Skip to content
This repository has been archived by the owner on Jan 4, 2022. It is now read-only.

Build(deps-dev): Bump vimeo/psalm from 3.11.6 to 3.12.1 #258

Merged
merged 1 commit into from
Jun 23, 2020

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 23, 2020

Bumps vimeo/psalm from 3.11.6 to 3.12.1.

Release notes

Sourced from vimeo/psalm's releases.

Improve taint analysis a little

Taint analysis

  • $_REQUEST is now treated as a source, and taints now flow through trim and similar funcs
  • @psalm-taint-specialize now works in static methods

Also @TysonAndre added a --debug-emitted-issues command line flag to help debug the route of a Psalm issue.

Bugfixes

  • preg_replace_callback now supports arrays properly even when the closure is not well-documented (#3639)

Add --taint-analysis command

This will be the officially-supported taint analysis command going forward.

Add more taint analysis features

Features

  • various taint analysis improvements
  • added an <extraFiles> tag to tell Psalm about directories it should scan, but not analyse (#3618)

Bugfixes

  • add better support for complex switch (true) case statements (#3603)
  • allow lists to have their types refined in @psalm-assert calls (#3605)
  • treat (Foo\Bar::class)::baz() as Foo\Bar::baz() (#3609)
  • @andrei-petre improved error message casing for undefined methods (#3615)
  • @iluuu1994 allowed strings with leading backslashes e.g. '\Foo\Bar::baz' to be treated as callables (#3607)
  • prevent a crash when analysing an assertion on a class constant where the class doesn’t exist (#3607)
Commits
  • 9b86021 Fix #3639 - allow coerced types to count when picking callmap options
  • 1f86afe Revert "Fix #3631 - apply assertions to RHS of equality in conditional"
  • fc8212e Fix static call specialisation via annotation
  • bee10a2 Add a --debug-emitted-issues flag (#3637)
  • e8be2c5 Support taint flows in more functions
  • 7f05b3c Add $_REQUEST as a taint source
  • f2f5606 Document other supported --report file names (#3633)
  • 9c17795 Fix #3631 - apply assertions to RHS of equality in conditional
  • 29eb830 Remove taint annotation as it could confuse
  • d462830 Add --taint-analysis to command line help
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@codecov
Copy link

codecov bot commented Jun 23, 2020

Codecov Report

Merging #258 into main will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@             Coverage Diff             @@
##                main      #258   +/-   ##
===========================================
  Coverage     100.00%   100.00%           
  Complexity        41        41           
===========================================
  Files              4         4           
  Lines            159       159           
===========================================
  Hits             159       159           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 7051f1c...811fa64. Read the comment docs.

@ergebnis-bot ergebnis-bot self-requested a review June 23, 2020 05:43
@ergebnis-bot ergebnis-bot self-assigned this Jun 23, 2020
@ergebnis-bot ergebnis-bot merged commit 928fda0 into main Jun 23, 2020
@dependabot dependabot bot deleted the dependabot/composer/vimeo/psalm-3.12.1 branch June 23, 2020 05:43
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant