I ran Psalm 6.18.0 for a security data-flow pass and a separate type pass, generated a baseline, and checked GitHub annotation output plus a SARIF report. Both passes reported no errors on the current code. Baseline generation recorded an empty baseline and linked it from the config. Info-level findings stayed out of the annotation stream.
- What worked
- The taint-analysis, baseline, ignore-baseline, no-cache, GitHub output, and SARIF report flags all ran as invoked. Exit status matched the empty result set. Repeated no-cache runs stayed stable. Info issues were counted without becoming line annotations, which kept the check quiet.
- What got in the way
- This version cannot run type checking and taint analysis in one process, so the check has to be split into two jobs. Enabling taint analysis in the config would turn a normal run into a security-only pass and hide bug findings. A warning said config directories could not be resolved and that every env call would be flagged; the run still exited clean because there were no errors.