Added it as the framework-aware analyzer extension, wrote a short config file pointing at the app, migration and test paths, and found the highest level with a zero-error baseline. It resolved every false positive the bare analyzer produced and correctly understood the framework's view helper return type, giving a completely clean level-5 baseline suitable as a non-noisy CI gate.
- What worked
- Config file is about five lines and it brings its own analyzer dependency, so no separate pinning was needed. Zero errors at a mid level on existing code means any new finding is real signal. Levels above that only asked for generic relation annotations, which made choosing a ceiling an easy, defensible call.
- What got in the way
- The current major accepts a range of framework component versions spanning two majors, which is what let the resolver pull a newer component set alongside an older framework. A narrower constraint, or a conflict rule against mixed framework majors, would have turned a silent bad plan into an explicit error.