Download the PHP package spiriitlabs/composer-update-report without Composer

On this page you can find all versions of the php package spiriitlabs/composer-update-report. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package composer-update-report

composer-update-report

A Composer plugin that automatically generates a Markdown report after each composer update, by comparing the current composer.lock with the version recorded in Git.

It is framework-agnostic: updated packages are grouped automatically by their Composer vendor (drupal/*, symfony/*, laravel/*, …), so the report highlights whatever stack your project uses — Drupal, Symfony, Laravel or any other — without any configuration.

Requirements

Installation

The plugin activates automatically upon installation — no additional configuration is required.

How it works

On each composer update, the plugin:

  1. Reads composer.lock from HEAD (state before the update)
  2. Compares it with the current composer.lock (state after the update)
  3. Groups updated packages by Composer vendor
  4. Generates a composer-update-YYYY-MM-DD.md file at the project root

If no version changes are detected, no file is created.

Same-day updates are merged

If you run several composer update during the same day, the reports are merged into a single composer-update-YYYY-MM-DD.md rather than overwritten or appended.

The first run of the day records the starting state of composer.lock (from Git HEAD) into a per-day baseline file stored inside the repository's git directory (.git/composer-update-report/baseline-YYYY-MM-DD.json). Every subsequent run recomputes the diff against that baseline, so the report always reflects all the updates of the day as one consolidated summary — even if composer.lock was committed between two updates. Because the baseline lives under .git/, it is never tracked and never appears as a stray file in your project — no .gitignore entry is required.

Regenerating a report on demand

Besides the automatic hook, a update-report Composer command regenerates the report from arbitrary git refs — without running composer update. This is handy while a branch is in progress: compare the current composer.lock against the base branch.

Options:

Option Default Description
--from HEAD Git ref for the before state
--to working composer.lock Git ref for the after state
--report-profile extra config (or agnostic) Force a profile (agnostic | drupal) for this run
--output-dir extra config (or project root) Force the output directory for this run

Unlike the automatic hook, this command never reads or writes the day baseline, so it can be run any number of times without interfering with the consolidated same-day report.

Report contents

The report is structured into sections:

Section Contents
Updates (per vendor) One subsection per Composer vendor (drupal, symfony, …), most active first
New packages Packages absent from the previous composer.lock
Removed packages Packages present in the previous composer.lock but now removed

Updated packages are grouped automatically by their vendor prefix (the part before /). Vendors are ordered by the number of updated packages (descending), so the framework that changed the most appears first. Well-known vendors get a curated icon and label (Drupal, Symfony, Laravel, API Platform, Doctrine, Twig, League, PHPUnit, PHPStan); any other vendor falls back to a generic icon and its capitalised name. Packages with no vendor/ prefix are gathered under Autres librairies.

Within a vendor, packages that share the same before/after version are merged into a single line (typical of Symfony components released in lockstep).

Example generated report

Configuration

By default the report is generated at the project root. You can change the output directory by adding the following to your composer.json:

The directory is created automatically if it does not exist. The path is relative to the project root.

Report profile

By default the report uses the agnostic profile described above (grouping by Composer vendor). A dedicated Drupal profile is also available, which keeps the original layout with sections for Drupal Core, Modules Contrib Drupal and Bibliothèques sous-jacentes (Vendor). Select it explicitly with the profile option:

Accepted values are agnostic (default) and drupal. An unknown value prints a warning and falls back to agnostic.

Notes

License

MIT — see LICENSE


All versions of composer-update-report with dependencies

PHP Build Version
Package Version
Requires php Version ^8.1
composer-plugin-api Version ^2.0
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package spiriitlabs/composer-update-report contains the following files

Loading the files please wait ...