Skip to content
CAI
Software that uses CAICheck a score

symfony/process

56.0

Adequate · 26 September 2026

3k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Symfony Process component, a library for executing external system commands and managing background processes. It provides core capabilities for synchronous and asynchronous execution via the Messenger component, including support for PHP subprocesses and signal handling. The implementation has been modernized to require PHP 8.4.1+ and features a refactored exception hierarchy for improved error handling and debugging.

Features

Add Messenger integration for running background processes

The Messenger component now includes support for executing system processes asynchronously via the new \RunProcessMessage\, \RunProcessMessageHandler\, and \RunProcessContext\ classes. Users can dispatch a \RunProcessMessage\ (constructed with a command array or via \fromShellCommandline\) to queue a process execution; the handler runs the process and returns a \RunProcessContext\ containing the exit code, output, and error output, or throws a \RunProcessFailedException\ if the process fails.

Messenger · high confidence

Added Process Bundle configuration for messenger integration

The Resources/config/process.php file has been added to register the RunProcessMessageHandler service within the dependency injection container. This configuration automatically tags the handler with 'messenger.message\_handler', enabling the Symfony Process component to integrate with the Messenger component for asynchronous process execution.

Resources · high confidence

Symfony Process component v8.2 release

This release introduces the ProcessBundle for easier integration, adds the PhpSubprocess class to run PHP commands while preserving the parent's php.ini settings, and provides the RunProcessMessage and RunProcessMessageHandler for asynchronous process execution via the Messenger component. It also adds the fromShellCommandline factory method to RunProcessMessage, the setIgnoredSignals method to the Process class to disable signal propagation, and the getStartTime method to retrieve the process start time.

(repo-wide) · high confidence

Behavioural changes

Process component exceptions now implement Throwable and expose process details

The Process component's exception hierarchy has been refactored so that all exceptions (including ProcessFailedException, ProcessSignaledException, ProcessStartFailedException, ProcessTimedOutException, and RunProcessFailedException) implement the new ExceptionInterface which extends PHP's native Throwable. This allows catching all process-related errors with a single try-catch block. Additionally, ProcessFailedException now includes the working directory, exit code, and output/error streams in its message, and all exception classes provide a getProcess() method to access the underlying Process instance for further inspection.

Exception · high confidence

Refactored Process Pipes to use modern PHP types and constructor property promotion

The Pipes component has been updated to use modern PHP 8.1+ features, including constructor property promotion, native type declarations, and union types. This refactoring improves code clarity and maintainability for the internal pipe implementations (AbstractPipes, UnixPipes, WindowsPipes) without changing the external behavior of process execution.

Pipes · high confidence

Test coverage

Added test coverage for Symfony Process component; Added tests for RunProcessMessageHandler.

Dependencies

Symfony Process component requires PHP 8.4.1+

The Symfony Process component now requires PHP 8.4.1 or higher. This update also aligns development dependencies with Symfony 7.4 and 8.1, and enforces a conflict with Symfony Dependency Injection versions prior to 8.1 to ensure compatibility.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 47 → 56 (+9.2)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 97 → 91 (-5.9)
  • Architecture 94 → 96 (+1.7)
  • Maturity 43 → 43 (-0.4)
  • Readiness 24 → 43 (+18.6)
  • Security 88 → 95 (+7.1)

Resolved (9)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (6 lines × 2) (Tests/ProcessFailedExceptionTest.php)
  • High: security finding (details withheld)
  • No exposed public API
  • No tests found
  • No usage example showing how to instantiate or call Process::execute(). (README.md)
  • Only one sponsor link; the README's own backer is not claimed. (README.md)
  • Test reliability not included

New (49)

  • AbstractPipes.write (cognitive 57) (Pipes/AbstractPipes.php)
  • AbstractPipes.write (cyclomatic 27) (Pipes/AbstractPipes.php)
  • Change coupling: UnixPipes.php ↔ WindowsPipes.php (Pipes/UnixPipes.php)
  • ClassTooLong: Process (Process.php)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • ExecutableFinder.find (cognitive 32) (ExecutableFinder.php)
  • ExecutableFinder.find (cyclomatic 24) (ExecutableFinder.php)
  • FileTooLong: ./Process.php (Process.php)
  • Hotspot: Process.php (Process.php)
  • No assertions: testOptionCreateNewConsole (Tests/CreateNewConsoleTest.php)
  • PhpExecutableFinder.find (cognitive 23) (PhpExecutableFinder.php)
  • PhpExecutableFinder.find (cyclomatic 20) (PhpExecutableFinder.php)
  • Process.doSignal (cognitive 20) (Process.php)
  • Process.getIterator (cognitive 29) (Process.php)
  • Process.start (cognitive 30) (Process.php)
  • Process.start (cyclomatic 27) (Process.php)
  • Process.waitUntil (cognitive 19) (Process.php)
  • Skipped (documented): testExitCodeCommandFailed (Tests/ProcessTest.php)
  • Skipped (documented): testFind (Tests/ExecutableFinderTest.php)
  • …and 29 more

Changes since last survey

  • 19 commits — 18 feature/other, 1 fixes

By area

  • (repo) — 11 commits
  • (root) — 6 commits
  • Pipes/AbstractPipes.php — 1 commit
  • Tests/ProcessTest.php — 1 commit

Notable commits

  • fix: bug #65739 [Process] Ignore invalid env var names and non-scalar env values (nicolas-grekas, dionisvl)
  • change: Merge branch '5.4' into 6.4
  • change: Merge branch '6.4' into 7.4
  • change: Merge branch '6.4' into 7.4
  • change: Merge branch '6.4' into 7.4
  • change: Merge branch '6.4' into 7.4
  • change: Merge branch '7.4' into 8.1
  • change: Merge branch '7.4' into 8.1
  • change: Merge branch '7.4' into 8.1
  • change: Merge branch '7.4' into 8.1
  • change: Merge branch '8.1' into 8.2
  • change: [Process] Do not wait for output when the input iterator has more data
  • change: [Process] Ignore array env values before proc_open
  • change: [Process] Ignore invalid env var names
  • change: [Process] Remove outdated LogicException PHPDoc
  • change: [Process] Stop leaking CGI/FastCGI request-context vars to subprocesses
  • change: [Process] Use an absolute path for the cmd.exe fallback on Windows
  • change: [Process] Widen the timing bound of testIteratorInputDoesNotWaitForOutput
  • change: [Process][FrameworkBundle] Add ProcessBundle

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

symfony/process was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit df7cd19281696e082ba41d035d5de534ead60279 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.