Composer Rules
Dependency manager for PHP projects. Install, update, and autoload packages with version constraints and lock files.
3 rules
composer.json Configuration Standards
Beginner
Enforce composer.json best practices — required fields, version constraint conventions, autoloading configuration, platform requirements, and sort order for clean PHP dependency management.
globs: **/composer.json, **/composer.lock
composer-json, version-constraints, platform-config, autoloading
View Rule
Composer Lock File Policy
Beginner
Enforce composer.lock management rules — commit for applications, ignore for libraries, use install in CI, and update workflow for controlled dependency upgrades.
globs: **/composer.json, **/composer.lock, **/.gitignore
composer-lock, dependency-locking, reproducible-installs, update-workflow
View Rule
Composer Security Standards
Intermediate
Enforce security standards for PHP Composer projects — mandatory audit in CI, no dev dependencies in production, package verification, and vulnerability response procedures.
globs: **/composer.json, **/composer.lock, **/.github/workflows/**
security-audit, production-install, vulnerability-management, dependency-review
View Rule