0.13.0
Released 2026-09-15
Changed
- viv is now licensed GPL-3.0-or-later, not MIT. Three native adapters are ports of GPL-2.0-or-later plugins —
drupal/core-composer-scaffoldand both WordPress core installers — so the binary is a derivative work of them and MIT was never a licence it could be distributed under. Theor laterterm in those upstreams is what permits GPL-3.0. Every adapter is kept; the newNOTICE.mdrecords each port, its upstream and its licence, andadapter-drift.ymlnow checks the licence as well as the version so an incompatible port fails rather than ships (#245) -
Usage errors — an unrecognised flag, an unknown subcommand, a missing required argument — now exit 1; exit 2 is reserved for the dependency resolver failing to find a solution. A script that greps for exit 2 to detect a resolver failure previously matched a typo in the command line too (#236)
-
The README speed table is re-measured for this release — 10 corpus projects, four tools including vivacity, from the local mirror — rather than carried forward from 0.11.0 as 0.12.0's was (#248)
Added
--ignore-platform-reqsand--ignore-platform-req=<name>onupdate,requireandremove, and thecomposershim passes both through instead of dropping them, same asinstall/dump-autoloadalready did. On all three, the flag only affects the chained install's autoload write (whethervendor/composer/platform_check.phpgets written); the solve itself still only offers versions the detected platform satisfies, since--ignore-platform-req(s)has no port insrc/solver/solver.rsyet (#231)config.bump-after-update: afterupdateresolves,composer.json's requirements are rewritten up to the versions just locked, as Composer does, so the lock'scontent-hashdescribes the same file Composer's would rather than diverging on every project that sets it (#205)viv validateaccepts-d/--project-dir, like every other project-scoped command, so a script that passes it project-wide no longer needs a special case forvalidate(#234)- Problem messages: a package that exists but conflicts with the root requirement now gets Composer's own wording —
found acme/a[2.0.0] but it conflicts with your root composer.json require (^1.0)— instead of the generic "could not be found in any version, there may be a typo". Theminimum-stabilitybranch is not ported: those versions are filtered a stage earlier, where the reason is not recorded (#152) - The bench harness gains vivacity, another Rust reimplementation of Composer and the closest comparison viv has, as a fourth tool measured alongside Composer and riff; the first corpus run records its four known plugin refusals so a newer vivacity is retried automatically instead of the run silently going stale
- Dependabot opens pull requests for
github-actionsandcargoupdates, auto-merging patch and minor bumps; CI's own action pins (actions/checkout,download-artifact,github-script,taiki-e/install-action) caught up several majors behind (#192, #232)
Fixed
viv rmfor a package that isn't required now names it instead of silently succeeding, and — unlike a normal removal — leavescomposer.jsonuntouched rather than rewriting it for nothing; a deliberate divergence from Composer, which rewrites the file even on a no-op (#241)- stderr diagnostics that told the user to run
composer installorcomposer updatenow sayviv installandviv update(#239) - The
composershim names the argument it did not recognise before falling back to real Composer, instead of silently running Composer and leaving a migrated CI job looking like it used viv when it didn't;VIV_SHIM_STRICT=1makes that fallback a hard error (#230) dump-autoload --apcu-autoloaderreuses the prefix already written invendor/'s autoloader instead of writing a fresh random one on every run, sovendor/is reproducible and a deploy no longer orphans the APCu cache (#237)- A version blocked by a security advisory is reported as blocked, naming
--no-blocking, instead of "could not be found in any version, there may be a typo" (#238) viv validatereports the same publish errors Composer does, such as a missingdescription, and exits 2, instead of exiting 0 on a manifest Composer would reject for publishing (#233)viv runwith no script name errors naming the missing argument instead of listing scripts, and on a project with noscriptssection no longer prints nothing and exits 0;viv run --liston such a project says so (#235)viv cache cleanno longer refuses a cache holding only viv's own metadata, andviv cache pruneno longer deletes the repository-metadata and git-mirror buckets on every run — the bucket list existed twice and knew neither. One list now, and the metadata bucket isrepo-v0/like every other; an existingrepo/is pruned as stale, costing one metadata refetch (#240)- A refused-plugin row in the compat report says
identicalonly alongside the flags that earned it, so the word can no longer be quoted out of context as proof of a plugin-enabled run (#225) - The
roots/wordpress-core-installerandsymfony/runtimeadapters move their pinned upstream to v4.0.0 and v8.1.0 after the weekly drift check flagged them; the ported surface is byte-identical across those ranges, so no fixture changed (#162) - A store test that failed under
cargo test --libraced a sibling test over a process-wide environment variable; a lock now serialises the two. Separately, nextest caps at 8 threads, so several concurrentmake checkruns no longer exhaust memory (#217, #219) - The bench corpus run no longer exits non-zero for known third-party (riff) failures with viv clean, and a mirror recorded before a fix now self-heals instead of needing to be cleared by hand (#220, #221)