viv update-lock

update --lock's own first-class subcommand: re-derive composer.lock from itself, without solving or installing. Reach for this after a manual edit to composer.lock, or to refresh its content-hash after a non-dependency composer.json change.

Usage

`update --lock`'s own first-class subcommand (#86): re-derive `composer.lock` from itself without solving or installing

Usage: viv update-lock [OPTIONS] [PACKAGES]...

Arguments:
  [PACKAGES]...  Only these packages (and, with `-w`/`-W`, their dependencies) may change version; everything else stays at its locked version (`Request::UPDATE_*`). Empty means a full update

Options:
  -v, --verbose
          Raise logging to debug
  -w, --with-dependencies
          Also allow each listed package's dependencies to update, except ones also directly required by the root `composer.json` (`UPDATE_LISTED_WITH_TRANSITIVE_DEPS_NO_ROOT_REQUIRE`)
      --cache-dir <CACHE_DIR>
          Store location (default `$XDG_CACHE_HOME/vivace`, or `~/.cache/vivace`)
  -W, --with-all-dependencies
          Like `-w`, but a dependency directly required by the root `composer.json` may update too (`UPDATE_LISTED_WITH_TRANSITIVE_DEPS`)
      --minimal-changes
          Prefer already-locked versions over the newest one an update could otherwise pick, for every package not on this update's own literal package list (`Installer::setMinimalUpdate`, `preferred_versions` below)
      --offline
          Fail fast on any request instead of connecting: install errors, naming every package not already in the store; update solves from cached repository metadata only, erroring on an uncached package. Also set by `COMPOSER_DISABLE_NETWORK` (any value but unset, empty or `0`; Composer's own git-priming `prime` value is not special-cased here, since neither `install` nor `update` touch a git source)
      --lock [<LOCK>]
          Bare `--lock` re-derives `composer.lock` from itself (content-hash, key order, `fixupJsonDataType`) without solving: `composer update --lock`. `--lock native` solves normally, still writes `composer.lock` unchanged, and additionally writes `viv.lock` beside it (chapter 1's research format, #272, `docs/research.md`). Implied (as `native`) when `viv.lock` already exists beside `composer.lock` and this flag is omitted entirely, so a project that adopted the format doesn't have to keep passing it (#297)
      --no-dev
          Solve without `require-dev`, but still resolve and record dev packages in the lock (`composer update --no-dev`'s actual behaviour: only `install`'s package selection skips them, not the lock)
      --prefer-lowest
          Prefer the lowest package versions that satisfy every constraint
      --prefer-stable
          Prefer stable releases, even when a less stable one would otherwise win the version pick
      --dry-run
          Solve and print, but don't write `composer.lock`
      --bump-after-update [<BUMP_AFTER_UPDATE>]
          Increases the lower bound of every root requirement whose package this update just installed or upgraded to a caret constraint on the version it locked (`Composer\Command\BumpCommand`), same rule `config.bump-after-update` applies. Bare `--bump-after-update` bumps both `require` and `require-dev`; `=dev` limits it to `require-dev`, `=no-dev` to `require`. Wins over `config.bump-after-update` when passed
  -d, --project-dir <PROJECT_DIR>
          Project directory holding `composer.json` [default: .]
      --no-scripts
          Skip `pre-update-cmd`/`post-update-cmd` and every other root `scripts` listener, including the chained install's own `pre-autoload-dump`/`post-autoload-dump`
      --no-plugins
          Passed straight through to the chained install (`docs/plugin-strategy.md`)
      --no-install
          Skip the install step after writing `composer.lock` (`composer update --no-install`): today's `viv update` behaviour
      --ignore-platform-reqs
          Ignore every platform (`php`/`ext-*`/`lib-*`) requirement in the solve and in the chained install's platform check, as Composer's flag does (#242): the pool then offers versions whose platform requirements this interpreter does not satisfy
      --ignore-platform-req <REQ>
          Ignore one named platform requirement (`*` glob, repeatable) in the solve and in the chained install's platform check (#242)
      --no-blocking
          Allows installing a version a known security advisory covers or a package Packagist marks abandoned, instead of blocking it by default (#175, `audit.block-insecure`/`audit.block-abandoned`). Also settable via `COMPOSER_NO_SECURITY_BLOCKING=1`
      --metadata-ttl <METADATA_TTL>
          Seconds a cached `/p2/` provider file may be served without revalidating it (#191): within the window, a back-to-back `update` makes no metadata requests at all. `0` (the default) always revalidates, matching today's behaviour. Also settable via `VIV_METADATA_TTL` (this flag wins); `--offline` always wins over either
  -h, --help
          Print help

Reads and writes

  • Reads: composer.json, composer.lock.
  • Writes: composer.lock.

Exit codes

Same as viv update: 0 success, 1 a filesystem error or bad flag, 2 a dependency-resolution failure.

See also

viv update, viv lock