#1109613 ITP: php-nikic-php-parser -- PHP parser written in PHP for static code analysis

Package:
wnpp
Source:
wnpp
Submitter:
Ahmed Gamal
Date:
2025-08-10 18:31:02 UTC
Severity:
normal
Tags:
#1109613#5
Date:
2025-07-20 20:31:00 UTC
From:
To:
* Package name    : php-nikic-php-parser
  Version         : 4.15.4
  Upstream Author : Nikita Popov <nikita.ppv@gmail.com>
* URL             : https://github.com/nikic/PHP-Parser
* License         : BSD-3-Clause
  Programming Lang: PHP
  Section         : php

Description:
 PHP parser written in PHP for static code analysis and manipulation

 The PHP Parser is a PHP 5.2 to PHP 8.2 parser written in PHP. Its purpose
is to
 simplify static code analysis and manipulation of PHP code. The library
provides
 the following key features:

 * Parsing PHP 5, PHP 7, and PHP 8 code into an abstract syntax tree (AST)
 * Dumping the AST in human-readable form
 * Converting an AST back to PHP code with formatting preservation
 * Infrastructure to traverse and modify ASTs
 * Resolution of namespaced names
 * Evaluation of constant expressions
 * Builders to simplify AST construction for code generation
 * Converting an AST into JSON and back

 This package is essential for PHP development tools, static analyzers, and
code
 transformation utilities.

Rationale:
 This package is required as a dependency for FOSSology, an open source
license
 compliance system. FOSSology uses PHP-based tools for source code analysis
and
 license detection, which rely on the PHP Parser library for parsing and
analyzing
 PHP source code during the compliance scanning process.

 The PHP Parser is a critical component for:
 - Static code analysis tools in FOSSology
 - License detection algorithms that need to parse PHP code
 - Code transformation utilities used in the compliance workflow
 - Development tools that analyze PHP code structure

Technical Details:
 - Requires PHP >= 7.0
 - Uses PSR-4 autoloading
 - Provides command-line tool: bin/php-parse
 - Minimal runtime dependencies (only ext-tokenizer)
 - Comprehensive test suite included
 - Well-documented with extensive examples

Dependencies:
 - php (>= 7.0)
 - php-tokenizer
 - Build dependencies: phpunit, ircmaxell/php-yacc (for development)

The package will be maintained by Ahmed Gamal <ahmed.gamal9541@gmail.com>
as part
of the FOSSology packaging effort.

#1109613#12
Date:
2025-08-10 13:45:06 UTC
From:
To:
Please do some research before opening ITP/RFP bugs.
This package already exists in Debian.

#1109613#17
Date:
2025-08-10 22:20:51 UTC
From:
To:
Dear William,

I need to clarify the version-specific requirement that led to this ITP
filing.

VERSION COMPATIBILITY REQUIREMENT:
FOSSology requires php-nikic-php-parser version 4.15.4, which may differ
from the version currently available in Debian. This is essential for
FOSSology's static code analysis and license detection capabilities.

STATIC ANALYSIS DEPENDENCY:
FOSSology's license compliance system relies on specific PHP-Parser
functionality:
- PHP code parsing for license detection algorithms
- Abstract syntax tree (AST) analysis for compliance scanning
- Integration with FOSSology's existing static analysis tools
- Compatibility with FOSSology's PHP code inspection workflows

TECHNICAL INTEGRATION REQUIREMENTS:
FOSSology's analysis components expect:
- Specific AST node structures from PHP-Parser 4.15.4
- Compatible parsing interfaces for PHP code analysis
- Consistent behavior in license detection algorithms
- Integration with FOSSology's existing PHP analysis pipeline

VERSION-SPECIFIC FUNCTIONALITY:
FOSSology's license detection relies on:
- Specific PHP-Parser API methods from version 4.15.4
- Particular AST traversal capabilities
- Compatible parsing output for license compliance algorithms
- Tested integration with FOSSology's code analysis tools

EVIDENCE FROM INTEGRATION:
FOSSology's composer dependencies specify PHP-Parser 4.15.4 to ensure:
- Stable license detection functionality
- Consistent static analysis results
- Compatibility with FOSSology's PHP inspection tools
- Reliable parsing for compliance workflows

PROPOSED SOLUTION:
Package as php-nikic-php-parser-4.15 if the current Debian version differs,
ensuring FOSSology can use the tested and validated parser version.

JUSTIFICATION:
FOSSology's license compliance accuracy depends on consistent PHP parsing
behavior, making version compatibility critical for reliable compliance
scanning.

REQUEST:
Please reopen to discuss providing PHP-Parser 4.15.4 for FOSSology's static
analysis requirements if version incompatibility exists.

Best regards,
Ahmed Gamal
FOSSology Debian Packaging Team

#1109613#22
Date:
2025-08-10 22:26:24 UTC
From:
To:
Dear William,

I need to reopen this ITP due to critical version requirements for
FOSSology's license compliance functionality.

VERSION REQUIREMENT:
FOSSology requires php-nikic-php-parser version 4.15.4 for its license
detection and compliance analysis, which may differ from the current Debian
version.

CORE FUNCTIONALITY DEPENDENCY:
FOSSology's license compliance system relies on specific PHP-Parser
capabilities:
- PHP code parsing for license detection algorithms
- Abstract syntax tree (AST) analysis for compliance scanning
- Static code analysis for license identification
- Integration with FOSSology's license detection pipeline

TECHNICAL INTEGRATION:
FOSSology's analysis components expect:
- Specific AST node structures from PHP-Parser 4.15.4
- Compatible parsing interfaces for license detection
- Consistent behavior in compliance scanning algorithms
- Tested integration with FOSSology's code analysis tools

CRITICAL FOR LICENSE DETECTION:
FOSSology's core mission depends on:
- Reliable PHP code parsing for license identification
- Consistent AST traversal for compliance analysis
- Stable parser behavior for accurate license detection
- Integration with FOSSology's compliance workflows

EVIDENCE FROM INTEGRATION:
FOSSology's dependencies specify PHP-Parser 4.15.4 to ensure:
- Accurate license detection functionality
- Consistent compliance analysis results
- Reliable static analysis for license identification

PROPOSED SOLUTION:
Package as php-nikic-php-parser-4.15 if version differences exist, ensuring
FOSSology's license compliance accuracy.

JUSTIFICATION:
FOSSology's license detection accuracy - its core mission - depends on
consistent PHP parsing behavior.

REQUEST:
Please reopen to discuss providing PHP-Parser 4.15.4 for FOSSology's
license compliance requirements.

Best regards,
Ahmed Gamal
FOSSology Debian Packaging Team