viv validate

Catches a malformed composer.json, or a lock file that's out of sync with it, before you commit it, against Composer's own hand-written rules.

Usage

Validate a composer.json (and composer.lock) against Composer's own hand-written rules

Usage: viv validate [OPTIONS] [FILE]

Arguments:
  [FILE]  Path to the `composer.json` file to validate (default: `composer.json` in the current directory). Combining this with `--project-dir` is an error: a `FILE` picks the manifest, `--project-dir` picks the directory `FILE` and `composer.lock` both default from, and giving both leaves it ambiguous which lock the freshness check should read

Options:
  -d, --project-dir <PROJECT_DIR>  Run as though invoked from this directory (#234): `composer.json`, `composer.lock` and (with `--with-dependencies`) `vendor/` all resolve from here instead of the current directory [default: .]
  -v, --verbose                    Raise logging to debug
      --cache-dir <CACHE_DIR>      Store location (default `$XDG_CACHE_HOME/vivace`, or `~/.cache/vivace`)
      --no-check-all               Skip the unbound-version-constraint warning
      --check-lock                 Check the lock file is up to date even when `config.lock` is off (vivace has no `config.lock` support, so this only affects the error/warning split, not whether the check runs)
      --offline                    Fail fast on any request instead of connecting: install errors, naming every package not already in the store; update solves from cached repository metadata only, erroring on an uncached package. Also set by `COMPOSER_DISABLE_NETWORK` (any value but unset, empty or `0`; Composer's own git-priming `prime` value is not special-cased here, since neither `install` nor `update` touch a git source)
      --no-check-lock              Don't check whether the lock file is up to date
      --no-check-publish           Don't check for publish errors: a missing `description`, or a name that isn't lower-cased-with-dashes. For an application that will never be on Packagist
  -A, --with-dependencies          Also validate the `composer.json` of every installed dependency
      --strict                     Exit non-zero for warnings too, not just errors
      --fix                        Apply every finding that has one unambiguous fix (#262), then re-run validation and report what's left. Composer has no equivalent flag
  -h, --help                       Print help

Reads and writes

  • Reads: composer.json (or the FILE/--project-dir you name), composer.lock.
  • Writes: with --fix, rewrites composer.json (through the normalizer) and, if its content-hash was stale, composer.lock.

Exit codes

  • 0 — no errors or warnings (or --fix left none).
  • 1 — warnings only, or --strict escalating any finding to failing.
  • 2 — errors found.
  • 3 — the file wasn't found or wasn't valid JSON.

See also

viv normalize