#1109621 ITP: php-squizlabs-php-codesniffer -- PHP coding standard enforcement tool

Package:
wnpp
Source:
wnpp
Submitter:
Ahmed Gamal
Date:
2025-08-10 18:29:02 UTC
Severity:
normal
Tags:
#1109621#5
Date:
2025-07-21 04:20:52 UTC
From:
To:
* Package name    : php-squizlabs-php-codesniffer
  Version         : 3.7.2
  Upstream Author : Greg Sherwood <squiz@squiz.net>
* URL             : https://github.com/squizlabs/PHP_CodeSniffer
* License         : BSD-3-Clause
  Programming Lang: PHP
  Section         : php

Description:
 PHP coding standard enforcement tool

 This package provides PHP_CodeSniffer, a set of two PHP scripts that
tokenize
 PHP, JavaScript and CSS files to detect violations of defined coding
standards.
 The main `phpcs` script detects violations, while `phpcbf` automatically
 corrects coding standard violations.

 PHP_CodeSniffer is an essential development tool that ensures code remains
 clean and consistent by enforcing coding standards like PSR-12, PEAR, and
 custom standards. It helps maintain code quality and consistency across
 development teams.

Rationale:
 This package is required as a dependency for FOSSology, an open source
license
 compliance system. FOSSology uses PHP-based tools for source code analysis
and
 license detection, which need comprehensive code quality tools to ensure
 maintainable and consistent codebase.

 The php-squizlabs-php-codesniffer package is essential for:
 - Enforcing coding standards in FOSSology's PHP components
 - Maintaining code quality and consistency across the codebase
 - Automated code style checking and fixing
 - Supporting development workflow with coding standard compliance
 - Ensuring readable and maintainable code for license detection algorithms
 - Integration with CI/CD pipelines for automated code quality checks

Technical Details:
 - Requires PHP >= 5.4.0
 - Provides two command-line tools: phpcs and phpcbf
 - Supports multiple coding standards (PSR-12, PEAR, custom)
 - Tokenizes PHP, JavaScript, and CSS files
 - Includes extensive rule sets for various coding standards
 - BSD-3-Clause licensed for maximum compatibility
 - Provides both library and executable components

Dependencies:
 - php (>= 5.4.0)
 - php-ext-tokenizer
 - php-ext-xmlwriter
 - php-ext-simplexml
 - Build dependencies: phpunit

The package will be maintained by Ahmed Gamal <ahmed.gamal9541@gmail.com>
as part
of the FOSSology packaging effort.

#1109621#12
Date:
2025-08-10 13:45:06 UTC
From:
To:
Please do some research before opening ITP/RFP bugs.
This package already exists in Debian.

#1109621#17
Date:
2025-08-10 22:23:26 UTC
From:
To:
Dear William,

I need to clarify the version-specific requirement that led to this ITP
filing.

VERSION COMPATIBILITY REQUIREMENT:
FOSSology requires php-squizlabs-php-codesniffer version 3.7.2, which may
differ from the version currently available in Debian. This is essential
for FOSSology's development workflow and code quality standards.

DEVELOPMENT TOOLCHAIN DEPENDENCY:
FOSSology's development and build process relies on specific CodeSniffer
functionality:
- Consistent code style enforcement across FOSSology's PHP components
- Integration with FOSSology's existing development workflow
- Compatibility with FOSSology's custom coding standards and rules
- Build process integration for automated code quality checks

TECHNICAL INTEGRATION REQUIREMENTS:
FOSSology's development pipeline expects:
- Specific CodeSniffer rule implementations from version 3.7.2
- Compatible command-line interfaces for build scripts
- Consistent behavior in automated code quality checks
- Integration with FOSSology's CI/CD and packaging workflows

VERSION-SPECIFIC FUNCTIONALITY:
FOSSology's build system relies on:
- Particular CodeSniffer API methods from version 3.7.2
- Specific rule configurations and standard definitions
- Compatible output formats for development tools
- Tested integration with FOSSology's code quality pipeline

EVIDENCE FROM INTEGRATION:
FOSSology's development dependencies specify CodeSniffer 3.7.2 to ensure:
- Consistent code quality enforcement
- Stable build process behavior
- Compatibility with FOSSology's development tools
- Reliable integration with packaging workflows

PROPOSED SOLUTION:
Package as php-squizlabs-php-codesniffer-3.7 if the current Debian version
differs, ensuring FOSSology can use the tested and validated CodeSniffer
version.

JUSTIFICATION:
FOSSology's development workflow and code quality depend on consistent
CodeSniffer behavior, making version compatibility important for
maintainable packaging and development processes.

REQUEST:
Please reopen to discuss providing CodeSniffer 3.7.2 for FOSSology's
development requirements if version incompatibility exists.

Best regards,
Ahmed Gamal
FOSSology Debian Packaging Team

#1109621#22
Date:
2025-08-10 22:24:23 UTC
From:
To:
Dear William,

I need to reopen this ITP due to specific version requirements for
FOSSology's development and build workflow.

VERSION REQUIREMENT:
FOSSology requires php-squizlabs-php-codesniffer version 3.7.2 for its
development pipeline, which may differ from the current Debian version.

DEVELOPMENT WORKFLOW DEPENDENCY:
FOSSology's build and development process relies on:
- Specific CodeSniffer rule implementations from version 3.7.2
- Integration with FOSSology's automated build system
- Compatibility with existing development workflows
- Consistent code quality enforcement across the project

TECHNICAL INTEGRATION:
FOSSology's development pipeline expects:
- Particular API methods and command-line interfaces from 3.7.2
- Specific rule configurations for FOSSology's coding standards
- Compatible output formats for development and CI/CD tools
- Tested integration with packaging workflows

EVIDENCE FROM DEVELOPMENT:
FOSSology's development dependencies specify CodeSniffer 3.7.2 to ensure:
- Consistent code quality checks
- Stable build process behavior
- Compatibility with FOSSology's development tools
- Reliable CI/CD pipeline integration

PROPOSED SOLUTION:
Package as php-squizlabs-php-codesniffer-3.7 if version differences exist,
ensuring FOSSology can maintain its established development workflow.

JUSTIFICATION:
Development toolchain consistency is critical for FOSSology's code quality
and maintainable packaging processes.

REQUEST:
Please reopen to discuss providing CodeSniffer 3.7.2 for FOSSology's
development requirements if version incompatibility exists.

Best regards,
Ahmed Gamal
FOSSology Debian Packaging Team