misaf / vendra
The skeleton application for the Vendra framework.
Requires
- php: ^8.3
- api-platform/laravel: ^4.3
- api-platform/mcp: ^4.3.14
- awcodes/filament-badgeable-column: ^4.0
- bezhansalleh/filament-language-switch: ^5.0
- bezhansalleh/filament-panel-switch: ^3.1
- cknow/laravel-money: ^8.5
- filament/filament: ^5.6.8
- filament/spatie-laravel-google-fonts-plugin: ^5.6.8
- filament/spatie-laravel-media-library-plugin: ^5.6.8
- filament/spatie-laravel-settings-plugin: ^5.6.8
- filament/spatie-laravel-tags-plugin: ^5.6.8
- filament/support: ^5.6.8
- flowframe/laravel-trend: ^0.5.0
- illuminate/console: ^13.0
- illuminate/contracts: ^13.0
- illuminate/database: ^13.0
- illuminate/http: ^13.0
- illuminate/support: ^13.0
- lara-zeus/spatie-translatable: ^2.0.1
- laravel/framework: ^13.19
- laravel/horizon: ^5.47.2
- laravel/pennant: ^1.24
- laravel/prompts: ^0.3.21
- laravel/pulse: ^1.7
- laravel/sanctum: ^4.3.2
- laravel/tinker: ^3.0.2
- mcp/sdk: ^0.6
- misaf/filament-jalali: ^5.1.4
- misaf/laravel-authify-log: ^1.0.2
- misaf/laravel-email-validation: ^1.0
- misaf/laravel-email-validation-emailable: ^1.0
- misaf/laravel-email-webhooks: ^1.0.1
- misaf/vendra-activity-log: v1.10.0
- misaf/vendra-address: v1.10.0
- misaf/vendra-affiliate: v1.10.0
- misaf/vendra-affiliate-api: v1.10.0
- misaf/vendra-api: v1.10.0
- misaf/vendra-attribute: v1.10.0
- misaf/vendra-attribute-api: v1.10.0
- misaf/vendra-authify-log: v1.10.0
- misaf/vendra-blog: v1.10.0
- misaf/vendra-blog-api: v1.10.0
- misaf/vendra-cart: v1.10.0
- misaf/vendra-cart-api: v1.10.0
- misaf/vendra-currency: v1.10.0
- misaf/vendra-custom-page: v1.10.0
- misaf/vendra-custom-page-api: v1.10.0
- misaf/vendra-document: v1.10.0
- misaf/vendra-faq: v1.10.0
- misaf/vendra-faq-api: v1.10.0
- misaf/vendra-language: v1.10.0
- misaf/vendra-localization: v1.10.0
- misaf/vendra-multimedia: v1.10.0
- misaf/vendra-multimedia-api: v1.10.0
- misaf/vendra-newsletter: v1.10.0
- misaf/vendra-permission: v1.10.0
- misaf/vendra-phone: v1.10.0
- misaf/vendra-product: v1.10.0
- misaf/vendra-product-api: v1.10.0
- misaf/vendra-socialite: v1.10.0
- misaf/vendra-subscription: v1.10.0
- misaf/vendra-support: v1.10.0
- misaf/vendra-tagger: v1.10.0
- misaf/vendra-tenant: v1.10.0
- misaf/vendra-testing: v1.10.0
- misaf/vendra-transaction: v1.10.0
- misaf/vendra-user: v1.10.0
- misaf/vendra-user-profile: v1.10.0
- misaf/vendra-verification: v1.10.0
- owenvoke/blade-fontawesome: ^3.3
- spatie/eloquent-sortable: ^5.0.1
- spatie/laravel-activitylog: ^5.0
- spatie/laravel-medialibrary: ^11.23.2
- spatie/laravel-multitenancy: ^4.1.3
- spatie/laravel-package-tools: ^1.93.1
- spatie/laravel-permission: ^8.0
- spatie/laravel-queueable-action: ^2.17
- spatie/laravel-sluggable: ^4.0.2
- spatie/laravel-translatable: ^6.14.1
- spatie/laravel-translation-loader: ^2.8.3
- spatie/laravel-webhook-client: ^3.6.3
- staudenmeir/belongs-to-through: ^2.18
- staudenmeir/eloquent-has-many-deep: ^1.22.1
- staudenmeir/laravel-adjacency-list: ^1.26.1
- stijnvanouplines/blade-country-flags: ^1.0.9
- symfony/finder: ^8.1.1
- symfony/mcp-bundle: 0.10.0
Requires (Dev)
- ergebnis/composer-normalize: ^2.52
- fakerphp/faker: ^1.24.1
- fruitcake/laravel-debugbar: ^4.4.0
- larastan/larastan: ^3.10.0
- laravel/boost: ^2.4.12
- laravel/pail: ^1.2.7
- laravel/pao: ^1.1.2
- laravel/pint: ^1.29.3
- misaf/vendra-developer-logins: v1.10.0
- mockery/mockery: ^1.6.12
- nunomaduro/collision: ^8.9.4
- orchestra/testbench: ^11.1
- pestphp/pest: ^5.0
- pestphp/pest-plugin-arch: ^5.0
- pestphp/pest-plugin-laravel: ^5.0
- pestphp/pest-plugin-livewire: ^5.0
- pestphp/pest-plugin-profanity: ^5.0
- pestphp/pest-plugin-type-coverage: ^5.0
- phpstan/extension-installer: ^1.4.3
- symplify/monorepo-builder: ^12.7.1
README
Vendra is a modular Laravel 13 application for commerce, content, customer management, and multi-tenant platform development. This repository contains the host application and every first-party Vendra package in one Composer monorepo.
Requirements
- PHP 8.3+
- Laravel 13
- Composer
- Node.js and npm
- MySQL or another Laravel-supported database
Local Development
composer setup composer dev
composer setup installs PHP and JavaScript dependencies, creates .env,
generates the application key, runs migrations, and builds frontend multimedia.
composer dev starts the web server, queue listener, logs, and Vite in watch
mode.
Package Catalog
Packages are independently installable through Composer and are auto-discovered by Laravel unless their README says otherwise.
| Area | Packages |
|---|---|
| Foundation | Support, API, Tenant, Testing |
| Standalone dependencies | Email Validation, Emailable Driver |
| Catalog and sales | Product, Attribute, Currency, Cart, Transaction, Subscription |
| Content and marketing | Blog, Custom Page, FAQ, Multimedia, Tagger, Newsletter, Affiliate |
| Customers and access | User, User Profile, Address, Phone, Document, Verification, Permission, Socialite |
| Operations and localization | Activity Log, Authify Log, Developer Logins (development only), Language, Localization |
| API Platform modules | Affiliate API, Attribute API, Blog API, Cart API, Custom Page API, FAQ API, Multimedia API, Product API |
Domain packages depend on the provider-neutral contracts in Vendra Support. Installing Vendra Tenant activates tenant awareness by binding the concrete resolver; domain and API packages do not depend on the tenant provider.
The host exposes the package-owned API Platform resources below /api and
publishes OpenAPI documentation at /api/docs. Frontend code should use the
dedicated window.api fetch client configured in resources/js/bootstrap.js.
Domain endpoints use /api/{admin-navigation-group}/{model-resource} so the
public API follows the Filament admin structure, for example
/api/catalog/products.
Docker
The docker/Dockerfile builds the production image (FrankenPHP,
Composer install from the committed lock file, Vite asset build). Pushing a
MAJOR.MINOR.PATCH tag publishes linux/amd64 and linux/arm64 images to
ghcr.io/misaf/vendra (:1.0.0, :1.0, :latest).
Host lifecycle and storefront containers are owned by the standalone Go
controller at vendra-controller.
Operators need only Docker and its vendra binary; this Laravel repository
contains no Compose stack or Docker-socket integration.
Laravel stores tenant and storefront business state. Its queued provisioning,
retry, and reconciliation workflows call the controller's authenticated
POST /v1/storefronts API. Configure that boundary with
STOREFRONT_PROVISIONER_URL and STOREFRONT_PROVISIONER_TOKEN.
Module Development
Modules are developed locally through symlinked Composer path repositories in
packages/*.
Typical workflow:
- Edit the module inside
packages/<module-name>. - Ensure the package is required in root
composer.json. - Run
composer update <vendor/package>orcomposer dump-autoloadwhen needed. - Run the package's tests and static analysis as documented in its README.
For production builds, rely on installed Composer packages rather than local path repository workflows.
See UPGRADING.md before changing the host application's Vendra release line.
Documentation and AI Guidance
Every package maintains the same documentation set:
README.mdis the user-facing contract for features, requirements, installation, usage, and package-level checks.resources/boost/guidelines/core.blade.phpcontains concise, always-loaded package boundaries and invariants.resources/boost/skills/*/SKILL.mdcontains the on-demand workflow and implementation guidance for that package.
Keep these files aligned with composer.json, the package source, and its
tests. Describe optional integrations as optional, do not document behavior
that is not implemented, and update all affected layers in the same change.
The root AGENTS.md, CLAUDE.md, and .agents/skills files are generated by
Laravel Boost and may be refreshed with:
php artisan boost:update --no-interaction
Testing
- Run the smallest relevant test scope first, then expand to broader suites only when necessary.
- Use
php artisan test --parallelby default for targeted tests and full suites to minimize feedback time. - Omit
--parallelonly when debugging a failure, investigating race conditions or concurrency issues, using shared mutable state or external resources that cannot be isolated, or when the execution environment does not support parallel testing. - Keep intentionally non-parallel coverage, profiling, mutation testing, and benchmarking commands unchanged unless parallel execution is clearly safe.
php artisan test --parallel --compact php artisan test --parallel --compact --filter=testName vendor/bin/pint --dirty --format agent composer stan
Troubleshooting
- If package changes are not reflected, run
composer dump-autoload. - If provider discovery seems stale, run
php artisan package:discover. - If configuration values look outdated, run
php artisan config:clear. - If frontend changes do not appear, run
npm run devornpm run build.
License
MIT. See LICENSE.