ActionRank

Install PHP Dependencies with Composer

Stale

ramsey/composer-install · MIT

A GitHub Action to streamline installation of PHP dependencies with Composer.

259 starsLast commit 3 months agoLatest 4.0.0
C
55
/ 100
Security 56Maintenance 57Popularity 46Reliability 58

Security signals

OpenSSF Scorecard2.7 / 10
SECURITY.md presentYes
Immutable releasesEnabled
Known vulnerabilitiesNone on record

How to use it safely

Recommended: pin to commit SHA
uses: ramsey/composer-install@65e4f84970763564f46a70b8a54b90d033b3bdda # 4.0.0

Mutable tags like 4.0.0 can be rewritten to point at malicious commits. Pinning to the full commit SHA is the only reference GitHub guarantees immutable.

Full workflow example
steps:
  - uses: ramsey/composer-install@65e4f84970763564f46a70b8a54b90d033b3bdda # 4.0.0

Score breakdown

Security (35%)56
Popularity (20%)46
Maintenance (30%)57
Reliability (15%)58

Add this badge to your README

ActionRank grade badge for Install PHP Dependencies with Composer
Markdown
[![ActionRank](https://actionrank.dev/api/badge/ramsey-composer-install)](https://actionrank.dev/actions/ramsey-composer-install)
HTML version
HTML
<a href="https://actionrank.dev/actions/ramsey-composer-install"><img src="https://actionrank.dev/api/badge/ramsey-composer-install" alt="ActionRank score"></a>

Free to use, no attribution required — the badge updates itself as the score changes. How badges work

Get alerts for Install PHP Dependencies with Composer

We'll email you only if Install PHP Dependencies with Composer becomes abandoned or a new advisory is published. Unsubscribe any time. How we handle your address