Skip to content

Request: validate composer, package.json #80

Open
@bingalls

Description

@bingalls

Please add a test for composer validate
If package.json exists, run npm audit
Check that roave/security-advisories: dev-master is in composer.json
It should be the only package as dev-master, which can affect composer validate
Composer Validate should handle semver checking, but you may wish to roll your own, to accommodate user configurable checks for these prefix/suffixes:

  • ^1.2.3
  • ~1.2.3
  • 1.2.*
    Of course, Composer Validate does much more, including composer.lock checks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions