viv update-lock
update --lock's own first-class subcommand: re-derive composer.lock
from itself, without solving or installing. Reach for this after a manual
edit to composer.lock, or to refresh its content-hash after a
non-dependency composer.json change.
Usage
`update --lock`'s own first-class subcommand (#86): re-derive `composer.lock` from itself without solving or installing
Usage: viv update-lock [OPTIONS] [PACKAGES]...
Arguments:
[PACKAGES]... Only these packages (and, with `-w`/`-W`, their dependencies) may change version; everything else stays at its locked version (`Request::UPDATE_*`). Empty means a full update
Options:
-v, --verbose
Raise logging to debug
-w, --with-dependencies
Also allow each listed package's dependencies to update, except ones also directly required by the root `composer.json` (`UPDATE_LISTED_WITH_TRANSITIVE_DEPS_NO_ROOT_REQUIRE`)
--cache-dir <CACHE_DIR>
Store location (default `$XDG_CACHE_HOME/vivace`, or `~/.cache/vivace`)
-W, --with-all-dependencies
Like `-w`, but a dependency directly required by the root `composer.json` may update too (`UPDATE_LISTED_WITH_TRANSITIVE_DEPS`)
--minimal-changes
Prefer already-locked versions over the newest one an update could otherwise pick, for every package not on this update's own literal package list (`Installer::setMinimalUpdate`, `preferred_versions` below)
--offline
Fail fast on any request instead of connecting: install errors, naming every package not already in the store; update solves from cached repository metadata only, erroring on an uncached package. Also set by `COMPOSER_DISABLE_NETWORK` (any value but unset, empty or `0`; Composer's own git-priming `prime` value is not special-cased here, since neither `install` nor `update` touch a git source)
--lock [<LOCK>]
Bare `--lock` re-derives `composer.lock` from itself (content-hash, key order, `fixupJsonDataType`) without solving: `composer update --lock`. `--lock native` solves normally, still writes `composer.lock` unchanged, and additionally writes `viv.lock` beside it (chapter 1's research format, #272, `docs/research.md`). Implied (as `native`) when `viv.lock` already exists beside `composer.lock` and this flag is omitted entirely, so a project that adopted the format doesn't have to keep passing it (#297)
--no-dev
Solve without `require-dev`, but still resolve and record dev packages in the lock (`composer update --no-dev`'s actual behaviour: only `install`'s package selection skips them, not the lock)
--prefer-lowest
Prefer the lowest package versions that satisfy every constraint
--prefer-stable
Prefer stable releases, even when a less stable one would otherwise win the version pick
--dry-run
Solve and print, but don't write `composer.lock`
--bump-after-update [<BUMP_AFTER_UPDATE>]
Increases the lower bound of every root requirement whose package this update just installed or upgraded to a caret constraint on the version it locked (`Composer\Command\BumpCommand`), same rule `config.bump-after-update` applies. Bare `--bump-after-update` bumps both `require` and `require-dev`; `=dev` limits it to `require-dev`, `=no-dev` to `require`. Wins over `config.bump-after-update` when passed
-d, --project-dir <PROJECT_DIR>
Project directory holding `composer.json` [default: .]
--no-scripts
Skip `pre-update-cmd`/`post-update-cmd` and every other root `scripts` listener, including the chained install's own `pre-autoload-dump`/`post-autoload-dump`
--no-plugins
Passed straight through to the chained install (`docs/plugin-strategy.md`)
--no-install
Skip the install step after writing `composer.lock` (`composer update --no-install`): today's `viv update` behaviour
--ignore-platform-reqs
Ignore every platform (`php`/`ext-*`/`lib-*`) requirement in the solve and in the chained install's platform check, as Composer's flag does (#242): the pool then offers versions whose platform requirements this interpreter does not satisfy
--ignore-platform-req <REQ>
Ignore one named platform requirement (`*` glob, repeatable) in the solve and in the chained install's platform check (#242)
--no-blocking
Allows installing a version a known security advisory covers or a package Packagist marks abandoned, instead of blocking it by default (#175, `audit.block-insecure`/`audit.block-abandoned`). Also settable via `COMPOSER_NO_SECURITY_BLOCKING=1`
--metadata-ttl <METADATA_TTL>
Seconds a cached `/p2/` provider file may be served without revalidating it (#191): within the window, a back-to-back `update` makes no metadata requests at all. `0` (the default) always revalidates, matching today's behaviour. Also settable via `VIV_METADATA_TTL` (this flag wins); `--offline` always wins over either
-h, --help
Print help
Reads and writes
- Reads:
composer.json,composer.lock. - Writes:
composer.lock.
Exit codes
Same as viv update: 0 success, 1 a filesystem error or
bad flag, 2 a dependency-resolution failure.