chez14 / lib
Framework-agnostic PHP library template with PHPUnit, PHP-CS-Fixer, phpcs and GitLab CI.
Requires
- php: ^8.3
Requires (Dev)
- chez14/phpcs: ^1.0.5
- friendsofphp/php-cs-fixer: ^3.95
- phpunit/phpunit: ^12.5 || ^13.4
- squizlabs/php_codesniffer: ^3.13
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is auto-updated.
Last update: 2026-10-04 11:19:44 UTC
README
Boilerplate for framework-agnostic PHP libraries. Zero runtime dependencies, hosted on GitLab, published to Packagist.
Quick start
composer create-project chez14/lib my-library
A setup script runs at the end and asks for the package name, namespace, description and author. It rewrites composer.json, the namespaces, LICENSE and this README, then deletes itself.
Not on Packagist yet? Point Composer at the repo instead (add -s dev if there are no tags):
composer create-project chez14/lib my-library \
--repository='{"type":"vcs","url":"https://gitlab.com/net.christianto/templates/php-lib-vanilla"}'
What's inside
| Tool | Purpose | Command |
|---|---|---|
| PHPUnit | Tests, in tests/ | composer test |
| PHP-CS-Fixer | Formatting (@PER-CS, .php-cs-fixer.dist.php) | composer lint:style / composer lint:fix |
| phpcs | Coding rules (chez14/phpcs: docblocks, no ternaries) | composer lint:rules |
| GitLab CI | Lint, tests + coverage on PHP 8.3-8.5, auto-tag, publish | .gitlab-ci.yml |
| dependabot-gitlab | Weekly dependency MRs | .gitlab/dependabot.yml |
composer lint runs PHP-CS-Fixer (check only) and phpcs; composer check runs lint and tests together, same as CI.
The template itself ships every file, so create-project gives you the full skeleton. The setup script then writes a .gitattributes into your new project that keeps tests/, docs/, CI and tooling config out of release tarballs.
Releasing
Auto-release is off by default. Nothing is tagged or released until you opt in, so you can push a new repository without publishing anything.
What it does once enabled: every merge to the default branch tags the next version from Conventional Commits (fix: patch, feat: minor, ! major) using autotag, pushed with the CI job token. The release job then creates the GitLab release with glab in the production environment.
Turning it on
- Allow the job token to push tags: Settings > CI/CD > Job token permissions > allow Git push requests.
- Add a project access token (role Maintainer, scope
api) asGITLAB_TOKEN, scoped to theproductionenvironment so only the release job sees it.glabreads it to create the release:glab variable set GITLAB_TOKEN --scope production --masked(it prompts for the value; use
--repo group/projectoutside the checkout) - Flip the switch:
glab variable set AUTO_RELEASE trueOr add
AUTO_RELEASE=trueunder Settings > CI/CD > Variables. Delete the variable or set it to anything buttrueto turn it off again.
Packagist is kept up to date by GitLab's built-in Packagist integration (Settings > Integrations > Packagist). Submit the package on Packagist once and enable that integration.
CI/CD variables
| Variable | Needed | Notes |
|---|---|---|
AUTO_RELEASE | to release | Must be true to run auto-tag and release. Not defined in .gitlab-ci.yml, so unset means off |
GITLAB_TOKEN | to release | Project access token for glab. Scope it to environment production |
Skipping
Add [skip-release] to a commit message to skip the release for that commit, or [skip-ci] to skip all jobs. They are defined as .dont-run-on-skip-release and .dont-run-on-skip-ci in .gitlab-ci.yml; pull them into a job with - !reference [.dont-run-on-skip-ci, rules].
Dependabot
dependabot-gitlab is configured in .gitlab/dependabot.yml. Register the project in your dependabot-gitlab instance to activate it.