Laravel Vet: Review Composer Packages Before Install | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com/public) - [Home](https://www.msaied.com/public)
- [Projects](https://www.msaied.com/public/projects)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [About](https://www.msaied.com/public#about)

           [  Contact](https://www.msaied.com/public#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com/public)
- [ProjectsCase studies](https://www.msaied.com/public/projects)
- [ArticlesEngineering notes](https://www.msaied.com/public/articles)
- [CertificatesCredentials](https://www.msaied.com/public/certificates)
- [AboutHow I work](https://www.msaied.com/public#about)
- [ContactGet in touch](https://www.msaied.com/public#contact)

  [Start a conversation](https://www.msaied.com/public#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com/public)
2. /
3. [Articles](https://www.msaied.com/public/articles)
4. /
5. [Laravel](https://www.msaied.com/public/articles?category=laravel)
6. /
7. Laravel Vet: Review Composer Packages Before They Install

   [Laravel](https://www.msaied.com/public/articles?category=laravel) [Composer Pacakge](https://www.msaied.com/public/articles?category=composer-pacakge) 

 Laravel Vet: Review Composer Packages Before They Install
==========================================================

 Laravel Vet is a new official Composer plugin that intercepts every `composer update`, shows you the code diffs, and records trusted packages in a `vet.json` file — with optional AI agent review built in.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com/public#person) Published 15 Sep 2026 · Updated 17 Sep 2026 · 4 min read

ShareCopy linkCopied

 ![Laravel Vet: Review Composer Packages Before They Install](https://cdn.msaied.com/673/b28242efe2234ba0270b986e508570d2.png) 

  On this page +1. [What Is Laravel Vet?](#what-is-laravel-vet)
2. [Why This Matters Now](#why-this-matters-now)
3. [Installation](#installation)
4. [How the Review Flow Works](#how-the-review-flow-works)
5. [AI Agent Integration](#ai-agent-integration)
6. [The vet.json Format](#the-vetjson-format)
7. [Key Takeaways](#key-takeaways)

 What Is Laravel Vet?
--------------------

Laravel Vet is an official package from the Laravel team that gives you a code-review gate between `composer update` and your `vendor/` directory. It ships as a Composer plugin, so it runs automatically after every install and before every update writes anything to disk. The concept is borrowed directly from `cargo vet` in the Rust ecosystem: every dependency update brings new code into your project, and Vet makes sure someone — or something — has read it first.

Once you mark a package as trusted, Vet remembers it in a `vet.json` file. Future updates only surface what actually changed. A package that nobody has trusted causes Vet to exit with a non-zero status, which is exactly what you need to block an unreviewed dependency in CI.

Vet works with any project that has a `composer.json` — Laravel, Symfony, WordPress, or plain PHP.

Why This Matters Now
--------------------

Every `composer update` silently writes thousands of lines of third-party code into your project. Most teams either audit diffs manually (rarely) or trust Packagist blindly (usually). Supply-chain incidents have made that second option increasingly risky: 2025 and 2026 have already seen malware-blocking policies land in Composer 2.10 and a remote-access trojan shipped inside a popular npm package.

Laravel Vet adds a structured, repeatable review step that fits into your normal workflow.

Installation
------------

Vet requires **PHP 8.4 or later**. Install it as a dev dependency and allow the Composer plugin when prompted:

```bash
composer require laravel/vet --dev

```

Then trust everything currently in `vendor/` to create your baseline:

```bash
./vendor/bin/vet --init

```

This writes a `vet.json` file that records a version and a file-tree hash for each installed package. Commit this file to your repository.

How the Review Flow Works
-------------------------

When you run `composer update`, Vet intercepts the process and lists every package with changed files. If any package is untrusted, Composer exits with an error before writing anything:

```css
ERROR  [1] package is not trusted.
Run [./vendor/bin/vet] in a terminal to pick the ones that you trust.

```

Run `./vendor/bin/vet` to open the interactive review. You can read the diffs yourself and press Space to select packages you trust, or you can let a coding agent do the first pass.

### AI Agent Integration

Vet can hand each changed package to a coding agent already installed on your machine — Claude Code, Codex, Gemini, or opencode. The agent returns one of four verdicts:

- **PASS** — review complete, no attack detected.
- **FAIL** — a specific file and reason are reported (e.g., "reads `.env` and posts it to an unknown host").
- **WARN** — review is incomplete; a file may be too large, contain binary data, or the agent returned no answer.
- **SKIP** — nothing changed or Vet could not read the package files.

Vet pre-selects PASS packages. You review the rest, adjust the selection, and press Enter. The agent's verdict alone does not update `vet.json` — your explicit confirmation does.

The vet.json Format
-------------------

Each trusted entry stores a version and a hash derived from every file in the package:

```json
{
    "schema": 4,
    "require": {
        "carbonphp/carbon-doctrine-types": {
            "version": "3.2.1",
            "hash": "tree-v2:0f158f3b909fc01e691ed5f5121186056232b049031e7d3a914676d49881ece5"
        }
    }
}

```

If a package's files change without a version bump, the hash no longer matches and Vet requires a new review.

Key Takeaways
-------------

- Vet intercepts `composer update` before any files are written to `vendor/`.
- `--init` bootstraps trust for all currently installed packages.
- `vet.json` records version + file-tree hash; commit it to source control.
- AI agents (Claude Code, Codex, Gemini, opencode) can pre-screen diffs for you.
- A non-zero exit on untrusted packages makes Vet useful as a CI gate.
- Vet is currently in beta; behavior may change before the stable release.
- Works with Laravel, Symfony, WordPress, and any `composer.json` project.

For full documentation visit the [Laravel Vet GitHub repository](https://github.com/laravel/vet).

---

*Source: [Laravel News — Laravel Vet: Review Composer Code Before It Installs](https://laravel-news.com/laravel-vet)*

- [Laravel](https://www.msaied.com/public/articles?search=Laravel)
- [Composer](https://www.msaied.com/public/articles?search=Composer)
- [Security](https://www.msaied.com/public/articles?search=Security)
- [Supply Chain](https://www.msaied.com/public/articles?search=Supply%20Chain)
- [Open Source](https://www.msaied.com/public/articles?search=Open%20Source)

 Frequently asked questions 
---------------------------

  What PHP version does Laravel Vet require?Laravel Vet requires PHP 8.4 or later.

   Does the AI agent's PASS verdict automatically update vet.json?No. The agent's verdict is advisory only. You must explicitly confirm your selection in the interactive terminal prompt before Vet writes anything to vet.json.

   Can Laravel Vet be used in a CI pipeline to block unreviewed packages?Yes. Vet exits with a non-zero status when any package is untrusted, which causes a CI build to fail until a developer reviews and approves the changes locally and commits the updated vet.json.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com/public#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com/public#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articleWhat's New in PHP 8.6: Every Feature You Need to Know](https://www.msaied.com/public/articles/whats-new-in-php-86-every-feature-you-need-to-know) [Next articleFilament v4.13.2 Released: Bug Fixes, UI Improvements, and Translation Updates](https://www.msaied.com/public/articles/filament-v4132-released-bug-fixes-ui-improvements-and-translation-updates)  

   On this page
-------------

1. [What Is Laravel Vet?](#what-is-laravel-vet)
2. [Why This Matters Now](#why-this-matters-now)
3. [Installation](#installation)
4. [How the Review Flow Works](#how-the-review-flow-works)
5. [AI Agent Integration](#ai-agent-integration)
6. [The vet.json Format](#the-vetjson-format)
7. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com/public#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/public/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) [ ![](https://cdn.msaied.com/739/2d6897fdcdcf090613f96f72a64b8a78.png)  · 4 min read### MySQL Full-Text Search in Laravel: Indexes, Relevance Scoring, and Boolean Mode

4 Oct 2026 ](https://www.msaied.com/public/articles/mysql-full-text-search-in-laravel-indexes-relevance-scoring-and-boolean-mode) [ ![](https://cdn.msaied.com/738/073696a3fefe18bec825beec5ac658f5.png)  · 4 min read### Laravel Queue Rate-Limited Middleware: Throttling Jobs Without Losing Work

4 Oct 2026 ](https://www.msaied.com/public/articles/laravel-queue-rate-limited-middleware-throttling-jobs-without-losing-work) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com/public#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com/public)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/public/sitemap.xml)
