se7enxweb / ezupdate
Composer updates and installs, packagist.org browsing and the Composer and Exponential package servers of an Exponential installation, from the admin and the command line
Package info
Type:ezpublish-legacy-extension
pkg:composer/se7enxweb/ezupdate
Fund package maintenance!
Requires
- php: >=7.4
- se7enxweb/ezpublish-legacy-installer: *
Requires (Dev)
None
Suggests
None
Provides
None
Conflicts
None
Replaces
None
README
The package manager for Exponential: Composer, packagist.org, your extensions and your package servers, in the admin and on the command line.
An Exponential installation is a few dozen Composer packages, a few dozen extension directories and a handful of settings that decide which of them run. eZ Update puts all of that on one screen, keeps it honest, and lets you update and install packages from the admin with the same guard rails you would use on the command line: a check that changes nothing, a dry run, a backup confirmation, and Composer's own output as it runs.
Why eZ Update
- See the truth, not a guess.
composer.jsonsays what you asked for,composer.locksays what was resolved,vendor/composer/installed.jsonsays what is on disk, andsite.inisays which extensions actually run. eZ Update reads all four and tells you, package by package, where they disagree. - Update without fear. Updating and installing are off until you switch them on. Every run offers a dry run first, asks you to confirm that a backup exists, runs in the background (no web request time limit), and shows Composer's output live, in colour.
- One tool, two front ends. Everything the admin pages do, the command line does too, with the same settings and the same lists. Runs started on one show up on the other.
- Made for Exponential. It knows extension directories,
ActiveExtensionsandActiveAccessExtensions, the.ezpkgpackage servers the setup wizard uses, and the admin3 design it lives in. - Free software. GPL v2 or later, no service to sign up for, no telemetry: it talks to packagist.org and to the servers you list, nothing else.
Features at a glance
| Overview | Where Composer is and which PHP runs it, whether updating and installing are allowed, a check for updates (composer outdated) that changes nothing, an update dry run, a guarded update, and the recent runs. Cards count the installed packages, the extensions and what needs attention. |
| Installed packages | Every Composer package and every extension directory in one list: the composer.json constraint, the locked and the installed version, the git branch and commit of a working copy, the extension and where it is switched on. Mismatches are named. Filter, search, sort, open a row for details, share a filtered view by its address, download as JSON or CSV. |
| Find packages | Search packagist.org (Exponential extensions by default, any type on request) or every server in composer.json. A package page shows its versions, requirements, license, downloads, source and, when installed, how it was fetched and the state of its git working copy. Install from there. |
| dist or source | Install from release archives (fast) or as git clones with their history, so a package's branch and commit can be read and worked on; or let Composer decide. Per run. |
| Package servers | The Composer repositories of composer.json (packagist.org can be switched off) and the Exponential .ezpkg package servers the setup wizard reads; fetch a .ezpkg into the local package repository. |
| Live runs | Updates and installs run in the background, one at a time. The run page follows Composer's output as it is written; any run can be run again, and a dry run can be run for real. |
| Funding | Who the installed packages ask to be funded by, as composer fund prints it, read from their metadata and .github/FUNDING.yml; as a page, as JSON and as text. |
| Command line | php extension/ezupdate/bin/php/ezupdate.php with status, installed, outdated, search, show, servers, packages, fetch, require, update, jobs, fund. |
Screenshots
| Overview | A package |
|---|---|
![]() |
![]() |
| What needs attention, one row opened | A run, followed live |
![]() |
![]() |
| Find packages | Package servers |
![]() |
![]() |
The pages adapt to the room they get: between the admin's two side panels each package becomes a card (narrow layout).
Quick start
# 1. Install the extension into your Exponential installation composer require se7enxweb/ezupdate # 2. Switch it on (settings/override/site.ini.append.php) # [ExtensionSettings] # ActiveExtensions[]=ezupdate # 3. Refresh the autoloads and the caches php bin/php/ezpgenerateautoloads.php --extension php bin/php/ezcache.php --clear-all # 4. Open the admin: Setup > Updates and packages
Administrators see it at once. To let other roles in, give them the
update/ezupdate policy (look, check, dry run) and, where they may change the
installation, update/manage.
Updating and installing from the admin stay off until you set
[UpdateSettings] AllowUpdate=enabled and AllowInstall=enabled in
settings/override/ezupdate.ini.append.php. The full walk-through is in
doc/INSTALL.md.
Documentation
| Guide | What is in it |
|---|---|
| Installation | Requirements, installing, activating, permissions, first run, upgrading, removing. |
| User guide | Every page of the admin, step by step: checking, dry runs, updating, installing, servers, runs, funding. |
| Installed packages | How the inventory is built, every column and status explained, filters, shareable addresses, the JSON and CSV downloads. |
| Configuration | Every setting of ezupdate.ini, with its default and when to change it. |
| Command line | Every command, its options and what it prints; using it in scripts and cron. |
| Security | What eZ Update may do, what it never does, and how it is guarded. |
| Architecture | Classes, views, templates, the background runs and how to extend it. |
| FAQ | Answers to the questions that come up first. |
| Changelog | What changed in each release. |
| Contributing | How to report a problem, propose a change and send a pull request. |
| Roadmap | What is planned next, and where help is welcome. |
Requirements
- Exponential 6 (the extension also runs on the legacy kernel it grew from).
- PHP 7.4 or later (tested up to PHP 8.5), with
proc_open, andcurlfor fetching pages and packages. - Composer 2 on the server, or a
composer.phar(found on its own; see[ComposerSettings]). - The admin3 design for the best look; admin2 works.
- Runs under PHP-FPM, Apache mod_php and persistent-worker servers such as Exponential Velocity.
Safety in one paragraph
Nothing changes the installation unless an administrator switched it on, chose
it, and confirmed a backup. Composer is started without a shell, with checked
arguments, a time limit and its own COMPOSER_HOME; server addresses must be
https://; every form carries the form token; Composer's output is escaped
before it is coloured. Read doc/SECURITY.md for the details.
Get involved
eZ Update is developed in the open at
github.com/se7enxweb/ezupdate. Bug
reports, ideas, translations and pull requests are welcome: start with
CONTRIBUTING.md. The interface is translated into English and
German; adding a language is one file (translations/<locale>/translation.ts).
License
eZ Update is free software: GNU General Public License v2.0 (or any later version). See LICENSE.md. Copyright 7x and the Exponential community; the extension skeleton is by Serhey Dolgushev (see doc/CREDITS.md).






