Composer 5,243 (https://github.com/composer/composer 29,535 ) (MIT) reads composer.json, resolves every constraint against the Packagist 4,624 (https://packagist.org 4,624 ) registry, downloads the result into vendor/ and writes an autoloader. Ubuntu 26.04 225 's apt install composer gives 2.9.5; the getcomposer.org installer gives 2.10.3, and composer self-update keeps it current.
composer init --no-interaction --name=acme/shop-money --type=library \
--description="Money and currency value objects for the bookshop" \
--author="Ann Author <ann@example.com>" --license=MIT \
--require="php:^8.4" --require="ext-intl:*" --autoload=src/
composer require --dev phpunit/phpunitWriting ./composer.json PSR-4 autoloading configured. Use "namespace Acme\ShopMoney;" in src/ ... Using version ^13.3 for phpunit/phpunit
composer.json now holds the name, license, author, PSR-4 mapping, a require block (php and ext-intl are platform packages, checked against the running PHP) and require-dev with "phpunit/phpunit": "^13.3", never installed for your dependents or under --no-dev.
| Constraint | Means | Typical use |
|---|---|---|
| ^1.2.3 | >=1.2.3 <2.0.0 | the default: non-breaking releases |
| ^0.3 | >=0.3.0 <0.4.0 | 0.x, where a minor may break |
| ~1.2.3 | >=1.2.3 <1.3.0 | only the last digit may grow |
| 3.10.* | >=3.10 <3.11 | patch releases only |
| *, dev-main, ^2.0@beta | any stable, a branch, a beta | extensions, unreleased code |
Stabilities run dev, alpha, beta, RC, stable; minimum-stability (default stable) hides the rest unless an @ flag allows it. composer.lock records the exact version, commit and download URL of all 27 packages the solver chose, plus a content-hash of composer.json. Commit it in applications so every machine installs identical code; a library's lock pins only its own CI. Never commit vendor/.