Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 13 additions & 1 deletion docs/api/inspectors.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,18 @@
### SecurityInspector
### QualityInspector

`QualityInspector` combines package metadata and repository contents into a score from 0 to 100. Each available quality signal contributes 15 points:

- README
- license
- tests
- description
- repository URL
- `.gitattributes`
- `.gitignore`

Ignored example, demo, documentation, test, and specification files reduce the score by 2 points each, up to a maximum 15-point penalty. Scores are capped between 0 and 100 and graded as follows: A from 90, B from 75, C from 60, D from 40, and F below 40.

## Usage Patterns

### Single Inspector Usage
Expand All @@ -40,4 +52,4 @@

### Provider Ordering
### Parallel Execution
### Caching Strategy
### Caching Strategy
2 changes: 1 addition & 1 deletion docs/bridges/packagist.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,7 +86,7 @@ Determines latest release and commit time from available versions.
Uses GitHub API as a fallback to fetch YAML advisories for the package path under `FriendsOfPHP/security-advisories`.

### **Content Provider**
Downloads the distribution archive of the latest version using `SecureFileHandler` and analyses its files.
Downloads the distribution archive of the latest version using `SecureFileHandler` and analyses its files. When constructing the provider directly, its optional third argument selects the parent directory for temporary extraction; it defaults to `sys_get_temp_dir()`.

### **Statistics Provider**
`ComposerDownloadStatsProvider` wraps `PackagistApiClient` to expose download counts as `DownloadStats` models.
Expand Down
3 changes: 3 additions & 0 deletions src/Auth/EnvAuthenticationManager.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@

namespace PackApi\Auth;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class EnvAuthenticationManager implements AuthenticationManagerInterface
{
public function __construct(private readonly string $githubTokenEnvVariable = 'GITHUB_TOKEN')
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/BundlePhobia/BundlePhobiaApiClient.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use Symfony\Contracts\HttpClient\Exception\TransportExceptionInterface;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class BundlePhobiaApiClient
{
public function __construct(
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/BundlePhobia/BundlePhobiaProviderFactory.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use PackApi\Provider\BundleSizeProviderInterface;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class BundlePhobiaProviderFactory
{
private readonly HttpClientInterface $scopedClient;
Expand Down
5 changes: 4 additions & 1 deletion src/Bridge/BundlePhobia/BundlePhobiaSizeProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@
use PackApi\Package\Package;
use PackApi\Provider\BundleSizeProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class BundlePhobiaSizeProvider implements BundleSizeProviderInterface
{
public function __construct(private readonly BundlePhobiaApiClient $client)
Expand Down Expand Up @@ -73,7 +76,7 @@ public function getPackageHistory(Package $package): ?array

try {
return $this->client->getPackageHistory($package->getName());
} catch (\Exception $e) {
} catch (\Exception) {
return null;
}
}
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/GitHub/GitHubActivityProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use PackApi\Package\Package;
use PackApi\Provider\ActivityProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubActivityProvider implements ActivityProviderInterface
{
public function __construct(private GitHubApiClient $client)
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/GitHub/GitHubApiClient.php
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,9 @@
use Symfony\Contracts\HttpClient\Exception\TransportExceptionInterface;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubApiClient
{
public function __construct(
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/GitHub/GitHubContentProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@
use PackApi\Package\Package;
use PackApi\Provider\ContentProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubContentProvider implements ContentProviderInterface
{
public function __construct(private GitHubApiClient $client)
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/GitHub/GitHubMetadataProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,9 @@
use PackApi\Package\Package;
use PackApi\Provider\MetadataProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubMetadataProvider implements MetadataProviderInterface
{
public function __construct(
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/GitHub/GitHubProviderFactory.php
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@

use PackApi\Http\HttpClientFactoryInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubProviderFactory
{
private readonly GitHubApiClient $apiClient;
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/GitHub/GitHubSearchProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@

use PackApi\Provider\PackageSearchInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubSearchProvider implements PackageSearchInterface
{
public function __construct(private readonly GitHubApiClient $client)
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/GitHub/GitHubSecurityProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use PackApi\Package\Package;
use PackApi\Provider\SecurityProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubSecurityProvider implements SecurityProviderInterface
{
public function __construct(private GitHubApiClient $client)
Expand Down
6 changes: 3 additions & 3 deletions src/Bridge/GitHub/GitHubStatisticProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@
use PackApi\Package\Package;
use PackApi\Provider\DownloadStatsProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class GitHubStatisticProvider implements DownloadStatsProviderInterface
{
public function __construct(
Expand Down Expand Up @@ -72,9 +75,6 @@ public function getStatsForPeriod(Package $package, DownloadPeriod $period): ?Do
return null;
}

// Map GitHub stats to download-like metrics
$stats = $activityData['activity_stats'];

$count = (int) ($repoData['stargazers_count'] ?? 0);
$computedPeriod = new DownloadPeriod(
$period->getType(),
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Npm/NpmApiClient.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use Symfony\Contracts\HttpClient\Exception\TransportExceptionInterface;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class NpmApiClient
{
public function __construct(
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Npm/NpmProviderFactory.php
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,9 @@
use PackApi\System\Npm\NpmMetadataProvider;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class NpmProviderFactory
{
private readonly HttpClientInterface $registryClient;
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/OSV/OSVApiClient.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use Symfony\Contracts\HttpClient\Exception\TransportExceptionInterface;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class OSVApiClient
{
public function __construct(
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/OSV/OSVProviderFactory.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use PackApi\Provider\SecurityProviderInterface;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class OSVProviderFactory
{
private readonly HttpClientInterface $scopedClient;
Expand Down
8 changes: 3 additions & 5 deletions src/Bridge/OSV/OSVSecurityProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@
use PackApi\Package\Package;
use PackApi\Provider\SecurityProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class OSVSecurityProvider implements SecurityProviderInterface
{
public function __construct(private readonly OSVApiClient $client)
Expand Down Expand Up @@ -156,11 +159,6 @@ private function extractSeverity(array $vulnerability): string
return strtoupper($vulnerability['database_specific']['severity']);
}

if (isset($vulnerability['database_specific']['github_reviewed'])
&& isset($vulnerability['database_specific']['severity'])) {
return strtoupper($vulnerability['database_specific']['severity']);
}

return 'MEDIUM';
}

Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Packagist/PackagistActivityProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use PackApi\Package\Package;
use PackApi\Provider\ActivityProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistActivityProvider implements ActivityProviderInterface
{
public function __construct(private PackagistApiClient $client)
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Packagist/PackagistApiClient.php
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@

use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistApiClient
{
public function __construct(
Expand Down
15 changes: 9 additions & 6 deletions src/Bridge/Packagist/PackagistContentProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,19 @@
use PackApi\Provider\ContentProviderInterface;
use PackApi\Security\SecureFileHandlerInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistContentProvider implements ContentProviderInterface
{
private readonly string $tempDir;

public function __construct(
private readonly PackagistApiClient $client,
private readonly SecureFileHandlerInterface $fileHandler,
?string $tempDir = null,
) {
$this->tempDir = $tempDir ?? sys_get_temp_dir();
}

public function supports(Package $package): bool
Expand All @@ -51,8 +58,8 @@ public function getContentOverview(Package $package): ?ContentOverview

$tarPath = $this->fileHandler->downloadSafely($distUrl);

$tmp = sys_get_temp_dir().'/packapi_'.uniqid('', true);
if (!mkdir($tmp, 0755, true) && !is_dir($tmp)) {
$tmp = $this->tempDir.'/packapi_'.uniqid('', true);
if (!@mkdir($tmp, 0755, true) && !is_dir($tmp)) {
throw new ValidationException('Cannot create extraction directory');
}

Expand Down Expand Up @@ -116,10 +123,6 @@ public function getContentOverview(Package $package): ?ContentOverview

private function cleanupDirectory(string $path): void
{
if (!is_dir($path)) {
return;
}

$files = new \RecursiveIteratorIterator(
new \RecursiveDirectoryIterator($path, \RecursiveDirectoryIterator::SKIP_DOTS),
\RecursiveIteratorIterator::CHILD_FIRST
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Packagist/PackagistMetadataProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use PackApi\Package\Package;
use PackApi\Provider\MetadataProviderInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistMetadataProvider implements MetadataProviderInterface
{
public function __construct(private PackagistApiClient $client)
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Packagist/PackagistProviderFactory.php
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,9 @@
use PackApi\Security\SecureFileHandler;
use Symfony\Contracts\HttpClient\HttpClientInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistProviderFactory
{
private readonly HttpClientInterface $scopedClient;
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Packagist/PackagistSearchProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@

use PackApi\Provider\PackageSearchInterface;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistSearchProvider implements PackageSearchInterface
{
public function __construct(private readonly PackagistApiClient $client)
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Packagist/PackagistSecurityProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,9 @@
use PackApi\Provider\SecurityProviderInterface;
use Symfony\Component\Yaml\Yaml;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistSecurityProvider implements SecurityProviderInterface
{
public function __construct(
Expand Down
3 changes: 3 additions & 0 deletions src/Bridge/Packagist/PackagistStatisticsProvider.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@

namespace PackApi\Bridge\Packagist;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class PackagistStatisticsProvider
{
}
3 changes: 3 additions & 0 deletions src/Exception/ApiException.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@

namespace PackApi\Exception;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class ApiException extends \RuntimeException
{
/**
Expand Down
3 changes: 3 additions & 0 deletions src/Exception/NetworkException.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@

namespace PackApi\Exception;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class NetworkException extends \RuntimeException
{
}
3 changes: 3 additions & 0 deletions src/Exception/PackageNotFoundException.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@

namespace PackApi\Exception;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class PackageNotFoundException extends \Exception implements PackageExceptionInterface
{
}
3 changes: 3 additions & 0 deletions src/Exception/RateLimitException.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@

namespace PackApi\Exception;

/**
* @author Simon André <smn.andre@gmail.com>
*/
class RateLimitException extends \Exception implements ProviderExceptionInterface
{
}
3 changes: 3 additions & 0 deletions src/Exception/UnsupportedPackageException.php
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,9 @@

namespace PackApi\Exception;

/**
* @author Simon André <smn.andre@gmail.com>
*/
final class UnsupportedPackageException extends \LogicException
{
public function __construct(string $packageClass)
Expand Down
Loading
Loading