0.3.0

Released 2026-09-07

Added

  • Port Composer's 19 install-from-lock installer fixtures (#4)
  • Dependency resolver: viv update and viv require (#10)
  • Scripts: lifecycle and custom (#11)
  • Plugin strategy (#12)
  • path and vcs repositories (#13)
  • viv normalize (#14)
  • composer shim (#15)
  • CI: fail on warm or no-op benchmark regressions (#18)
  • installed.php gaps: root replace/provide, natural sort case, numeric alias check (#28)
  • bin-dir default must derive from vendor-dir (#30)
  • plan: a kept package must exist on disk (#31)
  • store: verify archive completeness with a marker, not directory existence (#32)
  • install: check lock freshness against composer.json (#33)
  • fetch: enforce https (secure-http) and redact URL credentials in logs and errors (#34)
  • lock: reject a package present in both packages and packages-dev (#35)
  • Clean up interrupted-install litter in vendor and add viv cache prune to the CLI (#36)
  • Resolver stage 1: semver facade and PHP-compatible content-hash (#38)
  • Resolver stage 2: Packagist v2 repository client with cache (#39)
  • Resolver stage 3: pool and CDCL solver port (#40)
  • Resolver stage 4: lock writer and dev split (#41)
  • Resolver stage 5: viv require, partial update, problem messages (#42)
  • Native adapter for composer/installers and wordpress-core-installer, refuse unknown plugins (#51)

Fixed

  • viv creates an empty vendor/bin when no package declares a binary (#50)
  • Classmap scanner must skip dot files, dot directories and VCS directories like Symfony Finder (#60)
  • Metapackages with a dist must not be installed (#63)

Tooling

  • Release compatibility sweep against popular and random Packagist projects (#49)