Abubakar Siddiq Ango – GitLab Demo: Using GitLab Composer Repository To Manage PHP Dependencies
Join Abubakar Siddiq Ango, Technical Evangelism Program Manager at GitLab, and he demonstrates how to use GitLab Composer Repository to manage PHP dependencies
Transcript
Hi. Thank you very much for joining me on how you can manage your PHP dependencies with Composer Repositories from GitLab because there is no need to add good luck in this thing. We'll be showing you how you can publish your lab projects into the Composer Repository Registry that was recently introduced in GitLab fifteen point two and also how you can avoid being used as dependencies in subsequent projects.
Yeah, how obviously used to see is basically how to publish your projects into the registry and how you can use them. So I have two projects already created for the purpose of this demo. The first one is a composite package that I've already created and the seven projects will consume the package I've created to show you how it works.
So for the purpose of this, they will be using the DSU API to get a quote of the day to basically ith al the codes records and the author of the code. So let me show you out of my comfort zone package project, not first to the most important aspect of any Pocono's. I predict the percentages.
In fact, this is where you specify everything about the package, what dependencies has the most elaborate licenses and so on what issue of how basically what how the package is built is simply have a single class called code. And within this class we can call the keyholder, which is set up to the code of the method, adding to returns to us after making an API call to the API. It returns to us.
It calls other parts of the code. That's basically what the package does not. Also, once you've created your composite, agisting five, everything is acceptable to you.
The next thing is to create a structure to move on. Now there are two parts to my CFR here. The first one is why at this stage is basically for me to run new companies out there to get all the necessary packages that I need, all the necessary dependencies for my packages, and also see if everything's working fine.
I have a test file which basically calls the positive response. So you get any bug I can see from here. But the most important part of my CFR is this Polish section.
This is where it publishes my package to get in those countries a repository. No, you don't necessarily need to wrap your head around how this was constructed. People are already provided as part of the template.
For example, if I got everything here and I come to the list of templates, they will have this this year and I enter composer games, just silly for me and pretty predefined decades of how you can publish your composer package to the registry. You don't necessarily need to edit anything here if there are any uses, all the variables that is required to publish your package. Now basically, why dossier's to use this call to publish the package to the EPA?
The API for the package companies are endpoints and normally you should you do this yourself, but it does everything for you is to not let me read on my my normal CFR. So like I said previously, basically what I'm doing here is to test my package first to make sure everything is working fine. Then the next thing is to publish.
And I'm only publishing whenever a month is done to muster. Now, that's all I need to do here, so let's see, for example, I'd say to Ron. I decide to run my pipeline so that it publishes my application running on.
Here and your packages will be published on that. If you go to the middle of Gitlow on the left, we have packages and registries. Then you go to a package registry.
So I will wait for this trial and issue quickly. Here you see, we have a different package which is composed by the AMPM gates. And by then this is for composer.
This is the one that I just published that it's published was this is a previously published I was the CI is done and if I get any new updates, it's going to updated. Now let's see what it looks like now. This was published two hours ago and it was published.
Dash must have French. You can decide to use the tag black version one or whatever it is for here. I'm choosing to use the master branch now.
It's showing me how to use it here. If you want to use this particular package in your computer industry, you need to copy this particular path into your entry and you must mention it to your composable disinfo and you must mention the package. No.
They see the progress of our pipeline. So basically here everything writes Donitz, is simply checks on those companies, our and it's my testifier, which basically displeased the court and the court. Now, in this project I have, which is the project that is consuming the packet, to use my page here, agreed to compose a digital file specifying the repository I want to perform, just like it was shown in the package details earlier and required the package I want to use.
And if you notice here, I specify the package name I could. That's dependent on how you specify it in the way you're creating the package. And I specify what version I'm using, which is Def Mustoe.
That's the name of the Brutsch now was a specified of this. Then I created a. The CI will file in my CI file, I do two things at first.
The first one is to set up the authentication that composer will use to authenticate with the Composer Repository Registry now. And you can do that by using composer config, specify what configuration is going to modify and compose as config and specify that you should use the repository. Dates will be polyfoam.
And if you remember in my scenario with a specified a user and a token, this token be your private access token. They've created some settings, especially when you are using Twitter feed. You cannot use your normal password.
Now, the next thing I do here is to run through. The object was composed as authenticated. Yeah, updates my dependencies and I proceeded to test my application using index, which is now my index few files quite similar to the tests that speechify in my package.
And all it does is to require the power to use the code plus from the package and display code. And if there's an arrow to display an but basically I wanted to see what was said and so on, no less. That's basically what my this project is doing now.
m. My ultimate customers are already what's being done for it to be to right for the phone call, which means for everyone. Oh awesome.
Our job is finished. As you can see here, the change we need. He's here, it says, quote of the day when Brownlow's said, we don't have to do all of it.
Never means to. I hope you enjoyed this demo and look forward to you using more of the composer Position in GitLab. Thank you very much for joining the this session bye.