Skip to content

Update phpmd/phpmd requirement from ^2.15 to ^3.0 in the dev-dependencies group - #120

Merged
PDowney merged 1 commit into
mainfrom
dependabot/composer/dev-dependencies-5d80abdc54
Oct 9, 2026
Merged

PDowney merged 1 commit into
mainfrom
dependabot/composer/dev-dependencies-5d80abdc54

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on phpmd/phpmd to permit the latest version.
Updates phpmd/phpmd to 3.0.0

Release notes

Sourced from phpmd/phpmd's releases.

PHPMD 3.0.0

New major release of PHPMD. See UPGRADING.md for a detailed migration guide from PHPMD 2 to PHPMD 3.

Key New Features

  • Interactive Configuration Wizard: Run phpmd init to generate a custom configuration file through an interactive setup tool.
  • Configuration Migration Tool: Run phpmd migrate to upgrade legacy PHPMD 2 XML configurations directly into YAML.
  • Zero-Config CLI Execution: Running phpmd without arguments now automatically detects configuration and target paths.
  • Centralized Settings: Most analysis options (such as paths, format, cache, threads, and baseline) can now be defined directly inside configuration files instead of requiring CLI arguments.
  • PHP 8 Attributes Support: Use #[SuppressWarnings] as the preferred way to suppress warnings, backed by a new UnusedSuppression rule to identify stale suppressions.
  • Parallel Processing: Speed up analysis on large codebases using the new --threads option for multi-threaded parsing.
  • Visual Feedback: Added a progress bar during CLI analysis (with controls via --no-progress and --progress).
  • New Analysis Rules: IfStatementWithoutLogic and LongMethodName For flagging dead code and long method names.
  • Enhanced Rule Flexibility: Added exceptions parameter support to ignore specific methods across UnusedFormalParameter, UnusedPrivateField, and ExcessiveParameterList, along with enum method handling in StaticAccess.
  • GitHub Check Runs Renderer: Added native output renderer support for GitHub Check Runs integration.

Breaking changes:

  • Changed minimum PHP version from 5.3.9 to 8.1.
  • Changed CLI from positional arguments to Symfony Console with named options. The command signature is now phpmd analyze [options] [--] [<paths>...].
  • Standardized rule threshold properties to maximum (#670). Rules now report only when the measured value exceeds (>) the configured maximum. Rules that check a lower bound (ShortVariable, ShortMethodName, ShortClassName) keep the minimum property. Renamed properties (the old names remain accepted as aliases):
    • CyclomaticComplexity: reportLevel -> maximum
    • NPathComplexity: minimum -> maximum
    • ExcessiveMethodLength: minimum -> maximum
    • ExcessiveClassLength: minimum -> maximum
    • ExcessiveParameterList: minimum -> maximum
    • ExcessivePublicCount: minimum -> maximum
    • TooManyFields: maxfields -> maximum
    • TooManyMethods: maxmethods -> maximum
    • TooManyPublicMethods: maxmethods -> maximum
    • NumberOfChildren: minimum -> maximum
    • DepthOfInheritance: minimum -> maximum
    • Rules that previously reported when the value equaled the threshold (CyclomaticComplexity, NPathComplexity, ExcessiveMethodLength, ExcessiveClassLength, ExcessiveParameterList, ExcessivePublicCount, NumberOfChildren, DepthOfInheritance, ExcessiveClassComplexity, CouplingBetweenObjects) now only report when the value is greater than the threshold, so the configured maximum is the highest accepted value.
  • Removed --ignore option, use --exclude instead.
  • Removed --extensions option, use --suffixes instead.
  • Removed --reportfile option, use --reportfile-text, --reportfile-xml, etc.
  • Removed --minimumpriority and --maximumpriority aliases, use --minimum-priority and --maximum-priority.
  • Removed PHPMD\PHPMD::getIgnorePatterns() and setIgnorePatterns(), use getExcludePatterns() and addExcludePatterns().
  • Removed deprecated PHP_PMD_* class aliases.
  • Require pdepend/pdepend 3.x.
  • Changed exit code for processing errors from 1 to 3.
  • Introduced PHPMD-specific exception hierarchy under PHPMD\Exception\.
  • Removed PHPMD\RuleSetFactory::getIgnorePattern(), use getExcludePatterns() instead.
  • Renamed Rule::getBooleanProperty() to isTruthyProperty().
  • Renamed RuleSetFactory::getCache() to isCacheEnabled().
  • Changed --update-baseline to report violations that are not in the baseline (#1344). They are rendered with the configured format, make the command exit with code 2 and are not added to the baseline file. PHPMD\Baseline\BaselineValidator no longer takes a BaselineMode.
  • Renamed the rule classes PHPMD\Rule\Design\LongClass to ExcessiveClassLength, LongMethod to ExcessiveMethodLength, LongParameterList to ExcessiveParameterList, NpathComplexity to NPathComplexity and WeightedMethodCount to ExcessiveClassComplexity. The rule names are unchanged.
  • Changed suppressions to be applied by filtering the violations after the rules have run, instead of skipping suppressed code. RuleSet::apply() no longer skips suppressed nodes, and AbstractRule::setStrict() has been removed. Custom rules no longer need to check for suppressions.
  • Marked the parallel rule runner, the PDepend integration, the suppression handling and the Baseline, Cache, Config, RuleProperty, TextUI and Utility namespaces @internal. They are not covered by the 3.x compatibility promise.

... (truncated)

Changelog

Sourced from phpmd/phpmd's changelog.

phpmd-3.0.0 (unreleased)

See UPGRADING.md for a detailed migration guide from PHPMD 2 to PHPMD 3.

Breaking changes:

  • Changed minimum PHP version from 5.3.9 to 8.1.

  • Changed CLI from positional arguments to Symfony Console with named options. The command signature is now phpmd analyze [options] [--] [<paths>...].

  • Standardized rule threshold properties to maximum (#670). Rules now report only when the measured value exceeds (>) the configured maximum. Rules that check a lower bound (ShortVariable, ShortMethodName, ShortClassName) keep the minimum property. Renamed properties (the old names remain accepted as aliases):

    • CyclomaticComplexity: reportLevel -> maximum
    • NPathComplexity: minimum -> maximum
    • ExcessiveMethodLength: minimum -> maximum
    • ExcessiveClassLength: minimum -> maximum
    • ExcessiveParameterList: minimum -> maximum
    • ExcessivePublicCount: minimum -> maximum
    • TooManyFields: maxfields -> maximum
    • TooManyMethods: maxmethods -> maximum
    • TooManyPublicMethods: maxmethods -> maximum
    • NumberOfChildren: minimum -> maximum
    • DepthOfInheritance: minimum -> maximum

    Rules that previously reported when the value equaled the threshold (CyclomaticComplexity, NPathComplexity, ExcessiveMethodLength, ExcessiveClassLength, ExcessiveParameterList, ExcessivePublicCount, NumberOfChildren, DepthOfInheritance, ExcessiveClassComplexity, CouplingBetweenObjects) now only report when the value is greater than the threshold, so the configured maximum is the highest accepted value.

  • Removed --ignore option, use --exclude instead.

  • Removed --extensions option, use --suffixes instead.

  • Removed --reportfile option, use --reportfile-text, --reportfile-xml, etc.

  • Removed --minimumpriority and --maximumpriority aliases, use --minimum-priority and --maximum-priority.

  • Removed PHPMD\PHPMD::getIgnorePatterns() and setIgnorePatterns(), use getExcludePatterns() and addExcludePatterns().

  • Removed deprecated PHP_PMD_* class aliases.

  • Require pdepend/pdepend 3.x.

  • Changed exit code for processing errors from 1 to 3.

  • Introduced PHPMD-specific exception hierarchy under PHPMD\Exception\.

  • Removed PHPMD\RuleSetFactory::getIgnorePattern(), use getExcludePatterns() instead.

  • Renamed Rule::getBooleanProperty() to isTruthyProperty().

  • Renamed RuleSetFactory::getCache() to isCacheEnabled().

  • Changed --update-baseline to report violations that are not in the baseline (#1344). They are rendered with the configured format, make the command exit with code 2 and are not added to the baseline file. PHPMD\Baseline\BaselineValidator no longer takes a BaselineMode.

  • Renamed the rule classes PHPMD\Rule\Design\LongClass to ExcessiveClassLength, LongMethod to ExcessiveMethodLength, LongParameterList to ExcessiveParameterList, NpathComplexity to

... (truncated)

Commits
  • b0f328d Fix #991 UndefinedVariable false positives for static properties from traits ...
  • 68ffb31 Merge pull request #1356 from phpmd/3.x-pdepend
  • 168a37f Update to latest Pdepend
  • 54ee353 Fix UndefinedVariable false positives for $this in anonymous classes
  • 3b04dbb Merge pull request #1353 from phpmd/3.x-internal
  • 19554f5 Mark internal APIs
  • 7e875c9 Add UnusedSuppression rule
  • 4879072 Add config managment commands
  • a9e2504 Run the rules in parallel
  • c8187fe Adjust to new Pdepend IPC format
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [phpmd/phpmd](https://github.com/phpmd/phpmd) to permit the latest version.

Updates `phpmd/phpmd` to 3.0.0
- [Release notes](https://github.com/phpmd/phpmd/releases)
- [Changelog](https://github.com/phpmd/phpmd/blob/3.x/CHANGELOG)
- [Commits](phpmd/phpmd@2.15.0...3.0.0)

---
updated-dependencies:
- dependency-name: phpmd/phpmd
  dependency-version: 3.0.0
  dependency-type: direct:development
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Thanks for contributing to EngineScript Site Exporter!

Before we review:

  • Have you tested your changes with WordPress 6.8+?
  • Are your changes compatible with PHP 8.2+?
  • Have you followed WordPress coding standards?
  • Did you update the CHANGELOG.md if needed?

Security Reminder
This plugin creates site export archives, so please ensure:

  • All user input is properly sanitized
  • All output is properly escaped
  • No security vulnerabilities are introduced

We'll review your PR soon.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@PDowney
PDowney merged commit 100cf81 into main Oct 9, 2026
26 checks passed
@dependabot
dependabot Bot deleted the dependabot/composer/dev-dependencies-5d80abdc54 branch October 9, 2026 06:57
PDowney added a commit that referenced this pull request Oct 9, 2026
PHPMD 3 (pull request #120) prints "positional arguments are deprecated"
for the 2.x command. The Composer script and the workflow step now call
"phpmd analyze" with --format and --ruleset.

Each excluded directory gets its own --exclude: the analyze command reads
a comma-separated list as one pattern, which excludes nothing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant