laravel-agent maintained by nodisrupt
NoDisrupt Laravel Agent
Reports your Laravel app's installed Composer dependencies to NoDisrupt, so each package can be matched against known vulnerabilities.
A Laravel app can't be versioned from the outside — there's no version header, tag or feed — and on managed hosting (Laravel Cloud, Vapor) there's no server to install a host agent on. This package runs inside the app: it reads what Composer actually installed and posts the list on your app's scheduler. No host access required.
Install
composer require nodisrupt/laravel-agent
Then set two environment values — generate them in NoDisrupt under Monitor → Vulnerabilities →
Add the package. On Laravel Cloud / Vapor, set them in the dashboard's environment (not in the
repo — NODISRUPT_KEY is a live credential):
NODISRUPT_KEY=<your key>
NODISRUPT_MONITOR_ID=<your monitor id>
That's it. As long as your app's scheduler is running (php artisan schedule:run each minute, or
your platform's scheduler — on by default on Laravel Cloud), the agent reports once a day.
Reporting now
php artisan nodisrupt:report-inventory
What it sends
The package name and resolved version of every installed Composer package (dev dependencies
flagged as such), read from Composer's runtime InstalledVersions. Nothing else — no code, no
environment, no secrets. It POSTs to NODISRUPT_API_BASE/v1/agent/inventory (default
https://api.production.nodisrupt.com).
Configuration
Publish the config to change the cadence (hourly, twiceDaily, daily, weekly):
php artisan vendor:publish --tag=nodisrupt-config
License
MIT.