Laravel Packages

Heimdall: A Minimum Age Policy for Your Composer Dependencies

Published
Heimdall: A Minimum Age Policy for Your Composer Dependencies image

Most malicious Composer releases get reported and pulled within a day or two of going up. Heimdall, a plugin from Encore Digital Group, takes advantage of that by making your project wait. Set a number of days, and it won't install any version younger than that. The name comes from the Norse watchman who guarded the bridge into Asgard, and the package description carries the metaphor through: the bridge here is the one between Packagist and your vendor/ directory.

Setting a Minimum Package Age

Configuration goes under extra.heimdall in your composer.json. The minimum_age key takes a number of days:

{
"extra": {
"heimdall": {
"minimum_age": 7
}
}
}

Now a package released three days ago won't get installed. Composer falls back to the newest version that's old enough and carries on. If you leave minimum_age out, the plugin does nothing, so there's no policy until you ask for one.

Trusting Vendors and Packages

A flat rule across every dependency is going to annoy you eventually. It stalls your own packages for a week, and it stalls the security patch you actually want today. Heimdall lets you create exceptions by vendor or by individual package:

{
"extra": {
"heimdall": {
"minimum_age": 7,
"trusted": {
"vendors": [
"encoredigitalgroup"
],
"packages": [
"acme/widgets"
]
}
}
}
}

Anything matching a trusted vendor or listed in trusted.packages skips the age check. Everything else still has to wait.

Filtering Before the Solver Runs

Heimdall does its work on Composer's PluginEvents::PRE_POOL_CREATE, which fires before the dependency solver starts. Versions that are too new get dropped from the candidate pool, so the solver never considers them in the first place. You end up with an ordinary install result instead of an error after the fact, and resolution stays deterministic.

Need to skip the policy once? composer install --no-plugins turns Heimdall off along with every other plugin.

Installation

You'll need PHP 8.4 or newer and Composer 2.0 or later:

composer require encoredigitalgroup/heimdall

Composer will ask whether to allow the plugin to run. Say yes, add your extra.heimdall block, and the policy applies from the next install or update onward.

How This Compares to Composer's Own Policies

Composer and Packagist have both tightened up on supply chain security lately. Composer 2.10 introduced a policy config block for security advisories, abandoned packages, and versions flagged as malware. Packagist.org wired in Aikido malware detection and stopped stable versions from being quietly rewritten by re-tagging. Every one of those depends on someone knowing something is wrong first.

A compromised release does most of its damage in the first few hours, before there's an advisory or a malware flag to go on. Heimdall doesn't need either one. All it looks at is the publish date. Packagist makes the same point in its update on Composer and Packagist supply chain security, where a minimum release age shows up on the list of things still to come.

Composer does plan to handle this itself. The config docs already reserve the name minimum-release-age, so you can't use it for a custom policy, and PR #12692 from Viktor Djupsjöbacka adds a cooldown policy for exactly this. As of this writing, it's milestoned for Composer 2.11. Heimdall gets you there sooner, and it runs on Composer 2.0 and up if you're not on the newest release.

You can learn more about this package, get full installation instructions, and view the source code on the Heimdall GitHub repository.

Yannick Lyn Fatt photo

Staff Writer at Laravel News and Full stack web developer.

Sponsored

serpapi logo
SerpApi

The Web Search API for Your LLM and AI Applications

Visit SerpApi

The latest

View all →
Find Unexpected Test Inputs with Fuzz for Pest image

Find Unexpected Test Inputs with Fuzz for Pest

Read article
Laravel Rulebook: Business Rules That Change by Date image

Laravel Rulebook: Business Rules That Change by Date

Read article
Taylor disabled GitHub Issues on most Laravel open-source packages. image

Taylor disabled GitHub Issues on most Laravel open-source packages.

Read article
Exclude Vendor and Default Commands in `php artisan dev` image

Exclude Vendor and Default Commands in `php artisan dev`

Read article
The Laracon Archive image

The Laracon Archive

Read article
Group Adjacent Collection Items in Laravel with chunkBy() image

Group Adjacent Collection Items in Laravel with chunkBy()

Read article