Package manager governance (Composer + npm)
composer install # Install from lock file
composer require vendor/package # Add dependency
composer update vendor/package # Update specific package
composer update without specifying a packagecomposer.lock--dev flag for dev-only dependencies"laravel/framework": "^11.0"npm install # Install from lock file
npm install package-name # Add dependency
npm install -D package-name # Add dev dependency
package-lock.json--save-exact for critical packagesnpm install without lock file in CI# Backend
composer audit # Check for vulnerabilities
# Frontend
npm audit # Check for vulnerabilities
npm audit fix # Fix vulnerabilities (review changes)
npm install -g — no global installs in project contextcomposer global require — no global PHP packages