Package uploads are the focus of this release. You can now publish Composer packages from zip archives, without a Git repository, both from the web app and from CI.

New Features

  • Package uploads (#132): Owners and admins can create a package by uploading a zip whose composer.json is at the root or in a single top-level folder. New versions can be uploaded from the package page. Released versions are immutable, while dev versions such as dev-main can be replaced. The package page shows each version's README, size and checksum.
  • Publishing from CI (#132): Organization tokens can now be created with Allow publishing packages. Those tokens can upload new versions of existing uploaded packages through POST /{organization}/api/packages/upload. Existing tokens stay read-only, and php artisan token:create --publish creates a publishing token from the command line.
  • Upload activity: The activity feed now shows each uploaded version, including which user or token uploaded it.

Improvements

  • Upload limits: The maximum archive size (ARTIFACT_MAX_SIZE, default 64 MB) and the per-token upload rate limit (ARTIFACT_UPLOAD_RATE_LIMIT, default 30 per minute) are now configurable. The bundled nginx config accepts request bodies up to 64 MB.
  • Separate package sources: Repository and mirror syncs no longer take over an uploaded package with the same name, and archive cleanup never removes an uploaded package's archives.

Fixes

  • Fixed package names from synced repositories not being validated as plain vendor/package names. Such a name could place archives outside the package's storage folder.