🚀 Available for Freelance, Remote, and Full-Time Opportunities. Let's build something amazing together.

News
1 min read

Laravel Vet: Review Composer Code Before It Installs

Laravel Vet is a Composer plugin that analyzes third-party package dependencies for supply chain risks, malicious scripts, and CVE vulnerabilities prior to package installation.

A

Author

2 weeks ago

Supply Chain Security with Laravel Vet

Open-source dependencies power modern web development, but supply chain attacks and package account takeovers have become increasingly sophisticated. Laravel Vet is an automated security gatekeeper that vets every Composer package before it touches your disk.

Pre-Installation Protection

Traditional security checkers run after packages have already been extracted and post-install hooks have executed. Laravel Vet intercepts Composer execution during resolution:

  • Script Hook Verification: Warns when a package attempts to execute arbitrary shell scripts or downloads binaries in post-autoload-dump hooks.
  • Maintainer Reputation Checks: Flags freshly published package versions or sudden ownership reassignments.
  • CVE & Advisory Database Audits: Correlates dependencies with the FriendsOfPHP and GitHub Security Advisory databases.
# Install Laravel Vet globally
composer global require laravel/vet

# Run safe package installation
composer require vendor/cool-package
# [VETTING] vendor/cool-package (v1.2.0)
#  ✓ Maintainer verified: JohnDoe (5 yrs active)
#  ✓ Zero reported CVEs
#  ✓ No suspicious install lifecycle hooks
# [STATUS] Package approved for installation.