Open Source
Shaping the tools I use every day, one pull request at a time
A hand-picked selection: only the contributions worth reading about, not every merged pull request. Articles about Magento and Adobe Commerce are on the blog.
Align the bootstrap PHP version check with what Magento requires — on GitHub
app/bootstrap.php still gated on PHP 8.1 while composer.json demanded 8.3, so anyone on 8.1 or 8.2 sailed past the friendly message and hit an opaque Composer failure instead.
Change quote.applied_rule_ids to TEXT — on GitHub
quote.applied_rule_ids was VARCHAR(255) while quote_item and quote_address_item used TEXT. Past ~100 applied rules the parent column truncated and stopped matching its children.
Stop evaluating project .env values as shell code — on GitHub
loadEnvConfig piped the project .env straight into eval, so cloning a repository and running any warden env command executed whatever the .env author put in a variable value. Replaced with parsing that does not run the file.
Expose invoice and credit memo CRUD, API routes and events — on GitHub
The entities, validators, ACL features and search indexes were already there — nothing exposed them. Added the commands, /api/sales/invoices and /api/sales/credit-memos routes, credit memo events, document number sequences and audit-trail keys across 15 files.
Show the country in order grid address columns — on GitHub
Sales > Orders rendered street, city, region and postcode but not the country, which is ambiguous for anyone shipping internationally. Added country_id to both address aggregators.
Enable the compiled configuration cache for test execution — on GitHub
The compiled_config cache holds the merged di.xml graph, and integration tests rebuilt it instead of reusing it. Straight wall-clock off every suite run.
Handle negative page numbers on category listings — on GitHub
A negative ?p= value was treated as a valid request and ended in an exception instead of a sensible response — trivially reachable by any crawler that guesses at URLs.
Fix the escaping example in the view models guide — on GitHub
Official docs showed $block->escape…() for output escaping and had the @var annotation the wrong way round. Documentation is copy-pasted into production more often than anyone admits.
Escape table names so encryption key rotation survives them — on GitHub
Table names containing special characters broke the generated SQL mid-rotation — a bad moment to discover a quoting bug, given what the tool is re-encrypting.
Only merged work is listed here, and only the parts worth a comment — the full history, including everything still in review, lives on GitHub.
ProductsList::getCacheKeyInfo()serialized raw$_GET— so a single malformed byte in the query string threw out ofjson_encode()and took the whole page down to the generic error page. Bots find those bytes for you.