SecurityAdvisories
warning on by default quick-fixGroup: Security · PhpStorm name: SecurityAdvisoriesInspection
Works on a project's composer.json (not on PHP code). Two concerns: development-only packages (test frameworks, debuggers, static analysers…) listed under require end up in production; and an application that pulls third-party packages should also require the advisory "firewall" meta-package in require-dev, which blocks installing versions with known vulnerabilities.
Throughout this spec:
- ADV is the advisory meta-package: vendor
roave, packagesecurity-advisories; its full name is vendor,/, package. - CHK is the alternative checker package: vendor
sensiolabs, packagesecurity-checker. - DEV is the effective development-package list (option
optionConfiguration, see Options).
Options
| Option | Type | Default | Effect |
|---|---|---|---|
REPORT_MISSING_ROAVE_ADVISORIES | bool | false | Enables kinds A (missing advisory package, with fix) and L (advisory package not on dev-latest). |
REPORT_MISPLACED_DEPENDENCIES | bool | true | Enables kind M (development packages under require). |
optionConfiguration | list of strings | the default list below | The development-package list DEV, used for kind M and for the owner skip (D2). |
Effective DEV: upstream always merges the default list into whatever the user configured (user entries ∪ defaults, deduplicated). Recommendation for custos: DEV = defaults ∪ user entries. Entries may also be vendor prefixes ending in / (only meaningful for the owner skip D2).
Conformance note: upstream test cases that do not add the defaults run with an empty DEV (the merge happens only when settings are loaded). With the upstream fixtures this makes no difference to the outcome, except that the two cases which explicitly add the defaults are the only ones where kind M or the owner skip can fire. Using the defaults always is safe.
Default list (vendor / package; the list entry is vendor/package, compared case-insensitively — the entry is stored as mikey179/vfsStream):
| Vendor | Package | Vendor | Package | |
|---|---|---|---|---|
| phpunit | phpunit | phpspec | prophecy | |
| johnkary | phpunit-speedtrap | phpspec | phpspec | |
| brianium | paratest | humbug | humbug | |
| mybuilder | phpunit-accelerator | infection | infection | |
| codedungeon | phpunit-result-printer | mockery | mockery | |
| spatie | phpunit-watcher | satooshi | php-coveralls | |
| symfony | phpunit-bridge | mikey179 | vfsStream | |
| symfony | debug | filp | whoops | |
| symfony | maker-bundle | friendsofphp | php-cs-fixer | |
| zendframework | zend-test | phpstan | phpstan | |
| zendframework | zend-debug | vimeo | psalm | |
| yiisoft | yii2-gii | jakub-onderka | php-parallel-lint | |
| yiisoft | yii2-debug | squizlabs | php_codesniffer | |
| orchestra | testbench | slevomat | coding-standard | |
| barryvdh | laravel-debugbar | doctrine | coding-standard | |
| codeception | codeception | phpcompatibility | php-compatibility | |
| behat | behat | zendframework | zend-coding-standard | |
| yiisoft | yii2-coding-standards | wp-coding-standards | wpcs | |
| phpmd | phpmd | pdepend | pdepend | |
| sebastian | phpcpd | povils | phpmnd | |
| phan | phan | phpro | grumphp | |
| wimg | php-compatibility | sstalle | php7cc | |
| phing | phing | composer | composer | |
| roave | security-advisories | kalessil | production-dependencies-guard |
(48 entries.) ADV itself is in the list, so ADV under require is reported as kind M.
Configure
In custos.json:
{
"rules": {
"SecurityAdvisories": {
"enabled": false,
"options": {
"REPORT_MISSING_ROAVE_ADVISORIES": false,
"REPORT_MISPLACED_DEPENDENCIES": true,
"optionConfiguration": []
}
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
// @custos-ignore SecurityAdvisories
/**
* @noinspection SecurityAdvisoriesInspection
*/