kalessil/production-dependencies-guard
Composer 安装命令:
composer require kalessil/production-dependencies-guard
包简介
Prevents adding of development packages into require-section (should be require-dev).
README 文档
README
Prevents development packages from being added into require and getting into production environment. In practical field
prevents e.g. debug tool-bars deployment into production environments.
Additionally, you can configure the guard to decline packages with missing/unfit license, abandoned or mentioning debug
in description and analyze packages on basis of composer.lock (deeper analysis).
Installation
composer require --dev kalessil/production-dependencies-guard:dev-master
Configuration
Additional guard checks can be enabled in the top-level composer.json file:
{
"name": "...",
"extra": {
"production-dependencies-guard": [
"check-lock-file",
"check-description",
"check-license",
"check-abandoned",
"white-list:vendor/package-one",
"white-list:vendor/package-two",
"accept-license:MIT",
"accept-license:proprietary"
]
}
}
white-list:...adds a package to white-list, so it's not getting reported in spite of violationscheck-lock-fileuses composer.lock instead of composer.json, allowing deeper dependencies analysischeck-descriptionenables description and keywords analysis (searchesdebug), allowing to detect custom dev-packagescheck-abandonedenables abandoned packages checkingcheck-licenseenables license checking (packages must provide license information)accept-license:...specifies which licenses should be accepted (if the setting omitted, any license incl. proprietary)
Usage
When the package is added to require-dev section of your composer.json file ("kalessil/production-dependencies-guard": "dev-master"),
it'll prevent adding dev-packages into require section. Since dev-packages has no security guaranties
(not intended for production use, only development purposes), this also improves your application security.
composer require --dev kalessil/production-dependencies-guard:dev-master
composer require phpunit/phpunit:*
# it should be `composer require --dev phpunit/phpunit:*` here
will run with an error (profit!):
./composer.json has been updated
Installation failed, reverting ./composer.json to its original content.
[RuntimeException]
Dependencies guard has found violations in require-dependencies (source: manifest):
- phpunit/phpunit: dev-package-name
Stability
This package is only available in its dev-master version: according to the package purpose.
统计信息
- 总下载量: 1.17M
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 87
- 点击次数: 1
- 依赖项目数: 2
- 推荐数: 0
其他信息
- 授权协议: MIT
- 更新时间: 2019-04-28