# Composer Update

> Use when analyze composer update results, detect conflicts, and summarize changelogs of updated dependencies

- Skill: `pekral/composer-update` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add pekral/composer-update`
- Raw SKILL.md: https://api.skillmd.com/api/skills/pekral/composer-update/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Research & Search
- License: MIT
- Author: pekral (https://skillmd.com/u/pekral)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/pekral/composer-update

---


# Composer Update

## Purpose
Analyze dependency updates after `composer update`, detect conflicts, and summarize relevant changes.

---

## Constraints
- Apply @rules/php/core-standards.mdc
- Apply @rules/php/dependency-selection.mdc — this skill primarily *bumps* existing packages (rule out of scope per its *Scope* section), but a bump frequently uncovers an upstream that has been archived or marked abandoned. When that happens, re-run the Activity gate + Compatibility gate against the suggested replacement (or against a fresh search if no replacement is documented) before recommending the migration. Never silently keep an archived / abandoned package in the lockfile just because the bump compiles.
- Output Markdown only

---

## Execution

### 1. Update Context
- Use output from `composer update` if available
- Otherwise compare current `composer.lock` with the previous version

### 2. Detect Updated Packages
- List all added or changed packages
- Include version changes: `old → new`

### 3. Conflict Detection
- Identify dependency conflicts from:
    - composer output
    - version constraint mismatches (`composer.json` vs `composer.lock`)
- Summarize conflicts clearly (package → reason)
- If none: state "No conflicts detected"

### 4. Changelog Extraction
For each updated package:

- Prefer:
    - `vendor/<package>/CHANGELOG*`
- Fallback:
    - repository releases (GitHub/GitLab)
    - package homepage

- Extract:
    - breaking changes
    - new features
    - important fixes

- If unavailable:
    - state "No changelog found"

### 5. Suggested Follow-up
- Recommend relevant checks:
    - run tests
    - `composer validate`
    - `composer audit`

---

## Output Format

Use the template defined in `templates/update-report.md`.
---

## Principles

- Focus on impactful changes, not noise
- Highlight breaking changes first
- Prefer local sources over remote
- Be concise and actionable
- Highlight security-related changes when present

