Looking to hire Laravel developers? Try LaraJobs

laravel-agent maintained by nodisrupt

Description
Reports a Laravel app's installed Composer dependencies to NoDisrupt, so its packages can be matched against known vulnerabilities. For apps that can't be versioned remotely (Laravel Cloud, Vapor, Forge, self-hosted).
Last update
2026/10/01 11:34 (dev-main)
License
Downloads
3

Comments
comments powered by Disqus

NoDisrupt Laravel Agent

Reports your Laravel app's installed Composer dependencies to NoDisrupt, so each package can be matched against known vulnerabilities.

A Laravel app can't be versioned from the outside — there's no version header, tag or feed — and on managed hosting (Laravel Cloud, Vapor) there's no server to install a host agent on. This package runs inside the app: it reads what Composer actually installed and posts the list on your app's scheduler. No host access required.

Install

composer require nodisrupt/laravel-agent

Then set two environment values — generate them in NoDisrupt under Monitor → Vulnerabilities → Add the package. On Laravel Cloud / Vapor, set them in the dashboard's environment (not in the repo — NODISRUPT_KEY is a live credential):

NODISRUPT_KEY=<your key>
NODISRUPT_MONITOR_ID=<your monitor id>

That's it. As long as your app's scheduler is running (php artisan schedule:run each minute, or your platform's scheduler — on by default on Laravel Cloud), the agent reports once a day.

Reporting now

php artisan nodisrupt:report-inventory

What it sends

The package name and resolved version of every installed Composer package (dev dependencies flagged as such), read from Composer's runtime InstalledVersions. Nothing else — no code, no environment, no secrets. It POSTs to NODISRUPT_API_BASE/v1/agent/inventory (default https://api.production.nodisrupt.com).

Configuration

Publish the config to change the cadence (hourly, twiceDaily, daily, weekly):

php artisan vendor:publish --tag=nodisrupt-config

License

MIT.