composer.json

composer.json, Version Constraints and the Lock File

Composer 5,243 (https://github.com/composer/composer 29,535 ) (MIT) reads composer.json, resolves every constraint against the Packagist 4,624 (https://packagist.org 4,624 ) registry, downloads the result into vendor/ and writes an autoloader. Ubuntu 26.04 225 's apt install composer gives 2.9.5; the getcomposer.org installer gives 2.10.3, and composer self-update keeps it current.

Creating the package manifest, then adding a development dependencyShell
composer init --no-interaction --name=acme/shop-money --type=library \
  --description="Money and currency value objects for the bookshop" \
  --author="Ann Author <ann@example.com>" --license=MIT \
  --require="php:^8.4" --require="ext-intl:*" --autoload=src/
composer require --dev phpunit/phpunit
Output
Writing ./composer.json
PSR-4 autoloading configured. Use "namespace Acme\ShopMoney;" in src/
...
Using version ^13.3 for phpunit/phpunit

composer.json now holds the name, license, author, PSR-4 mapping, a require block (php and ext-intl are platform packages, checked against the running PHP) and require-dev with "phpunit/phpunit": "^13.3", never installed for your dependents or under --no-dev.

Composer version constraints
Constraint Means Typical use
^1.2.3 >=1.2.3 <2.0.0 the default: non-breaking releases
^0.3 >=0.3.0 <0.4.0 0.x, where a minor may break
~1.2.3 >=1.2.3 <1.3.0 only the last digit may grow
3.10.* >=3.10 <3.11 patch releases only
*, dev-main, ^2.0@beta any stable, a branch, a beta extensions, unreleased code

Stabilities run dev, alpha, beta, RC, stable; minimum-stability (default stable) hides the rest unless an @ flag allows it. composer.lock records the exact version, commit and download URL of all 27 packages the solver chose, plus a content-hash of composer.json. Commit it in applications so every machine installs identical code; a library's lock pins only its own CI. Never commit vendor/.