Re: Disable PEAR by default
| From: | Alice Wonder | Date: | Sat, 02 Feb 2019 01:12:44 +0000 |
| Subject: | Re: Disable PEAR by default | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-104007@lists.php.net to get a copy of this message | ||
On 2/1/19 5:08 PM, Alice Wonder wrote:
On 2/1/19 3:06 PM, Peter Kokot wrote:"because that is what composer provides." should be "because that is what composer specifies."Hello, On Fri, 1 Feb 2019 at 12:44, Joe Watkins <krakjoe@gmail.com> wrote:I do not like composer. A problem I have encountered, a project specifies a version for a dependency. That version has vulnerability, developer fixed it in newer release, but composer keeps pulling in the older version because that is what composer provides. And it can be the dependency of a dependency of a dependency. I do not like Composer. Adding a "recognition page" while cutting PEAR off also seems, well, slimy.+1 On Fri, 1 Feb 2019 at 12:35, Sebastian Bergmann <sebastian@php.net> wrote:Thank you Nikita for the pull request for this. With all the respect to PEAR project and people behind it, maybe the PEAR itself should be added to some sort of recognition page in the manual for their involvement and work on the first installer of PHP code and initial move into code reuse, open source PHP libraries, and all that. As time went forward, Composer took over the role of such installer in PHP community.Am 01.02.2019 um 12:27 schrieb Nikita Popov:I would like to suggest that installation of PEAR is disabled by defaultinPHP 7.4. PR: https://github.com/php/php-src/pull/3781+1