执行全局Composer命令时在composer.json中使用外部变量
问题:Composer中用外部变量替代私有仓库令牌,避免明文暴露
我需要将分属不同GitHub用户和组织的私有项目引入到一个大型项目中,因此至少需要使用2个GitHub令牌。我找到了一个直接在composer.json中写入令牌的方案,但这样上传到Web服务器时会暴露令牌,存在安全风险。
直接写入令牌的composer.json示例
{ "require": { "organization-name/repository-1": "^1.2", "organization-name/repository-2": "^1.2", "username/repository-3": "^1.2" }, "repositories": [ { "type": "git", "url": "https://github_pat_token-first@github.com/organization-name/repository-1.git" }, { "type": "git", "url": "https://github_pat_token-first@github.com/organization-name/repository-2.git" }, { "type": "git", "url": "https://github_pat_token-second@github.com/username/repository-3.git" } ] }
需求
如何将令牌替换为变量,并在执行composer install或composer update这类全局Composer命令时声明这些变量?
期望实现的效果示例
外部变量配置(仅为示例):
{ "firstToken": "token-first", "secondToken": "token-second" }
修改后的composer.json:
{ "require": { "organization-name/repository-1": "^1.2", "organization-name/repository-2": "^1.2", "username/repository-3": "^1.2" }, "repositories": [ { "type": "git", "url": "https://github_pat_${firstToken}@github.com/organization-name/repository-1.git" }, { "type": "git", "url": "https://github_pat_${firstToken}@github.com/organization-name/repository-2.git" }, { "type": "git", "url": "https://github_pat_${secondToken}@github.com/username/repository-3.git" } ] }
内容的提问来源于stack exchange,提问作者rozsazoltan
相关产品推荐
相关产品推荐

