Commit composer.lock for an application so deployments and CI install the reviewed, reproducible dependency graph. Run composer install in CI rather than an unconstrained composer update, use composer audit, and review lockfile diffs before committing them. Do not commit vendor/.
Installs into .claude/skills of the current project.
Are you the author of Php Tooling?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-php-tooling-330637a3)
Commit composer.lock for an application so deployments and CI install the reviewed, reproducible dependency graph. Run composer install in CI rather than an unconstrained composer update, use composer audit, and review lockfile diffs before committing them. Do not commit vendor/.