composer require --dev phpunit/phpunit:^13.3 installs PHPUnit 13.3.4 79,198 (15 September 2026) into vendor/bin/phpunit. PHPUnit 13 requires PHP 8.4.1 or later, and Pest 5 requires PHP ^8.4 with PHPUnit ^13.3.4 underneath it: a server on 8.2 or 8.3 cannot run the current test stack, one more reason (beside Subsection 4.1.6) why this book targets 8.5. PHPUnit 12 (PHP 8.3+, bug fixes until 5 February 2027) is what the Laravel 13 2,157 skeleton still ships: a composer create-project laravel/laravel on 23 September 2026 gives PHPUnit 12.5.35 (Testing and Deployment). Classes live in src/ (namespace Shop\), tests in tests/, and the configuration in the project root:
<phpunit bootstrap="vendor/autoload.php" cacheDirectory=".phpunit.cache"
failOnWarning="true" failOnDeprecation="true" failOnRisky="true">
<testsuites>
<testsuite name="unit"><directory>tests/Unit</directory></testsuite>
<testsuite name="database"><directory>tests/Database</directory></testsuite>
</testsuites>
<source>
<include><directory>src</directory></include>
</source>
<php>
<env name="DB_DSN" value="mysql:host=127.0.0.1;dbname=shop_test;charset=utf8mb4"/>
<env name="DB_USER" value="shop_test"/>
<env name="DB_PASS" value="change-me"/>
</php>
</phpunit>The failOn* flags make warnings, deprecations and risky tests (no assertion) fail the run. Two suites let you run the fast tests alone (--testsuite unit), <source> marks your code for coverage, and <env> sets variables (commit credentials only for a throwaway test database).