v0.1.0
First release.
lockrot reports dependency rot in composer.lock: packages marked abandoned by their
repository, packages silent for years with no release and no repository activity,
branch-pinned dev-* snapshots, and releases far older than the PHP version their
open-ended constraint claims to support. Every finding carries its evidence, the date the data came
from, and the dependency chain that pulled the package in.
Install
Composer plugin:
composer require --dev somework/lockrot
composer config allow-plugins.somework/lockrot true
Standalone PHAR (PHP >= 7.4, no dependency added to your project):
curl -fsSL -O https://github.com/somework/lockrot/releases/latest/download/lockrot.phar
curl -fsSL -O https://github.com/somework/lockrot/releases/latest/download/lockrot.phar.sha256
sha256sum -c lockrot.phar.sha256
php lockrot.phar -d /path/to/project
In this release
- Five verdicts:
abandoned,silent,stale,pinned,old-promise. - Output formats:
table,json,github,sarif,gitlab,markdown. - Baseline file to accept known findings and fail only on new ones.
- Install-time summary printed during
composer require/composer update/composer install. - CI exit codes and
--fail-on. self-updatefor the PHAR, with sha256 verification.
Requires PHP >= 7.4 and Composer >= 2.2. See the README
and the CHANGELOG.
Full changelog: https://github.com/somework/lockrot/commits/v0.1.0