Skip to content

fix: validate prepared SQL through typed wpdb receivers - #4

Merged
brianvarskonst merged 2 commits into
mainfrom
fix/review-20261001
Oct 2, 2026
Merged

brianvarskonst merged 2 commits into
mainfrom
fix/review-20261001

Conversation

@brianvarskonst

Copy link
Copy Markdown
Member

Prepared SQL checks previously recognized only literal $wpdb receivers, leaving SQL passed through typed connection properties unchecked. The new PHPStan rule follows typed wpdb receivers, including nullable and union types, and distinguishes prepared values from documented trusted SQL-generation boundaries.

Stable dependency constraints and export rules make the next package reproducible. The weekly canary pins the reviewed reusable workflow and tests current allowed dependencies. PHPCompatibility remains on an actually available stable release; the documentation states its PHP-version coverage limits.

Validation: full PHPCS/PHPStan/PHPUnit passed, 111 tests / 378 assertions; fresh stable-only Composer installation and full QA passed; native actionlint passed. Candidate version: v1.1.1; no historical tag is changed.

Part of the organization review remediation. This package precedes QA and the remaining library release train.

@brianvarskonst
brianvarskonst marked this pull request as ready for review October 2, 2026 10:12
@brianvarskonst
brianvarskonst merged commit a3460f1 into main Oct 2, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant