NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2689 most downloaded on Packagist
Compares composer.lock changes and generates Markdown report so you can use it in PR description.
Last release 3 days ago
05 Oct 2026
Release timing varies
gaps range from 3 weeks to 1.6 years
Some releases are documented
notes for 14 of 33 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
33 releases · first in 2020
--with-platform now also reports platform requirements that come from your dependencies (see Platform requirements ):
--with-platform now also reports platform requirements that come from your dependencies (see Platform requirements):
php still show your own requirements from composer.json, exactly as writtenphp (effective) show the version range required by your project and all locked packages together, so you can see when a dependency raises its minimum PHP version or starts requiring a new extension>=7.2.5 <8.0), so a row only appears when the effective requirement actually changesprovide or replace (for example by symfony/polyfill-mbstring) are skipped, and constraints without a common range show conflicting (N constraints)effective field, and CSV output has a new last column, effective, so existing columns keep their positions--strict and --with-platform, changes in your dependencies' platform requirements now count as changes and set the exit code accordinglyFull Changelog: v2.3.0...v2.4.0
One column per quarter.
Add extension points (see Extensions ):
csv output format--formatpost-composer-diff event lets plugins or your project's composer.json scripts filter or change the reported packages and set the exit code, for example to fail CI on unwanted changesFull Changelog: v2.2.1...v2.3.0
Fix comparing against the wrong composer.lock when run from a subdirectory of a git repository
composer.lock when run from a subdirectory of a git repository| in Markdown tables and special characters in GitHub annotationsgitlab.com--format and --sort values and combining --no-dev with --no-prodThese fixes are also backported to v1.13.1
Full Changelog: v2.2.0...v2.2.1
Add --allow-missing option to ignore missing composer.lock files and treat them as empty.
--allow-missing option to ignore missing composer.lock files and treat them as empty.Add --filter option to restrict output to matching packages
Full Changelog: v2.0.0...v2.1.0
BC Break: Drop support for PHP < 7.2
Full Changelog: v1.13.0...v2.0.0
Fix comparing against the wrong composer.lock when run from a subdirectory of a git repository
composer.lock when run from a subdirectory of a git repository| in Markdown tables and special characters in GitHub annotationsgitlab.com--format values and combining --no-dev with --no-prodFull Changelog: v1.13.0...v1.13.1
Symfony 8 compatibility 🚀
Bug: Flip Bitbucket versions for compare URLs ( #45 ) thx @indykoning
BC break: Refactor internal classes (mostly Formatter and DiffEntry to allow using this package as a library
Formatter and DiffEntry to allow using this package as a library (#43)licenses are now string[] instead of string|null when using json format output🚀 Added support to filter out non-direct dependencies using --direct ( -D ) flag similarly to composer outdated ( #40 ) thx @royduin for the idea
📖 Add new --with-licenses ( -c ) option to display license information for each package change ( #38 thanks @giggsey )
🔗 Return package homepage when repository URL cannot be determined - this should provide better context for packages using custom repositories and Wor
🔗 Return package homepage when repository URL cannot be determined - this should provide better context for packages using custom repositories and WordPress Packagist.
🔧 Upgrade to PHPStan v2
🔗 Improve GitHub compare links to use 3-dot syntax ( #35 ) 💄 Fix Readme typos and ensure PSR-4 compliance ( #33 , #32 thx @szepeviktor )
🔗 Improve GitHub compare links to use 3-dot syntax (#35)
💄 Fix Readme typos and ensure PSR-4 compliance (#33, #32 thx @szepeviktor)
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →