Images and publishing
Composer repositories
Mirror Packagist for composer. The archive of each release is fetched and scanned by this box.
- Settings, Registries: switch on Composer repository.
- Add a Composer registry. For the public packages use
https://repo.packagist.org. - Write Composer rules: pattern
monolog/monologorsymfony/*, versions3.5.0,^3.5or>=3.5 <4.0. - Developers add the repository and turn Packagist off. See Set up Composer.
- The metadata lists only allowed releases. A package with none allowed is not found, and that opens a request.
- Each release points at one exact commit. ForgeRepo™ fetches that commit's zip once, keeps and scans it, and the metadata it hands out points composer at that copy.
- The git source of each release is taken out, so composer can not fall back to cloning it.
- A release that can not be fetched as a fixed zip is left out: one with only a git source, one pinned to a branch, or a tarball. An archive on an internal address is never fetched.
- Advisories come from OSV. Malware scanning, licenses, the kill switch, auto approve and Cache now all work.
- Branches (dev versions) are not served.