php-regex / regex-symfony
Symfony bundle for PHPRegex: the Regex service and the regex:lint, regex:routes, regex:security, regex:analyze, regex:compare and regex:transpile commands.
Package info
github.com/php-regex/regex-symfony
Type:symfony-bundle
pkg:composer/php-regex/regex-symfony
Fund package maintenance!
Requires
- php: >=8.2
- php-regex/regex-automata: ^2.0
- php-regex/regex-linter: ^2.0
- php-regex/regex-optimizer: ^2.0
- php-regex/regex-parser: ^2.0
- php-regex/regex-redos: ^2.0
- php-regex/regex-toolkit: ^2.0
- php-regex/regex-transpiler: ^2.0
- symfony/config: ^7.4|^8.0
- symfony/console: ^7.4|^8.0
- symfony/dependency-injection: ^7.4|^8.0
- symfony/http-kernel: ^7.4|^8.0
Requires (Dev)
None
Suggests
- nikic/php-parser: To extract patterns with a full PHP parser.
- symfony/routing: To analyze route requirements with regex:routes.
- symfony/validator: To lint the patterns of Regex constraints.
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-05 22:22:03 UTC
README
PHPRegex Symfony
Symfony bundle for PHPRegex: the Regex service and the regex:lint, regex:routes, regex:security, regex:analyze, regex:compare and regex:transpile commands.
Features
- A
Regexservice, autowired asPHPRegex\Toolkit\Regex, to validate, parse, optimize, transpile and ReDoS-check patterns from your own code - Six console commands:
regex:lint,regex:routes,regex:security,regex:analyze,regex:compareandregex:transpile regex:lintreads your PHP files, your route requirements and your validator constraints in one pass- Reports in console, JSON, GitHub, Checkstyle and JUnit formats, with clickable editor links
regex:lintjudges patterns for the PHP yourcomposer.jsonsupports, not for the one running itregex:routesandregex:securityanalyze route conflicts,access_controlordering and firewall regexes, including their ReDoS risk
Installation
composer require php-regex/regex-symfony
Requires PHP 8.2+ and Symfony 7.4+ or 8.0+. symfony/routing, symfony/validator and nikic/php-parser are optional and widen what regex:lint reads.
Configuration
Every key is optional and lives under php_regex in config/packages/php_regex.yaml:
| Option | Default | Role |
|---|---|---|
max_pattern_length, max_lookbehind_length |
100000, 255 |
Longest pattern string; longest variable-length lookbehind |
runtime_pcre_validation |
false |
The service also compiles each pattern with the running PHP |
php_version, pcre_version |
null |
PHP version and PCRE2 release regex:lint judges for ("8.2", "10.42") |
cache.pool, cache.directory, cache.prefix |
null, '%kernel.cache_dir%/php_regex', 'regex_' |
Cache for parsed ASTs: a PSR-6 pool, else this directory |
extractor_service |
null |
Service id of a custom pattern extractor |
redos.enabled, redos.threshold, redos.ignored_patterns |
false, 'high', [] |
ReDoS analysis on or off, minimum severity reported, patterns skipped |
analysis.warning_threshold |
50 |
Complexity score above which a warning is emitted |
automata.minimization_algorithm, automata.determinization_algorithm |
'hopcroft', 'subset-indexed' |
Algorithms behind the automata comparisons |
optimizations.* |
digits, word, ranges, canonicalize_char_classes true; possessive, factorize false; min_quantifier_count 4 |
Default optimization switches for regex:lint |
paths, exclude |
['src'], ['vendor'] |
Directories regex:lint scans, and skips |
ide |
'%env(default::SYMFONY_IDE)%' |
IDE behind the clickable links; falls back to framework.ide |
Usage
Inject PHPRegex\Toolkit\Regex where you need it — the container builds it from the configuration above:
$regex = Regex::create(); // what the container injects $regex->validate('/^[a-z0-9-]{3,}$/')->isValid; // true $invalid = $regex->validate('/^(unclosed/'); $invalid->error; // "Expected ) at end of input (found eof)"
Check one for ReDoS:
$analysis = $regex->redos('/^(a+)+$/'); $analysis->isSafe(); // false $analysis->severity->value; // 'critical' $analysis->getVulnerableSubpattern(); // 'a+' $analysis->headline(); // 'Exponential backtracking (proven)' $analysis->witness->render(); // '"a" x n . "!"', the input that triggers it
Optimize a pattern:
$optimized = $regex->optimize('/[0-9]{4}-[0-9]{2}/'); echo $optimized->optimized; // /\d{4}-\d{2}/
Or transpile it for another engine:
$transpiled = $regex->transpile('/^[a-z]+(?=\d)$/i', 'js'); echo $transpiled->literal; // /^[a-z]+(?=\d)$/i echo $transpiled->constructor; // new RegExp("^[a-z]+(?=\\d)$", "i")
The service also exposes parse, parseTolerant, analyze, explain, highlight, literals, generate and parsePattern.
Integration
Register the bundle in config/bundles.php:
return [ PHPRegex\Symfony\PHPRegexBundle::class => ['dev' => true, 'test' => true], ];
| Command | Description |
|---|---|
regex:lint |
Lint, validate and optimize the patterns in your code |
regex:routes |
Detect route requirement conflicts and overlaps |
regex:security |
Analyze access_control ordering and firewall regexes |
regex:analyze |
Run the routes and security analyzers in one pass |
regex:compare |
Compare two patterns with automata logic |
regex:transpile |
Translate a pattern for another regex engine |
bin/console regex:lint src/ --format=json
bin/console regex:routes --show-overlaps
bin/console regex:analyze --only=routes --redos-threshold=medium
bin/console regex:transpile '/^\d{4}$/' --target=python
Exit codes: 0 when nothing is wrong, 1 when the judged patterns or files have a problem, 2 when an option or the configuration cannot be used.
Documentation
- The Symfony guide — configuration, lint targets, the commands, upgrading from 1.x
- The CLI guide —
regex:lintin depth, exit codes - The ReDoS guide — how the risk analysis reaches its verdicts
- Backward compatibility promise — what stays stable across releases
Resources
- Documentation
- The runtime library behind the service: regex-toolkit
- Changelog
- Report issues and send pull requests in the main PHPRegex repository
Sponsors
If PHPRegex saves you time, consider sponsoring its maintenance.
License
MIT. See LICENSE.