phive
PHAR Installation and Verification
TLDR
SYNOPSIS
phive command [options]
DESCRIPTION
phive — the PHAR Installation and Verification Environment — manages command-line PHP tools distributed as PHAR archives. It downloads PHARs from a trusted repository, verifies their GPG signatures, and records pinned versions in a project-local phive.xml so they can be reproducibly reinstalled.Typical usage is project-local: phive install phpunit writes the tool into tools/ in the current project. System-wide installs are performed by combining --copy and --target with a directory on $PATH.
PARAMETERS
--copy
Copy the PHAR to the target location instead of symlinking it (needed for shared/system-wide installs).--target DIR
Install the PHAR into DIR. Use this together with --copy for a global install (there is no --global flag).--force-accept-unsigned
Accept PHARs that lack a valid GPG signature (not recommended).--trust-gpg-keys KEYIDS
Pre-trust specific GPG key IDs without prompting.--prefer-offline
Use cached metadata (useful with update).--help
Display help.
COMMANDS
install TOOL[@VERSION]
Install a PHAR tool, optionally pinning to a version constraint (e.g. @^9.5).update [TOOL...]
Update one or more installed tools to their latest compatible versions.remove TOOL
Uninstall a tool and delete its PHAR.reset [TOOL]
Re-download a tool without changing its version pin.status
List installed tools and any drift from the pinned version.outdated
Report tools that have newer versions available.list
List tools known to the configured repository.purge
Remove unused PHARs from the local cache.default
Show or change the default repository configuration.selfupdate
Update the Phive tool itself to the latest release.
INSTALL
CAVEATS
Requires PHP with the phar extension. GPG is used to verify PHAR signatures; missing or untrusted keys will block installation unless explicitly overridden. Tools must be published to the Phive registry (or a custom repository) to be installable by name.
HISTORY
Phive was created for secure phar distribution with signature verification.
