Skip to main content
Home
GrN.dk

Main navigation

  • Articles
  • Cases
  • Services
  • Your Digital Project Manager
  • About Greg Nowak
  • Image Gallery
  • Contact
User account menu
  • Log in

Join my community / free newsletter — sign up here

Breadcrumb

  1. Home
  2. Cases

The boring superpower: a weekly gate that keeps twelve sites' dependencies current

Client
GrN.dk — server fleet (12 production vhosts)
Sector
Maintenance automation / DevOps
Period
July 2026 — ongoing
The gate's weekly fleet report: twelve vhosts with their Drupal core version, web PHP, queued safe bumps and held breaking majors, plus the rule that composer resolves against each site's own web PHP.

At a glance

Twelve production websites on one server, each with its own Composer dependency tree, and the oldest question in hosting: are they up to date, and is it safe to make them so? The dependency-currency gate answers it weekly and automatically — it inventories every vhost, checks each dependency tree against the PHP version that site's web server actually runs, queues the semver-safe updates for approval, and reports the breaking ones instead of applying them.

12 production vhosts scanned weekly; safe bumps queued, majors held for review
Composer resolves against each site's web PHP — the CLI-PHP trap that 500'd two sites is closed by construction
Every apply run snapshots composer.lock + vendor: one command rolls a site back

The challenge

Unpatched dependencies are how sites get owned, but blind composer update is how sites go down — and there is a subtle trap between the two. A server's command-line PHP is often newer than the PHP the web server runs, so an update resolved with the CLI can install packages the live site literally cannot execute. That exact failure — CLI-resolved dependencies that were 8.4-only, on sites serving PHP 8.3 — had already produced HTTP 500s on two live sites here. The fix had to make that class of mistake impossible, not merely less likely.

The solution

A four-phase tool, built as separate approved stages: an inventory of every vhost and its real runtime; a currency check that runs Composer's resolver as each site's own web PHP (lsphp 8.3, not the newer CLI PHP), splitting available updates into semver-safe bumps and breaking majors; an apply stage that snapshots composer.lock and the vendor tree before touching anything, so one command rolls a site back; and a weekly cron that re-runs the check across the fleet and mails the report.

The judgment calls stay human: safe bumps are queued and applied on approval, majors are listed with what they would break, and nothing is ever auto-applied.

The results

The gate has run weekly since mid-July 2026. A typical report: 12 vhosts scanned, a handful of safe bumps queued, zero applied without approval. The two sites broken by the CLI-PHP trap were repaired by re-resolving at their web PHP, and the root cause is now structurally closed — the resolver simply never sees a PHP the live site does not have.

It is the least glamorous case on this page and possibly the most valuable one: the difference between "we should really update those sites sometime" and a Monday-morning email that says exactly what is safe to do.

  • Composer
  • php
  • DevOps
  • Automation
  • Maintenance

Got a project that needs the same kind of hands-on delivery?

Your digital project manager

Review Greg on Google

Greg Nowak Google Reviews

 

Written recommendations from Trafik og Veje, Aarhus Municipality (2011) and AgroTech (2010) — read them on LinkedIn.

Illustrated infographic summarizing: WordPress 7.1 Exposes AI-Ready Actions. Who Gets to Run Them?
WordPress 7.1 Exposes AI-Ready Actions. Who Gets to Run Them?
2026-09-02

WordPress 7.1 helps AI agents discover and invoke site abilities. Here is how to keep exposure, authentication and permission firmly separate.

Illustrated infographic summarizing: From Sales Meeting to CRM: Automate Follow-Up Without Compromising Data Quality
From Sales Meeting to CRM: Automate Follow-Up Without Compromising Data Quality
2026-09-01

How to use AI for meeting notes and follow-up while fixed rules protect CRM data, customer matching and the sales pipeline from errors and premature changes.

Illustrated infographic summarizing: Your AI Gateway Can Name the User. Decide What That Log Is For
Your AI Gateway Can Name the User. Decide What That Log Is For
2026-08-31

Identity-aware AI Gateway logs can sharpen security and cost control, but only when attribution, access, retention, guardrails, and response are clearly defined.

Illustrated infographic summarizing: Zero Data Retention Is a Workflow Audit, Not a Checkbox
Zero Data Retention Is a Workflow Audit, Not a Checkbox
2026-08-30

Zero Data Retention covers the provider, not every copy in your stack. See how to audit endpoints, logs, storage, deletion and project-level controls.

Illustrated infographic summarizing: MCP 2026-07-28 Is an Auth Migration, Not a Version Bump
MCP 2026-07-28 Is an Auth Migration, Not a Version Bump
2026-08-29

MCP’s July 2026 release removes protocol sessions and tightens OAuth. Here’s a practical plan for migrating clients, servers and enterprise access safely.

Illustrated infographic summarizing: Turn a Technician’s Voice Note into a Work Order—Not Raw Audio
Turn a Technician’s Voice Note into a Work Order—Not Raw Audio
2026-08-28

Voice input can reduce the technician’s documentation burden when hours, materials and status are validated before the information is saved in the work order system.

Illustrated infographic summarizing: ChatGPT Disabled Personal Knowledge Sync. What Broke on Your Team?
ChatGPT Disabled Personal Knowledge Sync. What Broke on Your Team?
2026-08-27

ChatGPT retired personal sync connections for Enterprise and Edu. Here is how to find affected workflows, migrate access, and test permissions.

Illustrated infographic summarizing: Cloudflare’s September Bot Defaults Could Quietly Cut AI Visibility
Cloudflare’s September Bot Defaults Could Quietly Cut AI Visibility
2026-08-26

Cloudflare’s September bot defaults give publishers more control, but one training block could also cut search crawling and AI-driven discovery.

Illustrated infographic summarizing: Does Your AI Chatbot Clearly Identify Itself?
Does Your AI Chatbot Clearly Identify Itself?
2026-08-25

The EU’s transparency requirements for AI chatbots now apply. Here is how to make your bot’s identity clear, limit its system access and provide a genuine route to a member of staff.

Illustrated infographic summarizing: Should publishers add Google’s new Preferred Sources button?
Should publishers add Google’s new Preferred Sources button?
2026-08-24

Google’s Preferred Sources button is worth a controlled test for eligible publishers, with careful choices around placement, performance and measurement.

More articles
RSS feed

Footer

  • All articles
  • Contact

GrN.dk — AI automation, web platforms, web optimization, data handling and logistics.

© 2026 GrN.dk · LinkedIn · Contact · AI automation in Danish: nowa.dk

Behind GrN.dk: Individual Entrepreneur Codecrafter · Tax ID 305669096 · Bakhtrioni St. 22, 0194 Tbilisi, Georgia · official business register