mxr576/composer-audit-changes
最新稳定版本:1.2.1
Composer 安装命令:
composer require --dev mxr576/composer-audit-changes
包简介
Composer command for only auditing installed or updated packages in composer.lock
README 文档
README
The audit-changes Composer command works similarly to the built-in composer audit command but it only audits newly
installed or updated packages since a previous version of composer.lock.
Why
Have you seen a pending CR/MR/PR before that was blocked because a security advisory has just been released for a existing dependency?
This solution can be ideal for auditing only those package changes that were made in a CR/MR/PR but not the complete content on composer.lock.
Installation
$ composer require --dev mxr576/composer-audit-changes
Usage
$ composer audit-changes [path-or-url-or-git-reference-to-previous-version-of-composer-lock] # the default is HEAD:composer.lock
Run composer audit-changes --help to see available command arguments and options.
Background story
This package was created to showcase that maybe there is a better alternative for handling randomly failing builds
than adding an opt-out feature to composer audit. See the related issue feature request at composer/composer#11298.
统计信息
- 总下载量: 116
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 2
- 点击次数: 2
- 依赖项目数: 0
- 推荐数: 1
其他信息
- 授权协议: MIT
- 更新时间: 2023-05-13