Skip to content

Report abandoned Composer packages instead of failing by default - #3

Merged
PavlosIsaris merged 1 commit into
mainfrom
composer-abandoned
Sep 30, 2026
Merged

PavlosIsaris merged 1 commit into
mainfrom
composer-abandoned

Conversation

@PavlosIsaris

Copy link
Copy Markdown
Contributor

composer audit fails on abandoned packages since Composer 2.7. The first real run of security.yml in annotation-management-system found no vulnerabilities, but failed on symplify/rule-doc-generator-contracts, a transitive dev dependency of Rector with no replacement. A pull request cannot fix that.

  • New input composer-abandoned (ignore, report, fail). The default report lists abandoned packages without failing.
  • Vulnerabilities still fail the job.

Release plan after merge: tag v0.1.2 and move v0.1 to it.

composer audit fails on abandoned packages since Composer 2.7. The first
real run failed on a transitive dev dependency with no replacement. The new
composer-abandoned input (ignore, report, fail) defaults to report.
@PavlosIsaris
PavlosIsaris merged commit 9f67128 into main Sep 30, 2026
28 checks passed
@PavlosIsaris
PavlosIsaris deleted the composer-abandoned branch September 30, 2026 08:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant