Загрузка видео...

Не удалось загрузить видео

На главную

you familiar with rust's cargo vet or go vet? we just did the same for php, introducing: Laravel vet see the code [composer update] is about to write into your vendor/ directory before it does 🤌🏻

10,796 просмотров • 17 дней назад •via X (Twitter)

Комментарии: 10

Фото профиля nunomaduro
nunomaduro17 дней назад

it's a dependency audit for php, so you actually know what's changing but we took it further: you can delegate the review to AI 🤌🏻 repository & documentation:

Фото профиля Yoel limbu
Yoel limbu17 дней назад

@laravel PHP has needed this for a long time considering how much of the ecosystem just trusts whatever composer pulls in. Does vet audit transitive dependencies too, or only the packages listed directly in composer.json?

Фото профиля nunomaduro
nunomaduro17 дней назад

@laravel transitive dependencies too

Фото профиля Mathias Onea
Mathias Onea17 дней назад

@laravel finally some transparency and granular control when upgrading composer packages 🙌

Фото профиля nunomaduro
nunomaduro17 дней назад

@laravel glad you like it

Фото профиля Arthur Minasyan 🐦‍🔥
Arthur Minasyan 🐦‍🔥17 дней назад

@laravel 🚀🎊

Фото профиля nunomaduro
nunomaduro17 дней назад

@laravel ty ty

Фото профиля Niccolò Banti
Niccolò Banti17 дней назад

@laravel The actual attack surface in most of these incidents is postinstall scripts, not the diff itself. Does vet flag those separately or just surface the vendor diff and let you miss the hook buried in composer.json?

Фото профиля nunomaduro
nunomaduro17 дней назад

@laravel not sure i follow, but if there is changes on the composer json of the package, they get reviewed too (by you or by AI)

Фото профиля Niccolò Banti
Niccolò Banti17 дней назад

@laravel Reviewed together with everything else isn't the same as flagged separately. If a postinstall script sits inside a composer.json change buried in a bigger diff, does vet call it out as its own line, or does it read the same as a version bump?

Похожие видео