Support
Where to report what
- A crash or wrong behaviour: open a bug report. Paste the output of
viv diagnose; it names auth sources but never prints secrets. vendor/orcomposer.lockthat differ from Composer's: open a compatibility report with adiff -rof the two trees.- A security problem: follow SECURITY.md and report privately.
- Anything else, questions included: open a blank issue. There is no discussion board.
How long to expect
One person maintains viv. Expect an acknowledgement within a week. Bugs that make viv write something Composer would not write come first; see Compatibility and scope for what viv promises to match.
What holds across releases
viv stays in the 0.x series; no 1.0 is planned. A minor release may add commands, change progress wording or get faster. It may not change the bytes of vendor/, composer.lock or the plain-text output of show, why and validate that Composer's pinned version would write for the same input, unless it fixes a bug in an earlier release's output. Each release states which Composer version it targets. The full contract is docs/stability.md.
If the maintainer stops
viv is GPL-3.0-or-later: the source, the test corpus and the compatibility sweep are all in the repository, so anyone can build, fix and release it. vivacity is an independent implementation checked against the same Composer, so the approach does not rest on one codebase or one maintainer.