doctrine/dbal
69.0
Adequate · 26 September 2026
40.4k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is the Doctrine Database Abstraction Layer (DBAL), a PHP library that provides a unified interface for interacting with various relational databases including MySQL, PostgreSQL, Oracle, SQL Server, SQLite, and IBM DB2. It manages database connections, executes SQL queries, and handles schema migrations through a modernized API that supports primary-replica routing, query building with CTEs and unions, and robust error handling. The library also includes tools for data type mapping, caching, and logging, ensuring type safety and compatibility with modern PHP versions.
How it got here
2007–2020 — PHP 8 modernization and API overhaul
64 changes.
This period focused on a comprehensive modernization of Doctrine DBAL to support PHP 8+, involving the complete rewrite of all database drivers to use native types, strict parameter binding, and modern exception handling. The library introduced a new QueryBuilder with CTE support, refactored the schema and cache layers for better type safety, and established a robust middleware architecture for portability and connection management.
2021–2023 — Driver modernization and middleware support
29 changes.
This period focused on modernizing the database driver layer by introducing native implementations for SQLite3 and PostgreSQL, alongside a new abstract middleware architecture for extensibility. It also enhanced core functionality with dedicated SQL builders for CTEs and unions, improved logging with sensitive data redaction, and refined type handling through specific exception classes and a new Money type.
2024–2025 — test coverage expansion
5 changes.
This period focused on expanding test coverage for the schema and driver components. New tests were added for schema name value objects, collection classes, and index validation logic. The work also included verifying compatibility with PHP 8.4 PDO subclasses and IPv6 URI support in the PgSQL driver.
Features
Add SQLSrv Error exception class
A new \Error\ exception class has been added to the SQLSrv driver to handle SQL Server errors. This class provides a static \new()\ method that retrieves error details (message, SQL state, and error code) from the \sqlsrv\_errors\ function and constructs an exception, ensuring users receive specific error information when a SQL Server operation fails.
src/Driver/SQLSrv/Exception · high confidence
Add StaticServerVersionProvider for explicit database version configuration
A new StaticServerVersionProvider class has been added to the Connection component, allowing users to explicitly define the database server version via a constructor argument. This provides a concrete implementation of the ServerVersionProvider interface, enabling deterministic version handling without relying on automatic detection or external configuration sources.
src/Connection · high confidence
Add logging middleware to capture database activity and redact sensitive connection data
A new logging middleware has been introduced that wraps the database driver, connection, and statement layers to provide visibility into database operations. Users can now log connection attempts (with passwords automatically redacted for security), SQL queries, statement executions with their bound parameters and types, and transaction lifecycle events (begin, commit, rollback). This allows for easier debugging and monitoring of database interactions without exposing sensitive credentials in log output.
src/Logging · high confidence
Initial repository structure and project metadata for Doctrine DBAL
This change establishes the foundational structure for the Doctrine DBAL repository. It introduces the \.doctrine-project.json\ configuration file, which defines the project's versioning strategy and lists supported branches (5.0, 4.5, 4.4, 3.10, etc.). It also adds essential project files including \README.md\ with build badges, \LICENSE\ (MIT), \SECURITY.md\ with reporting guidelines, \CONTRIBUTING.md\, and \UPGRADE.md\ documenting deprecations for versions 4.4 and 4.3. Additionally, it sets up development tooling configurations such as \.gitattributes\, \.gitignore\, \phpcs.xml.dist\ for code style, and \phpstan.neon.dist\ for static analysis.
(repo-wide) · high confidence
Introduce native PgSQL driver for PostgreSQL connections
Adds a new native PgSQL driver implementation (src/Driver/PgSQL) that replaces the previous PostgreSQL driver layer. This includes a new Connection class for managing the PgSql\\Connection resource, a Driver class that handles connection string construction (including IPv6 bracket notation and GSS encryption modes), a Statement class for prepared statement execution with boolean and resource parameter handling, and a Result class for fetching data. The driver also implements proper resource cleanup in destructors for connections, statements, and results, and provides a ConvertParameters visitor to map SQL parameters to PostgreSQL's positional format.
src/Driver/PgSQL · high confidence
Introduce native SQL parser for prepared statement parameters
A new SQL parser has been added to identify prepared statement parameters (both named and positional) within SQL strings. This component, located in src/SQL/Parser.php, implements parsing logic inspired by the PHP PDO parser to correctly handle string literals, comments, and special characters without confusing their contents with parameter placeholders. It supports both MySQL and ANSI SQL string escaping modes and includes error handling for regular expression failures.
src/SQL · high confidence
Introduce new SQLite3 driver implementation
This change introduces a new, standalone SQLite3 driver implementation within the Doctrine DBAL library. The new driver consists of dedicated classes for managing connections, executing statements, handling results, and managing exceptions, replacing or supplementing previous approaches. Key features include support for both file-based and in-memory databases, proper handling of parameter binding with type conversion, and the addition of a \getColumnName\ method to the Result interface for retrieving column names by index. The driver also enforces strict typing and uses modern PHP features like readonly properties and sensitive parameter attributes.
src/Driver/SQLite3 · high confidence
Introduction of new database mapping types and stricter JSON handling
This update adds several new database mapping types to the library, including \AsciiStringType\, \NumberType\ (mapping to \BcMath\\Number\), \SmallFloatType\, \EnumType\, and dedicated JSON types for PostgreSQL (\JsonbType\, \JsonbObjectType\) as well as standard JSON objects (\JsonObjectType\). It also introduces immutable variants for date and time types (\DateImmutableType\, \DateTimeImmutableType\, etc.) to provide safer, non-mutable date handling. Additionally, the JSON conversion logic has been updated to use \JSON\_THROW\_ON\_ERROR\ and \JSON\_PRESERVE\_ZERO\_FRACTION\, ensuring that JSON encoding and decoding errors are explicitly thrown as exceptions and that zero fractions in float values are preserved during serialization.
src/Types · high confidence
New PrimaryReadReplicaConnection for primary-replica database setups
A new \PrimaryReadReplicaConnection\ class is introduced to support primary-replica database configurations. This connection type automatically routes read operations to a randomly selected replica and write operations to the primary node. It enforces a strict separation where the primary is used for any state-changing operations (such as inserts, updates, deletes, or transactions) and remains active for subsequent operations once engaged. Users can manually switch connections using \ensureConnectedToPrimary()\ or \ensureConnectedToReplica()\. The class is instantiated via the \DriverManager\ by specifying \wrapperClass\ and providing separate \primary\ and \replica\ configuration arrays.
src/Connections · high confidence
New QueryBuilder implementation with CTE, UNION, and FOR UPDATE support
The QueryBuilder component has been replaced with a new implementation that introduces support for Common Table Expressions (CTE), UNION queries, and row locking (FOR UPDATE with SKIP\_LOCKED). Users can now build complex queries using dedicated classes like CommonTableExpression, Union, and ForUpdate, and benefit from stricter parameter handling and result caching.
src/Query · high confidence
New abstract middleware classes for driver components
Added abstract middleware classes (AbstractConnectionMiddleware, AbstractDriverMiddleware, AbstractResultMiddleware, AbstractStatementMiddleware) that provide default pass-through implementations for the Driver interface components. These classes allow users to extend specific middleware behaviors without having to implement every method of the underlying interfaces, simplifying the creation of custom driver middlewares.
src/Driver/Middleware · high confidence
New console command for executing arbitrary SQL
The \dbal:run-sql\ command is now available in the console tools, allowing users to execute arbitrary SQL statements directly from the command line. This new feature includes a \ConnectionProvider\ interface and a \SingleConnectionProvider\ implementation to manage database connections, enabling flexible integration with existing application setups.
src/Tools/Console · high confidence
New query expression builder components
The \src/Query/Expression\ directory now contains the \CompositeExpression\ and \ExpressionBuilder\ classes. \CompositeExpression\ provides an immutable way to group similar SQL expressions using AND or OR logic, supporting fluent construction via static factory methods and a \with()\ method for appending parts. \ExpressionBuilder\ offers a fluent API for dynamically creating SQL query parts, including comparison operators (equality, inequality, less/greater than), null checks, and logical conjunctions/disjunctions, relying on a \Connection\ instance for context.
src/Query/Expression · high confidence
SQLite driver now includes a dedicated exception converter
The SQLite driver now provides a concrete implementation of the exception conversion interface, mapping raw SQLite error messages to specific Doctrine DBAL exception types (such as UniqueConstraintViolationException, TableNotFoundException, and LockWaitTimeoutException). This allows applications to catch and handle database-specific errors more precisely rather than receiving generic driver exceptions.
src/Driver/API/SQLite · high confidence
Behavioural changes
Cache layer refactored to use PSR-6 and modern PHP types
The caching implementation in src/Cache has been updated to rely on PSR-6 (Psr\\Cache\\CacheItemPoolInterface) instead of the deprecated doctrine/cache library, with QueryCacheProfile now accepting PSR-6 pools for result caching. The new ArrayResult class implements the Driver\\Result interface, providing a modern, typed way to handle cached query results, including support for deserializing legacy data formats. Additionally, cache-related exceptions have been restructured into a dedicated namespace, and sensitive connection parameters like passwords are now excluded from cache key generation to improve security.
src/Cache · high confidence
Database platform abstraction layer restructured and modernized
The database platform implementation has been significantly refactored to improve type safety and maintainability. The base \AbstractPlatform\ class now requires an explicit \UnquotedIdentifierFolding\ configuration in its constructor, replacing the previous default behavior. Platform-specific logic for MySQL, DB2, and other databases has been organized into dedicated classes and metadata providers, with keyword lists marked as deprecated. New PHP 8.1 features, such as enums for \DateIntervalUnit\ and \LockMode\, are utilized to replace magic constants, and internal methods are strictly marked to prevent external usage.
src/Platforms · high confidence
Deprecation of 'service' connection parameter in Oracle Easy Connect string generation
The new EasyConnectString class in the AbstractOracleDriver now triggers a deprecation warning when the 'service' connection parameter is used, instructing users to switch to the 'servicename' parameter instead. This change ensures that Oracle database connections using the deprecated 'service' key are flagged for migration, while the underlying logic for constructing the Easy Connect string remains functional.
src/Driver/AbstractOracleDriver · high confidence
Exception hierarchy restructured with new base classes and specific error types
The exception system in src/Exception has been reorganized to provide a clearer hierarchy and more specific error handling. A new DriverException base class now chains the underlying driver exception and stores the executed SQL query, accessible via getQuery(). Connection-related errors now extend a new ConnectionException, while server errors extend ServerException. Several new specific exception classes have been added, including CommitFailedRollbackOnly, ConnectionLost, DatabaseRequired, DriverRequired, InvalidColumnDeclaration, InvalidColumnIndex, InvalidColumnType, InvalidDriverClass, InvalidWrapperClass, MalformedDsnException, NoActiveTransaction, NoKeyValue, ParseError, ReadOnlyException, SavepointsNotSupported, TransactionRolledBack, and UnknownDriver. The RetryableException marker interface has been introduced for exceptions that warrant transaction retries. This change improves the granularity of error reporting and makes it easier for users to catch and handle specific database-related issues.
src/Exception · high confidence
IBM DB2 driver now provides specific exception types for database errors
The IBM DB2 driver now includes a dedicated exception converter that maps specific DB2 error codes (such as -104 for syntax errors, -204 for missing tables, and -803 for unique constraint violations) to precise Doctrine exception classes. This allows applications to catch and handle database-specific issues like foreign key violations or connection failures with greater granularity, rather than receiving generic driver exceptions.
src/Driver/API/IBMDB2 · high confidence
IBM DB2 driver rewritten for PHP 8.1+ with modernized API and improved error handling
The IBM DB2 driver has been completely rewritten to target PHP 8.1+, introducing strict typing, readonly properties, and native return types across all components. The connection API now accepts a native resource directly and exposes it via \getNativeConnection()\, while \lastInsertId()\ no longer accepts a name argument and throws \NoIdentityValue\ if no identity is available. Statement parameter binding now requires explicit \ParameterType\ enums, and LOB (BLOB) handling has been refined to bind only non-NULL values correctly. The driver also introduces a new \Result::getColumnName()\ method, flags sensitive parameters with \\#\[SensitiveParameter\]\, and implements basic exception handling for connection, preparation, and statement errors.
src/Driver/IBMDB2 · high confidence
Improved error messages for invalid column type declarations
The library now provides more specific and descriptive exception classes for common column definition errors. When a column type requires a length, precision, scale, or specific values but these are omitted, users will now receive targeted error messages (e.g., 'MySQL requires the length of a varchar column to be specified') instead of generic exceptions, making it easier to identify and fix schema definition issues.
src/Exception/InvalidColumnType · high confidence
Introduce specific exception classes for Type conversion errors
The \src/Types/Exception\ directory now contains a dedicated set of exception classes (such as \InvalidFormat\, \InvalidType\, \SerializationFailed\, \TypeAlreadyRegistered\, \TypeNotFound\, \ValueNotConvertible\, and others) that implement the new \TypesException\ interface. These classes replace generic error handling with specific, typed exceptions for type registration and conversion failures, providing clearer error messages and allowing users to catch specific type-related issues.
src/Types/Exception · high confidence
Introduce structured exception handling for the IBM DB2 driver
The IBM DB2 driver now provides specific, dedicated exception classes (such as ConnectionError, ConnectionFailed, PrepareFailed, StatementError, CannotCreateTemporaryFile, and CannotCopyStreamToStream) that extend the base AbstractException. These classes replace generic error handling by extracting detailed DB2-specific error messages and SQL states via native functions (e.g., db2\_conn\_errormsg, db2\_stmt\_error) and using a Factory to parse SQL codes from error strings, resulting in more precise error reporting for connection, statement, and file-operation failures.
src/Driver/IBMDB2/Exception · high confidence
Introduction of SQL Parser exception hierarchy and visitor interface
The SQL parser now includes a dedicated exception interface and a specific RegularExpressionError class to handle PCRE failures, ensuring that regex-related parsing issues are caught and reported with standard error messages. Additionally, a new Visitor interface has been added to the parser, defining methods for accepting positional parameters, named parameters, and other SQL fragments, which establishes the contract for components that process parsed SQL structures.
src/SQL/Parser · high confidence
Introduction of native PHP enums and modernized parameter handling
The library now uses native PHP enums for configuration and type constants, replacing previous integer or string-based approaches. This includes new enums for ArrayParameterType (INTEGER, STRING, ASCII, BINARY), ColumnCase (UPPER, LOWER), LockMode (NONE, OPTIMISTIC, PESSIMISTIC\_READ, PESSIMISTIC\_WRITE), ParameterType (NULL, INTEGER, STRING, LARGE\_OBJECT, BOOLEAN, BINARY, ASCII), and TransactionIsolationLevel (READ\_UNCOMMITTED, READ\_COMMITTED, REPEATABLE\_READ, SERIALIZABLE). Additionally, the API introduces explicit fetch methods on the Result class (such as fetchNumeric, fetchAssociative, and fetchAllKeyValue) to replace legacy fetch modes, and adds a new ArrayParameterType enum to handle array expansion in SQL queries.
src · high confidence
MySQL driver now converts specific error codes into typed exceptions
The MySQL driver now maps specific MySQL error codes to distinct, typed exceptions (such as ConnectionLost, DatabaseDoesNotExist, and various constraint violations) instead of returning a generic DriverException. This allows applications to handle database errors more precisely, for example by catching ConnectionLost specifically for error code 4031 or handling unknown user/authentication issues in MySQL 8.4 via a dedicated workaround.
src/Driver/API/MySQL · high confidence
New PDO-based SQL Server driver implementation
The SQL Server driver has been replaced with a new implementation built on top of PHP's PDO extension. This change introduces new \Connection\, \Driver\, and \Statement\ classes that wrap native PDO objects, providing a modernized foundation for database interactions. The new driver enforces stricter typing by requiring explicit parameter types for \bindValue()\ and handles SQL Server-specific encoding options (binary and ASCII) internally within the statement layer.
src/Driver/PDO/SQLSrv · high confidence
New PDO-based SQLite driver with strict parameter validation
The SQLite connection logic has been replaced by a new \Driver\ class that leverages the generic PDO infrastructure. This change introduces strict validation for connection parameters, throwing an \InvalidConfiguration\ exception if the \user\ or \password\ values are not strings or null. Additionally, the \user\ and \password\ parameters are now flagged as sensitive to prevent accidental logging or exposure.
src/Driver/PDO/SQLite · high confidence
New SQL builders for schema operations, unions, and CTEs
The SQL generation logic in src/SQL/Builder has been restructured with new dedicated builders: CreateSchemaObjectsSQLBuilder and DropSchemaObjectsSQLBuilder now handle schema object creation and dropping (with sequences dropped before tables in the latter), DefaultUnionSQLBuilder adds support for UNION clauses, and WithSQLBuilder enables Common Table Expression (CTE) support in SELECT queries. Additionally, DefaultSelectSQLBuilder now supports SKIP LOCKED for row locking scenarios.
src/SQL/Builder · high confidence
New standalone DSN parser with improved path normalization and sensitive parameter handling
A new standalone DsnParser class has been introduced in src/Tools to handle database connection URL parsing. This change modifies how connection parameters are derived from DSN strings: it now correctly handles SQLite URLs with triple slashes by injecting a localhost host, and it only trims the leading slash from the database path if a host is present, preventing accidental removal of leading slashes from pure database names. Additionally, the parser now supports mapping DSN schemes to specific driver classes via a configurable scheme mapping, and it marks the password parameter as sensitive to prevent accidental logging or exposure.
src/Tools · high confidence
OCI driver now converts Oracle error codes into specific Doctrine exception types
The OCI driver now maps specific Oracle error codes (such as ORA-00001, ORA-00942, ORA-02091, etc.) to precise Doctrine exception classes like UniqueConstraintViolationException, TableNotFoundException, and TransactionRolledBack. This allows applications to catch and handle database errors with greater granularity instead of receiving generic DriverException instances.
src/Driver/API/OCI · high confidence
OCI8 driver introduces specific exception classes for connection and query errors
The OCI8 driver now includes dedicated exception classes—ConnectionFailed, Error, InvalidConfiguration, NonTerminatedStringLiteral, and UnknownParameterIndex—to provide more granular error handling. These changes allow users to catch specific OCI8-related issues, such as connection failures, invalid configurations (e.g., mutually exclusive persistent and exclusive options), and SQL statement errors like non-terminated string literals or unknown parameter indices, rather than relying on generic exceptions.
src/Driver/OCI8/Exception · high confidence
OCI8 driver now initializes session NLS settings and flags credentials as sensitive
The OCI8 driver now includes a new InitializeSession middleware that automatically configures Oracle session parameters (NLS\_DATE\_FORMAT, NLS\_TIME\_FORMAT, NLS\_TIMESTAMP\_FORMAT, NLS\_TIMESTAMP\_TZ\_FORMAT, and NLS\_NUMERIC\_CHARACTERS) upon connection, ensuring consistent date/time/numeric formatting for users. Additionally, the connection parameters array is now marked with \#\[SensitiveParameter\] to prevent accidental logging or exposure of sensitive credentials in stack traces or debug output.
src/Driver/OCI8/Middleware · high confidence
OCI8 driver rewritten for PHP 8+ with exclusive connections and named placeholders
The OCI8 driver has been completely rewritten to target PHP 8.0+, introducing support for establishing exclusive database connections via a new 'exclusive' driver option, and automatically converting positional query parameters into named placeholders to accommodate Oracle's limitations. The driver now returns row counts as numeric strings to safely handle values exceeding PHP\_INT\_MAX, enforces strict parameter type requirements for binding, and exposes the native OCI8 connection resource through a new getNativeConnection() method.
src/Driver/OCI8 · high confidence
Portability layer restructured as a middleware
The portability functionality has been refactored from a direct connection wrapper into a middleware architecture. This change introduces a new \Middleware\ class that wraps the database driver, allowing portability features (such as trimming empty strings, converting column cases, and handling nulls) to be applied via the driver stack rather than replacing the connection object directly. The implementation now uses dedicated middleware classes for the connection, statement, and result objects to intercept and transform data, providing a more modular and extensible approach to database portability.
src/Portability · high confidence
PostgreSQL driver now uses native PHP 8.4+ PDO subclasses and supports GSS encryption mode
The PostgreSQL PDO driver has been refactored to leverage the new native PDO subclasses introduced in PHP 8.4 (specifically \Pdo\\Pgsql\), falling back to the standard \PDO\ class for older PHP versions. This change improves type safety and aligns with modern PHP standards. Additionally, the driver now explicitly supports the \gssencmode\ connection parameter, allowing users to configure GSSAPI encryption modes for their PostgreSQL connections. The driver also enforces stricter validation on user and password parameters, ensuring they are strings or null, and flags sensitive parameters in the connection signature to prevent accidental logging.
src/Driver/PDO/PgSQL · high confidence
PostgreSQL exception handling now includes query context and improved connection loss detection
The PostgreSQL driver's exception converter has been refactored to implement the standard ExceptionConverter interface, ensuring that all converted exceptions now carry the original SQL query for better debugging. Additionally, the logic for detecting lost connections has been extended to recognize specific PostgreSQL error messages ('terminating connection' and 'server closed the connection'), providing more accurate ConnectionLost exceptions when the database server disconnects.
src/Driver/API/PostgreSQL · high confidence
Refactored DBAL driver interfaces and abstract base classes
The driver layer has been restructured to modernize the API and improve type safety. New abstract base classes (AbstractMySQLDriver, AbstractPostgreSQLDriver, etc.) now handle platform instantiation and version detection, with deprecation warnings triggered for older database versions (e.g., MySQL \< 8, MariaDB \< 10.6, PostgreSQL \< 12). The driver interfaces have been updated: Connection now exposes getNativeConnection() and returns int\|string for exec() and lastInsertId(); Statement requires explicit ParameterType for bindValue() and returns a new Result interface; Result replaces Statement for fetching data and includes getColumnName(). A new Middleware interface allows wrapping drivers, and FetchUtils provides helper methods for common fetch patterns.
src/Driver · high confidence
Refactored MySQLi driver exception classes to support PHP 8.1+ error handling
The MySQLi driver's exception classes (ConnectionError, ConnectionFailed, StatementError, InvalidCharset) have been updated to include an upcast method that converts native mysqli\_sql\_exception instances into the library's own exception hierarchy. This change ensures that connection and statement errors are handled consistently on PHP 8.1+, where MySQLi throws exceptions by default, while preserving the original exception as a previous instance for debugging. Additionally, new specific exception classes (FailedReadingStreamOffset, HostRequired, InvalidOption, NonStreamResourceUsedAsLargeObject) have been introduced to provide clearer error messages for parameter validation and configuration issues.
src/Driver/Mysqli/Exception · high confidence
Refactored MySQLi driver with new connection initializers and improved error handling
The MySQLi driver implementation has been rewritten to use a modular initializer pattern for connection setup (handling charset, options, and SSL securely) and to adopt PHP 8.1 features like readonly properties and native types. Error handling is now more robust, catching \mysqli\_sql\_exception\ and converting it to driver-specific exceptions, while \lastInsertId()\ now throws an exception if no identity value exists. The driver also returns row counts as strings for values exceeding \PHP\_INT\_MAX\ and exposes the native connection via \getNativeConnection()\.
src/Driver/Mysqli · high confidence
Refactored PDO driver with new connection and statement classes
The PDO driver implementation has been rewritten using modern PHP syntax and stricter typing. The Connection class now accepts a PDO instance directly and exposes a getNativeConnection() method, while the Statement class enforces explicit ParameterType arguments for binding values. Additionally, the driver now leverages PHP 8.4's PDO::connect() method when available and handles specific PDO error states for identity columns and lost connections more robustly.
src/Driver/PDO · high confidence
SQL Server driver now uses a dedicated exception converter
The SQL Server driver now includes a specific exception converter that maps native SQL Server error codes to precise Doctrine DBAL exception types. This allows applications to catch specific database errors, such as syntax errors, missing tables, or constraint violations, rather than receiving generic driver exceptions.
src/Driver/API/SQLSrv · high confidence
SQLSrv driver rewritten for PHP 8+ with stricter parameter binding and native connection support
The SQLSrv driver has been completely rewritten to target PHP 8.0+, introducing several behavioral changes for users. The \Connection\ class now requires a native SQLSRV resource in its constructor and exposes a new \getNativeConnection()\ method to retrieve it. Parameter binding in \Statement\ is stricter: \bindValue()\ and \bindParam()\ now require an explicit \ParameterType\ argument, and passing parameters directly to \Statement::execute()\ is no longer supported. Additionally, \lastInsertId()\ no longer accepts a name argument and will throw a \NoIdentityValue\ exception if no identity value is available, while \rowCount()\ may return a string for values exceeding \PHP\_INT\_MAX\ to prevent overflow.
src/Driver/SQLSrv · high confidence
Schema API overhaul with new editors and deprecation of legacy introspection methods
The schema management API has been significantly refactored to improve type safety and maintainability. Legacy introspection methods such as \listTableDetails\, \listTableColumns\, and \listTableIndexes\ are now deprecated in favor of new \introspect\*\ methods. Object naming is now handled via dedicated value objects in the \Name\ namespace, replacing the previous string-based approach. Additionally, a new set of editor classes (e.g., \ColumnEditor\, \TableEditor\, \ForeignKeyConstraintEditor\) has been introduced to facilitate schema modifications, while the old \TableDiff\-centric mutation patterns are being phased out. The \Comparator\ class now uses a \ComparatorConfig\ to control behavior, and internal properties of classes like \TableDiff\ and \SchemaDiff\ have been marked as private or internal to enforce the new API boundaries.
src/Schema · high confidence
Strict validation of user and password parameters in PDO drivers
The MySQL and OCI PDO drivers now enforce that the 'user' and 'password' connection parameters are strictly strings or null. If a non-string value is provided, the driver throws an InvalidConfiguration exception instead of attempting to connect, preventing potential issues with type coercion. This change also introduces a new InvalidConfiguration exception class to handle these specific configuration errors.
src/Driver/PDO/MySQL · high confidence
Test coverage
Added SQL Server comparator tests; Added SQLite-specific schema comparator tests; Added comprehensive test suite for QueryBuilder; Added comprehensive unit tests for DBAL Type classes; Added functional test for LockMode::NONE behavior; Added functional test for Oracle binary column comparison; Added functional test for the PDO SQLite driver; Added functional tests for DBAL types; Added functional tests for MySQL schema comparator behavior; Added functional tests for MySQLi and SQLSrv drivers; Added functional tests for PDO MySQL and OCI drivers; Added functional tests for PostgreSQL driver capabilities; Added functional tests for PostgreSQL schema comparison and sequence handling; Added functional tests for QueryBuilder UNION and FOR UPDATE capabilities; Added functional tests for SQL parsing edge cases; Added functional tests for SQLite3 driver connection parameter validation; Added functional tests for circular foreign key schema creation and dropping; Added functional tests for connection error handling and data fetching; Added functional tests for core database operations; Added functional tests for platform-specific schema and expression behaviors; Added functional tests for the IBM Db2 driver; Added functional tests for the PgSQL driver; Added functional tests for transaction rollback/commit and SQLite unsigned integer introspection; Added platform-specific column test cases; Added static analysis regression tests for DBAL schema management and connection handling; Added test coverage for OCI8 and SQLSrv driver components; Added test coverage for the Portability layer components; Added test for IPv6 URI support in PgSQL driver; Added test for Mysqli persistent connection validation; Added test for non-positive indexed column length validation; Added tests for ArrayResult serialization and QueryCacheProfile key generation; Added tests for CachingCollationMetadataProvider; Added tests for MySQL and MariaDB schema comparators; Added tests for MySQL schema comparison and table alteration; Added tests for Oracle EasyConnectString generation and deprecation handling; Added tests for PHP 8.4+ PDO subclasses; Added tests for Query Expression components; Added tests for Schema Name value objects; Added tests for abstract driver middleware classes; Added tests for driver platform instantiation and version handling; Added tests for query caching and array parameter expansion; Added tests for schema object collection classes; Added tests for the Money schema type; Added tests for the RunSqlCommand console command; Added tests for the logging middleware; Added tests for the new Schema API and deprecation warnings; Added tests for the standalone DSN parser; Added unit and driver tests for PDO drivers; Added unit and functional tests for DBAL core components; Added unit tests for the SQL parser; Expanded functional test coverage for schema introspection and table alteration; Migrated platform tests to PHPUnit 10 attributes and new schema editors.
Dependencies
Initial composer.json setup for DBAL and docs
The project now includes a root composer.json defining the Doctrine DBAL library with a PHP 8.2 requirement and dependencies on doctrine/deprecations, psr/cache, and psr/log. Development tools are pinned to specific versions, including PHPStan 2.1.30, PHPUnit 11.5.56, and Doctrine Coding Standard 14.0.0. A separate composer.json for the documentation directory requires the doctrine/docs-builder package.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 50 → 69 (+18.7)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 94 → 90 (-4.1)
- Architecture 96 → 99 (+3.3)
- Maturity 64 → 62 (-1.6)
- Readiness 35 → 76 (+40.8)
- Security 50 → 66 (+16.0)
Resolved (59)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- Duplicated block (10 lines × 2) (src/Connection.php)
- Duplicated block (10 lines × 2) (src/Driver/PDO/PgSQL/Driver.php)
- Duplicated block (16 lines × 2) (src/Platforms/SQLitePlatform.php)
- Duplicated block (31 lines × 12) (src/Platforms/Keywords/DB2Keywords.php)
- Duplicated block (31 lines × 3) (src/Platforms/Keywords/OracleKeywords.php)
- Duplicated block (31 lines × 3) (src/Platforms/Keywords/PostgreSQLKeywords.php)
- Duplicated block (31 lines × 3) (src/Platforms/Keywords/SQLiteKeywords.php)
- Duplicated block (31 lines × 5) (src/Platforms/Keywords/SQLServerKeywords.php)
- Duplicated block (31 lines × 7) (src/Platforms/Keywords/MariaDBKeywords.php)
- Duplicated block (31 lines × 7) (src/Platforms/Keywords/MySQLKeywords.php)
- Duplicated block (8 lines × 2) (src/Platforms/SQLServerPlatform.php)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 39 more
New (384)
- AbstractAsset._setName (cognitive 19) (src/Schema/AbstractAsset.php)
- AbstractAsset._setName (cyclomatic 18) (src/Schema/AbstractAsset.php)
- AbstractPlatform.buildCreateTableSQL (cognitive 17) (src/Platforms/AbstractPlatform.php)
- AbstractPlatform.getDefaultValueDeclarationSQL (cognitive 16) (src/Platforms/AbstractPlatform.php)
- AbstractPlatform.getDefaultValueDeclarationSQL (cyclomatic 16) (src/Platforms/AbstractPlatform.php)
- Change coupling clique: DB2Platform.php, OraclePlatform.php, PostgreSQLPlatform.php, SQLServerPlatform.php (src/Platforms/DB2Platform.php)
- Change coupling: AbstractPlatform.php ↔ MySQLPlatform.php (src/Platforms/AbstractPlatform.php)
- Change coupling: Index.php ↔ UniqueConstraint.php (src/Schema/Index.php)
- Change coupling: OracleSchemaManager.php ↔ PostgreSQLSchemaManager.php (src/Schema/OracleSchemaManager.php)
- Change coupling: PostgreSQLSchemaManager.php ↔ SQLServerSchemaManager.php (src/Schema/PostgreSQLSchemaManager.php)
- Change-coupling hub: DB2SchemaManager.php → MySQLSchemaManager.php, OracleSchemaManager.php, PostgreSQLSchemaManager.php, SQLServerSchemaManager.php (src/Schema/DB2SchemaManager.php)
- ClassTooLong: AbstractPlatform (src/Platforms/AbstractPlatform.php)
- ClassTooLong: AbstractSchemaManager (src/Schema/AbstractSchemaManager.php)
- ClassTooLong: Connection (src/Connection.php)
- ClassTooLong: OraclePlatform (src/Platforms/OraclePlatform.php)
- ClassTooLong: SQLServerPlatform (src/Platforms/SQLServerPlatform.php)
- ClassTooLong: SQLitePlatform (src/Platforms/SQLitePlatform.php)
- ClassTooLong: Table (src/Schema/Table.php)
- Comparator.compareSchemas (cognitive 31) (src/Schema/Comparator.php)
- Comparator.compareSchemas (cyclomatic 17) (src/Schema/Comparator.php)
- …and 364 more
Changes since last survey
- 12 commits — 9 feature/other, 3 fixes
By area
- (repo) — 4 commits
- (root) — 3 commits
- .github/workflows — 2 commits
- src/Types — 1 commit
- tests/Functional — 1 commit
- tests/Types — 1 commit
Notable commits
- fix: Fix TransactionTest for MySQL 9.7
- fix: Fix phantom schema diff for float columns with default values (#7501)
- fix: Merge pull request #7475 from fballiano/fix/mysql-index-fold-quoted-columns
- change: Add Oracle 18 back and document Oracle's weird versioning (#7497)
- change: Bump dev tools (#7500)
- change: CI: Use MySQL 9.7 (#7508)
- change: Don't pass JSON flags as depth (#7498)
- change: Merge branch '3.10.x' into 4.4.x
- change: Merge branch '3.10.x' into 4.4.x
- change: Merge branch '3.10.x' into 4.4.x
- change: phpunit/phpunit (11.5.50 => 11.5.56) (#7502)
- change: squizlabs/php_codesniffer (4.0.1 => 4.0.4) (#7495)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
doctrine/dbal was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 205fdf552ffafe33c1d12a41a2d6c7217666c32c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.