NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1217 most downloaded on Packagist
Jane runtime Library
Last release 7 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 3 months
Rarely documented
notes for 7 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
100 releases · first in 2018
chore(release): prepare the 8.0.0 release
chore(release): prepare the 8.0.0 release (#1106)
chore(release): prepare the 8.0.0 release
chore(release): prepare the 8.0.0 release (#1106)
fix: audit category A — bugs & correctness fixes (+ redirect option &…
fix: audit category A — bugs & correctness fixes (+ redirect option &…
One column per quarter.
fix: audit category A — bugs & correctness fixes (+ redirect option &…
fix: audit category A — bugs & correctness fixes (+ redirect option &…
fix: audit category A — bugs & correctness fixes (+ redirect option &…
fix: audit category A — bugs & correctness fixes (+ redirect option &…
feat: modernize emitted exception code and remove 8.x deprecations
Runtime quality & PHP modernization (cleanup-d-runtime) (#1060)
runtime(json-schema): add reference exception hierarchy and wrap foreign failures
Introduce domain exceptions under JsonSchemaRuntime\Exception, all extending
the existing ReferenceResolveException (itself a RuntimeException implementing
JaneExceptionInterface) so \RuntimeException catch blocks keep working:
Replace the remaining generic \RuntimeException throws in Reference with the
specific classes, and wrap the foreign exceptions (league/uri constructor,
Rs\Json\Pointer) with informative messages and previous-exception chaining.
Also cache the league/uri v6-vs-v7 method_exists() capability sniff once per
process instead of running it on every Reference construction.
Replace the three @realpath() calls with explicit existence guards (is_dir /
file_exists) before resolving, keeping the existing false-return fallbacks
so no warnings are emitted and behavior is unchanged.
resolve() now invokes-through when the deserializeCallback is null instead of
allocating an identity closure on every call; PHP passes scalars and arrays
by value anyway, so returning the resolved value directly is equivalent.
PR #1049 moved the runtime templates from Generator/Runtime/data to
Generator/Runtime, leaving the php-cs-fixer exclusions pointing at the old
paths: the templates (which are emitted verbatim into generated code and
deliberately use fully-qualified names) fell back into the fixer scope and
failed the cs:check gate.
Restore the exclusions to the moved directories, and reorder the trait uses
in the three NonBodyParameterGenerator variants that were already failing
cs:check on the base branch (unrelated to the runtime work but required for
the gate to pass).
Type the shipped runtime surface conservatively:
Modernize the emitted templates:
Add a comment documenting the by-design mapping of null query options to
empty values in BaseEndpoint::getQueryString (item: document-current).
Update Issue588RegressionTest: containment violations now implement
JaneExceptionInterface and are rendered as a console [ERROR] block by the
generate command (ADR 0002) instead of being thrown, so the test asserts on
the command exit code and the rendered message.
Regenerate every component's expected fixtures to match the updated shipped
runtime templates (typed Client constructor with promoted readonly properties,
collapsed authentication scope reuse, arrow-fn CheckArray, null-safe multipart
boundary) and the shorter $contentType !== null emission from the OpenAPI3 /
OpenAPI31 transformResponseBody generators. Runtime boilerplate in functional
(.full-compare) fixtures is refreshed in lockstep; manifest fixtures
(github, twitter, api-platform-demo) are re-hashed.
Soft-BC-risky generated-code contract changes (flagged for maintainer review):
Regenerated the OpenAPI fixtures (expected Client.php files) and the github /
twitter / api-platform-demo snapshot manifests to match.
CHANGELOG entries for items 1-6 of the runtime quality pass: the reference
exception hierarchy, the removed identity closure / cached league-uri sniff,
the conservatively typed shipped interface surface, the (flagged) generated
client contract changes, the emitted-template modernization, the documented
null-query-option behavior (document-current) and the @realpath removal.
cs:check considers @PARAM mixed redundant on a native mixed parameter and
@return array redundant on a native array return, so remove them from the
CustomQueryResolver interface (shipped + emitted copies) and from
ServerPluginGenerator::getServerPluginsStatements. The @PARAM object
docblock on the mixed $openApi parameters is kept: it conveys the actual
per-component model that mixed erases.
feat(json-schema)!: generate models with public typed properties (#1028)
feat(json-schema)!: generate models with public typed properties
fix(open-api): migrate leftover Schema accessor calls in BodyParameterGenerator
The public typed properties migration (37003b743) rewrote most document
model reads but missed getAllOf() / getType() / getFormat() on the
resolved body parameter schema, crashing generation for any Swagger 2
spec with an allOf body parameter reference (regression caught by the
issue-770 fixture, whose expected baseline had been deleted in the
fixture sweep for exactly this reason).
Reads now use null-coalesced property access, matching the idiom used
across the migrated guessers: uninitialized (unassigned) properties
behave like the former implicit nulls.
Restores the issue-770 expected baseline (6875 files) regenerated with
the fixed generator.
Generated models no longer ship getters/setters, so testClient()
exercised removed accessors and errored in every CI job:
Replaced with direct property access and regenerated the committed
client baselines for OpenApi2 / OpenApi3 / OpenApi31, which still held
the old accessor-based output.
refactor: architecture & design-pattern cleanup (category B) for 8.x (#1061)
refactor: eliminate global static state from reference resolution, validator factory, schema parser
Extract resolution config and fetch caches out of JsonSchemaRuntime\Reference
into a dedicated ReferenceResolver instance threaded through the generation
pipeline (generated code keeps binding to a shared default resolver). Convert
ChainValidatorFactory to an instance factory (custom validators + date
formats become constructor state) wired through Jane, JaneOpenApi and the
guesser factories. Drop the static SchemaParser cache. In OpenApiCommon's
ExceptionGenerator, move status-text lookup to a private const and split the
base exception file generation into a dedicated BaseExceptionsGenerator that
implements GeneratorInterface, fixing the memoization precedence bugs that
triggered 'undefined array key' warnings.
Split the oversized generator entry points into small focused collaborators,
keeping every emitted AST byte-for-byte identical:
Introduce Jane\JsonSchema\Generator\Options, an immutable value object
carrying every generation option with one canonical default each. The raw
array entry points (JsonSchema/OAI2/OAI3/OAI31 build(), the three guesser
factories and the console ConfigLoaders) keep accepting arrays and hydrate the
DTO via fromArray()/toArray(), so a new option only needs a default declared
in one place.
Behavioral cleanup folded in:
Introduce OpenApiCommon\Guesser\OpenApiSchema\AbstractXOfReferenceGuesser
carrying the shared union guessing logic, parameterized by the union keyword,
the version schema class and small behavioral hooks (OpenAPI 3.1 allOf-wrapped
references, richer has-content detection, optional class-guessing recursion for
oneOf). The mis-spelled version-local class names (AnyOfReferencefGuesser,
OneOfReferencefGuesser) are removed; OpenApi3\AnyOfReferenceGuesser,
OpenApi31\AnyOfReferenceGuesser and OpenApi31\OneOfReferenceGuesser replace
them and are wired in both guesser factories.
Move the 100% identical request body content generators (interface, default
and JSON payload generators plus their shared abstract) into
OpenApiCommon\Generator\RequestBodyContent, parameterized by the version
schema class; the version-local FormBodyContentGenerator and
RequestBodyGenerator stay (real per-version drift) but now extend the common
bases. EndpointGenerators (book marker: version flows)
Also move GetTransformResponseBodyTrait to OpenApiCommon\Generator\Endpoint
with three abstract hooks (schemaClassName / responseClassName /
responseNormalizerClassName) replacing the version imports, folding the
OpenAPI 3.1 array-type response handling into the shared convertResponseType
guard, and move the comment-only GetGetExtraHeadersTrait there too. Both
version-local copies are deleted (8.x, no BC aliases). GeneratorFactory and
the GuessClass forks stay version-local: they parameterize NonBodyParameter,
request-body and client generators and the version Parameter models.
Replace version-specific lookups with duck-typed / guarded accessors so
OpenApiCommon no longer imports OpenApi2/3/31 model classes:
Route guessers into typed buckets at registration time (class / type /
property guessers) instead of re-filtering a single list with instanceof on
every dispatch. Broadcast semantics for guessClass/guessProperties and
first-match semantics for guessType are now documented and enforced per role,
with registration order preserved so dispatch stays deterministic and
identical to the previous single-list behavior.
The preceding dead-code removal dropped guessClass()/getSchemaClass() from the
JsonSchema ArrayGuesser, but the OpenAPI ArrayGuesser relies on them (its
SchemaClassTrait override targets the version Schema model), silently breaking
array item model guessing. Restore the base methods with an explanatory
docblock; the plain JsonSchema component's guessClass stays inert (items are
never Registry\Schema containers).
Also make ClassGuesserInterface / TypeGuesserInterface /
PropertiesGuesserInterface extend GuesserInterface (every implementation
already provides supportObject) and give ChainGuesser the inherited
supportObject() stub so its typed dispatch buckets type-check.
Emitted-code modernization (regenerated fixtures):
Deprecation removal (8.x major):
Regenerated every component's expected fixtures (Exception promotion +
Runtime/Client cleanup); no Model/Normalizer/Endpoint drift.
Add ADR 0008 (instance-owned reference resolution), ADR 0009 (frozen
generation Options value object) and ADR 0010 (OpenAPI 3/3.1 generator
consolidation), and index them. Add an Unreleased 'Removed' / 'Changed'
section to the CHANGELOG documenting the 8.x deprecation removals (Reference
static state, JaneExceptionInterface alias, generated-client FETCH_RESPONSE
mode, mis-spelled guesser names) and the behavioral consolidations.
The github fixture uses a snapshot manifest; upstream cleanup-d-runtime (#1060)
changed generated runtime output, so the hashes are regenerated from the
current generator. Emitted-code changes from this branch are included.
Rebase onto c547f1909 (upstream merged cleanup-d-runtime #1060 which
regenerated document models with public typed properties and dropped getters)
required folding upstream's property-access style into the consolidated code:
The OpenAPI3 fixtures issue-737 and multipart-nested-object both generate a
FilePostBody model in the same Tests\Expected\Model namespace. phpstan scans
fixtures and whichever FilePostBody definition it discovers first wins; the
scan order differs between environments, so CI resolves the issue-737 model
(no $item property) and reports property.notFound in
MultipartNestedObjectRuntimeTest while local resolves the multipart one.
Restore the suppression for that environment-dependent error and set
reportUnmatchedIgnoredErrors: false (the documented PHPStan 2.x remedy for
ignore patterns that may not match in every environment), so the build stays
green both where the error is reported and where the scan happens to resolve
the correct model.
fix: audit category A — bugs & correctness fixes (+ redirect option &…
fix: audit category A — bugs & correctness fixes (+ redirect option &…
Validate $ref resolution to prevent SSRF, LFI, and path traversal
Validate $ref resolution to prevent SSRF, LFI, and path traversal (#961)
Validate $ref resolution to prevent SSRF, LFI, and path traversal
Validate $ref resolution to prevent SSRF, LFI, and path traversal (#961)
Remove all ext-json from composer.json
Remove all ext-json from composer.json (#931)
Remove all ext-json from composer.json
Remove all ext-json from composer.json (#931)
Remove all ext-json from composer.json
Remove all ext-json from composer.json (#931)
Updates project to the new documentation site and records related tooling changes.
Updates project to the new documentation site and records related tooling changes.
Fix version constraint for symfony 8
Fix version constraint for symfony 8 (#886)
Fix version constraint for symfony 8
Fix version constraint for symfony 8 (#886)
Fix version constraint for symfony 8
Fix version constraint for symfony 8 (#886)
Add SF8 support Try workflow with SF 8 Try Try Try Add fixtures Update matrix Fix Try
Add SF8 support
Try workflow with SF 8
Try
Try
Try
Add fixtures
Update matrix
Fix
Try
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →