为何Drupal官方推荐的Composer安装方式使用dev稳定性标记?
Great question—Composer’s stability settings can feel opaque at first, especially when Drupal’s official docs recommend a dev flag that seems counterintuitive for production. Let’s unpack this clearly:
What does --stability dev actually do?
The --stability dev flag tells Composer to allow consideration of development versions of packages when resolving dependencies. It does not force all packages to be installed as dev versions. Instead, Composer will prioritize stable versions by default (thanks to the implicit prefer-stable: true setting in most Drupal Composer templates) and only fall back to dev versions if no stable version meets the project’s dependency requirements.
For the drupal-composer/drupal-project:8.x-dev template, this flag is necessary because the template itself was maintained as a development branch, and some of its required dependencies (like certain Drush versions or Drupal core development tools) may only have been available in dev releases during the Drupal 8 lifecycle.
Is this command only for development environments?
The initial create-project command is meant to bootstrap your project—whether for development or production. However, you’ll want to adjust your workflow for production deployment:
- Never deploy a dev-only state to production: As you noted, dev versions lack security support and may contain untested, unstable code.
- Use
composer install --no-devfor production: This skips installation of dev-specific packages (like testing tools) defined in therequire-devsection ofcomposer.json. - Lock your versions: After setting up your project in development, commit the
composer.lockfile to version control. This ensures production gets exactly the same package versions you’ve tested, avoiding unexpected updates or compatibility issues. - Adjust stability settings long-term: You can set
minimum-stability: stableandprefer-stable: truein yourcomposer.jsonto enforce stable versions by default. This overrides the initial--stability devflag for futurecomposer updatecommands.
Why does Drupal.org recommend --stability dev?
Back when Drupal 8 was actively maintained, the drupal-composer/drupal-project:8.x-dev template was the most up-to-date way to set up a Drupal project with Composer best practices. The dev stability flag was required because:
- The template’s 8.x-dev branch relied on dependencies that hadn’t yet been tagged as stable.
- It allowed compatibility with Drupal core’s own development branches (if you needed to test pre-release features or bug fixes).
- It ensured the template could pull in the latest improvements that hadn’t been rolled into a formal stable release yet.
Final Workflow Recap
- Initialize: Run the official command to bootstrap your project:
composer create-project drupal-composer/drupal-project:8.x-dev my_site_name_dir --stability dev --no-interaction - Configure for stability: Update
composer.jsonto include:"minimum-stability": "stable", "prefer-stable": true - Develop: Use
composer updateas needed, testing all changes thoroughly. - Deploy to production: Commit
composer.lock, then run:composer install --no-dev --optimize-autoloader
内容的提问来源于stack exchange,提问作者Bytech

