PHP and Composer
Set up Composer
Point Composer at the ForgeRepo™ repository in place of Packagist, and give it your token.
Add ForgeRepo™ as a repository, turn Packagist off, and save your login once for your machine:
$ composer config repositories.company composer https://packages.example.com/composer $ composer config repositories.packagist.org false $ composer config --global http-basic.packages.example.com your-user-name "$REPO_TOKEN" $ cat composer.json { "name": "acme/shop", "require": { "monolog/monolog": "^3.0" }, "repositories": [{ "packagist.org": false },{ "name": "company", "type": "composer", "url": "https://packages.example.com/composer" }] }
Captured by running these commands against a real ForgeRepo™.
- With Packagist off, every package comes through packages.example.com, and so does its code. Composer never goes to GitHub for it.
--globalsaves the login in your ownauth.json, not in the project. Never commit a token inauth.json.- The user name is yours, and the password is your token.
Then install as usual:
$ composer install ... Updating dependencies Lock file operations: 2 installs, 0 updates, 0 removals - Locking monolog/monolog (3.12.0) - Locking psr/log (3.0.2) Writing lock file Installing dependencies from lock file (including require-dev) Package operations: 2 installs, 0 updates, 0 removals - Installing psr/log (3.0.2): Extracting archive - Installing monolog/monolog (3.12.0): Extracting archive Generating autoload files
Captured by running these commands against a real ForgeRepo™.
Note
A composer.lock made before you switched still points at GitHub. Run composer update once through packages.example.com, and commit the new lock file.