[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"problem-detail-error-engine-s-composer-blocks-dependencies-that-have-security":3},{"stack":4,"error":5,"seoName":6,"seoStack":7,"seo":8,"breadcrumb":10,"titlePrefix":17,"titleAccent":6,"lead":18,"facts":20,"why":35,"log":40,"fix":77,"engine":86,"related":90,"pitch":97},"php","engine-s-composer-blocks-dependencies-that-have-security","Engine's Composer blocks dependencies that have security advisories","Php",{"description":9},"This project's Composer dependencies cannot all be installed together. The full resolver output is in the deploy log.",[11,14,16],{"label":12,"href":13},"App Installations","\u002Fapps",{"label":7,"href":15},"\u002Fapps\u002Fstacks\u002Fphp",{"label":6},"",[19],{"text":9},[21,26,29,31],{"label":22,"value":23,"tone":24,"tooltip":25},"Type","Error","err","An error that occurred in the deployed application. It is not necessarily a PanelAlpha Engine error, but we keep working on improvements so you run into fewer of them.",{"label":27,"value":28},"Seen","2 times",{"label":30,"value":7},"Where",{"label":32,"value":33,"tooltip":34},"Status","In Analysis","Our team will look into this soon, verify the cause and try to fix it in an upcoming release.",{"heading":36,"body":37},"Why it happens",[38],{"text":39},"The project has no composer.lock, so its dependencies are resolved at deploy time. The Composer version the engine uses refuses package versions with published security advisories, and every version this project allows has one.",{"heading":41,"block":42},"What the log looks like",{"header":43,"lines":44},"Deploy log",[45,49,53,57,61,65,69,73],{"segments":46},[47],{"text":48},"[panelalpha] build: dependencies",{"segments":50},[51],{"text":52},"[panelalpha] composer plugins allowed: composer\u002Finstallers, drupal\u002Fcore-composer-scaffold, drupal\u002Fcore-recipe-unpack, drupal\u002Fcore-project-message, symfony\u002Fruntime; any other plugin is installed but not run",{"segments":54},[55],{"text":56},"No composer.lock file present. Updating dependencies to latest instead of installing from lock file. See https:\u002F\u002Fgetcomposer.org\u002Finstall for more information.",{"segments":58},[59],{"text":60},"Loading composer repositories with package information",{"segments":62},[63],{"text":64},"Updating dependencies",{"segments":66},[67],{"text":68},"Your requirements could not be resolved to an installable set of packages.",{"segments":70},[71],{"text":72},"Problem 1",{"segments":74},[75],{"text":76},"- Root composer.json requires league\u002Ffly…",{"heading":78,"steps":79,"block":83},"How to fix it",[80],[81],{"text":82},"Commit a composer.lock created with composer update --no-blocking, or raise the affected requirements in composer.json to versions without advisories.",{"header":84,"lines":85},"Fix by hand",[],{"heading":17,"body":87,"block":88},[],{"header":17,"lines":89},[],{"heading":91,"items":92},"Apps affected",[93],{"title":94,"badge":95,"tone":24,"href":96},"collectiveaccess\u002Fprovidence","2 occurrences","\u002Fapps\u002Fcollectiveaccess\u002Fprovidence",{"heading":98,"body":99,"footNote":100,"docsLabel":101,"docsHref":102},"Try PanelAlpha Engine yourself.","The easiest way to turn your server into a safe, controlled environment for your AI agent. Deploy, manage and maintain any project from Claude Code, Cursor, Codex or any other MCP client. Open source under Apache 2.0, free to run.","Requires Ubuntu 24.04 or 26.04 · 2 GB RAM · 1 CPU","Read the documentation","https:\u002F\u002Fpanelalpha.com\u002Fdocs"]