Skip to content

Guardrails

php ​

3 guardrails, all at version v1.

GuardrailDefault severityWhat it checks
php/dependencies-constrainedwarningEvery package the manifest requires has a version constraint, instead of accepting whatever the registry serves.
php/lockfile-committedwarningThe project commits composer.lock, so an install of the same commit resolves the same versions.
php/version-declaredwarningThe project declares the PHP version Composer resolves against, and that version is no older than the configured floor.

Shared inputs ​

Every php guardrail declares these inputs. Individual guardrails can add their own.

InputDescriptionDefault
projectDirDirectory holding the project, relative to the directory the CLI runs in..

Shared collectors ​

Every php guardrail receives the facts these collectors gather. Individual guardrails can ask for more collectors of their own.

CollectorGathers
phpThe Composer project in the project directory: the package it declares, the PHP version and extensions it asks for, the packages it requires and which of them are pinned, and whether the lock file is committed.

You configure every guardrail in this category the same way, in the guardrails.checks array of buildnote.json. Configuring guardrails lists every option, and Guardrails lets you search the whole library.

Buildnote Limited
Registered in England and Wales, Reg: 16140412