Skip to content

Command line ​

sh
custos analyse [flags] [paths...]   # report problems
custos fix [flags] [paths...]       # apply quick-fixes
custos explain <rule>               # describe a rule and its options
custos rules [--json]               # list rules
custos lsp                          # language server over stdio
custos version

analyze is accepted as an alias of analyse. Run custos <command> -h for the flags of a command. Flags can be written --php 8.1 or --php=8.1.

Paths ​

Without paths, custos uses paths from custos.json, or else the project root: the directory holding custos.json or composer.json. vendor, node_modules, .git, .idea, .custos and var/cache are always skipped. To skip more, use exclude in custos.json or --exclude a,b. Directories are searched for .php files (plus the few files some rules read, such as composer.json); a file named on the command line is analysed whatever its extension.

Common flags ​

These apply to both analyse and fix:

FlagMeaning
--php 8.1Target PHP version; rules are gated on it. Default: custos.json, then composer config.platform.php, then the lowest version require.php allows, then 8.4.
--rule A,BRun only these rules (IDs or PhpStorm inspection names).
--allEnable every rule, including the ones off by default.
--comparison-style regular|yodaPreferred operand order for comparison rules and their fixes.
--config DIRWhere to look for custos.json (default: the first path).
--exclude a,bExtra directories to skip.

analyse ​

FlagMeaning
--format text|json|checkstyle|github|sarifOutput format (default text).
--fail-on info|warning|error|neverExit 1 when a finding has at least this severity (default warning).
--baseline FILEIgnore the findings recorded in this baseline (default: baseline in custos.json).
--generate-baseline FILERecord all current findings in FILE and exit 0.
--statsPrint timing, file and rule counts on stderr.

Output formats:

  • text: file:line:col: severity: message [Rule] (fixable) and a summary line.
  • json: {"files": N, "findings": [...]}, each finding with path, line, column, endLine, endColumn, rule, severity, message and fixable.
  • checkstyle: Checkstyle XML, read by many CI dashboards.
  • github: GitHub Actions workflow commands, shown as annotations on the pull request diff.
  • sarif: SARIF 2.1.0, for GitHub code scanning and other SARIF viewers.

fix ​

FlagMeaning
--dry-runDo not write files.
--diffPrint a unified diff of the changes.

Fixes are applied repeatedly until nothing changes (at most 10 rounds), since one fix can reveal another finding. A file that cannot be read or written is reported and the other files are still fixed; fix then exits 2. custos never writes through symlinks.

explain and rules ​

sh
custos explain UnnecessarySemicolon     # summary, options, suppression name
custos rules                            # ✓ marks implemented rules; group, severity, default
custos rules --json                     # the full catalogue, for tooling

Exit codes ​

CodeMeaning
0Success; no finding at or above --fail-on.
1Findings at or above --fail-on.
2Usage or configuration error (unknown flag value, bad custos.json…), or files fix could not process.

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.