Skip to content
CAI
Software that uses CAICheck a score

composer/composer

72.1

Strong · 22 September 2026

64.5k

lines of production code

PHP

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Composer, a dependency management tool for PHP that resolves, downloads, and installs packages from various repositories. It provides a robust dependency solver that handles version constraints, conflicts, and security advisories while managing autoloading and binary symlinks. The system also supports package archiving, self-updating, and extensibility through a plugin API, ensuring reliable and secure project configuration across different environments.

How it got here

2011 — Dependency resolver and installation refactoring

30 changes.

This period focused on a major architectural overhaul of Composer's dependency resolution and installation subsystems, introducing parallel downloads, promise-based execution, and improved memory efficiency. Significant work included refactoring the solver internals, package models, and download managers to support better error handling and performance, alongside extensive new test coverage for these core components.

2012–2015 — Infrastructure refactoring and test expansion

21 changes.

This period focused on restructuring Composer's core infrastructure, including the IO subsystem, authentication handling, archiving logic, and plugin API, to improve modularity and security. Concurrently, extensive unit and functional test coverage was added across utilities, repositories, and command classes to ensure stability and regression protection.

2016–2022 — Extensibility and HTTP infrastructure overhaul

24 changes.

This period focused on modernizing Composer's architecture by introducing a capability-based plugin system and replacing the legacy HTTP transport with a robust, curl-based downloader featuring retry logic and improved proxy handling. Significant efforts were also directed toward strengthening security and reliability through granular error handling, strict input validation, and comprehensive static analysis upgrades to PHPStan level 8.

2023–2026 — Unified security policy and filter lists

9 changes.

This period focused on introducing a unified dependency policy configuration to consolidate security advisories, malware blocking, and abandoned package handling. It added external filter list support with robust error handling and strict HTTPS enforcement, alongside comprehensive test coverage for the new policy and autoloading systems.

Features

Add VCS drivers for Forgejo, Fossil, and Bitbucket Git

Composer now supports installing packages from Forgejo, Fossil, and Bitbucket Git repositories. The new ForgejoDriver and FossilDriver provide native integration for these version control systems, while the GitBitbucketDriver enables Composer to fetch package metadata and source code from Bitbucket-hosted Git repositories.

src/Composer/Repository/Vcs · high confidence

Added new exception classes for download and SSL errors

Composer now includes three new exception classes in the Composer\\Exception namespace: IrrecoverableDownloadException, NoSslException, and SecurityException. These classes provide specific error types for handling irrecoverable download failures, missing SSL support during HTTP downloader creation, and security-related issues, allowing for more granular error handling in plugin bootstrapping and HTTP operations.

src/Composer/Exception · high confidence

Improved static analysis accuracy for Composer config and rule reason data

Added PHPStan extensions (ConfigReturnTypeExtension and RuleReasonDataReturnTypeExtension) that provide precise type information for Composer's Config::get() method and Rule::getReasonData() method. This allows static analysis tools to better understand the return types of configuration keys (including specific constants for options like 'store-auths' or 'platform-check') and the structure of dependency resolver reason data, reducing false positives and improving type safety in codebases using Composer.

src/Composer/PHPStan · high confidence

Introduce ConfigSourceInterface for structured configuration manipulation

Composer now exposes a \ConfigSourceInterface\ and a \JsonConfigSource\ implementation in the \src/Composer/Config\ directory, providing a structured API for managing \composer.json\ and \auth.json\ files. This change adds specific methods to add, remove, and reorder repositories, manage config settings and properties, and manipulate package links (requires, dev-requires, etc.), replacing ad-hoc JSON manipulation with a more robust and type-safe approach for configuration updates.

src/Composer/Config · high confidence

Introduce dedicated JSON file handling and manipulation classes

Composer now includes a new \JsonFile\ class for reading and writing JSON files (including remote URLs), a \JsonManipulator\ class for safely modifying \composer.json\ content (such as adding dependencies or repositories) while preserving formatting and indentation, and a \JsonValidationException\ for reporting schema validation errors. A legacy \JsonFormatter\ class is also added for older PHP versions but is marked as deprecated in favor of standard \json\_encode\ flags.

src/Composer/Json · high confidence

Introduce filter lists to block or audit packages affected by malware

Composer now supports external filter lists that can block or audit packages identified as malware during installation. This change adds new internal classes in src/Composer/FilterList to parse repository metadata (including new summary-url and api-url fields), fetch and build filter list entries, and apply blocking or auditing logic based on a unified policy configuration. Users can configure which filter lists to use and specify sources to ignore, allowing for more granular control over security-related package filtering.

src/Composer/FilterList · high confidence

Introduce plugin capability interfaces for extensibility

Composer now exposes a new \Composer\\Plugin\\Capability\ namespace containing marker and provider interfaces to structure plugin extensibility. The \Capability\ interface serves as the base marker for all plugin capabilities, while the \CommandProvider\ interface allows plugins to declare commands by implementing \getCommands()\, receiving Composer, IO, and plugin instances via its constructor. This change shifts command registration from direct plugin methods to a capability-based model, enabling more future-proof and decoupled plugin architectures.

src/Composer/Plugin/Capability · high confidence

New ArrayDumper serializes Composer packages to arrays

The new ArrayDumper class in src/Composer/Package/Dumper converts Package objects into structured arrays, enabling serialization of package metadata for use cases like lock files or debugging. It outputs core identifiers (name, version), source and dist details (type, URL, reference, shasum, mirrors), dependency links, suggestions, and release time. For complete packages, it includes archive settings, scripts, license, authors, description, homepage, keywords, repositories, support, funding, and abandonment status. Root packages additionally expose minimum stability, and all packages can include transport options, with links and keywords sorted for consistency.

src/Composer/Package/Dumper · high confidence

New console output formatters and GitHub Actions error integration

The console subsystem now includes an HTML output formatter that converts terminal ANSI color codes into HTML spans, allowing Composer's output to be styled in web-based logs, and a GitHub Actions error helper that emits structured workflow commands (e.g., ::error file=...,line=...) when running in CI environments. These changes enhance how Composer presents diagnostic information and integrates with automated build pipelines.

src/Composer/Console · high confidence

New package comparer for detecting file changes

A new \Comparer\ class has been added to the \src/Composer/Package/Comparer\ directory to detect differences between a source and an update directory. This component recursively scans directories, computing file hashes (using xxh3 on PHP 8.1+ or sha1 otherwise) and tracking symlinks to identify added, removed, or modified files. It provides methods to retrieve these changes as structured arrays or formatted strings, supporting an 'explicated' mode that annotates items with their change type (added/removed/changed).

src/Composer/Package/Comparer · high confidence

New repository interfaces and implementations for security advisories and artifact repositories

This change introduces the AdvisoryProviderInterface, enabling repositories to supply security advisory data to the solver, and the ArtifactRepository, which allows users to install packages from local ZIP or TAR archives. The ComposerRepository is updated to implement AdvisoryProviderInterface, integrating security advisory fetching directly into the repository layer.

src/Composer/Repository · high confidence

New script event hooks and enhanced event context

Composer now exposes additional script lifecycle hooks, including pre- and post-status commands, pre- and post-archive commands, and a post-root-package-install event, allowing users to run custom logic at these specific stages. The script event class has been updated to provide access to the current development mode flag and the originating event in the chain, enabling scripts to make context-aware decisions based on how they were triggered.

src/Composer/Script · high confidence

Shell completion suggestions for Composer arguments and options

Composer now supports shell completion suggestions for command-line arguments and options. This is implemented by backporting the suggested values definition from Symfony Console 6.1 into Composer's own InputArgument and InputOption classes, allowing users to receive contextual completions when typing commands in supported shells.

src/Composer/Console/Input · high confidence

Architecture

Refactored downloaders with new interfaces and centralized download management

The download subsystem has been restructured to use a new \DownloaderInterface\ and \DownloadManager\ to coordinate package retrieval. This introduces a distinct prepare/download/install/cleanup lifecycle for better error recovery and parallelism, adds a \ChangeReportInterface\ to support the \composer status\ command for detecting local modifications, and creates a new \FilesystemException\ for clearer error reporting during local file operations.

src/Composer/Downloader · high confidence

Refactored version handling into dedicated classes

The version management logic in \src/Composer/Package/Version\ has been reorganized into specific classes: \VersionParser\ (extending the Semver parser with caching and name/version pair parsing), \VersionSelector\ (handling candidate selection with platform requirement filtering), \VersionGuesser\ (detecting local package versions from VCS), \VersionBumper\ (updating constraints to match installed versions), and \StabilityFilter\ (checking package stability flags).

src/Composer/Package/Version · high confidence

Behavioural changes

Atomic cache writes with retry logic

The Composer cache now writes files atomically by writing to a temporary file first and then renaming it to the final destination, which prevents cache corruption if a write is interrupted. Additionally, if a write fails despite initial checks, the cache automatically retries the operation to handle transient filesystem issues.

src/Composer · high confidence

Centralized authentication handling for GitHub, GitLab, and Bitbucket

Composer now uses a new \AuthHelper\ utility class to manage authentication prompts and credential storage for GitHub, GitLab, and Bitbucket. This change consolidates previously scattered logic into a single location, improving how Composer handles API rate limits, SSO requirements, and OAuth token storage in \auth.json\. It also introduces specific error messaging for Bitbucket OAuth consumer issues and ensures credentials are masked in debug output.

src/Composer/Util · high confidence

Centralized bootstrap logic with strict typing and dependency validation

The application now uses a dedicated \src/bootstrap.php\ file to handle autoloader initialization, enforcing strict types and adding explicit parameter types to the \includeIfExists\ helper. This change introduces a hard exit (exit code 1) with a clear error message if project dependencies are not installed, ensuring users are immediately notified of missing setup requirements rather than encountering cryptic errors later.

src · high confidence

Composer 2.3.0 runtime requirements and build process updates

The \bin/composer\ entry point now enforces a minimum PHP version of 7.2.5, adding an explicit check that aborts execution on older versions. It also raises the default memory limit to 1.5GB if the current setting is lower, while still respecting the \COMPOSER\_MEMORY\_LIMIT\ environment variable. Support for the \phpdbg\ SAPI is added alongside the existing CLI support. The \bin/compile\ script is introduced to handle PHAR building, utilizing \git rev-list\ for reproducible timestamps and configuring the autoloader suffix during the build process.

bin · high confidence

Deprecation of internal autoload generation classes in favor of external package

The \ClassMapGenerator\ class in \src/Composer/Autoload\ is now deprecated (since Composer 2.4.0) and delegates its logic to the external \composer/class-map-generator\ package. While \AutoloadGenerator\ and \ClassLoader\ remain the core components for generating and executing the autoloader, developers relying on the standalone \ClassMapGenerator\ should migrate to the dedicated package to ensure continued support and access to the latest class-mapping features.

src/Composer/Autoload · high confidence

Enforce HTTPS for filter list sources

Composer now validates that URLs used for filter lists (such as those for malware or abandoned packages) strictly use the HTTPS scheme. The new SourceValidator ensures that any configuration providing a URL source must begin with 'https://', rejecting plain HTTP URLs to improve security when fetching policy data.

src/Composer/FilterList/Source · high confidence

Filter list providers now handle unreachable repositories gracefully

The FilterListProviderSet now catches TransportException errors when initializing from repositories, storing them instead of failing immediately. This allows the ignoreUnreachable flag to be respected during construction, preventing crashes when a filter list source is temporarily unavailable. Additionally, the new UrlSourceFilterListProvider enables fetching filter list entries via a dedicated API endpoint, improving efficiency and reliability of security advisory and malware filtering.

src/Composer/FilterList/FilterListProvider · high confidence

Introduce unified dependency policy configuration

Composer now supports a new \config.policy\ section that unifies the configuration for security advisories, malware blocking, abandoned packages, and custom lists into a single, consistent structure. This replaces the legacy \config.audit\ and \config.filter\ settings, providing granular control over blocking and auditing behaviors for each category while maintaining backward compatibility with existing audit configurations.

src/Composer/Policy · high confidence

New curl-based HTTP transport layer with improved proxy and retry handling

Composer introduces a new \CurlDownloader\ and supporting classes (\CurlResponse\, \ProxyManager\, \RequestProxy\, \Response\) in the \src/Composer/Util/Http\ namespace to replace the legacy \RemoteFilesystem\. This change brings several behavioral improvements: it adds automatic retry logic for transient network errors (such as connection resets, DNS failures, and specific HTTP status codes), supports HTTP/3, and enforces stricter proxy handling (requiring explicit \https\_proxy\ configuration and disabling HTTP/3 multiplexing on known broken libcurl versions). Users will also see better error reporting, including included response bodies on failures and sanitized URLs in output, as well as support for IPv4/IPv6 resolution control via the \COMPOSER\_IPRESOLVE\ environment variable.

src/Composer/Util/Http · high confidence

PHPStan analysis upgraded to level 8 with PHP 8.4 baseline support

Static analysis strictness has been raised to level 8, requiring significantly more precise type handling across the codebase. To accommodate this, a new PHP 8.4-specific baseline file (baseline-8.4.neon) has been introduced, allowing the analysis to ignore known issues that are specific to the PHP 8.4 runtime while maintaining the higher standard. The configuration now includes bleeding-edge rules and several extensions (phpunit, deprecation-rules, strict-rules, symfony, pcre) to enforce better code quality, and custom PHPStan extensions have been added to resolve return types for internal configuration and rule-reason methods.

phpstan · high confidence

Parallel package downloads and single-step installation

The installation process now downloads all required packages in parallel before performing a single, unified installation step. This change significantly improves performance by reducing I/O overhead and ensures that the installation only proceeds if all downloads succeed, preventing partial or inconsistent states.

src/Composer/Command · high confidence

Plugin API v2.9.0 introduces capabilities, new events, and stricter plugin management

Composer now requires plugins to declare a dependency on the \composer-plugin-api\ package (version 2.9.0) to ensure compatibility. The plugin system has been expanded with a new \Capable\ interface, allowing plugins to expose implementations like \CommandProvider\ and \Validator\ via \getCapabilities()\. Several new events have been added to the plugin lifecycle: \INIT\, \COMMAND\, \PRE\_COMMAND\_RUN\, \PRE\_POOL\_CREATE\, \PRE\_FILE\_DOWNLOAD\, and \POST\_FILE\_DOWNLOAD\, giving plugins finer control over command execution, dependency resolution, and file downloads. The \PluginManager\ now enforces the \allow-plugins\ configuration, blocking incompatible or unapproved plugins in non-interactive modes to prevent security risks and broken states. Additionally, plugins can now be explicitly deactivated and uninstalled, and the system handles global vs. local plugin loading more robustly.

src/Composer/Plugin · high confidence

Refactor platform detection and version parsing into dedicated classes

The platform detection logic has been reorganized into the \src/Composer/Platform\ namespace with new classes: \HhvmDetector\ for detecting HHVM versions, \Runtime\ for runtime introspection (including HTML parsing for extension info), and \Version\ for parsing specific library versions like OpenSSL, libjpeg, and zoneinfo. This change improves robustness in version parsing (e.g., handling OpenSSL 3 and odd suffixes) and separates concerns for better maintainability.

src/Composer/Platform · high confidence

Refactor security advisory handling with new config and output models

The \src/Composer/Advisory\ location has been restructured to support more granular audit controls and improved output fidelity. A new \AuditConfig\ class centralizes audit enablement and format settings, while the \Auditor\ now relies on a unified \PolicyConfig\ to manage ignore lists, severity filters, and abandoned/malware blocking behaviors. The advisory data models have been refined: \SecurityAdvisory\ now explicitly includes severity and source metadata, \IgnoredSecurityAdvisory\ tracks the reason for ignoring an advisory, and \PartialSecurityAdvisory\ adds robust parsing for invalid version constraints. These changes enable the audit command to correctly display ignored advisory reasons, handle severity-based filtering, and provide more accurate JSON output for security and abandoned package checks.

src/Composer/Advisory · high confidence

Refactored IO subsystem with new BaseIO, BufferIO, and NullIO classes

The IO layer has been restructured to improve testability and authentication handling. A new BaseIO class centralizes authentication logic, automatically loading credentials from configuration for various providers (Bitbucket, GitHub, GitLab, Forgejo, HTTP Basic, Bearer, Custom Headers, and Client Certificates) and warning users when overwriting existing settings. A new BufferIO class replaces the previous ArrayIO, allowing interactive prompts to be simulated by setting user inputs and capturing output to a memory stream, which is essential for testing. Additionally, a NullIO class provides a silent, non-interactive implementation of IOInterface for scenarios where no output or interaction is desired.

src/Composer/IO · high confidence

Refactored archiving system with new exclude filters and archive manager

The archiving logic in src/Composer/Package/Archiver has been restructured to improve file filtering and archive generation. A new ArchiveManager centralizes the archiving workflow, handling source downloading, filename generation, and archiver selection. The file exclusion logic is now modularized into BaseExcludeFilter, GitExcludeFilter (respecting .gitattributes export-ignore), and ComposerExcludeFilter (respecting composer.json exclude rules), all coordinated by ArchivableFilesFinder. New ArchivableFilesFilter and ArchiverInterface define the iteration and contract for archivers. Specific archivers like ZipArchiver and PharArchiver have been updated to use these new filters, with ZipArchiver now correctly preserving Unix file permissions and handling Windows path separators, and PharArchiver supporting tar.gz and tar.bz2 compression formats.

src/Composer/Package/Archiver · high confidence

Refactored dependency resolution operations to distinguish upgrades from downgrades

The dependency resolver's operation classes (Install, Uninstall, Update, and alias operations) have been refactored to provide clearer, more specific output during installation and dry-run modes. Specifically, update operations now explicitly distinguish between 'Upgrading' and 'Downgrading' packages in the console output, rather than using a generic 'Updating' label. Additionally, lock file operations now display 'Locking' instead of 'Installing', and uninstall operations consistently use 'Removing'. These changes improve the clarity of Composer's feedback when managing package versions.

src/Composer/DependencyResolver/Operation · high confidence

Refactored dependency solver internals for improved performance and memory usage

The dependency resolution engine has been significantly refactored to improve performance and reduce memory consumption. Key changes include the introduction of a new Decisions class to encapsulate solver state, the use of a CompilingMatcher for faster version comparisons in the DefaultPolicy, and the implementation of a FilterListPoolFilter to efficiently block packages based on security advisories and malware lists. Additionally, the solver now uses GenericRule and MultiConflictRule classes to handle complex conflict scenarios more effectively, and transaction handling has been split into LocalRepoTransaction and LockTransaction for clearer separation of concerns.

src/Composer/DependencyResolver · high confidence

Refactored event system with new base Event class and dedicated ScriptExecutionException

The event dispatching infrastructure in src/Composer/EventDispatcher has been restructured to use a new base Event class that standardizes event properties (name, arguments, flags) and propagation control. This change introduces a dedicated ScriptExecutionException to handle script failures cleanly, preventing full exception traces from being shown to users when external processes fail. Additionally, an EventSubscriberInterface is now provided to allow plugins and subscribers to declaratively register for specific events, improving the modularity and maintainability of the event handling system.

src/Composer/EventDispatcher · high confidence

Refactored package installation into a batched, promise-based architecture with dedicated binary handling

The package installation logic in src/Composer/Installer has been restructured to support parallel downloads and batched execution. A new InstallationManager orchestrates operations (install, update, uninstall) using React promises, ensuring that all packages are downloaded before any are installed. This change introduces a dedicated BinaryInstaller to manage the creation and removal of binary symlinks/proxies, decoupling this responsibility from the LibraryInstaller. The refactoring also introduces new InstallerEvent and PackageEvent classes to provide granular lifecycle hooks (e.g., pre/post-package-install) for plugins and scripts, and adds a NoopInstaller to support dry-run modes.

src/Composer/Installer · high confidence

Refactored package loading into dedicated loader classes with strict validation

The package loading logic in \src/Composer/Package/Loader\ has been restructured into distinct classes: \ArrayLoader\ handles the core conversion of configuration arrays to package objects, \RootPackageLoader\ extends this to manage root-specific behaviors like version guessing and repository loading, and \ValidatingArrayLoader\ enforces strict schema rules (e.g., preventing path traversal in \bin\ entries, validating SPDX licenses, and checking package naming). \JsonLoader\ now acts as a thin wrapper around these loaders to parse JSON input, and a new \InvalidPackageException\ provides structured error and warning details for failed loads.

src/Composer/Package/Loader · high confidence

Refactored package model classes and lock file handling

The package model classes in src/Composer/Package have been refactored to improve type safety and separation of concerns. New classes like AliasPackage, CompleteAliasPackage, and RootAliasPackage manage package aliases, while BasePackage, Package, and CompletePackage handle core package data and metadata. The Locker class now uses a content hash for lock file integrity checks, and the Link class represents package dependencies with explicit types. These changes enhance the reliability of dependency resolution and lock file management.

src/Composer/Package · high confidence

Refactored platform requirement filtering with upper-bound support

The platform requirement filtering logic has been refactored into a new \PlatformRequirementFilter\ component, introducing a dedicated interface and factory. This change adds support for ignoring the upper bound of platform requirements using the \name+\ notation, allowing users to specify that only the lower bound of a platform constraint should be enforced. The implementation includes specific filters for ignoring all, ignoring nothing, and ignoring a list of requirements, ensuring that upper-bound ignores do not incorrectly apply to conflicts.

src/Composer/Filter · high confidence

Self-update now supports specific version channels and maintenance warnings

The self-update mechanism has been enhanced to allow users to pin Composer to specific major or minor release lines (such as 1.x, 2.x, or the 2.2 LTS branch) using new command-line flags like --1, --2, and --2.2. The system now stores the selected channel to persist this preference across updates and displays warnings when the current version is approaching end-of-life or entering critical security maintenance. Additionally, the self-update process respects the disable-tls configuration and caches version data to improve performance.

src/Composer/SelfUpdate · high confidence

Standardized project configuration and distribution files

Added \.editorconfig\ to enforce consistent coding styles (UTF-8, LF line endings, specific indentation) across editors and IDEs. Introduced \.gitattributes\ to ensure text files use LF line endings in the repository and to exclude non-essential development files (such as tests, documentation, and configuration) from distribution archives, while explicitly including \phpstan/rules.neon\. Added \.gitignore\ to prevent committing IDE settings, local caches, and generated artifacts. Added \.php-cs-fixer.php\ to configure the PHP CS Fixer tool for automated code style enforcement. Updated \README.md\ to reflect current project status, requirements, and community information, and updated \LICENSE\ to include all copyright holders.

(repo-wide) · high confidence

Strict confirmation questions reject ambiguous input

A new StrictConfirmationQuestion class has been added to the Composer question system. Unlike the standard confirmation question, this variant enforces strict yes/no responses by using regex patterns to match answers and throwing an exception for any input that does not clearly resolve to true or false, preventing ambiguous or non-standard answers from being treated as the default value.

src/Composer/Question · high confidence

Test coverage

Added autoload fixture files for testing autoloader generation; Added comprehensive fixture tests for the PoolBuilder dependency resolver; Added functional tests for create-project and InstalledVersions behavior; Added mock classes for testing capable plugins; Added test coverage for Composer command classes; Added test coverage for HTTP proxy handling and JSON response parsing; Added test coverage for package loader components; Added test fixture for GitHub issue \#7665 solver bug; Added test fixtures for ClassMapGenerator; Added test fixtures for PoolOptimizer edge cases; Added test fixtures for installed.php data structures; Added test fixtures for platform check scenarios; Added test fixtures for plugin lifecycle and capabilities; Added tests for ArrayDumper package serialization; Added tests for Console Application behavior and HTML output formatting; Added tests for EventDispatcher behavior; Added tests for FilterList policy configuration and API client transport options; Added tests for FilterListProviderSet unreachable repository handling; Added tests for JsonConfigSource repository and policy configuration; Added tests for PluginInstaller; Added tests for Script Event originating event logic; Added tests for StrictConfirmationQuestion; Added tests for minimum version support autoloading; Added tests for platform detection and version parsing; Added tests for self-update version selection and maintenance warnings; Added tests for the Composer Advisory Auditor; Added tests for the Installer component; Added tests for the unified Policy configuration system; Added unit tests for Composer JSON handling and validation; Added unit tests for Composer Util classes; Added unit tests for Package, Locker, and RootAliasPackage components; Added unit tests for VCS repository drivers; Added unit tests for platform requirement filter components; Added unit tests for repository implementations; Added unit tests for the Archiver package components; Added unit tests for the autoloader generator and class loader; Added unit tests for the dependency resolver components; Added unit tests for version management components; Expanded functional test coverage for the Composer installer; Expanded test coverage for Composer core components and CLI behavior; New test infrastructure and bootstrap configuration; New test mock classes for Composer internals.

Dependencies

Composer 2.11 dependency requirements and test fixtures

Composer 2.11 now requires PHP 7.2.5 or 8.0+, and updates its core dependencies to versions such as composer/semver ^3.3, justinrainbow/json-schema ^6.5.1, and Symfony components ^5.4.47/6.4.25/7.1.10/8.0. The project also adds new test fixtures for path-repo scenarios, plugin autoloading behavior, and minimum version support to validate these dependency interactions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 57 → 72 (+15.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 56 → 72 (+15.8)
  • Architecture 95 → 89 (-5.7)
  • Maturity 43 → 64 (+20.4)
  • Readiness 71 → 83 (+12.3)
  • Security 92 → 94 (+1.7)

Resolved (103)

  • Change coupling: AuditConfig.php ↔ AuditCommand.php (src/Composer/Advisory/AuditConfig.php)
  • Change coupling: Decisions.php ↔ RuleSetIterator.php (src/Composer/DependencyResolver/Decisions.php)
  • Change coupling: GenericRule.php ↔ MultiConflictRule.php (src/Composer/DependencyResolver/GenericRule.php)
  • Change coupling: GenericRule.php ↔ Rule2Literals.php (src/Composer/DependencyResolver/GenericRule.php)
  • Change coupling: GitDownloader.php ↔ HgDownloader.php (src/Composer/Downloader/GitDownloader.php)
  • Change coupling: GzipDownloader.php ↔ RarDownloader.php (src/Composer/Downloader/GzipDownloader.php)
  • Change coupling: PoolBuilder.php ↔ RuleSetIterator.php (src/Composer/DependencyResolver/PoolBuilder.php)
  • Change coupling: RarDownloader.php ↔ ZipDownloader.php (src/Composer/Downloader/RarDownloader.php)
  • Change coupling: RuleSetGenerator.php ↔ RuleSetIterator.php (src/Composer/DependencyResolver/RuleSetGenerator.php)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (src/Composer/Command/ConfigCommand.php)
  • Duplicated block (10 lines × 2) (src/Composer/Command/OutdatedCommand.php)
  • Duplicated block (10 lines × 2) (src/Composer/Command/SelfUpdateCommand.php)
  • Duplicated block (10 lines × 2) (src/Composer/DependencyResolver/RuleSetIterator.php)
  • Duplicated block (10 lines × 2) (src/Composer/Downloader/PathDownloader.php)
  • Duplicated block (10 lines × 2) (src/Composer/Installer.php)
  • Duplicated block (10 lines × 2) (src/Composer/Repository/PlatformRepository.php)
  • Duplicated block (10 lines × 3) (src/Composer/DependencyResolver/PoolBuilder.php)
  • Duplicated block (10 lines × 3) (src/Composer/Repository/Vcs/GitBitbucketDriver.php)
  • …and 83 more

New (388)

  • Change coupling: OutdatedCommand.php ↔ ShowCommand.php (src/Composer/Command/OutdatedCommand.php)
  • Change coupling: RemoveCommand.php ↔ RequireCommand.php (src/Composer/Command/RemoveCommand.php)
  • ClassTooLong: ComposerRepository (src/Composer/Repository/ComposerRepository.php)
  • ClassTooLong: ConfigCommand (src/Composer/Command/ConfigCommand.php)
  • ClassTooLong: DiagnoseCommand (src/Composer/Command/DiagnoseCommand.php)
  • ClassTooLong: Installer (src/Composer/Installer.php)
  • ClassTooLong: JsonManipulator (src/Composer/Json/JsonManipulator.php)
  • ClassTooLong: SelfUpdateCommand (src/Composer/Command/SelfUpdateCommand.php)
  • ClassTooLong: ShowCommand (src/Composer/Command/ShowCommand.php)
  • ClassTooLong: ValidatingArrayLoader (src/Composer/Package/Loader/ValidatingArrayLoader.php)
  • Distinct operations on distinct domains. composerRequire is a helper for generating require statements, loadClass is the actual autoloading mechanism. Not an inconsistency.
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Documentation: written for insiders
  • Duplicated block (10 lines × 2) (src/Composer/Autoload/AutoloadGenerator.php)
  • Duplicated block (10 lines × 2) (src/Composer/Command/ConfigCommand.php)
  • Duplicated block (10 lines × 2) (src/Composer/DependencyResolver/FilterListPoolFilter.php)
  • Duplicated block (10 lines × 2) (src/Composer/DependencyResolver/RuleSetIterator.php)
  • Duplicated block (10 lines × 2) (src/Composer/Downloader/PathDownloader.php)
  • Duplicated block (10 lines × 2) (src/Composer/Plugin/PluginManager.php)
  • …and 368 more

Changes since last survey

  • 25 commits — 21 feature/other, 4 fixes

By area

  • src/Composer — 14 commits
  • .github/workflows — 5 commits
  • (root) — 4 commits
  • doc/04-schema.md — 2 commits

Notable commits

  • fix: Fix Url::getOrigin prefix-matching a host against gitlab-domains (#12988)
  • fix: Fix repo docs gaps
  • fix: Fix: an empty command in a script should always be a NO-OP (#13053)
  • fix: Replace deprecated spl_object_hash with spl_object_id, fixes #13027 (#13028)
  • change: Add batching to the security advisories API queries for projects with very large dep count (#13051)
  • change: Add installed version to sub-dependencies in show --tree JSON output (#13049)
  • change: Add php8.6 to CI (#13054)
  • change: Bump actions/attest from 4.2.0 to 4.2.1 (#13020)
  • change: Bump actions/attest from 4.2.1 to 4.2.2 (#13033)
  • change: Bump actions/stale from 10.4.0 to 11.0.0 (#13019)
  • change: Bump deps
  • change: Bump zizmorcore/zizmor-action from 0.6.1 to 0.6.2 (#13032)
  • change: CI: Speedup PHPStan analysis (#13070)
  • change: Do not use a conflicted content-hash as the autoloader suffix (#13048)
  • change: Document the six composer.json fields missing from the schema chapter (#13058)
  • change: Include the failed URL in max-file-size and content-length errors (#13041)
  • change: Make it possible to pass transport options to FilterListApiClient (#13040)
  • change: Mask URL credentials anywhere in a string, not just at its start (#13044)
  • change: Merge commit from fork
  • change: Merge commit from fork
  • …and 5 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

composer/composer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 56a26ff6ad41a8972aae691e82d5a36a31d4684b — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-be726e82e277.