NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1181 most downloaded on Packagist
A composer plugin that enables source code quality checks.
Last release 4 days ago
03 Oct 2026
Ships fairly regularly
a new release about every 2 months
Rarely documented
notes for 13 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
115 releases · first in 2015
GrumPHP passed repository files to external tools as plain arguments, so a file whose name starts with - could be read as an option, such as --config
GrumPHP passed repository files to external tools as plain arguments, so a file whose name starts with - could be read as an option, such as --config, instead of a path. Paths starting with - are now prefixed with ./, and the git_blacklist task matches file names literally. See GHSA-fmpp-rfr9-jgpg for details.
Thanks to @jf0x3a for reporting this responsibly.
Full Changelog: v2.24.0...v2.25.0
One column per quarter.
feat(phpmd): PHPMD report format allowed values matches renderers by @freezysko in #1229
Full Changelog: v2.23.0...v2.24.0
Bump actions/cache from 5 to 6 by @dependabot [bot] in #1226
Full Changelog: v2.22.0...v2.23.0
GrumPHP just made a new friend. Starting this release, you can run Mago straight from your hooks.
GrumPHP just made a new friend. Starting this release, you can run Mago straight from your hooks.
Mago is a PHP toolchain written in Rust. The name means "wizard," which fits: it does the work of four tools at once. A formatter, a linter, a static analyzer, and an architectural guard, all in a single fast binary. It's already showing up in places like Drupal.
We didn't bolt it on as one big task. Each part gets its own, so you turn on only what you want and configure them separately:
mago_format keeps your code style consistentmago_lint catches style slips, smells, and likely bugsmago_analyze does the deeper work: types, control flow, logic errorsmago_guard enforces your architecture and layer rulesFormat, lint, and analyze run read-only by default. When one fails, GrumPHP offers to re-run it with fixes applied, so you stay in control. Guard only reports, because you can't auto-fix an architecture problem (Mago won't pretend otherwise).
Add it to your project like any other tool:
composer require --dev carthage-software/mago
vendor/bin/mago initThen point your grumphp.yml at whichever tasks you want. Full setup and options live in the Mago task docs.
The grump approves. Welcome to the family, Mago. 🧙🦊
amend! prefix in commit message task by @reynkonig in #1224Full Changelog: v2.21.0...v2.22.0
Bump actions/dependency-review-action from 4 to 5 by @dependabot [bot] in #1217
Full Changelog: v2.20.0...v2.21.0
Cover more of Drupal's custom file extensions by @damienmckenna in #1203
Full Changelog: v2.19.0...v2.20.0
Bump actions/cache from 4 to 5 by @dependabot [bot] in #1201
❗ Requires re-initialization from git hooks
In the new version of our dependency gitlib, you need to pass the --raw option to the git diff that is being parsed by the pre-commit hooks. This means you'll need to change your git hook after upgrading:
./vendor/bin/grumphp git:initIf you are using a custom hook, make sure to add the --raw parameter to git diff first:
DIFF=$(git -c diff.mnemonicprefix=false -c diff.noprefix=false --no-pager diff --raw -r -p -m -M --full-index --no-color --staged | cat)
Full Changelog: v2.18.0...v2.19.0
Fix installation link for deptrac by @codisart in #1190
Full Changelog: v2.17.0...v2.18.0
Php 85 upgrade by @veewee in #1189
Add composer_validate_autoload task by @TravisCarden in #1186
composer_validate_autoload task by @TravisCarden in #1186Full Changelog: v2.15.0...v2.16.0
Fix Security Checker Enlightn Allow List by @youwe-petervanderwal in #1180
Full Changelog: v2.14.0...v2.15.0
Mark 1.x as unsupported in SECURITY.md by @marcwrobel in #1176
Full Changelog: v2.13.0...v2.14.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Compare
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →