Skip to content

project dev makes validation and code health visible and first-class #1523

Description

Problem statement

Developers have to understand several commands, modes and scopes to know what was actually checked. My recent hands-on tour found that:


  • Full validation can appear stuck while Composer/tool setup runs without visible progress. Would differentiate between commands and project dev TUI.






  • In a disposable copy of FroshTools, ESLint reported one no-unused-expressions error. Running extension fix --only eslint --allow-non-git printed the same finding but produced no file changes, showing that validation can report an error without the selected fixer resolving it.

Goal

Following the mockup in #1524, provide a Validation tab that displays findings and provides an ignore flow.

The Validation experience must:

  • distinguish passed, not checked, suppressed and execution-failed checks;
  • show progress, elapsed time, coverage and grouped results;
  • keep project validation and local-extension validation as distinct scopes;
  • identify the source scope and baseline for every result;
  • preserve consistent findings and statuses across CLI, CI and machine-readable output;
  • expose an ignore flow without making suppressed findings disappear from the report;
  • distinguish findings that are automatically fixable from those requiring manual action.

Ongoing shopware-lsp investigations will be enabling work for us to understand where and how errors and suppression state are stored, which will impact related CLI operations.

Out of scope

New validation rules, upgrade-specific analysis, Store/account extension management.

Business / user impact

Lower TCO.

Acceptance criteria

Completion of the linked stories.

Readiness checklist

  • Acceptance criteria are clearly defined.
  • Backward compatibility impact addressed.
  • Developer docs written.
  • Tests added or adjusted accordingly.

Activity

  1. lasomethingsomething commented on Sep 9, 2026

    @lasomethingsomething
    ContributorAuthor

    One overlay to add after #1524: "ignore findings," where I can go over a finding (like "wrong class"), press a button, get an overlay with "do you want to ignore it" and even ignore for a file or type of error; choose either "everything" or "everything in this file." Default: errors are on. lsp work: understand where and how the errors are stored.

  2. lasomethingsomething commented on Sep 22, 2026

    @lasomethingsomething
    ContributorAuthor

    Martin Bens (@SpiGAndromeda) PTAL and let us know if you have any comments/questions/ideas. #1524 displays a mockup of a TUI dashboard we've discussed (intentionally simplistic functionality-wise for a first iteration)

  3. lasomethingsomething commented on Sep 23, 2026

    @lasomethingsomething
    ContributorAuthor

    Hey Patryk Tomczyk (@patzick) Nicolas Fortier (@nfortier-shopware): I'm wondering if you might have some perspectives to share on this epic and/or attached sub-issues. Your feedback would be very welcome.

    If you think this proposed work wouldn't solve much to improve your day-to-day, or the work life of our users, that's also valid feedback -- no need to sugarcoat, you will be helping us to work on the right problems. :) Feel free to pitch what you think could be more impactful.

    Attaching the mockup of the related dashboard mentioned in #1524 in the hope that it shows up for you. If it doesn't, I can point you to the Miro source doc.

    Image
  4. lasomethingsomething commented on Sep 24, 2026

    @lasomethingsomething
    ContributorAuthor
    Image Image Image
    Compressed validation-tour summary A compressed summary and diagram based on notes from my recent 77-step tour of `validate` and adjacent commands:
    Flow stage Current behavior Improvement opportunity
    Command and scope extension validate forcibly replaces --only with sw-cli unless --full is supplied. Project validation has no equivalent --full or --check-against model. (extension validate, project validate) A command can appear to accept a requested analyzer while silently running a different validation set.
    Tool selection The shared tool registry exposes tools whose behavior depends on the command scope. For example, sw-cli returns immediately when no extension is attached. (tool registry, sw-cli verifier) project validate --only sw-cli can succeed without validating project or extension metadata, and the final output still does not clearly summarize which tools actually ran.
    Version comparison PHPStan dependency setup only runs when vendor/ is absent. Once dependencies already exist, changing --check-against does not force a fresh lowest/highest resolution. Composer also runs with --no-progress and captures output until completion. (Composer setup) Results can be based on stale dependencies, while a long bootstrap appears frozen and the concrete resolved Shopware version is not surfaced.
    Workspace isolation Default validation copies the project or extension to a temporary directory; --no-copy runs directly against the source tree. (extension validate, project validate) The safe path repeatedly pays the dependency/bootstrap cost, while the fast path can leave vendor/, composer.lock, or other generated files in the working tree.
    Fix safety extension fix checks for .git directly inside the extension directory. A plugin nested inside a larger Git repository still needs --allow-non-git; project fix instead checks the resolved project root. (extension fix, project fix) The suggested XML fix can fail for a normal nested extension even though the surrounding project is version-controlled.
    Formatter execution PHP-CS-Fixer and Prettier still stream their native output directly and run concurrently. Dry-run therefore exposes tool-specific output and exit codes rather than one normalized CLI result. (extension format, PHP-CS-Fixer, Prettier) Output can interleave, formatter exit codes are not explained, and a clean dry-run is still noisier than necessary.
    Finding model CheckResult still contains only path, line, message, severity, identifier, and optional tip. (validation types) Reports still cannot distinguish ownership, fixability, confidence, target Shopware version, affected surface, or coverage.
    Project versus extension validation Project configuration aggregates source directories but does not attach each discovered extension to the sw-cli verifier. --local-only changes discovery scope; it does not add extension metadata validation. (project verifier, sw-cli verifier) A green project-level result still does not mean that every contained extension passes extension-level validation.
    Source versus artifact Directory input suppresses ZIP-specific findings, while archive input validates the extracted artifact. Packaging also copies, cleans, transforms, and augments the extension before creating the ZIP. (directory verifier, packaging flow) “The source directory passes” and “the distributable artifact passes” remain separate claims.
    Suppression semantics Validation ignores are applied before reporting and can remove all findings for an identifier or matching path/message. (ignore handling) A green result can still mean that relevant checks were suppressed rather than satisfied.

    Current conclusion

    The previously reported issues around Cobra usage noise, the --format transition, temporary-path leakage, duplicate license findings, GitHub summary output, and missing PHP line mapping have been addressed and are intentionally omitted here.

    The remaining themes are:

    • the actual tool set is often implicit;
    • project and extension validation still model different concepts;
    • dependency/version comparison is stateful and quiet;
    • formatters and analyzers leak tool-specific behavior;
    • source and artifact validation are materially different;
    • machine-readable findings still lack enough context for reliable automation.
  5. changed the title [-]`project dev` makes validation and code health first-class[/-] [+]`project dev` makes validation and code health visible and first-class[/+] on Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Fields

No fields configured for Epic.

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions