Composer-cve-gate – pre-install gate for Composer, built after Laravel-Lang
Composer-cve-gate is a pre-install gate designed to enhance security for Composer by blocking potentially vulnerable packages before installation. It checks packages against multiple vulnerability signals, ensuring that malicious code does not run on the user's machine. This tool is particularly useful in preventing issues that can arise from Composer's post-install scripts, which can execute arbitrary code immediately after download.
- ▪Composer-cve-gate blocks installations of vulnerable packages before any code is executed.
- ▪It checks against various vulnerability databases including OSV.dev, GitHub Advisory Database, and NIST NVD.
- ▪The tool includes a freshness hold that prevents the installation of packages published less than 72 hours ago.
Hacker News (Newest) files mainly under programming. We currently carry 5,306 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | GitHub |
| Canonical URL | https://github.com/sharkyger/composer-cve-gate |
| Publication time | Mon, 25 May 2026 09:34:20 +0000 |
| Retrieval time | 2026-05-25T09:37:36.550Z |
| Last seen | 2026-05-25T09:37:36.550Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | 6QK5Gp_Xm2ZN |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
composer-cve-gate Pre-install / pre-upgrade CVE gate for Composer. Blocks before post-install scripts run. Most of the time composer require is fine. Sometimes it isn't — and when it isn't, the damage is usually done by the time composer audit flags it, because audit runs after post-install scripts. composer-cve-gate adds two subcommands that resolve the full transitive tree, check every package against multiple vulnerability signals, and block the install before any code touches your machine. What it checks OSV.dev — Google's aggregated vulnerability feed, native Packagist coverage. GitHub Advisory Database — composer ecosystem, version-range filtered. NIST NVD — keyword + CPE-version match for upstream CVEs. Packagist freshness hold — packages published less than 3 days ago are held.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.