Skip to content
CAI
Software that uses CAICheck a score

symfony/dependency-injection

54.1

Adequate · 19 September 2026

22.5k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is the Symfony DependencyInjection component, a framework for managing service containers, autowiring, and configuration in PHP applications. It provides mechanisms for defining services via attributes, PHP DSL, and environment variables, while supporting modern features like lazy ghost objects and OPcache preloading. The component also handles container compilation, caching, and lifecycle management through a standalone kernel infrastructure.

How it got here

2010–2012 — DependencyInjection modernization and PHP 8.4 alignment

20 changes.

This period focused on modernizing the DependencyInjection component by removing legacy XML configuration support and refactoring loaders and compilers to leverage modern PHP features like type declarations and constructor property promotion. The work also introduced new capabilities such as OPcache preloading, environment variable placeholders, and comprehensive test coverage to ensure stability ahead of the PHP 8.4 requirement.

2013–2017 — PHP DSL and lazy proxy modernization

17 changes.

This period focused on introducing a fluent PHP-based DSL for configuring the service container and modernizing the lazy proxy infrastructure to leverage native PHP ghost objects. Significant work also involved restructuring argument classes for modern PHP features and expanding test coverage for the new configuration APIs and proxy mechanisms.

2018–2026 — Dependency Injection attributes and standalone kernel

18 changes.

This period focused on introducing comprehensive PHP attributes for service configuration and autowiring within the DependencyInjection component, alongside a new standalone Kernel infrastructure for building applications without the full HttpKernel stack. Extensive test coverage was added to validate these new features, including attribute behavior, kernel lifecycle management, and various edge cases in service discovery and autoconfiguration.

Features

Initial repository structure and service alias deprecation support

This change establishes the initial repository layout by adding .gitattributes and .gitignore files to exclude test and configuration artifacts from distribution archives. It also introduces the Alias class, which provides the core mechanism for managing service aliases within the dependency injection container, including the ability to mark aliases as deprecated with specific package and version context.

(repo-wide) · high confidence

Introduce Preloader for PHP OPcache preloading and modernize Dumper APIs

The Dumper component now includes a new Preloader class that enables PHP OPcache preloading by collecting classes, interfaces, and traits from the service container and their type declarations, while allowing specific classes or namespaces to be ignored. Additionally, the dumper base classes and interfaces have been modernized: the abstract Dumper class now uses constructor property promotion, the DumperInterface's dump method returns a typed string or array, and the PhpDumper now supports splitting the generated container into multiple files via the 'as\_files' option and includes options for namespace and hot-path tagging to optimize runtime performance.

Dumper · high confidence

Introduces PHP DSL configurator traits for service definitions

Adds a suite of new traits in the \Loader/Configurator/Traits\ directory to support the new PHP-based dependency injection configuration format. These traits provide fluent methods for defining service properties, including \abstract\, \args\/\arg\, \autoconfigure\, \autowire\, \bind\, \call\, \class\, \configurator\, \constructor\, \decorate\/\decorateTag\, \deprecate\, \factory\, \file\, \fromCallable\, \lazy\, \parent\, \property\, \public\/\private\, \share\, \synthetic\, and \tag\/\resourceTag\. This enables users to configure services using PHP code with type hints and IDE support instead of XML or YAML.

Loader/Configurator/Traits · high confidence

Introduces a PHP DSL for configuring the service container

Symfony now provides a fluent PHP-based configuration API for the DependencyInjection component, allowing services, parameters, aliases, and environment variables to be defined in PHP files instead of YAML or XML. This new Loader/Configurator layer introduces classes like ContainerConfigurator, ServicesConfigurator, and EnvConfigurator, along with helper functions such as service(), param(), and env(), enabling type-safe, IDE-friendly container definitions with features like environment-conditional configuration and inline service definitions.

Loader/Configurator · high confidence

Introduction of native lazy proxy dumping infrastructure

The LazyProxy/PhpDumper component now provides a new interface (DumperInterface) and implementation (LazyServiceDumper) to generate PHP code for lazy-loading service proxies. This change introduces support for native PHP lazy objects (ghost objects) as the default proxy mechanism, while retaining support for virtual proxies for non-ghostable services. It also includes a NullDumper for disabling proxy generation. This allows the dependency injection container to create more efficient, native lazy proxies for services marked as lazy, improving performance and reducing overhead compared to previous proxy implementations.

LazyProxy/PhpDumper · high confidence

New PHP attributes for service configuration and autowiring

This release introduces a comprehensive set of PHP attributes for the DependencyInjection component, allowing developers to configure services directly in code. New attributes include \\#\[AsAlias\]\ for service aliases, \\#\[AsDecorator\]\ and \\#\[AsTagDecorator\]\ for service decoration, and \\#\[Autoconfigure\]\ for defining autoconfiguration rules. Autowiring is enhanced with \\#\[Autowire\]\ for parameter injection, \\#\[AutowireCallable\]\ and \\#\[AutowireMethodOf\]\ for closures, \\#\[AutowireInline\]\ for inline service definitions, and \\#\[AutowireLocator\]\/\\#\[AutowireIterator\]\ for service collections. Environment-specific registration is handled by \\#\[When\]\ and \\#\[WhenNot\]\, while \\#\[Target\]\ aids named autowiring and \\#\[Lazy\]\ controls lazy loading.

Attribute · high confidence

New standalone Kernel and Bundle infrastructure for DI-powered applications

Symfony introduces a new \Symfony\\Component\\DependencyInjection\\Kernel\ namespace providing the foundational classes for building applications driven by the Dependency Injection component without requiring the full HttpKernel stack. This includes \AbstractKernel\ and \KernelTrait\ for managing the application lifecycle, container initialization, and caching, as well as \AbstractBundle\ and \BundleInterface\ to standardize how bundles register extensions and configuration. The \ServicesBundle\ automatically wires core infrastructure services (such as the event dispatcher, clock, and filesystem) and registers necessary compiler passes, while the \RequiredBundle\ attribute allows bundles to declare their dependencies for automatic registration.

Kernel · high confidence

ParameterBag now supports deprecation, non-empty validation, and environment variable placeholders

The ParameterBag component has been significantly enhanced to improve parameter management and debugging. It now supports marking parameters as deprecated via the new \deprecate()\ method and tracking them for reporting, as well as enforcing non-empty constraints on parameters that must have a value. Additionally, the introduction of \EnvPlaceholderParameterBag\ allows environment variables to be handled as placeholders during container compilation, preventing premature resolution and enabling better type safety. The \ContainerBag\ class was added to expose container parameters via the PSR-11 \ContainerInterface\, and the core \ParameterBag\ now rejects numeric parameter names and provides richer error messages with suggestions for similar parameter names when a lookup fails.

ParameterBag · high confidence

Removals

Removal of Resource classes from DependencyInjection

The \FileResource\ class and \ResourceInterface\ have been removed from the \Symfony\\Component\\DependencyInjection\\Resource\ namespace. This change eliminates the filesystem resource tracking implementation from this component, indicating that resource management logic has been relocated or refactored elsewhere.

Resource · high confidence

Architecture

Refactored dependency injection compiler with new base pass and tag management

The dependency injection compiler infrastructure has been refactored to introduce \AbstractRecursivePass\ as a shared base class for recursive service graph processing, replacing scattered logic in individual passes. This change includes the addition of \AddBehaviorDescribingTagsPass\ to allow bundles to extend the list of behavior-describing tags (such as 'proxy' and 'service\_locator') and \AliasDeprecatedPublicServicesPass\ to automatically create deprecated aliases for public services marked as private, improving the transition to private-by-default services. These compiler passes now leverage the new base class for consistent handling of definitions, arguments, and expressions.

Compiler · high confidence

Behavioural changes

Dependency Injection Argument classes restructured and modernized for Symfony 8.1

The Argument component has been refactored to support modern PHP features and new container capabilities. Key changes include the introduction of lazy service injection via LazyProxyArgument and LazyClosure, allowing services to be injected as proxies on a per-argument basis. Environment variable handling is improved with EnvClosureArgument, which keeps placeholders refreshable at runtime. Tagged service collections (TaggedIteratorArgument) now support automatic exclusion of the referencing service and deprecate the old default index/priority methods in favor of the \#\[AsTaggedItem\] attribute. Additionally, ServiceLocatorArgument is updated to generate optimized array-based locators, and all classes now use native PHP 8.1+ type declarations and constructor property promotion.

Argument · high confidence

Dependency Injection component introduces new exception classes and lazy message evaluation

The Dependency Injection component now includes a dedicated set of exception classes (such as ServiceNotFoundException, ParameterNotFoundException, and AutowiringFailedException) that implement the component's ExceptionInterface and PSR-11's NotFoundExceptionInterface. These exceptions provide more specific error messages, including suggestions for similar services or parameters, and support lazy evaluation of error messages to improve performance when Xdebug is enabled.

Exception · high confidence

DependencyInjection Loader component refactored and modernized

The Loader component has undergone a significant architectural overhaul. The legacy abstract Loader, DelegatingLoader, and their associated interfaces (LoaderInterface, LoaderResolver, LoaderResolverInterface) have been removed in favor of a modernized FileLoader that extends Symfony's Config component's FileLoader. This change introduces native PHP type declarations, constructor injection for the ContainerBuilder and FileLocator, and support for environment-specific loading via the $env parameter. New capabilities include recursive directory loading via the new DirectoryLoader, glob-based file loading via GlobFileLoader, and a shared ContentLoaderTrait to unify parsing logic across formats. Additionally, an UndefinedExtensionHandler has been added to provide better error messages and package suggestions when configuration keys are not recognized.

Loader · high confidence

Deprecation of EventDispatcherInterface autowiring alias and introduction of service resetter

The default service configuration now registers the \ServicesResetter\ to support resetting non-shared services, enabling better lifecycle management for stateful services. Additionally, the autowiring alias for \EventDispatcherInterface\ is deprecated in favor of the contract-based \ContractsEventDispatcherInterface\ and the new \ListenerIntrospectionInterface\, ensuring clearer type resolution and introspection capabilities for event listeners.

Kernel/Resources · high confidence

Invalidate routing cache when container parameters change

The configuration system now detects changes to container parameters and invalidates the routing cache accordingly. This is achieved by introducing a new \ContainerParametersResource\ that tracks parameter values and a corresponding \ContainerParametersResourceChecker\ that verifies freshness against the current container state, ensuring that cached routes remain consistent when underlying configuration values are modified.

Config · high confidence

New lazy proxy instantiator architecture with ghost object support

The LazyProxy component now introduces a dedicated Instantiator interface and two implementations: LazyServiceInstantiator, which automatically uses PHP 8.4's native lazy ghost objects when possible (falling back to virtual proxies otherwise), and RealServiceInstantiator, which bypasses proxying entirely to return the real service instance directly. This change provides a cleaner, more performant foundation for lazy-loading services by leveraging native language features where available, while still supporting older proxy mechanisms for non-ghostable services.

LazyProxy/Instantiator · high confidence

Removal of XML service configuration schema

The XML schema file for service definitions (services-1.0.xsd) has been removed from the project. This change eliminates support for validating and parsing service configurations defined in XML format, meaning users must now rely on other configuration formats such as YAML or PHP arrays for defining services and parameters.

Loader/schema/dic · high confidence

Simplified container extension configuration via new configurator-based API

The Extension component introduces a new, simplified way to define container extensions. A new \AbstractExtension\ base class and \ConfigurableExtensionInterface\ allow extensions to use \ContainerConfigurator\ objects for loading and prepending configuration, replacing the previous imperative approach. The \Extension\ class now provides a default \getAlias()\ implementation and a \processConfiguration()\ helper, while the \ExtensionInterface\ has been streamlined to remove XML namespace and XSD path methods, reflecting the deprecation of XML configuration support. This change shifts the extension model towards a more declarative, configuration-object-oriented style.

Extension · high confidence

Test coverage

Added Graphviz test fixtures for service container visualization; Added compiler pass unit tests for the DependencyInjection component; Added container fixture files for DependencyInjection tests; Added test coverage for DependencyInjection dumper components; Added test coverage for new DependencyInjection attribute classes; Added test fixture for late-aliased interface in instanceof autoconfiguration; Added test fixture for missing parent class in PSR-4 discovery; Added test fixture for the Exclude attribute; Added test fixtures for CheckTypeDeclarationsPass; Added test fixtures for DependencyInjection autowiring and type resolution; Added test fixtures for HotPath DI container scenarios; Added test fixtures for INI configuration parsing; Added test fixtures for PSR-4-discovered abstract types with \#\[Autoconfigure\]; Added test fixtures for Preload type handling; Added test fixtures for Prototype DI attributes; Added test fixtures for dumped container constructors and lazy service generation; Added test fixtures for extension configuration validation scenarios; Added test fixtures for prototype service discovery in nested directories; Added test fixtures for prototype tagged priority behavior; Added test fixtures for recursive directory loading; Added test fixtures for singly-implemented interface detection; Added test fixtures for static constructor prototype services; Added test fixtures for the \#\[AsAlias\] attribute; Added test fixtures for the PHP DependencyInjection DSL; Added tests for ContainerParametersResource and ContainerParametersResourceChecker; Added tests for DependencyInjection Loader Configurator components; Added tests for DependencyInjection exception classes; Added tests for LazyServiceInstantiator and RealServiceInstantiator; Added tests for new DependencyInjection Kernel infrastructure; Added tests for the LazyServiceDumper and NullDumper components; Added tests for the new DI extension configuration API; Added unit tests for Dependency Injection argument classes; Added unit tests for DependencyInjection loaders; Added unit tests for ParameterBag components; Added unit tests for the DependencyInjection component; Expanded test fixtures for DependencyInjection attributes and services.

Dependencies

Symfony DependencyInjection v8.1 initial release

The Symfony DependencyInjection component has been updated to version 8.1, introducing a new composer.json manifest that enforces a minimum PHP version of 8.4.1. This release aligns with the broader Symfony 8 ecosystem, requiring psr/container ^1.1\|^2.0 and symfony/var-exporter ^8.1, while dropping support for older PHP versions and Symfony components below 8.2 (specifically http-kernel).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 54.

Lenses

  • Code Health 74
  • Architecture 99
  • Maturity 48
  • Readiness 42
  • Security 88

Changes since last survey

  • 300 commits — 240 feature/other, 60 fixes

By area

  • (repo) — 161 commits
  • (root) — 31 commits
  • Tests/Fixtures — 21 commits
  • Loader/Configurator — 11 commits
  • Tests/Compiler — 10 commits
  • Compiler/AutowirePass.php — 6 commits
  • Dumper/PhpDumper.php — 6 commits
  • Kernel/KernelTrait.php — 4 commits
  • Argument/TaggedIteratorArgument.php — 2 commits
  • Compiler/AddBehaviorDescribingTagsPass.php — 2 commits
  • Compiler/CheckFactoryBuilderCircularReferencePass.php — 2 commits
  • Compiler/DecoratorServicePass.php — 2 commits
  • Compiler/PriorityTaggedServiceTrait.php — 2 commits
  • Compiler/ResolveInstanceofConditionalsPass.php — 2 commits
  • Tests/ContainerTest.php — 2 commits
  • Tests/Dumper — 2 commits
  • Tests/EnvVarProcessorTest.php — 2 commits
  • Tests/Kernel — 2 commits
  • Tests/LazyProxy — 2 commits
  • .github/PULL_REQUEST_TEMPLATE.md — 1 commit

Notable commits

  • fix: Backport some CS fixes from 7.4
  • fix: CS fix
  • fix: CS fixes
  • fix: CS fixes - native_function_invocation & static_lambda
  • fix: Fix handling of container.behavior_describing_tags
  • fix: Fix merge
  • fix: Fix tests with 8.1 deps
  • fix: More CS fixes
  • fix: [DependencyInjection] Fix #[AsTaggedItem] discovery through multi-level decoration chains
  • fix: [DependencyInjection] Fix ParameterBag::clear() leaving stale deprecations and resolution state
  • fix: [DependencyInjection] Fix PriorityTaggedServiceTrait not discovering #[AsTaggedItem] on decorated services
  • fix: [DependencyInjection] Fix TypeError when using a custom container base class with typed $parameterBag
  • fix: [DependencyInjection] Fix #[Autoconfigure] being processed twice for PSR-4-discovered abstract types
  • fix: [DependencyInjection] Fix service() as invokable factory in array-based PHP config
  • fix: [DependencyInjection] Fix alias chain inversion when deprecated alias points to decorated service
  • fix: [DependencyInjection] Fix autowiring nullable intersection types
  • fix: [DependencyInjection] Fix bundles cache freshness check
  • fix: [DependencyInjection] Fix circular references through expressions
  • fix: [DependencyInjection] Fix class-level tag attributes being overridden by interface-level ones
  • fix: [DependencyInjection] Fix compiling nested service locators
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

symfony/dependency-injection was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0e7dc53cc13aae42e7e8c736dee3474fb63b4932 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.