Skip to content

Update starter kit dependencies and upstream tooling - #7

Merged
zacksmash merged 13 commits into
mainfrom
starter-kit-upgrade/20260812-dependencies-chisel
Aug 14, 2026
Merged

zacksmash merged 13 commits into
mainfrom
starter-kit-upgrade/20260812-dependencies-chisel

Conversation

@zacksmash

@zacksmash zacksmash commented Aug 12, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • update direct Composer and Node dependency constraints to their current compatible releases
  • adopt Laravel Multiplex for composer dev, with Octane when its configured runtime is available and Laravel's built-in server as the portable fallback
  • add Chokidar 5 as a direct development dependency for Octane watch mode
  • retain the existing well-known passkey endpoint and make it follow the passkey Chisel selection
  • restore Laravel's one-shot Chisel installer for registration, email verification, 2FA, passkeys, and password confirmation
  • make the package fully compatible with laravel new --using=zacksmash/summit
  • keep Passport, MCP, Octane, teams, and oxlint as mandatory starter-kit features

Why

This repository is a reusable Laravel Vue starter kit rather than an existing application. It should begin new projects with current dependencies and inherit useful upstream starter-kit behavior without overwriting its team, Passport, Octane, and tooling customizations.

The previous composer setup workflow assumed a specific local machine: it initialized Git, required Herd, installed a platform-specific FrankenPHP binary, installed Playwright browsers, and reset the database. It also did not generate Passport keys during Laravel Installer project creation. The setup is now split into a portable default and explicitly optional local tooling.

Chisel runs during project creation, removes unselected auth source, tests, migrations, and Node packages, refreshes generated Wayfinder and Composer lock metadata, then deletes its own installer files, source-only contract test, and hook.

Developer impact

  • laravel new my-project --using=zacksmash/summit now creates the environment and SQLite database, generates application and Passport keys, runs migrations, and invokes Chisel through Laravel's installer hook.
  • composer setup is safe and portable for a direct clone; it no longer initializes Git, requires Herd, or runs migrate:fresh.
  • composer setup:octane installs the optional FrankenPHP runtime.
  • composer setup:tools initializes Git when needed, then installs the opinionated Octane, Whisky, IDE Helper, Playwright, and Herd HTTPS tooling.
  • composer setup:tools formats the completed project and creates an Initial commit; Whisky's pre-commit hook must pass before that commit succeeds.
  • composer dev uses Octane when the configured runtime exists and otherwise falls back to php artisan serve.
  • Octane --watch has Chokidar available for Swoole and RoadRunner; FrankenPHP continues to use Octane's native watcher.

Notable decisions

  • TypeScript remains at ^6.0.3 because TypeScript 7 currently breaks vue-tsc through an unexported typescript/lib/tsc entry point.
  • The root Composer and npm lockfiles were regenerated locally but remain uncommitted because this repository excludes them through .git/info/exclude.
  • Local Chisel hardening also removes 2FA factory/model metadata, its request and response classes, and feature-specific tests when 2FA is deselected.
  • Octane is optional because its native server requirements are platform-specific; Laravel's default server keeps generated projects immediately runnable everywhere Laravel supports.

Verification

  • source repository: 94 tests, 364 assertions
  • composer lint
  • composer types:check
  • composer validate --strict
  • npm run format
  • npm run lint
  • npm run types:check
  • npm run build
  • Chokidar 5 loaded through Octane's watcher script and detected a disposable file change with polling
  • FrankenPHP started successfully with php artisan octane:start --watch
  • disposable generated project initialized Git, installed Whisky hooks, passed the Whisky pre-commit checks, created an Initial commit, and finished with a clean worktree
  • starter-kit baseline regression comparison passed
  • disposable Chisel outputs passed PHP tests, Vue type checks, and production builds for:
    • all auth features
    • no optional auth features
    • passkeys without 2FA
    • 2FA without passkeys
  • remote composer create-project from this branch passed the full Composer lifecycle, generated application and Passport keys, ran every migration, built assets, removed Chisel's one-shot files, and selected the portable dev server without an Octane runtime
  • generated application: 91 tests, 338 assertions; Vue type check passed
  • Laravel Installer's deferred-hook lifecycle passed with LARAVEL_INSTALLER_DEFER_HOOKS=1
  • Laravel Installer's --no-node lifecycle passed with LARAVEL_INSTALLER_NO_NODE=1 and did not create node_modules

Upstream: laravel/vue-starter-kit@bccddd6, laravel/vue-starter-kit@d167a29
Files updated (manual merge): composer.json, package.json
Files kept as-is: app/Providers/AppServiceProvider.php (existing Octane dev command registration), concurrently (Windows fallback)
Upstream: e86668f, c1e23aa, d61b61d, 70f7ba3, 9753ec7, f491c6c

Manually merged Chisel boundaries into the customized Fortify, teams, passkey, Vue, and Pest files. Preserve Passport, MCP, Octane, teams, and oxlint as mandatory starter features.

Also remove local 2FA factory/model/test/request/response artifacts when 2FA is deselected and refresh Composer lock metadata after Chisel removes its own hook.
@zacksmash
zacksmash marked this pull request as ready for review August 14, 2026 20:49
@zacksmash
zacksmash merged commit 786efb7 into main Aug 14, 2026
3 checks passed
@zacksmash
zacksmash deleted the starter-kit-upgrade/20260812-dependencies-chisel branch August 14, 2026 20:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant