Purpose
This document provides a transparent, unfiltered analysis of the Provisionr Workspace CLI dependency tree. It is intended for CISOs, security researchers, and procurement teams evaluating supply chain risk for enterprise deployment. We believe transparency builds trust where technology has its own limits. Rather than present a sanitized inventory, this narrative explains why each dependency exists, what architectural constraints we are working within, and what we are doing about it.This document is a companion to the Software Bill of Materials, which provides the formal CycloneDX 1.6 inventory in both human-readable and machine-readable formats.
Distribution Model
Provisionr Workspace CLI is distributed as a compiled PHP binary via Homebrew. The binary bundles all runtime dependencies at compile time. No packages are fetched at install time or at runtime. The application makes outbound HTTPS connections only to the Provisionr API. This means the dependency tree is frozen at build time. End users receive a self-contained binary with no ability to modify, inject, or update individual dependencies post-install.Dependency Overview
The gap between “present” and “invoked” is the central topic of this narrative.
The Composer Replace Mechanism
This is the single most important architectural constraint to understand.What Happens
The CLI framework, Laravel Zero, is designed as a lightweight CLI framework. It deliberately requires only the individualilluminate/* component packages it needs:
laravel/framework package declares that it replaces all illuminate/* packages in its composer.json:
laravel/framework monolith satisfies all illuminate/* requirements. This is standard Composer behavior and cannot be overridden without forking the framework.
The Consequence
Installinglaravel/framework as a monolith pulls in 27 packages that Laravel Zero does not need and our application never calls:
- Email subsystem:
symfony/mailer,symfony/mime,egulias/email-validator,symfony/css-selector,tijsverkoyen/css-to-inline-styles - HTTP server subsystem:
symfony/routing,symfony/http-foundation,symfony/http-kernel,fruitcake/php-cors - Markdown subsystem:
league/commonmark,league/config,nette/schema,nette/utils,dflydev/dot-access-data - Other unused:
doctrine/inflector,league/flysystem,league/flysystem-local,league/uri,dragonmantank/cron-expression, various polyfills
Our Assessment
Risk level: Low, but material for SBOM purposes. While these packages cannot execute without being explicitly called, their presence means:- They appear in automated vulnerability scans (Nessus, Snyk, FOSSA, Dependency-Track). A CVE against
symfony/mailerwould flag in your scan even though the code path is unreachable in our application. - They expand the binary size unnecessarily.
- They introduce license complexity (see: Nette dual-licensing below).
Dependency Provenance Map
Every production dependency traces back to one of 8 directcomposer.json entries. The following map shows the full chain.
laravel-zero/framework (52 transitive packages)
The heaviest direct dependency. It provides the CLI application framework and accounts for the majority of the dependency tree. Directly required by laravel-zero/framework:
Pulled in via laravel/framework monolith (all unused):
provisionesta/datadumper (19 transitive packages)
Provides CSV, JSON, and YAML data export capabilities with diff changelog and manifest features. This is a first-party Provisionr package.laravel/prompts (0 unique transitive packages)
All of its dependencies (symfony/console and chain) are already pulled by laravel-zero/framework.
illuminate/http, illuminate/log, illuminate/validation (0 unique)
These are declared as direct dependencies to make intent explicit, but they are resolved by thelaravel/framework monolith that is already in the tree.
symfony/uid (1 transitive package)
Pullssymfony/polyfill-uuid only.
Supply Chain Risk Assessment
Elevated Attention Items
Unused Network-Capable Packages
The following packages have the technical capability to make network connections or invoke OS-level processes, but are never called by our application:
These packages cannot execute without explicit invocation. PHP does not auto-execute library code simply because it exists on disk. The Laravel Zero framework uses conditional service provider registration — only components with both their package installed and their configuration file present are registered at runtime.
Single-Maintainer / Stale Packages
Dead Polyfills
The application requires PHP 8.4+. The following polyfills backport features from PHP versions the application already requires or exceeds:symfony/polyfill-php80— PHP 8.0 features (4 major versions behind)symfony/polyfill-php83— PHP 8.3 features (1 minor version behind)symfony/polyfill-php84— PHP 8.4 features (current version)symfony/polyfill-ctype—ctypeis standard in PHP 8.4
laravel/framework supports a wider PHP version range than our application.
License Risk
All 88 packages use permissive licenses (MIT, BSD-3-Clause, Apache-2.0). Two packages (nette/schema, nette/utils) are dual-licensed under BSD-3-Clause and GPL-2.0/GPL-3.0. Provisionr elects the BSD-3-Clause license for both, as permitted by Nette’s published licensing terms. This election is documented in the SBOM.
Automated SBOM scanners (FOSSA, Black Duck, Snyk) may flag the GPL option in metadata. The composer.lock reports all available licenses, not the elected one. Security teams should reference this document and the SBOM for the authoritative license election.
CVE Monitoring
When a CVE is published against any dependency listed in the SBOM — including unused transitive dependencies — Provisionr evaluates the following:- Is the vulnerable code path reachable? For the ~58 unused packages, the answer is almost always no.
- Does the CVE affect the version we ship? Checked against
composer.lockpinned versions. - What is the CVSS score and exploitability? Evaluated in context of a compiled CLI binary (no network listener, no user-uploaded content processing).
Recommendations for Security Reviewers
Interpreting Scan Results
If you are scanning the Provisionr Workspace CLI binary or its SBOM with Nessus, Dependency-Track, Snyk, or similar tools, expect the following:- ~88 components will appear in the inventory.
- Nette packages may flag as GPL. See License Elections — BSD-3-Clause is elected.
- CVEs against
symfony/mailer,symfony/routing,league/commonmark,fruitcake/php-cors, or other unused packages should be evaluated as not applicable — the code paths are unreachable. provisionesta/datadumpermay flag asdev-mainin older builds. Current builds pin to a tagged release.
OWASP SAMM Alignment
This dependency narrative supports the following OWASP Software Assurance Maturity Model (SAMM) practices:NIS2 and EU Cyber Resilience Act
For organizations subject to the NIS2 Directive (EU 2022/2555) or preparing for the EU Cyber Resilience Act:- This SBOM satisfies the supply chain transparency requirements under NIS2 Article 21(2)(d) regarding supply chain security.
- The CycloneDX 1.6 JSON artifact is compatible with the machine-readable SBOM requirements anticipated under the Cyber Resilience Act’s vulnerability handling obligations.
- The dependency narrative provides the risk assessment context required for due diligence under both frameworks.