Skip to content

Entries with the tag “composer”

These entries are tagged “composer” which is a PHP package manager.

Give your Composer script a second name

A composer script is often named after the underlying tool, like phpstan, because that is the binary the script calls. But what if you or the team always refers to the tool as larastan because that is the plugin or package providing most of the functionality for your project? “Did Larastan catch that?” asks another programmer, even though composer.json says phpstan.

Jun 2, 2026 1 min read #composer #ide-and-web-dev-tools

Composer Security Concerns with Create Project

One of the lesser known pieces of functionality from Composer is the ability to create a project from skeleton/scaffolding. This ability allows you to create a project structure, directory, files and requirements based on the suggested setup from the project maintainer. A common installation mechanism of Laravel uses this functionality. (Even I use it to save time and set up my own custom configuration for new project skeletons.)

Jan 21, 2019 3 min read #composer #php #security

Composer Dry Run

Just another case of RTFM I’m sure, but I was wondering how to preview the changes that will happen if I do a composer update on my current project. I wanted to get an idea of how many libraries would change so I could see if it would be a short or long project (potentially) to do a 3rd Party Library update. (I already hear you - and I agree - the number of files changing isn’t always indicative of how long the task to update your project’s dependencies will take. Shhh - quiet you.)

Aug 22, 2017 1 min read #composer #php