Reference

One page per command, generated from its own --help output so the flags here never drift from the binary.

Global options

Fast composer install from composer.lock

Usage: viv [OPTIONS] <COMMAND>

Commands:
  init           Write a composer.json for a new project and stop (#143): no interactive question flow, defaults inferred from git and the directory. `--require`/`--require-dev` chain into the same resolve/lock/install `viv add` runs (`--no-install` opts out)
  new            Start a project in a directory that doesn't exist yet (#139): a bare directory name runs `init`'s own defaults inside it; a `vendor/package[:constraint]` spec downloads that package's dist as a skeleton and installs it there. `create-project` is Composer's own name, kept as an alias along with its `vendor/package dir constraint` three-positional shape (prefer `vendor/package:constraint` instead) [alias: create-project]
  install        Install packages from composer.lock
  update         Resolve composer.json, write a composer.lock (full or partial update) and install (`--no-install` opts out)
  update-lock    `update --lock`'s own first-class subcommand (#86): re-derive `composer.lock` from itself without solving or installing
  add            Add a dependency to composer.json, resolve it and install (`--no-install`/`--no-update` opt out) [alias: require]
  rm             Remove a dependency from composer.json, resolve the rest and install (`--no-install`/`--no-update` opt out) [alias: remove]
  dump-autoload  Regenerate the autoload files and `vendor/bin` from an already installed `vendor/`, without fetching or linking
  normalize      Normalize composer.json's key order and formatting, a native `composer normalize` (ergebnis/composer-normalize)
  cache          Cache maintenance: prune stale entries, or remove the cache outright
  lock           Lock file maintenance: translate an existing `composer.lock` into chapter 1's `viv.lock` (#273), without re-solving, or merge one as a git merge driver (#275)
  audit          Check installed (or locked) packages for security vulnerability advisories and abandoned packages
  show           List installed packages, or inspect one (`--tree`/`-t` for the require tree)
  tree           `show --tree`'s spelling (#86)
  why            `composer why`/`depends`'s alias (#86): `tree --invert`, listing which installed packages require `package`
  outdated       List installed packages with a newer version available (`show --latest --outdated`)
  validate       Validate a composer.json (and composer.lock) against Composer's own hand-written rules
  x              Install (if needed) and run a package's bin in an isolated, content-hashed env, npx-style (#85)
  run            Run a script, a vendor/bin binary or a PATH command on the project's PHP
  exec           Exec a `vendor/bin` binary with `vendor/bin` prepended to `PATH`
  diagnose       Environment and configuration report to paste into a bug report: cache, auth sources (names only), PHP/git/Composer, platform packages and the plugin decision per lock entry
  workspace      `list` (#276): discover `extra.viv.workspace` members and report inter-member requirements. `init`/`add` (#315): write the aggregate root composer.json from member glob patterns and resolve/install
  php            Download a static-php-cli PHP build and pin `config.platform.php` to it (#337), or list what's already installed
  isolate        Prefix a plugin's bundled dependency tree with php-scoper so it can coexist with the site's own copy of the same library (#351): `<package>` adds it to `extra.viv.isolate` and isolates it, `--rm <package>` removes it and relinks the plain archive, `--list` prints every isolated plugin and its prefix
  completions    Print a shell completion script
  help           Print this message or the help of the given subcommand(s)

Options:
  -v, --verbose                Raise logging to debug
      --cache-dir <CACHE_DIR>  Store location (default `$XDG_CACHE_HOME/vivace`, or `~/.cache/vivace`)
      --offline                Fail fast on any request instead of connecting: install errors, naming every package not already in the store; update solves from cached repository metadata only, erroring on an uncached package. Also set by `COMPOSER_DISABLE_NETWORK` (any value but unset, empty or `0`; Composer's own git-priming `prime` value is not special-cased here, since neither `install` nor `update` touch a git source)
  -h, --help                   Print help
  -V, --version                Print version

Commands

Command What it does
viv init Writes a new project's composer.json and stops, no interactive prompts.
viv new Starts a project from a bare name or a vendor/package skeleton.
viv install Installs the exact versions composer.lock records.
viv update Resolves composer.json, writes the lock and installs.
viv add Adds a dependency to composer.json, resolves it and installs.
viv rm Removes a dependency from composer.json, resolves the rest and installs.
viv dump-autoload Regenerates the autoload files from an already-installed vendor/.
viv normalize Tidies composer.json's key order and formatting.
viv cache Prunes, cleans or reports the size of the shared store.
viv audit Checks installed or locked packages for security advisories and abandoned packages.
viv show Lists installed packages, or inspects one.
viv tree Shorthand for show --tree.
viv why Lists installed packages that require the named package.
viv outdated Flags installed packages with a newer version available.
viv validate Checks composer.json (and composer.lock) against Composer's rules.
viv x Installs and runs a package's binary in an isolated, cached environment.
viv run Runs a scripts entry from the root composer.json.
viv exec Runs a vendor/bin binary with vendor/bin prepended to PATH.
viv php Downloads a static-php-cli build and pins config.platform.php to it.
viv diagnose Prints an environment and configuration report for a bug report.
viv lock Converts, merges or exports a viv.lock/composer.lock pair.
viv workspace Discovers and manages a monorepo's member packages.
viv isolate Prefixes a plugin's bundled dependencies so they stop clashing with the site's own.
viv completions Prints a bash, zsh or fish completion script.

Environment variables

viv's own:

Variable What it does Commands
VIV_METADATA_TTL Same as --metadata-ttl: skip revalidating cached metadata younger than this many seconds; the flag wins when both are set. update, add, rm
VIV_MAX_INFLATED_BYTES Overrides the computed cap on how many bytes a single archive may inflate to, viv's zip-bomb guard. install, update, add, rm
VIV_COMPOSER_PATH Points the composer shim at the real Composer binary, when it isn't first on PATH. the composer shim
VIV_SHIM_STRICT Set to make the composer shim hard-error on an unrecognised command or flag, instead of falling back to the real Composer. the composer shim
VIV_VIA_SHIM Set by the shim itself so install --adopt's own detection can tell it's running under it. install
VIV_PHP_DIST_URL Overrides the static-php-cli build base URL php install fetches from. php install

Composer's own, that viv also reads:

Variable What it does Commands
COMPOSER_HOME Where viv looks for auth.json and config.json. all
COMPOSER_AUTH JSON credentials, merged over the Composer home's and the project's auth.json. all
COMPOSER_DISABLE_NETWORK Any value but unset, empty or 0 acts like --offline. all
COMPOSER_NO_SECURITY_BLOCKING Any value but unset, empty or 0 acts like --no-blocking. update, add, rm
XDG_CACHE_HOME Where viv's store lives, as $XDG_CACHE_HOME/vivace; falls back to ~/.cache/vivace. all
XDG_CONFIG_HOME Falls back into COMPOSER_HOME's own default when neither it nor a legacy ~/.composer is present. all
COLUMNS Terminal width viv show wraps its output to; defaults to 80 when unset or not a number. show, tree, why

COMPOSER_CACHE_DIR is Composer's own cache location variable; viv doesn't read it: use XDG_CACHE_HOME or --cache-dir instead.

Exit codes

0 on success. A dependency-resolution failure (update, add, rm, install, workspace init/add) exits 2, matching Composer's own ERROR_DEPENDENCY_RESOLUTION_FAILED; every other error, including a bad flag, exits 1. audit and validate use their own exit codes to report a finding rather than a failure to run; see each page.