Engine's Composer blocks dependencies that have security advisories

This project's Composer dependencies cannot all be installed together. The full resolver output is in the deploy log.

Seen2 times
WherePhp

Why it happens

The project has no composer.lock, so its dependencies are resolved at deploy time. The Composer version the engine uses refuses package versions with published security advisories, and every version this project allows has one.

What the log looks like

Deploy log
[panelalpha] build: dependencies[panelalpha] composer plugins allowed: composer/installers, drupal/core-composer-scaffold, drupal/core-recipe-unpack, drupal/core-project-message, symfony/runtime; any other plugin is installed but not runNo composer.lock file present. Updating dependencies to latest instead of installing from lock file. See https://getcomposer.org/install for more information.Loading composer repositories with package informationUpdating dependenciesYour requirements could not be resolved to an installable set of packages.Problem 1- Root composer.json requires league/fly…

Try PanelAlpha Engine yourself.

The easiest way to turn your server into a safe, controlled environment for your AI agent. Deploy, manage and maintain any project from Claude Code, Cursor, Codex or any other MCP client. Open source under Apache 2.0, free to run.

Requires Ubuntu 24.04 or 26.04 · 2 GB RAM · 1 CPURead the documentation