Skip to content

Validation findings should use stable source paths and locations #1503

Description

Shopware Version

6.7.13.1

Shopware CLI Version

0.18.3

PHP Version

8.5.10

Operating System

macOS 26.5.2

CLI Command

The issue is visible when validating a packaged extension and in machine-readable reporters, for example:

shopware-cli extension validate <extension.zip>
shopware-cli extension validate <extension.zip> --format github
shopware-cli extension validate <extension.zip> --format junit

Actual behaviour

Validation of an extension ZIP reports files using the temporary extraction directory rather than a stable path belonging to the extension.

Example shape from the tour:

/var/folders/.../T/extension.../src/...
/var/folders/.../T/extension.../composer.json

The temporary path then leaks into reporter output:

  • GitHub annotations reference the temporary file, so GitHub cannot map the annotation to repository source.
  • JUnit reports inherit the same path.
  • The package/validation log can expose the extraction directory as well.

Some metadata findings also use line 0, even when a meaningful source file or location could be reported.

This means the same finding can be understandable in terminal output but unusable for CI navigation.

Expected behaviour

User-facing findings should use a stable path relative to the input being validated.

For example:

src/Subscriber/ExampleSubscriber.php:24
composer.json:12

rather than:

/var/folders/.../T/extension12345/src/Subscriber/ExampleSubscriber.php:24
  • Extension directories use extension-relative paths.
  • ZIP validation uses paths relative to the archive root.
  • Project validation uses project-relative paths.
  • Temporary working directories never appear in findings or reporter output.
  • A real line/location is reported where it can be determined.
  • GitHub, GitLab, JUnit and terminal output use the same normalized source location.

Relevant log/output

Observed during the CLI tour:

    validate source directory
    → findings refer to the source tree

    validate packaged ZIP
    → extension extracted to /var/folders/.../T/extension...
    → findings report that temporary path

    GitHub reporter
    → annotation path contains /var/folders/.../T/extension...
    → annotation cannot map to repository source

    JUnit reporter
    → same temporary path is emitted
    → available line information is not consistently preserved

Also observed metadata findings with locations such as:

    composer.json:0

The path should describe the developer's source/artifact, not the verifier's internal workspace.

Activity

  1. changed the title [-]Validation findings use stable source paths and locations[/-] [+]Validation findings should use stable source paths and locations[/+] on Sep 7, 2026
  2. moshimorschi commented on Sep 7, 2026

    @moshimorschi
    Contributor

    cursor tackle this

  3. shyim commented on Sep 7, 2026

    @shyim
    Member

    cursor tackle this

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Fields

Priority

None yet

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions