Загрузка видео...
Не удалось загрузить видео
you familiar with rust's cargo vet or go vet? we just did the same for php, introducing: Laravel vet see the code [composer update] is about to write into your vendor/ directory before it does 🤌🏻
10,796 просмотров • 17 дней назад •via X (Twitter)
Комментарии: 10

it's a dependency audit for php, so you actually know what's changing but we took it further: you can delegate the review to AI 🤌🏻 repository & documentation:

@laravel PHP has needed this for a long time considering how much of the ecosystem just trusts whatever composer pulls in. Does vet audit transitive dependencies too, or only the packages listed directly in composer.json?

@laravel transitive dependencies too

@laravel finally some transparency and granular control when upgrading composer packages 🙌

@laravel glad you like it

@laravel 🚀🎊

@laravel ty ty

@laravel The actual attack surface in most of these incidents is postinstall scripts, not the diff itself. Does vet flag those separately or just surface the vendor diff and let you miss the hook buried in composer.json?

@laravel not sure i follow, but if there is changes on the composer json of the package, they get reviewed too (by you or by AI)

@laravel Reviewed together with everything else isn't the same as flagged separately. If a postinstall script sits inside a composer.json change buried in a bigger diff, does vet call it out as its own line, or does it read the same as a version bump?
