nodisrupt / laravel-agent
Reports a Laravel app's installed Composer dependencies to NoDisrupt, so its packages can be matched against known vulnerabilities. For apps that can't be versioned remotely (Laravel Cloud, Vapor, Forge, self-hosted).
Requires
- php: ^8.1
- illuminate/console: ^10.0 || ^11.0 || ^12.0 || ^13.0
- illuminate/contracts: ^10.0 || ^11.0 || ^12.0 || ^13.0
- illuminate/http: ^10.0 || ^11.0 || ^12.0 || ^13.0
- illuminate/support: ^10.0 || ^11.0 || ^12.0 || ^13.0
Requires (Dev)
- orchestra/testbench: ^8.0 || ^9.0 || ^10.0 || ^11.0
- phpunit/phpunit: ^10.0 || ^11.0
Suggests
None
Provides
None
Conflicts
None
Replaces
None
This package is not auto-updated.
Last update: 2026-10-01 18:35:33 UTC
README
Reports your Laravel app's installed Composer dependencies to NoDisrupt, so each package can be matched against known vulnerabilities.
A Laravel app can't be versioned from the outside — there's no version header, tag or feed — and on managed hosting (Laravel Cloud, Vapor) there's no server to install a host agent on. This package runs inside the app: it reads what Composer actually installed and posts the list on your app's scheduler. No host access required.
Install
composer require nodisrupt/laravel-agent
Then set two environment values — generate them in NoDisrupt under Monitor → Vulnerabilities →
Add the package. On Laravel Cloud / Vapor, set them in the dashboard's environment (not in the
repo — NODISRUPT_KEY is a live credential):
NODISRUPT_KEY=<your key>
NODISRUPT_MONITOR_ID=<your monitor id>
That's it. As long as your app's scheduler is running (php artisan schedule:run each minute, or
your platform's scheduler — on by default on Laravel Cloud), the agent reports once a day.
Reporting now
php artisan nodisrupt:report-inventory
What it sends
The package name and resolved version of every installed Composer package (dev dependencies
flagged as such), read from Composer's runtime InstalledVersions. Nothing else — no code, no
environment, no secrets. It POSTs to NODISRUPT_API_BASE/v1/agent/inventory (default
https://api.production.nodisrupt.com).
Configuration
Publish the config to change the cadence (hourly, twiceDaily, daily, weekly):
php artisan vendor:publish --tag=nodisrupt-config
License
MIT.