viv update

Run this when composer.json has changed and you want viv to resolve fresh versions, write composer.lock (a full or partial update, depending on the packages you name) and install them.

Usage

Resolve composer.json, write a composer.lock (full or partial update) and install (`--no-install` opts out)

Usage: viv update [OPTIONS] [PACKAGES]...

Arguments:
  [PACKAGES]...  Only these packages (and, with `-w`/`-W`, their dependencies) may change version; everything else stays at its locked version (`Request::UPDATE_*`). Empty means a full update

Options:
  -v, --verbose
          Raise logging to debug
  -w, --with-dependencies
          Also allow each listed package's dependencies to update, except ones also directly required by the root `composer.json` (`UPDATE_LISTED_WITH_TRANSITIVE_DEPS_NO_ROOT_REQUIRE`)
      --cache-dir <CACHE_DIR>
          Store location (default `$XDG_CACHE_HOME/vivace`, or `~/.cache/vivace`)
  -W, --with-all-dependencies
          Like `-w`, but a dependency directly required by the root `composer.json` may update too (`UPDATE_LISTED_WITH_TRANSITIVE_DEPS`)
      --minimal-changes
          Prefer already-locked versions over the newest one an update could otherwise pick, for every package not on this update's own literal package list (`Installer::setMinimalUpdate`, `preferred_versions` below)
      --offline
          Fail fast on any request instead of connecting: install errors, naming every package not already in the store; update solves from cached repository metadata only, erroring on an uncached package. Also set by `COMPOSER_DISABLE_NETWORK` (any value but unset, empty or `0`; Composer's own git-priming `prime` value is not special-cased here, since neither `install` nor `update` touch a git source)
      --lock [<LOCK>]
          Bare `--lock` re-derives `composer.lock` from itself (content-hash, key order, `fixupJsonDataType`) without solving: `composer update --lock`. `--lock native` solves normally, still writes `composer.lock` unchanged, and additionally writes `viv.lock` beside it (chapter 1's research format, #272, `docs/research.md`). Implied (as `native`) when `viv.lock` already exists beside `composer.lock` and this flag is omitted entirely, so a project that adopted the format doesn't have to keep passing it (#297)
      --no-dev
          Solve without `require-dev`, but still resolve and record dev packages in the lock (`composer update --no-dev`'s actual behaviour: only `install`'s package selection skips them, not the lock)
      --prefer-lowest
          Prefer the lowest package versions that satisfy every constraint
      --prefer-stable
          Prefer stable releases, even when a less stable one would otherwise win the version pick
      --dry-run
          Solve and print, but don't write `composer.lock`
      --bump-after-update [<BUMP_AFTER_UPDATE>]
          Increases the lower bound of every root requirement whose package this update just installed or upgraded to a caret constraint on the version it locked (`Composer\Command\BumpCommand`), same rule `config.bump-after-update` applies. Bare `--bump-after-update` bumps both `require` and `require-dev`; `=dev` limits it to `require-dev`, `=no-dev` to `require`. Wins over `config.bump-after-update` when passed
  -d, --project-dir <PROJECT_DIR>
          Project directory holding `composer.json` [default: .]
      --no-scripts
          Skip `pre-update-cmd`/`post-update-cmd` and every other root `scripts` listener, including the chained install's own `pre-autoload-dump`/`post-autoload-dump`
      --no-plugins
          Passed straight through to the chained install (`docs/plugin-strategy.md`)
      --no-install
          Skip the install step after writing `composer.lock` (`composer update --no-install`): today's `viv update` behaviour
      --ignore-platform-reqs
          Ignore every platform (`php`/`ext-*`/`lib-*`) requirement in the solve and in the chained install's platform check, as Composer's flag does (#242): the pool then offers versions whose platform requirements this interpreter does not satisfy
      --ignore-platform-req <REQ>
          Ignore one named platform requirement (`*` glob, repeatable) in the solve and in the chained install's platform check (#242)
      --no-blocking
          Allows installing a version a known security advisory covers or a package Packagist marks abandoned, instead of blocking it by default (#175, `audit.block-insecure`/`audit.block-abandoned`). Also settable via `COMPOSER_NO_SECURITY_BLOCKING=1`
      --metadata-ttl <METADATA_TTL>
          Seconds a cached `/p2/` provider file may be served without revalidating it (#191): within the window, a back-to-back `update` makes no metadata requests at all. `0` (the default) always revalidates, matching today's behaviour. Also settable via `VIV_METADATA_TTL` (this flag wins); `--offline` always wins over either
  -h, --help
          Print help

Reads and writes

  • Reads: composer.json, the existing composer.lock (for a partial update's untouched packages), the store under $XDG_CACHE_HOME/vivace.
  • Writes: composer.lock, viv.lock (when the project already uses it), and, unless --no-install, vendor/ and the store.

Exit codes

  • 0 — resolved and installed cleanly.
  • 1 — a filesystem, network, or archive error; a bad flag.
  • 2 — the solver found no solution, Composer's ERROR_DEPENDENCY_RESOLUTION_FAILED code.

See also

viv update-lock, viv install, viv add