Repository navigation
project dev makes validation and code health visible and first-class #1523
Description
Activity
- added sub-issues
on Sep 9, 2026 lasomethingsomething commented
on Sep 9, 2026 ContributorAuthorMore actionsOne overlay to add after #1524: "ignore findings," where I can go over a finding (like "wrong class"), press a button, get an overlay with "do you want to ignore it" and even ignore for a file or type of error; choose either "everything" or "everything in this file." Default: errors are on. lsp work: understand where and how the errors are stored.
- added sub-issues
on Sep 18, 2026 lasomethingsomething commented
on Sep 22, 2026 ContributorAuthorMore actionsMartin Bens (@SpiGAndromeda) PTAL and let us know if you have any comments/questions/ideas. #1524 displays a mockup of a TUI dashboard we've discussed (intentionally simplistic functionality-wise for a first iteration)
lasomethingsomething commented
on Sep 23, 2026 ContributorAuthorMore actionsHey Patryk Tomczyk (@patzick) Nicolas Fortier (@nfortier-shopware): I'm wondering if you might have some perspectives to share on this epic and/or attached sub-issues. Your feedback would be very welcome.
If you think this proposed work wouldn't solve much to improve your day-to-day, or the work life of our users, that's also valid feedback -- no need to sugarcoat, you will be helping us to work on the right problems. :) Feel free to pitch what you think could be more impactful.
Attaching the mockup of the related dashboard mentioned in #1524 in the hope that it shows up for you. If it doesn't, I can point you to the Miro source doc.

lasomethingsomething commented
on Sep 24, 2026 ContributorAuthorMore actions
Compressed validation-tour summary
A compressed summary and diagram based on notes from my recent 77-step tour of `validate` and adjacent commands:Flow stage Current behavior Improvement opportunity Command and scope extension validateforcibly replaces--onlywithsw-cliunless--fullis supplied. Project validation has no equivalent--fullor--check-againstmodel. (extension validate, project validate)A command can appear to accept a requested analyzer while silently running a different validation set. Tool selection The shared tool registry exposes tools whose behavior depends on the command scope. For example, sw-clireturns immediately when no extension is attached. (tool registry, sw-cli verifier)project validate --only sw-clican succeed without validating project or extension metadata, and the final output still does not clearly summarize which tools actually ran.Version comparison PHPStan dependency setup only runs when vendor/is absent. Once dependencies already exist, changing--check-againstdoes not force a fresh lowest/highest resolution. Composer also runs with--no-progressand captures output until completion. (Composer setup)Results can be based on stale dependencies, while a long bootstrap appears frozen and the concrete resolved Shopware version is not surfaced. Workspace isolation Default validation copies the project or extension to a temporary directory; --no-copyruns directly against the source tree. (extension validate, project validate)The safe path repeatedly pays the dependency/bootstrap cost, while the fast path can leave vendor/,composer.lock, or other generated files in the working tree.Fix safety extension fixchecks for.gitdirectly inside the extension directory. A plugin nested inside a larger Git repository still needs--allow-non-git; project fix instead checks the resolved project root. (extension fix, project fix)The suggested XML fix can fail for a normal nested extension even though the surrounding project is version-controlled. Formatter execution PHP-CS-Fixer and Prettier still stream their native output directly and run concurrently. Dry-run therefore exposes tool-specific output and exit codes rather than one normalized CLI result. (extension format, PHP-CS-Fixer, Prettier) Output can interleave, formatter exit codes are not explained, and a clean dry-run is still noisier than necessary. Finding model CheckResultstill contains only path, line, message, severity, identifier, and optional tip. (validation types)Reports still cannot distinguish ownership, fixability, confidence, target Shopware version, affected surface, or coverage. Project versus extension validation Project configuration aggregates source directories but does not attach each discovered extension to the sw-cliverifier.--local-onlychanges discovery scope; it does not add extension metadata validation. (project verifier, sw-cli verifier)A green project-level result still does not mean that every contained extension passes extension-level validation. Source versus artifact Directory input suppresses ZIP-specific findings, while archive input validates the extracted artifact. Packaging also copies, cleans, transforms, and augments the extension before creating the ZIP. (directory verifier, packaging flow) “The source directory passes” and “the distributable artifact passes” remain separate claims. Suppression semantics Validation ignores are applied before reporting and can remove all findings for an identifier or matching path/message. (ignore handling) A green result can still mean that relevant checks were suppressed rather than satisfied. Current conclusion
The previously reported issues around Cobra usage noise, the
--formattransition, temporary-path leakage, duplicate license findings, GitHub summary output, and missing PHP line mapping have been addressed and are intentionally omitted here.The remaining themes are:
- the actual tool set is often implicit;
- project and extension validation still model different concepts;
- dependency/version comparison is stateful and quiet;
- formatters and analyzers leak tool-specific behavior;
- source and artifact validation are materially different;
- machine-readable findings still lack enough context for reliable automation.
- changed the title
[-]`project dev` makes validation and code health first-class[/-][+]`project dev` makes validation and code health visible and first-class[/+]on Sep 30, 2026
Problem statement
Developers have to understand several commands, modes and scopes to know what was actually checked. My recent hands-on tour found that:
0 problemscan mean a requested check did not actually run or findings were suppressed.--onlyselections and reports invoked/skipped checkers. fix: extension validate + fix + format should report what actually ran #1611--fullis deprecated. feat!: deprecate full and make it default for extension validate #1618builtin;sw-cliremains a deprecated alias for selections. feat!: rename sw-cli tool to builtin #1627project validate --only sw-cli --format jsoncan still return onlyresults: []. Validation tells developers what actually ran #1502, Aggregate project and extension validation results #1310project devTUI.--no-progressand captures output until completion. Couldn't be sure that cancellation works; "Working" or a spinner.project devValidation tab should show progress, elapsed time, coverage and grouped results, and distinguish passed, failed and not-run checks. Run and inspect project validation inproject dev#1524vendor/orcomposer.lockstate overriding the requested comparison. Make validation use an explicit Shopware baseline #1308--no-copyis faster but can leavevendor/andcomposer.lockbehind.--no-copycan still modify the source tree through generated dependencies or lock files.vendor/orcomposer.lockstate. Make validation use an explicit Shopware baseline #1308extension validateandproject validatewithout--no-copyflag is bad on MacOS with MS Defender #1634; slow perf would block potential internal adoption--no-copyflag.project validateandextension validatecover different things, so a green project does not mean its extensions are valid.extension validateresults as a distinct scope. Show local extension validation health inproject dev#1526project dev#1526extension validate --format jsonreturnedresults: []for a plugin, whileproject validate --only sw-cli --format jsonalso returnedresults: []even thoughsw-cliperforms no project-level check. Empty results therefore do not reliably communicate whether validation passed or whether nothing applicable was checked.toolsarray with invoked/skipped status. fix: extension validate + fix + format should report what actually ran #1611project dev#1524project validatein CI #1528extension fix --only sw-cliandproject fix --only sw-cliexited successfully without changing files or reporting that no fix was available. A zero-exit invocation offixtherefore does not prove that any fix was performed.sw-cliis now rejected as an unsupported fixer in both commands because it implements checking, not fixing. fix: extension validate + fix + format should report what actually ran #1611extension fixcan resolve #1309extension fixandproject fix.extension fixrejects extensions inside a Git project whileproject fixaccepts them #1530FroshTools,extension fix --only eslint --allow-non-gitexited silently and changed no files. The CLI does not explain whether ESLint found nothing fixable, whether no applicable files were selected, or whether no fix was performed.Fixerstable showing that ESLint was invoked. fix: extension validate + fix + format should report what actually ran #1611extension fixcan resolve #1309project validatein CI #1528, Quiet formatter output when it isn't going to a terminal #1544FroshTools, ESLint reported oneno-unused-expressionserror. Runningextension fix --only eslint --allow-non-gitprinted the same finding but produced no file changes, showing that validation can report an error without the selected fixer resolving it.--fixwithout post-fix validation and does not surface a normalized “remaining findings” result.extension fixcan resolve #1309Goal
Following the mockup in #1524, provide a Validation tab that displays findings and provides an
ignoreflow.The Validation experience must:
Ongoing shopware-lsp investigations will be enabling work for us to understand where and how errors and suppression state are stored, which will impact related CLI operations.
Out of scope
New validation rules, upgrade-specific analysis, Store/account extension management.
Business / user impact
Lower TCO.
Acceptance criteria
Completion of the linked stories.
Readiness checklist