4 ms·
Agreed. Modern PHP development is very similar to Java development (although there are still quirks). I've programmed in PHP professionally for the last 8 years
by MattyRad 8y ago
Agreed. Modern PHP development is very similar to Java development (although there are still quirks). I've programmed in PHP professionally for the last 8 years and can confirm that the language is improved by leaps and bounds. Composer by itself is a joy to use (especially compared to npm). We introduced PHPStan recently and it's basically a magic bug finder, it's fantastic.
- porkloin 8y agoWhile I do think Composer is an awesome improvement for the PHP ecosystem in general, I still find it insane that you cannot run `composer update` on a machine that has less than 1.5G memory allocated to PHP. It is an absolute resource hog, which is problematic for a lot of reasons.
- flanbiscuit 8y agoI really enjoy using Composer as well but my exposure is limited. Does composer do anything for security that npm fails at? The most I've seen is that packages in composer tend to have way less dependencies than npm packages but that's not really a great reason to call it more secure (better, yes, but not ideal). Just wondering if Composer has some security features that I'm not aware of.
- MattyRad 8y agoI'm not aware of any security advantages compared to npm. But one thing that comes to mind is that a while ago npm, by default, did not generate lock files, which is very much a risk concerning deployment and dependency-management in general. It's not an issue any longer, though, both yarn (yarn.lock) and npm (package-lock.json?) generate lock files by default.