roave/security-advisories is a PHP library that prevents installation of Composer packages with known security vulnerabilities: no API, simply require it. This means that roave/security-advisories keeps known security vulnerabilities out of your project.
roave/security-advisories means you don't have to install and run an additional CLI tool for something that Composer can provide directly.
What does that mean?
roave/security-advisories compiles a list of conflict versions from into a composer metapackage, which has tons of advantages, like:
roave/security-advisories has been downloaded more than 9 million times.
You can learn more about roave/security-advisories in this blog post written by the creator.
roave/security-advisories is available via the Packagist package manager.
and customize specifically for your organization
Verified updates for zero-day vulnerabilities, coordinated security responses, and immediate notifications of which of your applications are impacted, with the fix prepared for you. Like your phone, just "apply updates" to stay secure.
Verified-accurate open source licenses (including IP indemnification) and customizable policy enforcement. Your up-to-date software “bill of materials” is always one click away.
Tidelift continuously guides you on your upgrade path, steering you towards the best packages and versions for your particular application. It’s like a GPS for open source software.