steps.get-date.outputs.date }}

- name: Make Composer packages available globally
run: echo "${PWD}/vendor/bin" >> "$GITHUB_PATH"

- name: Cache PHP Static Analysis scan cache
uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4.2.3
with:
path: .cache # This is defined in the base.neon file.
key: "phpstan-result-cache-${{ github.run_id }}"
restore-keys: |
phpstan-result-cache-

- name: Run PHP static analysis tests
id: phpstan
run: phpstan analyse -vvv --error-format=checkstyle | cs2pr

- name: "Save result cache"
uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4.2.3
if: ${{ !cancelled() }}
with:
path: .cache
key: "phpstan-result-cache-${{ github.run_id }}"

- name: Ensure version-controlled files are not modified or deleted
run: git diff --exit-code
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ wp-tests-config.php
/build
/tests/phpunit/build
/wp-cli.local.yml
/phpstan.neon
/jsdoc
/composer.lock
/vendor
Expand Down
2 changes: 2 additions & 0 deletions composer.json
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@
"squizlabs/php_codesniffer": "3.13.2",
"wp-coding-standards/wpcs": "~3.2.0",
"phpcompatibility/phpcompatibility-wp": "~2.1.3",
"phpstan/phpstan": "~2.1.31",
"yoast/phpunit-polyfills": "^1.1.0"
},
"config": {
Expand All @@ -32,6 +33,7 @@
"lock": false
},
"scripts": {
"analyse": "@php ./vendor/bin/phpstan analyse --memory-limit=2G",
"compat": "@php ./vendor/squizlabs/php_codesniffer/bin/phpcs --standard=phpcompat.xml.dist --report=summary,source",
"format": "@php ./vendor/squizlabs/php_codesniffer/bin/phpcbf --report=summary,source",
"lint": "@php ./vendor/squizlabs/php_codesniffer/bin/phpcs --report=summary,source",
Expand Down
1 change: 1 addition & 0 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -192,6 +192,7 @@
"env:logs": "node ./tools/local-env/scripts/docker.js logs",
"env:pull": "node ./tools/local-env/scripts/docker.js pull",
"test:performance": "wp-scripts test-playwright --config tests/performance/playwright.config.js",
"test:php:stan": "node ./tools/local-env/scripts/docker.js run --rm php ./vendor/bin/phpstan analyse --memory-limit=2G",
"test:php": "node ./tools/local-env/scripts/docker.js run --rm php ./vendor/bin/phpunit",
"test:coverage": "npm run test:php -- --coverage-html ./coverage/html/ --coverage-php ./coverage/php/report.php --coverage-text=./coverage/text/report.txt",
"test:e2e": "wp-scripts test-playwright --config tests/e2e/playwright.config.js",
Expand Down
3 changes: 3 additions & 0 deletions phpcs.xml.dist
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,9 @@
<exclude-pattern>/tests/phpunit/build*</exclude-pattern>
<exclude-pattern>/tests/phpunit/data/*</exclude-pattern>

<!-- PHPStan bootstrap, stubs, and baseline. -->
<exclude-pattern>/tests/phpstan/*</exclude-pattern>

<exclude-pattern>/tools/*</exclude-pattern>

<!-- Drop-in plugins. -->
Expand Down
55 changes: 55 additions & 0 deletions phpstan.neon.dist
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# PHPStan configuration for WordPress Core.
#
# To overload this configuration, copy this file to phpstan.neon and adjust as needed.
#
# https://phpstan.org/config-reference

includes:
# The WordPress Core configuration file includes the base configuration for the WordPress codebase.
- tests/phpstan/base.neon
# The baseline file includes preexisting errors in the codebase that should be ignored.
# https://phpstan.org/user-guide/baseline

- tests/phpstan/baseline.php # level 0.
- tests/phpstan/baseline/level-1.php
- tests/phpstan/baseline/level-2.php
- tests/phpstan/baseline/level-3.php
- tests/phpstan/baseline/level-4.php
- tests/phpstan/baseline/level-5.php
- tests/phpstan/baseline/level-6.php

parameters:
level: 6
reportUnmatchedIgnoredErrors: true

ignoreErrors:
# Level 0:
- # Inner functions arent supported by PHPstan.
message: '#Function wxr_[a-z_]+ not found#'
path: src/wp-admin/includes/export.php
-
identifier: function.inner
path: src/wp-admin/includes/export.php
count: 13
-
identifier: function.inner
path: src/wp-admin/includes/file.php
count: 1
-
identifier: function.inner
path: src/wp-includes/canonical.php
count: 1

# Level 1:
- # These are too noisy at the moment.
message: '#Variable \$[a-zA-Z0-9_]+ might not be defined\.#'

# Level 2:
- # Callable-strings are used as callables in WordPress.
message: '#Default value of the parameter .* is incompatible with type callable.*#'

# Level 6:
- # WPCS syntax for iterable types is not supported.
identifier: missingType.iterableValue
- # Too noisy until `void` return types are allowed.
identifier: missingType.return
1 change: 1 addition & 0 deletions src/wp-admin/includes/class-wp-filesystem-ssh2.php
Original file line number Diff line number Diff line change
Expand Up @@ -672,6 +672,7 @@ public function size( $file ) {
* Default 0.
*/
public function touch( $file, $time = 0, $atime = 0 ) {
// @phpstan-ignore-next-line
// Not implemented.
}

Expand Down
4 changes: 2 additions & 2 deletions src/wp-admin/press-this.php
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,8 @@ function wp_load_press_this() {
403
);
} elseif ( is_plugin_active( $plugin_file ) ) {
include WP_PLUGIN_DIR . '/press-this/class-wp-press-this-plugin.php';
$wp_press_this = new WP_Press_This_Plugin();
include WP_PLUGIN_DIR . '/press-this/class-wp-press-this-plugin.php'; // @phpstan-ignore include.fileNotFound
$wp_press_this = new WP_Press_This_Plugin(); // @phpstan-ignore class.notFound
$wp_press_this->html();
} elseif ( current_user_can( 'activate_plugins' ) ) {
if ( file_exists( WP_PLUGIN_DIR . '/' . $plugin_file ) ) {
Expand Down
4 changes: 3 additions & 1 deletion src/wp-includes/class-wp-theme-json.php
Original file line number Diff line number Diff line change
Expand Up @@ -3365,7 +3365,7 @@ public function get_svg_filters( $origins ) {
* @param array $theme_json The theme.json like structure to inspect.
* @param array $path Path to inspect.
* @param bool|array $override Data to compute whether to override the preset.
* @return bool
* @return bool|null True if the preset should override the defaults, false if not. Null if the override parameter is invalid.
*/
protected static function should_override_preset( $theme_json, $path, $override ) {
_deprecated_function( __METHOD__, '6.0.0', 'get_metadata_boolean' );
Expand Down Expand Up @@ -3400,6 +3400,8 @@ protected static function should_override_preset( $theme_json, $path, $override

return true;
}

return null;
}

/**
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,7 @@ final class WP_Customize_Background_Image_Setting extends WP_Customize_Setting {
* @since 3.4.0
*
* @param mixed $value The value to update. Not used.
* @return bool|void Nothing is returned.
*/
public function update( $value ) {
remove_theme_mod( 'background_image_thumb' );
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ class WP_Customize_Filter_Setting extends WP_Customize_Setting {
* @since 3.4.0
*
* @param mixed $value The value to update.
* @return bool|void Nothing is returned.
*/
public function update( $value ) {}
}
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@ final class WP_Customize_Header_Image_Setting extends WP_Customize_Setting {
* @global Custom_Image_Header $custom_image_header
*
* @param mixed $value The value to update.
* @return bool|void Nothing is returned.
*/
public function update( $value ) {
global $custom_image_header;
Expand Down
2 changes: 1 addition & 1 deletion src/wp-includes/media.php
Original file line number Diff line number Diff line change
Expand Up @@ -4118,7 +4118,7 @@ function get_taxonomies_for_attachments( $output = 'names' ) {
* false otherwise.
*/
function is_gd_image( $image ) {
if ( $image instanceof GdImage
if ( $image instanceof GdImage // @phpstan-ignore class.notFound (Only available with PHP8+.)
|| is_resource( $image ) && 'gd' === get_resource_type( $image )
) {
return true;
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ public static function get_store( $store_name = 'default' ) {
return;
}
if ( ! isset( static::$stores[ $store_name ] ) ) {
// @phpstan-ignore new.static (In PHPStan 2.x we can enforce with `@phpstan-consistent-constructor`)
static::$stores[ $store_name ] = new static();
// Set the store name.
static::$stores[ $store_name ]->set_name( $store_name );
Expand Down
2 changes: 1 addition & 1 deletion src/wp-includes/template.php
Original file line number Diff line number Diff line change
Expand Up @@ -796,7 +796,7 @@ function load_template( $_template_file, $load_once = true, $args = array() ) {
}

if ( isset( $s ) ) {
$s = esc_attr( $s );
$s = esc_attr( $s ); // @phpstan-ignore variable.undefined (It's extracted from query vars.)
}

/**
Expand Down
Loading
Loading