You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

执行全局Composer命令时在composer.json中使用外部变量

问题:Composer中用外部变量替代私有仓库令牌,避免明文暴露

我需要将分属不同GitHub用户和组织的私有项目引入到一个大型项目中,因此至少需要使用2个GitHub令牌。我找到了一个直接在composer.json中写入令牌的方案,但这样上传到Web服务器时会暴露令牌,存在安全风险。

直接写入令牌的composer.json示例

{
  "require": {
    "organization-name/repository-1": "^1.2",
    "organization-name/repository-2": "^1.2",
    "username/repository-3": "^1.2"
  },
  "repositories": [
    {
      "type": "git",
      "url": "https://github_pat_token-first@github.com/organization-name/repository-1.git"
    },
    {
      "type": "git",
      "url": "https://github_pat_token-first@github.com/organization-name/repository-2.git"
    },
    {
      "type": "git",
      "url": "https://github_pat_token-second@github.com/username/repository-3.git"
    }
  ]
}

需求

如何将令牌替换为变量,并在执行composer install或composer update这类全局Composer命令时声明这些变量?

期望实现的效果示例

外部变量配置(仅为示例):

{
  "firstToken": "token-first",
  "secondToken": "token-second"
}

修改后的composer.json:

{
  "require": {
    "organization-name/repository-1": "^1.2",
    "organization-name/repository-2": "^1.2",
    "username/repository-3": "^1.2"
  },
  "repositories": [
    {
      "type": "git",
      "url": "https://github_pat_${firstToken}@github.com/organization-name/repository-1.git"
    },
    {
      "type": "git",
      "url": "https://github_pat_${firstToken}@github.com/organization-name/repository-2.git"
    },
    {
      "type": "git",
      "url": "https://github_pat_${secondToken}@github.com/username/repository-3.git"
    }
  ]
}

内容的提问来源于stack exchange,提问作者rozsazoltan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 02:12:52