Skip to content

SecurityAdvisories ​

warning on by default quick-fix

Group: Security · PhpStorm name: SecurityAdvisoriesInspection

Works on a project's composer.json (not on PHP code). Two concerns: development-only packages (test frameworks, debuggers, static analysers…) listed under require end up in production; and an application that pulls third-party packages should also require the advisory "firewall" meta-package in require-dev, which blocks installing versions with known vulnerabilities.

Throughout this spec:

  • ADV is the advisory meta-package: vendor roave, package security-advisories; its full name is vendor, /, package.
  • CHK is the alternative checker package: vendor sensiolabs, package security-checker.
  • DEV is the effective development-package list (option optionConfiguration, see Options).

Options ​

OptionTypeDefaultEffect
REPORT_MISSING_ROAVE_ADVISORIESboolfalseEnables kinds A (missing advisory package, with fix) and L (advisory package not on dev-latest).
REPORT_MISPLACED_DEPENDENCIESbooltrueEnables kind M (development packages under require).
optionConfigurationlist of stringsthe default list belowThe development-package list DEV, used for kind M and for the owner skip (D2).

Effective DEV: upstream always merges the default list into whatever the user configured (user entries ∪ defaults, deduplicated). Recommendation for custos: DEV = defaults ∪ user entries. Entries may also be vendor prefixes ending in / (only meaningful for the owner skip D2).

Conformance note: upstream test cases that do not add the defaults run with an empty DEV (the merge happens only when settings are loaded). With the upstream fixtures this makes no difference to the outcome, except that the two cases which explicitly add the defaults are the only ones where kind M or the owner skip can fire. Using the defaults always is safe.

Default list (vendor / package; the list entry is vendor/package, compared case-insensitively — the entry is stored as mikey179/vfsStream):

VendorPackageVendorPackage
phpunitphpunitphpspecprophecy
johnkaryphpunit-speedtrapphpspecphpspec
brianiumparatesthumbughumbug
mybuilderphpunit-acceleratorinfectioninfection
codedungeonphpunit-result-printermockerymockery
spatiephpunit-watchersatooshiphp-coveralls
symfonyphpunit-bridgemikey179vfsStream
symfonydebugfilpwhoops
symfonymaker-bundlefriendsofphpphp-cs-fixer
zendframeworkzend-testphpstanphpstan
zendframeworkzend-debugvimeopsalm
yiisoftyii2-giijakub-onderkaphp-parallel-lint
yiisoftyii2-debugsquizlabsphp_codesniffer
orchestratestbenchslevomatcoding-standard
barryvdhlaravel-debugbardoctrinecoding-standard
codeceptioncodeceptionphpcompatibilityphp-compatibility
behatbehatzendframeworkzend-coding-standard
yiisoftyii2-coding-standardswp-coding-standardswpcs
phpmdphpmdpdependpdepend
sebastianphpcpdpovilsphpmnd
phanphanphprogrumphp
wimgphp-compatibilitysstallephp7cc
phingphingcomposercomposer
roavesecurity-advisorieskalessilproduction-dependencies-guard

(48 entries.) ADV itself is in the list, so ADV under require is reported as kind M.

Configure ​

In custos.json:

json
{
  "rules": {
    "SecurityAdvisories": {
      "enabled": false,
      "options": {
        "REPORT_MISSING_ROAVE_ADVISORIES": false,
        "REPORT_MISPLACED_DEPENDENCIES": true,
        "optionConfiguration": []
      }
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore SecurityAdvisories

/**
 * @noinspection SecurityAdvisoriesInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.