doctrine/lexer
63.7
Adequate · 26 September 2026
336
lines of production code
PHP
primary language
4
measurements over time
What this system is
Features
Added project metadata, upgrade guide, and developer tooling configuration
The project now includes a \.doctrine-project.json\ file that defines the versioning and maintenance status for each release branch (3.1, 3.0, 2.1, 2.0, 1.2, 1.1, 1.0). A new \UPGRADE.md\ file documents breaking changes for versions 2.0 and 3.0, specifically noting that \Token\ no longer implements \ArrayAccess\ and that parameter type declarations have been added to \AbstractLexer\ and \Token\. Additionally, configuration files for PHP\_CodeSniffer (\phpcs.xml.dist\), PHPStan (\phpstan.neon.dist\), and PHPUnit (\phpunit.xml.dist\) have been added to standardize code quality and testing workflows.
(repo-wide) · high confidence
Introduced new Lexer and Token classes for tokenization
Added the new \AbstractLexer\ and \Token\ classes in the \src\ directory, establishing the core infrastructure for lexical analysis. The \Token\ class now supports \float\ and \bool\ value types alongside strings and integers, and the lexer provides methods to manage token streams, reset positions, and check token types.
src · high confidence
Removals
Removal of the legacy AbstractLexer base class
The \AbstractLexer\ class in \lib/Doctrine/Common/Lexer/AbstractLexer.php\ has been removed. This change eliminates the legacy array-based token representation in favor of a stricter, object-oriented token model, which may require updates to any custom lexer implementations that previously extended this base class.
lib/Doctrine · high confidence
Test coverage
Added lexer test suite and supporting test utilities
Added a new test suite for the lexer component, including AbstractLexerTest, TokenTest, and supporting test fixtures (ConcreteLexer, EnumLexer, MutableLexer) and a TokenType enum to facilitate testing of the AbstractLexer implementation.
tests · high confidence
Dependencies
Dropped support for PHP versions below 8.1 and updated dev dependencies
The package now requires PHP 8.1 or higher, dropping support for older PHP versions. Development dependencies have been updated to use PHPUnit 10.5.58 or 12.5.4, PHPStan 2, and Doctrine Coding Standard 14. The project has also migrated its autoloading from PSR-0 to PSR-4, moving the main source code to the 'src' directory and tests to 'tests'.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 49 → 64 (+14.9)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 52 → 52 (+0.0)
- Readiness 32 → 73 (+40.3)
- Security 71 → 77 (+6.3)
Resolved (7)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- No artifact signing
- No exposed public API
- No tests found
- Test reliability not included
- The README links to an architecture/design doc but does not mention the DQL-lexer example in its own body, so a reader might infer the library serves both purposes without seeing it. (docs/en/simple-parser-example.rst)
New (8)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Naming collision and semantic ambiguity: isA is used on both the Lexer (to check if a value matches a token type) and the Token object (to check if the token matches a type). While the signatures differ, the name isA is non-standard and confusingly similar to isNextToken/isNextTokenAny on the Lexer. It suggests a type-checking operation but is overloaded with different contexts.
- Workflow token permissions not restricted
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
doctrine/lexer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e96fe45e92a54233726014a7cc7340abf29bb14c — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.