
Part 05 - Composer
Source Code Files of this Chapter project-root/ ├── app/ │ ├──...
Tag archive

Source Code Files of this Chapter project-root/ ├── app/ │ ├──...
If you've ended up here, you probably already know why you need this: some API, some legacy SOAP...
Lessons Laravel Developers Should Learn from the laravel-lang Attack On 22–23 May 2026,...
How Anokii went from one monolithic repo with duplicate identity code to three composable Composer packages, published by a governed CI split instead of a manual release process.

Composer is the standard tool for managing PHP dependencies. It automates library installation,...

Two Loopress Full features, each useful on their own: Composer dependency management installs any...
tl;dr Le script de completion est sur ce gist, et cette commande installe tout d'un coup...

In May 2026, 700+ compromised Laravel-Lang package versions shipped a credential stealer through Composer. Here's how to harden your Laravel deploy pipeline: --no-scripts, allow-plugins, lockfile discipline, scoped deploy keys, and a full incident checklist.

Need to pull in a Packagist package on a WordPress site? The usual path is SSH into the server, install Composer, run composer require, and pray. The Loopress plugin does this from the admin panel.

We asked the wordpress.org plugin review team if a Composer package installer belonged in the official directory. The answer was no, and it reshaped how we ship the Loopress plugin.

Composer scripts and plugins turn a PHP repo into one that checks itself on install. Here's how to wire the boring parts once.

composer audit checks your lock file against the advisory database. Wire it into CI so a known CVE fails the build before it ships.