CycloneDX / CycloneDX/cyclonedx-php-composer
feat: document platform dependencies
- Dominant language
- PHP
- Stars
- 87
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
Extraneous dependencies and platform requirements should be marked as such.
Relevant CycloneDX specification:
- https://github.com/CycloneDX/specification/issues/321
- https://github.com/CycloneDX/specification/issues/233
How this is specified in composer:
> The following types of platform packages exist and can be depended on:
>
> PHP (`php` and the subtypes: `php-64bit`, `php-ipv6`, `php-zts php-debug`)
> PHP Extensions (`ext-*`, e.g. `ext-mbstring`)
> PHP Libraries (`lib-*`, e.g. `lib-curl`)
> Composer (`composer`, `composer-plugin-api`, `composer-runtime-api`)
>
> To see the complete list of platform packages available in your environment you can run `php composer.phar show --platform` (or `show -p` for short).
>
> The differences between the various Composer platform packages are explained further in this document.
Contributor guide
Assessment
This issue has not been assessed yet.