viv is a Rust reimplementation of Composer that installs from
composer.lock and writes the vendor/ directory Composer would write,
byte for byte. A cold laravel/laravel install from a local package mirror takes 0.30 s against
Composer's 1.58 s, and the compatibility sweep run before every release
finds an identical vendor/ on every project viv installs. Merged as a
git merge driver, composer.lock conflicted 228 times in 355 real merges
under git and 6 times with viv.
It began as a question, whether a person directing coding agents can build a faster drop-in Composer, and that question is answered. The compatible mode is finished and frozen as a control; viv continues as a research vehicle for package-manager design, one measured chapter at a time.
cargo binstall vivace # or: brew install svandragt/tap/vivace
viv install # in a project with composer.json and composer.lockcargo binstall also installs a composer shim next to viv (the Homebrew
formula installs viv only); put the shim first on PATH and your existing
scripts run through viv unedited. If Composer already
wrote vendor/, viv adopts it. You can stop at any point: a vendor/
viv wrote is a valid Composer install, and viv cache clean removes
everything else.
Prebuilt binaries for Linux and macOS, a .deb, a container image and a
GitHub Action are on the releases page
and in the install guide.
The tarballs, the .deb and the Homebrew formula include man pages and
bash, zsh and fish completions; viv completions <shell> prints the script
for any other install.
- Getting started — install, first
install, the
composershim, CI and Docker. - Guides — merging locks without
conflicts, committing
viv.lockalone, a PHP per project, running tools withviv x, workspaces, plugins, prefixing a plugin's bundled libraries withviv isolate, speed, and the reasons for and against. - Reference — every command with
its live
--help, environment variables, exit codes, the files viv reads and writes. - Architecture and research — how it works, the Composer output contract, what a minor release may change, and the research programme with its measurements.
- Releases — the changelog.
viv's contract is that its output matches Composer's byte for byte, and
the compatibility sweep
checks it before every release: on v0.21.0, all 20 install rows of the
pinned corpus and all 10 exported locks are identical, 9 of the 10
resolved locks are identical, and every random-sample project Composer
could install is identical too. One pinned project needs --no-plugins,
for a plugin viv refuses by design.
It stays 0.x; Windows is not supported; a plugin without a native adapter
stops the install with an error naming it.
Reasons not to use viv
has the full list.
Tooling comes from devbox: PHP, Composer and hyperfine for the fixtures and benchmarks.
make install # put viv on your PATH (~/.cargo/bin), refreshing an installed composer shim; make install-shim adds the shim
make check # fmt, clippy, tests, cargo deny, cargo machete, cargo docTo report a bug or ask a question, see the
Support page and
SECURITY.md for anything security-related.
JOURNAL.md is the engineering log; AGENTS.md
is how the project is worked on.
GPL-3.0-or-later. viv ports three Composer plugins whose own source is
GPL-2.0-or-later, so the binary is a derivative work of them and carries
their licence. A few files are vendored from MIT-licensed projects and keep
their original copyright notices. NOTICE.md records every
port, its upstream and its licence.