PHPStan v2 #106
Annotations
4 errors and 6 warnings
|
Tests on 8.1
The process '/opt/hostedtoolcache/setup-php/tools/composer' failed with exit code 2
|
|
Tests on 8.1
Your requirements could not be resolved to an installable set of packages.
Problem 1
- Root composer.json requires craftcms/cms ^4.0.0|^5.0.0 -> satisfiable by craftcms/cms[4.18.3, ..., 4.x-dev, 5.10.8, ..., 5.x-dev].
- craftcms/cms[4.18.3, ..., 4.x-dev] require twig/twig ~3.19.0 -> found twig/twig[v3.19.0] but these were not loaded, because they are affected by security advisories ("�]8;;https://github.com/advisories/GHSA-529h-vh3j-85hq�\PKSA-8zx5-v2nz-58pb�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48808-sandbox-property-allowlist-bypass-via-the-column-filter-under-sourcepolicyinterface�\PKSA-fbvq-z33h-r2np�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48805-sandbox-state-regression-in-deprecated-internal-wrappers-in-src-resources-core-php�\PKSA-g9zw-qxh8-pq8w�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-46636-sandbox-filter-tag-and-function-allow-list-bypass-when-sandbox-state-changes-between-renders�\PKSA-yd6k-t2gh-1m43�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48806-sandbox-tostring-policy-bypass-via-dynamic-mapping-keys�\PKSA-1tmc-rt7x-12w6�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48807-sandbox-tostring-policy-bypass-via-traversable-in-join-replace-and-in-not-in-operators�\PKSA-xx6c-6d96-db2w�]8;;�\", "�]8;;https://symfony.com/cve-2026-46640�\PKSA-5k7f-wvjj-jrgw�]8;;�\", "�]8;;https://symfony.com/cve-2026-46628�\PKSA-sjvz-tbbr-vwth�]8;;�\", "�]8;;https://symfony.com/cve-2026-46633�\PKSA-h8hf-ytnd-5t9q�]8;;�\", "�]8;;https://symfony.com/cve-2026-47730�\PKSA-wwb1-81rc-pd65�]8;;�\", "�]8;;https://symfony.com/cve-2026-46627�\PKSA-kvv6-36cr-fkzb�]8;;�\", "�]8;;https://symfony.com/cve-2026-46635�\PKSA-n14z-jjjg-g8vd�]8;;�\", "�]8;;https://symfony.com/cve-2026-46638�\PKSA-3mcc-k66d-pydb�]8;;�\", "�]8;;https://symfony.com/cve-2026-24425�\PKSA-gw7n-z4yx-7xjt�]8;;�\", "�]8;;https://symfony.com/cve-2026-47732�\PKSA-dpx1-78wg-1kqs�]8;;�\", "�]8;;https://symfony.com/cve-2026-46634�\PKSA-21g2-dzjv-sky5�]8;;�\"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
- craftcms/cms[5.10.8, ..., 5.x-dev] require php ^8.2 -> your php version (8.1.34) does not satisfy that requirement.
|
|
Tests on 8
The process '/opt/hostedtoolcache/setup-php/tools/composer' failed with exit code 2
|
|
Tests on 8
Your requirements could not be resolved to an installable set of packages.
Problem 1
- Root composer.json requires craftcms/cms ^4.0.0|^5.0.0 -> satisfiable by craftcms/cms[4.18.3, ..., 4.x-dev, 5.10.8, ..., 5.x-dev].
- craftcms/cms[4.18.3, ..., 4.x-dev] require twig/twig ~3.19.0 -> found twig/twig[v3.19.0] but these were not loaded, because they are affected by security advisories ("�]8;;https://github.com/advisories/GHSA-529h-vh3j-85hq�\PKSA-8zx5-v2nz-58pb�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48808-sandbox-property-allowlist-bypass-via-the-column-filter-under-sourcepolicyinterface�\PKSA-fbvq-z33h-r2np�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48805-sandbox-state-regression-in-deprecated-internal-wrappers-in-src-resources-core-php�\PKSA-g9zw-qxh8-pq8w�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-46636-sandbox-filter-tag-and-function-allow-list-bypass-when-sandbox-state-changes-between-renders�\PKSA-yd6k-t2gh-1m43�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48806-sandbox-tostring-policy-bypass-via-dynamic-mapping-keys�\PKSA-1tmc-rt7x-12w6�]8;;�\", "�]8;;https://symfony.com/blog/cve-2026-48807-sandbox-tostring-policy-bypass-via-traversable-in-join-replace-and-in-not-in-operators�\PKSA-xx6c-6d96-db2w�]8;;�\", "�]8;;https://symfony.com/cve-2026-46640�\PKSA-5k7f-wvjj-jrgw�]8;;�\", "�]8;;https://symfony.com/cve-2026-46628�\PKSA-sjvz-tbbr-vwth�]8;;�\", "�]8;;https://symfony.com/cve-2026-46633�\PKSA-h8hf-ytnd-5t9q�]8;;�\", "�]8;;https://symfony.com/cve-2026-47730�\PKSA-wwb1-81rc-pd65�]8;;�\", "�]8;;https://symfony.com/cve-2026-46627�\PKSA-kvv6-36cr-fkzb�]8;;�\", "�]8;;https://symfony.com/cve-2026-46635�\PKSA-n14z-jjjg-g8vd�]8;;�\", "�]8;;https://symfony.com/cve-2026-46638�\PKSA-3mcc-k66d-pydb�]8;;�\", "�]8;;https://symfony.com/cve-2026-24425�\PKSA-gw7n-z4yx-7xjt�]8;;�\", "�]8;;https://symfony.com/cve-2026-47732�\PKSA-dpx1-78wg-1kqs�]8;;�\", "�]8;;https://symfony.com/cve-2026-46634�\PKSA-21g2-dzjv-sky5�]8;;�\"). Go to https://packagist.org/security-advisories/ to find advisory details. To ignore the advisories, add their IDs to the "policy.advisories.ignore-id" config or add the package to "policy.advisories.ignore". To turn the feature off entirely, you can set "policy.advisories.block" to false.
- craftcms/cms[5.10.8, ..., 5.x-dev] require php ^8.2 -> your php version (8.0.30) does not satisfy that requirement.
|
|
Tests on 8.1
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v2, ramsey/composer-install@v1. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Tests on 8.1
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
|
|
Tests on 8.1
The `save-state` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
|
|
Tests on 8
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v2, ramsey/composer-install@v1. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Tests on 8
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
|
|
Tests on 8
The `save-state` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
|