viv 0.15 to 0.21

viv 0.15 to 0.21

It's been a while since I last wrote about Vivace, my Composer alternative (a PHP package manager). There have been seven releases since, so let's get you up to speed.

The goalposts of the project have shifted a little. Viv started as a viability test to see if rewriting Composer in Rust would bring benefits. When that turned out to be the case, I wanted it to become a faster Composer with a few extra features. Viv 0.14 is the ultimate version of that, and it's very fast.

I'm now more interested in what else is possible: if we are not beholden to Composer's lock file and vendor setup, and just want to build a correct, working PHP application from the dependencies provided, what else can we do?

Using viv, you are no longer affected by these common developer gotchas:

Automatic conflict resolution (0.20)

If you've worked with Composer for any length of time with two or more coders, you've encountered lock merge conflicts.

I've analysed 355 merge conflicts from real projects I've been involved in, and all but 6 now merge automatically without losing compatibility with Composer. The remaining 6 mostly involve packages or commits that no longer exist.

viv lock merge introduces a git merge driver, and there's a viv.lock lock file, versioned alongside Composer's, that adds the information needed to make this possible. Even without it, the majority of merges resolve cleanly.

PHP versioned projects (0.19)

viv php install downloads a self-contained PHP build and pins it to the project. This means you can run the installed tooling (viv run phpcs) and isolated external tools (viv x phpunit/phpunit:^11) on the project's PHP version with zero setup.

A global PHP install is no longer needed.

Dependency isolation (0.21)

Many WordPress plugins ship their own copy of libraries like Guzzle or the AWS SDK. When the site installs a different version of the same library, Composer installs both without complaint, and whichever loads first wins; the other plugin breaks at runtime. Viv warns you when this happens, and also provides a solution: viv isolate <package>.

This prefixes the namespaces of the plugin's bundled libraries and updates the autoloader, so both versions can be used at the same time, with no manual changes needed.

The rest

There's a bunch of other things that have changed; have a look at the changelog.

You can try viv and stop using it without affecting your project: it's either Composer-compatible or it stops.

Constructive feedback requested, positive or critical.

#projects #vivace