guzzle/promises
71.6
Strong · 26 September 2026
1.8k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a PHP library implementing asynchronous promise-based concurrency for handling multiple tasks without causing stack overflows. It provides utilities for managing promise states, aggregating exceptions, and executing iterative callbacks via a global task queue. The codebase includes comprehensive testing and strict static analysis to ensure reliability across supported PHP versions.
Behavioural changes
Guzzle Promises 3.0 release with breaking API changes
This release raises the minimum PHP version to 7.4 and introduces several breaking changes to the promise API. Collection helpers now strictly require iterable inputs, meaning single promises or scalars must be wrapped in an array before passing to functions like \Each::of()\ or \Utils::all()\. The \Utils::inspect()\ function now returns the actual rejection reason instead of unwrapping \RejectionException\ instances. Additionally, static helper classes like \Create\, \Each\, and \Utils\ are now non-instantiable, and native PHP serialization of runtime promise objects is rejected to prevent state corruption. Generic PHPDoc types have been added to improve static analysis, and \PromiseInterface::resolve()\ now accepts an optional value.
(repo-wide) · high confidence
Promise resolution is now asynchronous and iterative
The promise library has been refactored to avoid recursion and prevent stack overflows by executing all \then\ callbacks asynchronously via a global task queue (\Utils::queue\). This means that chaining handlers on \FulfilledPromise\ or \RejectedPromise\ no longer executes them immediately; instead, they are scheduled to run in the next task queue cycle. To support this, the \PromiseInterface\ has been updated with new constants (\PENDING\, \FULFILLED\, \REJECTED\), a new \otherwise\ method for rejection handling, and stricter type signatures. Additionally, new classes like \AggregateException\, \CancellationException\, \Coroutine\, and \Each\ have been introduced to provide higher-level abstractions for handling multiple promises, coroutines, and concurrent iteration.
src · high confidence
Test coverage
Comprehensive test suite for GuzzleHttp Promise library
Added a complete PHPUnit test suite covering the core promise components, including AggregateException, Coroutine, Create, EachPromise, Each, Is, NonSerializableTrait, PropertyHelper, RejectionException, TaskQueue, Utils, FulfilledPromise, and RejectedPromise. The tests verify promise states, resolution/rejection behaviors, concurrency limits, serialization restrictions, and utility functions, ensuring the library's reliability and correctness.
tests · high confidence
Dependencies
Updated PHP version requirements and static analysis tooling
The project now requires PHP 7.4 or 8.0, dropping support for older versions. Development dependencies have been updated to use PHPUnit 9.6.34 and the bamarni/composer-bin-plugin. Additionally, static analysis tooling has been configured via vendor-bin manifests, introducing specific versions for php-cs-fixer (3.95.2), phpstan (2.1.55), and composer-normalize (2.52.0).
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 48 → 72 (+23.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 99 (-0.9)
- Architecture 94 → 94 (+0.2)
- Maturity 59 → 53 (-6.2)
- Readiness 27 → 80 (+52.9)
- Security 59 → 100 (+41.2)
Resolved (16)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- No exposed public API
- No tests found
- Test reliability not included
- The README does not mention licensing or a For Enterprise section (the outline lists it but the visible text ends before mentioning enterprise support). (README.md)
New (22)
- Change coupling: FulfilledPromise.php ↔ RejectedPromise.php (src/FulfilledPromise.php)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (11 lines × 2) (src/Utils.php)
- Duplicated block (11–13 lines × 2) (src/FulfilledPromise.php)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: src/Promise.php (src/Promise.php)
- No assertions: testShouldCancelResultPromiseAndOutsideCurrentPromise (tests/CoroutineTest.php)
- No assertions: testShouldProxyPromiseMethodsToResultPromise (tests/CoroutineTest.php)
- No assertions: testShouldProxyResolveWithoutValueToResultPromiseAsNull (tests/CoroutineTest.php)
- No dependency advisory monitoring
- …and 2 more
Changes since last survey
- 3 commits — 3 feature/other, 0 fixes
By area
- (root) — 3 commits
Notable commits
- change: Add PHP 8.6 to the CI matrix and version guidance (#242)
- change: Document that getState() reflects settlement, not the eventual outcome (#240)
- change: Release 3.0.2
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
guzzle/promises was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 42118e66a53c492effaf92bc357e931985d5c6f9 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.