Skip to content
CAI
Software that uses CAICheck a score

doctrine/dbal

69.0

Adequate · 26 September 2026

40.4k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Doctrine Database Abstraction Layer (DBAL), a PHP library that provides a unified interface for interacting with various relational databases including MySQL, PostgreSQL, Oracle, SQL Server, SQLite, and IBM DB2. It manages database connections, executes SQL queries, and handles schema migrations through a modernized API that supports primary-replica routing, query building with CTEs and unions, and robust error handling. The library also includes tools for data type mapping, caching, and logging, ensuring type safety and compatibility with modern PHP versions.

How it got here

2007–2020 — PHP 8 modernization and API overhaul

64 changes.

This period focused on a comprehensive modernization of Doctrine DBAL to support PHP 8+, involving the complete rewrite of all database drivers to use native types, strict parameter binding, and modern exception handling. The library introduced a new QueryBuilder with CTE support, refactored the schema and cache layers for better type safety, and established a robust middleware architecture for portability and connection management.

2021–2023 — Driver modernization and middleware support

29 changes.

This period focused on modernizing the database driver layer by introducing native implementations for SQLite3 and PostgreSQL, alongside a new abstract middleware architecture for extensibility. It also enhanced core functionality with dedicated SQL builders for CTEs and unions, improved logging with sensitive data redaction, and refined type handling through specific exception classes and a new Money type.

2024–2025 — test coverage expansion

5 changes.

This period focused on expanding test coverage for the schema and driver components. New tests were added for schema name value objects, collection classes, and index validation logic. The work also included verifying compatibility with PHP 8.4 PDO subclasses and IPv6 URI support in the PgSQL driver.

Features

Add SQLSrv Error exception class

A new \Error\ exception class has been added to the SQLSrv driver to handle SQL Server errors. This class provides a static \new()\ method that retrieves error details (message, SQL state, and error code) from the \sqlsrv\_errors\ function and constructs an exception, ensuring users receive specific error information when a SQL Server operation fails.

src/Driver/SQLSrv/Exception · high confidence

Add StaticServerVersionProvider for explicit database version configuration

A new StaticServerVersionProvider class has been added to the Connection component, allowing users to explicitly define the database server version via a constructor argument. This provides a concrete implementation of the ServerVersionProvider interface, enabling deterministic version handling without relying on automatic detection or external configuration sources.

src/Connection · high confidence

Add logging middleware to capture database activity and redact sensitive connection data

A new logging middleware has been introduced that wraps the database driver, connection, and statement layers to provide visibility into database operations. Users can now log connection attempts (with passwords automatically redacted for security), SQL queries, statement executions with their bound parameters and types, and transaction lifecycle events (begin, commit, rollback). This allows for easier debugging and monitoring of database interactions without exposing sensitive credentials in log output.

src/Logging · high confidence

Initial repository structure and project metadata for Doctrine DBAL

This change establishes the foundational structure for the Doctrine DBAL repository. It introduces the \.doctrine-project.json\ configuration file, which defines the project's versioning strategy and lists supported branches (5.0, 4.5, 4.4, 3.10, etc.). It also adds essential project files including \README.md\ with build badges, \LICENSE\ (MIT), \SECURITY.md\ with reporting guidelines, \CONTRIBUTING.md\, and \UPGRADE.md\ documenting deprecations for versions 4.4 and 4.3. Additionally, it sets up development tooling configurations such as \.gitattributes\, \.gitignore\, \phpcs.xml.dist\ for code style, and \phpstan.neon.dist\ for static analysis.

(repo-wide) · high confidence

Introduce native PgSQL driver for PostgreSQL connections

Adds a new native PgSQL driver implementation (src/Driver/PgSQL) that replaces the previous PostgreSQL driver layer. This includes a new Connection class for managing the PgSql\\Connection resource, a Driver class that handles connection string construction (including IPv6 bracket notation and GSS encryption modes), a Statement class for prepared statement execution with boolean and resource parameter handling, and a Result class for fetching data. The driver also implements proper resource cleanup in destructors for connections, statements, and results, and provides a ConvertParameters visitor to map SQL parameters to PostgreSQL's positional format.

src/Driver/PgSQL · high confidence

Introduce native SQL parser for prepared statement parameters

A new SQL parser has been added to identify prepared statement parameters (both named and positional) within SQL strings. This component, located in src/SQL/Parser.php, implements parsing logic inspired by the PHP PDO parser to correctly handle string literals, comments, and special characters without confusing their contents with parameter placeholders. It supports both MySQL and ANSI SQL string escaping modes and includes error handling for regular expression failures.

src/SQL · high confidence

Introduce new SQLite3 driver implementation

This change introduces a new, standalone SQLite3 driver implementation within the Doctrine DBAL library. The new driver consists of dedicated classes for managing connections, executing statements, handling results, and managing exceptions, replacing or supplementing previous approaches. Key features include support for both file-based and in-memory databases, proper handling of parameter binding with type conversion, and the addition of a \getColumnName\ method to the Result interface for retrieving column names by index. The driver also enforces strict typing and uses modern PHP features like readonly properties and sensitive parameter attributes.

src/Driver/SQLite3 · high confidence

Introduction of new database mapping types and stricter JSON handling

This update adds several new database mapping types to the library, including \AsciiStringType\, \NumberType\ (mapping to \BcMath\\Number\), \SmallFloatType\, \EnumType\, and dedicated JSON types for PostgreSQL (\JsonbType\, \JsonbObjectType\) as well as standard JSON objects (\JsonObjectType\). It also introduces immutable variants for date and time types (\DateImmutableType\, \DateTimeImmutableType\, etc.) to provide safer, non-mutable date handling. Additionally, the JSON conversion logic has been updated to use \JSON\_THROW\_ON\_ERROR\ and \JSON\_PRESERVE\_ZERO\_FRACTION\, ensuring that JSON encoding and decoding errors are explicitly thrown as exceptions and that zero fractions in float values are preserved during serialization.

src/Types · high confidence

New PrimaryReadReplicaConnection for primary-replica database setups

A new \PrimaryReadReplicaConnection\ class is introduced to support primary-replica database configurations. This connection type automatically routes read operations to a randomly selected replica and write operations to the primary node. It enforces a strict separation where the primary is used for any state-changing operations (such as inserts, updates, deletes, or transactions) and remains active for subsequent operations once engaged. Users can manually switch connections using \ensureConnectedToPrimary()\ or \ensureConnectedToReplica()\. The class is instantiated via the \DriverManager\ by specifying \wrapperClass\ and providing separate \primary\ and \replica\ configuration arrays.

src/Connections · high confidence

New QueryBuilder implementation with CTE, UNION, and FOR UPDATE support

The QueryBuilder component has been replaced with a new implementation that introduces support for Common Table Expressions (CTE), UNION queries, and row locking (FOR UPDATE with SKIP\_LOCKED). Users can now build complex queries using dedicated classes like CommonTableExpression, Union, and ForUpdate, and benefit from stricter parameter handling and result caching.

src/Query · high confidence

New abstract middleware classes for driver components

Added abstract middleware classes (AbstractConnectionMiddleware, AbstractDriverMiddleware, AbstractResultMiddleware, AbstractStatementMiddleware) that provide default pass-through implementations for the Driver interface components. These classes allow users to extend specific middleware behaviors without having to implement every method of the underlying interfaces, simplifying the creation of custom driver middlewares.

src/Driver/Middleware · high confidence

New console command for executing arbitrary SQL

The \dbal:run-sql\ command is now available in the console tools, allowing users to execute arbitrary SQL statements directly from the command line. This new feature includes a \ConnectionProvider\ interface and a \SingleConnectionProvider\ implementation to manage database connections, enabling flexible integration with existing application setups.

src/Tools/Console · high confidence

New query expression builder components

The \src/Query/Expression\ directory now contains the \CompositeExpression\ and \ExpressionBuilder\ classes. \CompositeExpression\ provides an immutable way to group similar SQL expressions using AND or OR logic, supporting fluent construction via static factory methods and a \with()\ method for appending parts. \ExpressionBuilder\ offers a fluent API for dynamically creating SQL query parts, including comparison operators (equality, inequality, less/greater than), null checks, and logical conjunctions/disjunctions, relying on a \Connection\ instance for context.

src/Query/Expression · high confidence

SQLite driver now includes a dedicated exception converter

The SQLite driver now provides a concrete implementation of the exception conversion interface, mapping raw SQLite error messages to specific Doctrine DBAL exception types (such as UniqueConstraintViolationException, TableNotFoundException, and LockWaitTimeoutException). This allows applications to catch and handle database-specific errors more precisely rather than receiving generic driver exceptions.

src/Driver/API/SQLite · high confidence

Behavioural changes

Cache layer refactored to use PSR-6 and modern PHP types

The caching implementation in src/Cache has been updated to rely on PSR-6 (Psr\\Cache\\CacheItemPoolInterface) instead of the deprecated doctrine/cache library, with QueryCacheProfile now accepting PSR-6 pools for result caching. The new ArrayResult class implements the Driver\\Result interface, providing a modern, typed way to handle cached query results, including support for deserializing legacy data formats. Additionally, cache-related exceptions have been restructured into a dedicated namespace, and sensitive connection parameters like passwords are now excluded from cache key generation to improve security.

src/Cache · high confidence

Database platform abstraction layer restructured and modernized

The database platform implementation has been significantly refactored to improve type safety and maintainability. The base \AbstractPlatform\ class now requires an explicit \UnquotedIdentifierFolding\ configuration in its constructor, replacing the previous default behavior. Platform-specific logic for MySQL, DB2, and other databases has been organized into dedicated classes and metadata providers, with keyword lists marked as deprecated. New PHP 8.1 features, such as enums for \DateIntervalUnit\ and \LockMode\, are utilized to replace magic constants, and internal methods are strictly marked to prevent external usage.

src/Platforms · high confidence

Deprecation of 'service' connection parameter in Oracle Easy Connect string generation

The new EasyConnectString class in the AbstractOracleDriver now triggers a deprecation warning when the 'service' connection parameter is used, instructing users to switch to the 'servicename' parameter instead. This change ensures that Oracle database connections using the deprecated 'service' key are flagged for migration, while the underlying logic for constructing the Easy Connect string remains functional.

src/Driver/AbstractOracleDriver · high confidence

Exception hierarchy restructured with new base classes and specific error types

The exception system in src/Exception has been reorganized to provide a clearer hierarchy and more specific error handling. A new DriverException base class now chains the underlying driver exception and stores the executed SQL query, accessible via getQuery(). Connection-related errors now extend a new ConnectionException, while server errors extend ServerException. Several new specific exception classes have been added, including CommitFailedRollbackOnly, ConnectionLost, DatabaseRequired, DriverRequired, InvalidColumnDeclaration, InvalidColumnIndex, InvalidColumnType, InvalidDriverClass, InvalidWrapperClass, MalformedDsnException, NoActiveTransaction, NoKeyValue, ParseError, ReadOnlyException, SavepointsNotSupported, TransactionRolledBack, and UnknownDriver. The RetryableException marker interface has been introduced for exceptions that warrant transaction retries. This change improves the granularity of error reporting and makes it easier for users to catch and handle specific database-related issues.

src/Exception · high confidence

IBM DB2 driver now provides specific exception types for database errors

The IBM DB2 driver now includes a dedicated exception converter that maps specific DB2 error codes (such as -104 for syntax errors, -204 for missing tables, and -803 for unique constraint violations) to precise Doctrine exception classes. This allows applications to catch and handle database-specific issues like foreign key violations or connection failures with greater granularity, rather than receiving generic driver exceptions.

src/Driver/API/IBMDB2 · high confidence

IBM DB2 driver rewritten for PHP 8.1+ with modernized API and improved error handling

The IBM DB2 driver has been completely rewritten to target PHP 8.1+, introducing strict typing, readonly properties, and native return types across all components. The connection API now accepts a native resource directly and exposes it via \getNativeConnection()\, while \lastInsertId()\ no longer accepts a name argument and throws \NoIdentityValue\ if no identity is available. Statement parameter binding now requires explicit \ParameterType\ enums, and LOB (BLOB) handling has been refined to bind only non-NULL values correctly. The driver also introduces a new \Result::getColumnName()\ method, flags sensitive parameters with \\#\[SensitiveParameter\]\, and implements basic exception handling for connection, preparation, and statement errors.

src/Driver/IBMDB2 · high confidence

Improved error messages for invalid column type declarations

The library now provides more specific and descriptive exception classes for common column definition errors. When a column type requires a length, precision, scale, or specific values but these are omitted, users will now receive targeted error messages (e.g., 'MySQL requires the length of a varchar column to be specified') instead of generic exceptions, making it easier to identify and fix schema definition issues.

src/Exception/InvalidColumnType · high confidence

Introduce specific exception classes for Type conversion errors

The \src/Types/Exception\ directory now contains a dedicated set of exception classes (such as \InvalidFormat\, \InvalidType\, \SerializationFailed\, \TypeAlreadyRegistered\, \TypeNotFound\, \ValueNotConvertible\, and others) that implement the new \TypesException\ interface. These classes replace generic error handling with specific, typed exceptions for type registration and conversion failures, providing clearer error messages and allowing users to catch specific type-related issues.

src/Types/Exception · high confidence

Introduce structured exception handling for the IBM DB2 driver

The IBM DB2 driver now provides specific, dedicated exception classes (such as ConnectionError, ConnectionFailed, PrepareFailed, StatementError, CannotCreateTemporaryFile, and CannotCopyStreamToStream) that extend the base AbstractException. These classes replace generic error handling by extracting detailed DB2-specific error messages and SQL states via native functions (e.g., db2\_conn\_errormsg, db2\_stmt\_error) and using a Factory to parse SQL codes from error strings, resulting in more precise error reporting for connection, statement, and file-operation failures.

src/Driver/IBMDB2/Exception · high confidence

Introduction of SQL Parser exception hierarchy and visitor interface

The SQL parser now includes a dedicated exception interface and a specific RegularExpressionError class to handle PCRE failures, ensuring that regex-related parsing issues are caught and reported with standard error messages. Additionally, a new Visitor interface has been added to the parser, defining methods for accepting positional parameters, named parameters, and other SQL fragments, which establishes the contract for components that process parsed SQL structures.

src/SQL/Parser · high confidence

Introduction of native PHP enums and modernized parameter handling

The library now uses native PHP enums for configuration and type constants, replacing previous integer or string-based approaches. This includes new enums for ArrayParameterType (INTEGER, STRING, ASCII, BINARY), ColumnCase (UPPER, LOWER), LockMode (NONE, OPTIMISTIC, PESSIMISTIC\_READ, PESSIMISTIC\_WRITE), ParameterType (NULL, INTEGER, STRING, LARGE\_OBJECT, BOOLEAN, BINARY, ASCII), and TransactionIsolationLevel (READ\_UNCOMMITTED, READ\_COMMITTED, REPEATABLE\_READ, SERIALIZABLE). Additionally, the API introduces explicit fetch methods on the Result class (such as fetchNumeric, fetchAssociative, and fetchAllKeyValue) to replace legacy fetch modes, and adds a new ArrayParameterType enum to handle array expansion in SQL queries.

src · high confidence

MySQL driver now converts specific error codes into typed exceptions

The MySQL driver now maps specific MySQL error codes to distinct, typed exceptions (such as ConnectionLost, DatabaseDoesNotExist, and various constraint violations) instead of returning a generic DriverException. This allows applications to handle database errors more precisely, for example by catching ConnectionLost specifically for error code 4031 or handling unknown user/authentication issues in MySQL 8.4 via a dedicated workaround.

src/Driver/API/MySQL · high confidence

New PDO-based SQL Server driver implementation

The SQL Server driver has been replaced with a new implementation built on top of PHP's PDO extension. This change introduces new \Connection\, \Driver\, and \Statement\ classes that wrap native PDO objects, providing a modernized foundation for database interactions. The new driver enforces stricter typing by requiring explicit parameter types for \bindValue()\ and handles SQL Server-specific encoding options (binary and ASCII) internally within the statement layer.

src/Driver/PDO/SQLSrv · high confidence

New PDO-based SQLite driver with strict parameter validation

The SQLite connection logic has been replaced by a new \Driver\ class that leverages the generic PDO infrastructure. This change introduces strict validation for connection parameters, throwing an \InvalidConfiguration\ exception if the \user\ or \password\ values are not strings or null. Additionally, the \user\ and \password\ parameters are now flagged as sensitive to prevent accidental logging or exposure.

src/Driver/PDO/SQLite · high confidence

New SQL builders for schema operations, unions, and CTEs

The SQL generation logic in src/SQL/Builder has been restructured with new dedicated builders: CreateSchemaObjectsSQLBuilder and DropSchemaObjectsSQLBuilder now handle schema object creation and dropping (with sequences dropped before tables in the latter), DefaultUnionSQLBuilder adds support for UNION clauses, and WithSQLBuilder enables Common Table Expression (CTE) support in SELECT queries. Additionally, DefaultSelectSQLBuilder now supports SKIP LOCKED for row locking scenarios.

src/SQL/Builder · high confidence

New standalone DSN parser with improved path normalization and sensitive parameter handling

A new standalone DsnParser class has been introduced in src/Tools to handle database connection URL parsing. This change modifies how connection parameters are derived from DSN strings: it now correctly handles SQLite URLs with triple slashes by injecting a localhost host, and it only trims the leading slash from the database path if a host is present, preventing accidental removal of leading slashes from pure database names. Additionally, the parser now supports mapping DSN schemes to specific driver classes via a configurable scheme mapping, and it marks the password parameter as sensitive to prevent accidental logging or exposure.

src/Tools · high confidence

OCI driver now converts Oracle error codes into specific Doctrine exception types

The OCI driver now maps specific Oracle error codes (such as ORA-00001, ORA-00942, ORA-02091, etc.) to precise Doctrine exception classes like UniqueConstraintViolationException, TableNotFoundException, and TransactionRolledBack. This allows applications to catch and handle database errors with greater granularity instead of receiving generic DriverException instances.

src/Driver/API/OCI · high confidence

OCI8 driver introduces specific exception classes for connection and query errors

The OCI8 driver now includes dedicated exception classes—ConnectionFailed, Error, InvalidConfiguration, NonTerminatedStringLiteral, and UnknownParameterIndex—to provide more granular error handling. These changes allow users to catch specific OCI8-related issues, such as connection failures, invalid configurations (e.g., mutually exclusive persistent and exclusive options), and SQL statement errors like non-terminated string literals or unknown parameter indices, rather than relying on generic exceptions.

src/Driver/OCI8/Exception · high confidence

OCI8 driver now initializes session NLS settings and flags credentials as sensitive

The OCI8 driver now includes a new InitializeSession middleware that automatically configures Oracle session parameters (NLS\_DATE\_FORMAT, NLS\_TIME\_FORMAT, NLS\_TIMESTAMP\_FORMAT, NLS\_TIMESTAMP\_TZ\_FORMAT, and NLS\_NUMERIC\_CHARACTERS) upon connection, ensuring consistent date/time/numeric formatting for users. Additionally, the connection parameters array is now marked with \#\[SensitiveParameter\] to prevent accidental logging or exposure of sensitive credentials in stack traces or debug output.

src/Driver/OCI8/Middleware · high confidence

OCI8 driver rewritten for PHP 8+ with exclusive connections and named placeholders

The OCI8 driver has been completely rewritten to target PHP 8.0+, introducing support for establishing exclusive database connections via a new 'exclusive' driver option, and automatically converting positional query parameters into named placeholders to accommodate Oracle's limitations. The driver now returns row counts as numeric strings to safely handle values exceeding PHP\_INT\_MAX, enforces strict parameter type requirements for binding, and exposes the native OCI8 connection resource through a new getNativeConnection() method.

src/Driver/OCI8 · high confidence

Portability layer restructured as a middleware

The portability functionality has been refactored from a direct connection wrapper into a middleware architecture. This change introduces a new \Middleware\ class that wraps the database driver, allowing portability features (such as trimming empty strings, converting column cases, and handling nulls) to be applied via the driver stack rather than replacing the connection object directly. The implementation now uses dedicated middleware classes for the connection, statement, and result objects to intercept and transform data, providing a more modular and extensible approach to database portability.

src/Portability · high confidence

PostgreSQL driver now uses native PHP 8.4+ PDO subclasses and supports GSS encryption mode

The PostgreSQL PDO driver has been refactored to leverage the new native PDO subclasses introduced in PHP 8.4 (specifically \Pdo\\Pgsql\), falling back to the standard \PDO\ class for older PHP versions. This change improves type safety and aligns with modern PHP standards. Additionally, the driver now explicitly supports the \gssencmode\ connection parameter, allowing users to configure GSSAPI encryption modes for their PostgreSQL connections. The driver also enforces stricter validation on user and password parameters, ensuring they are strings or null, and flags sensitive parameters in the connection signature to prevent accidental logging.

src/Driver/PDO/PgSQL · high confidence

PostgreSQL exception handling now includes query context and improved connection loss detection

The PostgreSQL driver's exception converter has been refactored to implement the standard ExceptionConverter interface, ensuring that all converted exceptions now carry the original SQL query for better debugging. Additionally, the logic for detecting lost connections has been extended to recognize specific PostgreSQL error messages ('terminating connection' and 'server closed the connection'), providing more accurate ConnectionLost exceptions when the database server disconnects.

src/Driver/API/PostgreSQL · high confidence

Refactored DBAL driver interfaces and abstract base classes

The driver layer has been restructured to modernize the API and improve type safety. New abstract base classes (AbstractMySQLDriver, AbstractPostgreSQLDriver, etc.) now handle platform instantiation and version detection, with deprecation warnings triggered for older database versions (e.g., MySQL \< 8, MariaDB \< 10.6, PostgreSQL \< 12). The driver interfaces have been updated: Connection now exposes getNativeConnection() and returns int\|string for exec() and lastInsertId(); Statement requires explicit ParameterType for bindValue() and returns a new Result interface; Result replaces Statement for fetching data and includes getColumnName(). A new Middleware interface allows wrapping drivers, and FetchUtils provides helper methods for common fetch patterns.

src/Driver · high confidence

Refactored MySQLi driver exception classes to support PHP 8.1+ error handling

The MySQLi driver's exception classes (ConnectionError, ConnectionFailed, StatementError, InvalidCharset) have been updated to include an upcast method that converts native mysqli\_sql\_exception instances into the library's own exception hierarchy. This change ensures that connection and statement errors are handled consistently on PHP 8.1+, where MySQLi throws exceptions by default, while preserving the original exception as a previous instance for debugging. Additionally, new specific exception classes (FailedReadingStreamOffset, HostRequired, InvalidOption, NonStreamResourceUsedAsLargeObject) have been introduced to provide clearer error messages for parameter validation and configuration issues.

src/Driver/Mysqli/Exception · high confidence

Refactored MySQLi driver with new connection initializers and improved error handling

The MySQLi driver implementation has been rewritten to use a modular initializer pattern for connection setup (handling charset, options, and SSL securely) and to adopt PHP 8.1 features like readonly properties and native types. Error handling is now more robust, catching \mysqli\_sql\_exception\ and converting it to driver-specific exceptions, while \lastInsertId()\ now throws an exception if no identity value exists. The driver also returns row counts as strings for values exceeding \PHP\_INT\_MAX\ and exposes the native connection via \getNativeConnection()\.

src/Driver/Mysqli · high confidence

Refactored PDO driver with new connection and statement classes

The PDO driver implementation has been rewritten using modern PHP syntax and stricter typing. The Connection class now accepts a PDO instance directly and exposes a getNativeConnection() method, while the Statement class enforces explicit ParameterType arguments for binding values. Additionally, the driver now leverages PHP 8.4's PDO::connect() method when available and handles specific PDO error states for identity columns and lost connections more robustly.

src/Driver/PDO · high confidence

SQL Server driver now uses a dedicated exception converter

The SQL Server driver now includes a specific exception converter that maps native SQL Server error codes to precise Doctrine DBAL exception types. This allows applications to catch specific database errors, such as syntax errors, missing tables, or constraint violations, rather than receiving generic driver exceptions.

src/Driver/API/SQLSrv · high confidence

SQLSrv driver rewritten for PHP 8+ with stricter parameter binding and native connection support

The SQLSrv driver has been completely rewritten to target PHP 8.0+, introducing several behavioral changes for users. The \Connection\ class now requires a native SQLSRV resource in its constructor and exposes a new \getNativeConnection()\ method to retrieve it. Parameter binding in \Statement\ is stricter: \bindValue()\ and \bindParam()\ now require an explicit \ParameterType\ argument, and passing parameters directly to \Statement::execute()\ is no longer supported. Additionally, \lastInsertId()\ no longer accepts a name argument and will throw a \NoIdentityValue\ exception if no identity value is available, while \rowCount()\ may return a string for values exceeding \PHP\_INT\_MAX\ to prevent overflow.

src/Driver/SQLSrv · high confidence

Schema API overhaul with new editors and deprecation of legacy introspection methods

The schema management API has been significantly refactored to improve type safety and maintainability. Legacy introspection methods such as \listTableDetails\, \listTableColumns\, and \listTableIndexes\ are now deprecated in favor of new \introspect\*\ methods. Object naming is now handled via dedicated value objects in the \Name\ namespace, replacing the previous string-based approach. Additionally, a new set of editor classes (e.g., \ColumnEditor\, \TableEditor\, \ForeignKeyConstraintEditor\) has been introduced to facilitate schema modifications, while the old \TableDiff\-centric mutation patterns are being phased out. The \Comparator\ class now uses a \ComparatorConfig\ to control behavior, and internal properties of classes like \TableDiff\ and \SchemaDiff\ have been marked as private or internal to enforce the new API boundaries.

src/Schema · high confidence

Strict validation of user and password parameters in PDO drivers

The MySQL and OCI PDO drivers now enforce that the 'user' and 'password' connection parameters are strictly strings or null. If a non-string value is provided, the driver throws an InvalidConfiguration exception instead of attempting to connect, preventing potential issues with type coercion. This change also introduces a new InvalidConfiguration exception class to handle these specific configuration errors.

src/Driver/PDO/MySQL · high confidence

Test coverage

Added SQL Server comparator tests; Added SQLite-specific schema comparator tests; Added comprehensive test suite for QueryBuilder; Added comprehensive unit tests for DBAL Type classes; Added functional test for LockMode::NONE behavior; Added functional test for Oracle binary column comparison; Added functional test for the PDO SQLite driver; Added functional tests for DBAL types; Added functional tests for MySQL schema comparator behavior; Added functional tests for MySQLi and SQLSrv drivers; Added functional tests for PDO MySQL and OCI drivers; Added functional tests for PostgreSQL driver capabilities; Added functional tests for PostgreSQL schema comparison and sequence handling; Added functional tests for QueryBuilder UNION and FOR UPDATE capabilities; Added functional tests for SQL parsing edge cases; Added functional tests for SQLite3 driver connection parameter validation; Added functional tests for circular foreign key schema creation and dropping; Added functional tests for connection error handling and data fetching; Added functional tests for core database operations; Added functional tests for platform-specific schema and expression behaviors; Added functional tests for the IBM Db2 driver; Added functional tests for the PgSQL driver; Added functional tests for transaction rollback/commit and SQLite unsigned integer introspection; Added platform-specific column test cases; Added static analysis regression tests for DBAL schema management and connection handling; Added test coverage for OCI8 and SQLSrv driver components; Added test coverage for the Portability layer components; Added test for IPv6 URI support in PgSQL driver; Added test for Mysqli persistent connection validation; Added test for non-positive indexed column length validation; Added tests for ArrayResult serialization and QueryCacheProfile key generation; Added tests for CachingCollationMetadataProvider; Added tests for MySQL and MariaDB schema comparators; Added tests for MySQL schema comparison and table alteration; Added tests for Oracle EasyConnectString generation and deprecation handling; Added tests for PHP 8.4+ PDO subclasses; Added tests for Query Expression components; Added tests for Schema Name value objects; Added tests for abstract driver middleware classes; Added tests for driver platform instantiation and version handling; Added tests for query caching and array parameter expansion; Added tests for schema object collection classes; Added tests for the Money schema type; Added tests for the RunSqlCommand console command; Added tests for the logging middleware; Added tests for the new Schema API and deprecation warnings; Added tests for the standalone DSN parser; Added unit and driver tests for PDO drivers; Added unit and functional tests for DBAL core components; Added unit tests for the SQL parser; Expanded functional test coverage for schema introspection and table alteration; Migrated platform tests to PHPUnit 10 attributes and new schema editors.

Dependencies

Initial composer.json setup for DBAL and docs

The project now includes a root composer.json defining the Doctrine DBAL library with a PHP 8.2 requirement and dependencies on doctrine/deprecations, psr/cache, and psr/log. Development tools are pinned to specific versions, including PHPStan 2.1.30, PHPUnit 11.5.56, and Doctrine Coding Standard 14.0.0. A separate composer.json for the documentation directory requires the doctrine/docs-builder package.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 50 → 69 (+18.7)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 94 → 90 (-4.1)
  • Architecture 96 → 99 (+3.3)
  • Maturity 64 → 62 (-1.6)
  • Readiness 35 → 76 (+40.8)
  • Security 50 → 66 (+16.0)

Resolved (59)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (10 lines × 2) (src/Connection.php)
  • Duplicated block (10 lines × 2) (src/Driver/PDO/PgSQL/Driver.php)
  • Duplicated block (16 lines × 2) (src/Platforms/SQLitePlatform.php)
  • Duplicated block (31 lines × 12) (src/Platforms/Keywords/DB2Keywords.php)
  • Duplicated block (31 lines × 3) (src/Platforms/Keywords/OracleKeywords.php)
  • Duplicated block (31 lines × 3) (src/Platforms/Keywords/PostgreSQLKeywords.php)
  • Duplicated block (31 lines × 3) (src/Platforms/Keywords/SQLiteKeywords.php)
  • Duplicated block (31 lines × 5) (src/Platforms/Keywords/SQLServerKeywords.php)
  • Duplicated block (31 lines × 7) (src/Platforms/Keywords/MariaDBKeywords.php)
  • Duplicated block (31 lines × 7) (src/Platforms/Keywords/MySQLKeywords.php)
  • Duplicated block (8 lines × 2) (src/Platforms/SQLServerPlatform.php)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 39 more

New (384)

  • AbstractAsset._setName (cognitive 19) (src/Schema/AbstractAsset.php)
  • AbstractAsset._setName (cyclomatic 18) (src/Schema/AbstractAsset.php)
  • AbstractPlatform.buildCreateTableSQL (cognitive 17) (src/Platforms/AbstractPlatform.php)
  • AbstractPlatform.getDefaultValueDeclarationSQL (cognitive 16) (src/Platforms/AbstractPlatform.php)
  • AbstractPlatform.getDefaultValueDeclarationSQL (cyclomatic 16) (src/Platforms/AbstractPlatform.php)
  • Change coupling clique: DB2Platform.php, OraclePlatform.php, PostgreSQLPlatform.php, SQLServerPlatform.php (src/Platforms/DB2Platform.php)
  • Change coupling: AbstractPlatform.php ↔ MySQLPlatform.php (src/Platforms/AbstractPlatform.php)
  • Change coupling: Index.php ↔ UniqueConstraint.php (src/Schema/Index.php)
  • Change coupling: OracleSchemaManager.php ↔ PostgreSQLSchemaManager.php (src/Schema/OracleSchemaManager.php)
  • Change coupling: PostgreSQLSchemaManager.php ↔ SQLServerSchemaManager.php (src/Schema/PostgreSQLSchemaManager.php)
  • Change-coupling hub: DB2SchemaManager.php → MySQLSchemaManager.php, OracleSchemaManager.php, PostgreSQLSchemaManager.php, SQLServerSchemaManager.php (src/Schema/DB2SchemaManager.php)
  • ClassTooLong: AbstractPlatform (src/Platforms/AbstractPlatform.php)
  • ClassTooLong: AbstractSchemaManager (src/Schema/AbstractSchemaManager.php)
  • ClassTooLong: Connection (src/Connection.php)
  • ClassTooLong: OraclePlatform (src/Platforms/OraclePlatform.php)
  • ClassTooLong: SQLServerPlatform (src/Platforms/SQLServerPlatform.php)
  • ClassTooLong: SQLitePlatform (src/Platforms/SQLitePlatform.php)
  • ClassTooLong: Table (src/Schema/Table.php)
  • Comparator.compareSchemas (cognitive 31) (src/Schema/Comparator.php)
  • Comparator.compareSchemas (cyclomatic 17) (src/Schema/Comparator.php)
  • …and 364 more

Changes since last survey

  • 12 commits — 9 feature/other, 3 fixes

By area

  • (repo) — 4 commits
  • (root) — 3 commits
  • .github/workflows — 2 commits
  • src/Types — 1 commit
  • tests/Functional — 1 commit
  • tests/Types — 1 commit

Notable commits

  • fix: Fix TransactionTest for MySQL 9.7
  • fix: Fix phantom schema diff for float columns with default values (#7501)
  • fix: Merge pull request #7475 from fballiano/fix/mysql-index-fold-quoted-columns
  • change: Add Oracle 18 back and document Oracle's weird versioning (#7497)
  • change: Bump dev tools (#7500)
  • change: CI: Use MySQL 9.7 (#7508)
  • change: Don't pass JSON flags as depth (#7498)
  • change: Merge branch '3.10.x' into 4.4.x
  • change: Merge branch '3.10.x' into 4.4.x
  • change: Merge branch '3.10.x' into 4.4.x
  • change: phpunit/phpunit (11.5.50 => 11.5.56) (#7502)
  • change: squizlabs/php_codesniffer (4.0.1 => 4.0.4) (#7495)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

doctrine/dbal was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 205fdf552ffafe33c1d12a41a2d6c7217666c32c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.