NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #2522 most downloaded on Packagist
Applies a patch from a local or remote file to any package that is part of a given composer project. Patches can be defined both on project and on package level. Optional support for patch versioning, sequencing, custom patch applier configuration and patch command for testing/troubleshooting added patches.
Last release 7 days ago
28 Sep 2026
Release timing varies
gaps range from 2 weeks to 12 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
208 releases · first in 2017
forward-port (3.41.0): allow patcher config overrides per package instead of allowing it only per patch definition (reserved key: '_config'). More on
forward-port (3.40.0): allow patch to target the autoloader root (instead of targeting package root) by configuring 'cwd' key to 'autoload'
One column per quarter.
follow-up to incorrectly released version (4.8.1); no extra changes done
forward-port (3.39.1): patches not applied when dealing with requires that use dev branches (even when version available in package config or when dev
all features and fixes in this release are forward-ported from 3.39.0
all features and fixes in this release are forward-ported from 3.39.0
forward-port (3.38.0): hide all information on previously applied patches by default (when patches for certain package are re-applied) and only show t
forward-port (3.37.1): some patches that patched multiple files applied only half-way through on certain OS's without returning with proper exit code
forward-port (3.37.0): new flag introduced for patch:list to allow including patches that have been ruled out due to mismatch with certain constraint:
forward-port (3.36.0): allow '@type bundle' to be used for bundle package instead of using somewhat cryptic '@package *'
forward-port (3.35.3): backwards compatibility problems with composer.lock contents for projects that upgraded to latest releases of the plugin and ha
forward-port (3.35.2): lock management reworked (again) to make sure that under no circumstances does the plugin crash while sanitizing the lock
forward-port (3.35.1): lock management reworked to use built-in methods for locating a package to avoid issues with potential aliases, etc
forward-port (3.35.0): list command added (allows listing all registered patches and their state)
forward-port (3.34.0): allow patch path strip level to be defined in patch's embedded target-info declaration (@level )
forward-port (3.33.1): improved error reporting when encountering issues on composer lock cleanup
forward-port (3.33.0): allow patch applied root to be configured per patch to allow patching of files that are mapped by other composer plugins to pro
forward-port (3.32.1): definition list validation command returning with false failures when using #skip on patch paths
forward-port (3.32.0): allow comments on any level and with any keyword as long as it starts with underscore (_)
logic: installation/update/applying patches fails on first patch failure (used to be activated by COMPOSER_PATCHES_FATAL_FAIL); old default behavior u
Merge pull request #168 from vaimo/feature/applicable-variable-in-pat…
Merge pull request #168 from vaimo/feature/applicable-variable-in-pat…
bundled patches fail to apply when using patch-mapping configuration due to refactored code in 3.53.2 having messed up argument order used for a sub-f
patch applier crash when branch alias defined for root package (scenario: root-branch-alias) [pull/73]
patches applied before packages properly re-installed with Composer V2 (missed the fact that installations, like downloads are now done in asynchronou
minor issue addressed with V2-style call being in code without version-check (said call is currently backwards-compatible with V1, but you never know
add support for Composer 2 [issues/59]
remote patch availability validation crash under certain package setups
allow global usage of the plugin when explicitly enabled via environment variable: COMPOSER_PATCHER_ALLOW_GLOBAL_USAGE (pull/45)
some errors not properly reported in the 'most likely' errors brief report (for patches with corrupt content)
allow the plugin to be installed as dependency to globally installed package (as part of dependency of some global package); previously caused every c
allow defining OS-specific applier operation without overwriting the default operation value
running 'composer update --lock' not cleaning up composer.lock afterwards when patches already applied. No such issue when no patches applied at all (
loosened dependency on drupol/phposinfo to make sure that the module is installable on all PHP version (latest release of the module is only covering
the command patch:list not usable when some patch configuration included remote patches that would have resulted in 404 errors on apply (now listing s
allow defining sha1 checksum for remote patches through 'sha1' key within JSON definition
needless whitespace in output when using patches-search (extra line for patch label added for no reason)
package configuration and build flow updates
### Maintenance * code quality improvements Links: src diff
allow very precise configuration for specific OS based on OS names in drupol\phposinfo\Enum\OsName
more clear error reporting when encountering patch reversals (failures from log output analysis)
certain behaviour flags incorrectly forced to false (explicit flag) when using redo/undo with no option to override said falsey value
patches validation not failing when there are patch files present without patch target definition in JSON files and using sym-linked patch folder (not
using printf variable syntax in patch descriptions crashed the patch applier
the meta-data @skip tag not perceived properly (this actually affected all tags that had no value)
basePatch templates not being applied after code changes from last release
patch file meta-tags conflict in situations where there are values for all of: depends, package, version; the following setup now results in package+v
patch file meta-tags overwriting each-other rather than stacking (when, say @depends is used multiple times)
added notice to the 'most likely error' output (on patch failure) to indicate that the list presented is not the full list of details
broken compatibility with PHP 5.3 (wrong array syntax used)
highlight most probable error that caused patch to fail in the non-verbose error message (full logs available when running with -vvv); this change was
support for older (<1.1) Composer releases faultily implemented where the availability with CommandsProvider was incorrectly checked for
wrong path used for pre-loading classes while running composer commands when the plugin package used as ROOT
allow platform requirement dependencies on patches a'la php:>=7.2 (previously only package dependencies could be declared); usable with "depends" conf
This release comes basically with re-written logic to the core of the patch apply queue generation due to issues with the old logic. The listing comma
This release comes basically with re-written logic to the core of the patch apply queue generation due to issues with the old logic. The listing command now also uses same code which removes some of the confusion when using apply and seeing something different than what list reports
allow patch:validate to use only patches that the root package owns: --local
Allow declaration of pathces that only apply when owner package is used as ROOT package (README/Patches: local patch)
allow patch file paths, etc to be defined under extra/patcher key to make sure that they don't hog up too much main level keys of 'extra' config for g
additional rollbacks on newer array declaration usage (broke compatibility with 5.3)
rollback on newer array declaration usage (broke compatibility with 5.3)
added more informative patches configuration JSON validation (that gives exact details on what's wrong with the JSON file)
allow patcher config overrides per package instead of allowing it only per patch definition (reserved key: '_config'). More on this under the topic of
Your coding agent can read these notes before it upgrades. Set up the MCP server →