Your project uses dangerous command injection functions

More information: https://insight.symfony.com/what-we-analyse/php.use_command_injection_function

in scripts/init.php, line 156
  1. if ($overrides !== null) {
  2. $environment = \array_merge((array) \getenv(), $overrides);
  3. }
  4. $process = \proc_open(
    proc_open() is vulnerable to command injection attacks. Use the Symfony Process component instead.
    Time to fix: about 4 hours
    Read doc Open Issue Permalink Copy Prompt
    Last edited by Fery Wardiyanto
  5. $command,
  6. [
  7. 0 => ['pipe', 'r'],
  8. 1 => ['pipe', 'w'],
  9. 2 => ['pipe', 'w'],

Your project uses discouraged functions to kill scripts

More information: https://insight.symfony.com/what-we-analyse/php.use_exit_function

in scripts/init.php, line 718
  1. return true;
  2. }
  3. if (\realpath($_SERVER['SCRIPT_FILENAME'] ?? '') === __FILE__) {
  4. exit(main());
    This line stops the execution flow, without explanation. If this is for debug, you should remove it. If this is to deal with an error, use exceptions instead.
    Time to fix: about 4 hours
    Read doc Open Issue Permalink Copy Prompt
    Last edited by Fery Wardiyanto
  5. }

Your project should use dedicated PHP string functions 6

More information: https://insight.symfony.com/what-we-analyse/php.use_string_function

in scripts/init.php, line 374
  1. $path = $file->getPathname();
  2. $relative = \str_replace('\\', '/', \ltrim(\substr($path, \strlen($root)), '/'));
  3. $skip = $path === __FILE__;
  4. foreach ($skipped as $directory) {
  5. if (\strpos('/' . $relative . '/', $directory) !== false) {
    Consider replacing strpos() with str_contains() for improved readability.
    Last edited by Fery Wardiyanto
  6. $skip = true;
  7. break;
  8. }
  9. }
in scripts/init.php, line 386
  1. continue;
  2. }
  3. $content = \file_get_contents($path);
  4. if ($content === false || \strpos(\substr($content, 0, 8192), "\0") !== false) {
    Consider replacing strpos() with str_contains() for improved readability.
    Last edited by Fery Wardiyanto
  5. continue;
  6. }
  7. $visitor($relative, $content);
  8. }
in scripts/init.php, line 415
  1. $root,
  2. $target,
  3. $patterns,
  4. &$changed
  5. ): void {
  6. if (\strpos($content, 'projek-xyz/') === false) {
    Consider replacing strpos() with str_contains() for improved readability.
    Last edited by Fery Wardiyanto
  7. return;
  8. }
  9. $replaced = \str_replace($patterns, $target, $content);
in scripts/init.php, line 606
  1. }
  2. }
  3. $packageJson = \file_get_contents($root . '/package.json');
  4. if ($packageJson === false || \strpos($packageJson, '"version": "0.0.0"') === false) {
    Consider replacing strpos() with str_contains() for improved readability.
    Last edited by Fery Wardiyanto
  5. $failures[] = 'package.json version is not 0.0.0';
  6. }
  7. $attributes = \file_get_contents($root . '/.gitattributes');
  8. $totalEntries = $attributes === false ? 0 : \preg_match_all('/^.*export-ignore$/m', $attributes);
in scripts/init.php, line 644
  1. string $content
  2. ) use (
  3. &$failures,
  4. $patterns
  5. ): void {
  6. if (\strpos($content, $patterns[0]) !== false || \strpos($content, $patterns[1]) !== false) {
    Consider replacing strpos() with str_contains() for improved readability.
    Last edited by Fery Wardiyanto
  7. $failures[] = 'residual template reference in ' . $relative;
  8. }
  9. });
  10. }
in scripts/init.php, line 644
  1. string $content
  2. ) use (
  3. &$failures,
  4. $patterns
  5. ): void {
  6. if (\strpos($content, $patterns[0]) !== false || \strpos($content, $patterns[1]) !== false) {
    Consider replacing strpos() with str_contains() for improved readability.
    Last edited by Fery Wardiyanto
  7. $failures[] = 'residual template reference in ' . $relative;
  8. }
  9. });
  10. }