Skip to main content
The tools input accepts a comma-separated list of tools to install globally. This is useful for CI-only tools that you do not want to commit to your composer.json.

Basic usage

Supported tools

The following tools can be installed by name:

Tool version specification

Specify a version by appending :version to the tool name:
The version format accepts:
  • Semver — tool:1.2.3 or tool:1.2.3-beta1
  • Major only — tool:1 or tool:1.x (installs latest patch in that major)
  • Major.minor — tool:1.2 or tool:1.2.x (installs latest patch in that minor)

Composer version options

The latest stable Composer is installed by default. You can pin a specific version:
prestissimo and composer-prefetcher are skipped unless composer:v1 is also specified. It is recommended to drop prestissimo and use Composer v2 instead.

Installing arbitrary Composer packages

Any package on Packagist can be installed globally by specifying it as vendor/package. This format accepts the same version constraints as Composer:

Skipping Composer installation

If you do not use Composer in your workflow, specify tools: none to skip its installation:

Default tools on Linux and macOS

pear, pecl, phpize, and php-config are installed by default for all supported PHP versions on Linux and macOS. You do not need to list them in the tools input.

Composer environment variables

Setup-php sets the following Composer environment variables automatically: Override any of these in your workflow’s env block:

Allowing Composer plugins

Composer blocks all plugins by default. Tools installed via the tools input are automatically added to the allow list. If your dependencies include Composer plugins, allow them with COMPOSER_ALLOW_PLUGINS:

Fail-fast behavior

By default (except for composer itself), tools that cannot be set up leave an error message in the logs without interrupting the workflow. Set fail-fast to make the workflow fail instead:
Use the tools input for tools that are only needed in CI. This keeps your composer.json tidy and avoids pulling dev-dependencies into production builds. You can run composer install --no-dev and still have all the tools you need via the tools input.