Repository navigation
lockrot 0.7.0
Added
left-behind: a verdict for the branch you are on, not the package. Signal S8 takes the newest stable release on the installed version's release branch (1.x;0.3.xbelow 1.0; the patch alone below 0.1 — what a caret constraint stays inside; pre-releases do not count), measures its age againstrelease-warn-years/release-high-years, and fires only when a higher branch has released since and withinrelease-warn-yearsof today — a package dead on every branch stays S2's.composer outdated --major-onlysays a newer major exists; S2 sees the package's newest release and stays quiet; this says the branch installed here gets no fixes. The verdict isleft-behindat either threshold — betweenpinnedandold-promisein severity, base priorityhigh. The evidence readsbranch 1.x last released 2021-08-03 (5.1 years ago); 2.x released v2.12.5 (2026-04-17)— the higher branch whose release is newest, named as the branch fixes land on. A branch whose highest tag the repository leaves undated is not measured: Packagist dates a tag by its commit, and a subtree split (illuminate/*,symfony/*) has undated tags and tags dated years before the release.- Security advisories on the finding, with whether a fix is coming. Signal S9 carries the advisories that affect the installed version — the same ones
composer auditreports, fetched through Composer's own advisory API from the configured repositories, honouring Composer's ignore lists (config.policy.advisorieson 2.10+,config.audit.ignorebefore) — underdata.advisoriesin--format=json. S9 never decides a verdict. Each advisory is held against the highest stable tag on the installed version's branch and the package's highest stable tag, each only when above the installed version; one out of both ranges is already fixed, and the line says by what (fixed by 6.3.0;1 fixed by v3.4.47, 3 fixed by v8.1.7when they differ), withaffected_versions,fixed_byandfixed_on_branchon each advisory. On anabandoned,silentorleft-behindpackage the advisories nothing listed fixes — on a left-behind branch, nothing listed on the branch — earnno fix expected(no fix expected on 3.xnext to a fix in a higher branch) and the priority goes up one step,criticalat most. Advisories on packages the report does not flag stay off the rows and are totalled in the footer:53 security advisories on 17 packages the report does not flag; see composer audit. On Composer 2.2, under--offlineand once the install-time budget is spent the report carries one note instead.
Changed
- A package on a quiet branch of a living upstream is now
left-behindwhere it wasok,staleorold-promise;--fail-on=left-behindsees it. A baseline holding such a package atstaleorold-promisereports itworsened. - A priority threshold can trip on a verdict that did not move: an advisory on an
abandoned,silentorleft-behindpackage liftshightocritical, so--fail-on=criticalnow fails on it.left-behinditself starts athigh, so a run that passed--fail-on=highcan fail on a package that wasokbefore. The baseline, keyed on the verdict, still calls the findingknown. - S2 stays quiet when the package's highest non-dev tag carries no release date: "last release" would otherwise date the newest tag the repository dated and say nothing about the undated ones above it.
--strict-networkcovers the advisory request too: every repository that publishes advisories is asked, ascomposer auditasks them. A private repository that is down fails a strict run where it used to pass unnoticed.- The counts, priority and
pulled in by:lines fold between their·-separated items, never between a label and its number, and never wider than the terminal. The install-time block shows up to three notes, one per source that could not answer. - The evidence line opens with the signal that decided the verdict, then the rest in signal order, then what the package pulls in.
--format=jsonkeeps the signals in signal order. - The counts line gained
left-behind; theverdictenums in the config and baseline schemas, the SARIF rule list and--fail-onaccept it. The JSONschemanumber stays1: an added enum value and two new signal ids, nothing removed or renamed.
Verify this release
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.7.0/lockrot.phar
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.7.0/lockrot.phar.sha256
sha256sum -c lockrot.phar.sha256
gpg --keyserver hkps://keys.openpgp.org --recv-keys 39ECC3F64AE8D06A9A63FD99AB6F7F52AE513141
curl -fsSL -O https://github.com/somework/lockrot/releases/download/v0.7.0/lockrot.phar.asc
gpg --verify lockrot.phar.asc lockrot.phar
gh attestation verify lockrot.phar --repo somework/lockrotOr rebuild it: check out v0.7.0, run build/build-phar.sh with Composer 2.10.3, and compare the sha256 — see the PHAR page.
Full changelog: CHANGELOG.md.