Skip to content
CAI
Software that uses CAICheck a score

symfony/flex

60.1

Adequate · 19 September 2026

6.3k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is Symfony Flex v2, a Composer plugin that automates the installation, configuration, and updating of Symfony recipes. It manages project setup by modifying configuration files such as bundles, services, and environment variables, while also supporting Docker integration and frontend dependency synchronization. The tool provides CLI commands for dumping environment variables and synchronizing recipe states, ensuring consistent project structure across different environments.

How it got here

2016 — Symfony Flex v2 core architecture

5 changes.

This period focused on initializing the repository structure and upgrading Symfony Flex to version 2, which introduced a new core architecture driven by a dedicated Configurator system. The work established specialized configurators for managing recipe installations and updates across various project files, supported by comprehensive test coverage to ensure consistent behavior.

2017–2022 — Recipe management and testing expansion

8 changes.

This period focused on expanding Symfony Flex's capabilities by introducing new CLI commands for environment dumping and comprehensive recipe management, including installation, listing, and updating. Significant effort was dedicated to hardening the recipe update logic to prevent accidental file deletion and ensuring robust patch application. The work was supported by extensive additions to the test suite, covering core components, new commands, and complex fixture scenarios for Sylius plugins.

Features

Introduce Configurator system for recipe management

Symfony Flex now uses a dedicated Configurator system to manage recipe installations, updates, and removals. This change introduces a suite of specialized configurators—such as BundlesConfigurator for managing bundles.php, ContainerConfigurator for services.yaml parameters, DotenvConfigurator for .env files, and DockerComposeConfigurator/DockerfileConfigurator for Docker support—alongside base classes like AbstractConfigurator and AddLinesConfigurator. This architecture centralizes how recipes modify project files, ensuring consistent handling of configuration updates and unconfigurations across different file types.

src/Configurator · high confidence

Introduce Unpack operation and result models

Added the \Operation\ and \Result\ classes in the \src/Unpack\ namespace to support the new Composer package unpacking capability. The \Operation\ class manages the configuration for whether packages should be unpacked and sorted, while the \Result\ class tracks which packages have been successfully unpacked and which are required, ensuring the command always has at least one package to process.

src/Unpack · high confidence

New CLI commands for environment dumping and recipe management

This change introduces four new console commands to \src/Command\: \symfony:dump-env\ (aliased as \dump-env\) compiles \.env\ files into a PHP array in \.env.local.php\ for faster environment loading, supporting an \--empty\ flag to ignore existing content; \symfony:recipes:install\ (aliased as \sync-recipes\ and \fix-recipes\) installs or reinstalls recipes for existing packages, with options to force overwrite (\--force\), reset to initial state (\--reset\), or auto-confirm (\--yes\); \symfony:recipes\ lists available or outdated recipes; and \symfony:recipes:update\ applies patches to update installed recipes to their latest versions, handling conflicts and generating changelogs.

src/Command · high confidence

Behavioural changes

Improved recipe update logic prevents deletion of files still in use

The recipe update system now checks if files marked for deletion by a recipe are still referenced by other installed recipes before removing them. If a file is locked by another recipe, it is preserved and a warning is displayed to the user, preventing accidental loss of functionality. Additionally, the update process now correctly handles modified files that have been deleted in the user's project by excluding their patches from the final diff, and ensures patch files end with a blank line for valid git application.

src/Update · high confidence

Introduction of Symfony Flex v2 core architecture

This change introduces the core classes for Symfony Flex v2, including the main plugin entry point (Flex.php), the recipe downloader (Downloader.php), and the configurator system (Configurator.php) that manages recipe installation and updates. It adds a new Lock class to manage the symfony.lock file, a PackageFilter to handle version constraints, and a PackageJsonSynchronizer to keep frontend dependencies in sync. The update process is now driven by a dedicated UpdateEvent and an InformationOperation class, allowing for more granular control over recipe updates and version resolution.

src · high confidence

Repository initialization and configuration standardization

The repository has been initialized with standard configuration files to support development and distribution. A .gitattributes file is added to exclude development-specific files (such as .github, .travis.yml, and tests) from exported archives. A .php-cs-fixer.dist.php file establishes code style rules based on the Symfony standard. A LICENSE file (MIT) and a README.md file are added to define usage terms and provide project documentation. Additionally, a phpunit.xml.dist configuration file is introduced to define the test suite and source coverage, and the obsolete SymfonyStartPlugin.php file is removed.

(repo-wide) · high confidence

Test coverage

Added test coverage for Flex configurators; Added test fixtures for Sylius plugins; Added test fixtures for the recipe update system; Added test suite for Symfony Flex core components; Added tests for dump-env and recipe management commands; Added unit tests for the recipe update system.

Dependencies

Symfony Flex v2: PHP 8.1+ requirement and Composer 2.1+ upgrade

The Symfony Flex package has been upgraded to version 2, raising the minimum PHP version to 8.1 and requiring Composer 2.1 or later. This update also renames the package from 'symfony/symfony-start-composer' to 'symfony/flex', updates the autoloading to PSR-4 under the 'Symfony\\Flex' namespace, and bumps development dependencies including PHPUnit to v12.4 and Symfony components (dotenv, filesystem, process) to versions 6.4, 7.4, and 8.0. Additionally, test fixtures for package.json synchronization and recipe updates have been added to support these changes.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 60.

Lenses

  • Code Health 81
  • Architecture 100
  • Maturity 49
  • Readiness 51
  • Security 100

Changes since last survey

  • 300 commits — 171 feature/other, 129 fixes

By area

  • (repo) — 150 commits
  • src/Configurator — 38 commits
  • src/Flex.php — 27 commits
  • src/Command — 18 commits
  • (root) — 15 commits
  • src/Downloader.php — 15 commits
  • src/Update — 6 commits
  • src/PackageJsonSynchronizer.php — 4 commits
  • tests/Update — 4 commits
  • .github/workflows — 3 commits
  • src/Cache.php — 3 commits
  • tests/Configurator — 3 commits
  • src/GithubApi.php — 2 commits
  • src/PackageResolver.php — 2 commits
  • tests/Fixtures — 2 commits
  • tests/ScriptExecutorTest.php — 2 commits
  • src/PackageFilter.php — 1 commit
  • src/ParallelDownloader.php — 1 commit
  • src/Response.php — 1 commit
  • src/ScriptExecutor.php — 1 commit

Notable commits

  • fix: CS fixes
  • fix: CS fixes
  • fix: Fix "null as array offset" deprecation in DockerComposeConfigurator
  • fix: Fix BC with upgrading from flex < 1.18
  • fix: Fix CI on the main banches
  • fix: Fix CS
  • fix: Fix CS
  • fix: Fix CS
  • fix: Fix CS
  • fix: Fix FLEX_SERVERLESS feature flag
  • fix: Fix PHP Parse errors in tests.
  • fix: Fix PHP warning when using Composer 1
  • fix: Fix a merge-conflict residue (#1021)
  • fix: Fix checking for "flex-require-dev" in composer.json
  • fix: Fix compat with old composer versions
  • fix: Fix compat with older composer
  • fix: Fix detecting new packages before installing their recipes
  • fix: Fix dump-env command when .env files reference other env vars
  • fix: Fix flex upgrades
  • fix: Fix handling flex://defaults
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

symfony/flex was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4a6d98eea3ebc7f68d82810cb682eedca2649e99 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.