Common causes
- Running composer update on all packages, which makes the solver consider every version
- Still using Composer 1, which needs far more memory than Composer 2
- A small VPS or container with little RAM and no swap
- Wide version constraints like * or >=1.0 that force the solver to load many versions
- Many repositories or old package versions in a private Satis/Packagist mirror
- Running Composer on production servers instead of in CI or locally
How to fix it
- Raise the limit for one run. Run COMPOSER_MEMORY_LIMIT=-1 composer update, or php -d memory_limit=-1 $(which composer) update. This only affects that command, not your website's PHP.
- Upgrade Composer. Check composer --version and run composer self-update (or self-update --2 from version 1). Composer 2 resolves dependencies with a fraction of the memory.
- Update only what you need. Name the packages, such as composer update vendor/package -W, instead of updating everything. Narrower updates are faster and use far less memory.
- Install from the lock file on servers. On production run composer install --no-dev --optimize-autoloader. Installing from composer.lock skips the solver, so it rarely needs much memory.
- Add swap on small servers. If the machine itself runs out of RAM (mmap or fork errors), add swap, for example fallocate -l 2G /swapfile, chmod 600 /swapfile, mkswap /swapfile, swapon /swapfile. Better still, resolve dependencies elsewhere and deploy the lock file.
- Tighten loose constraints. Replace * or open-ended ranges with caret constraints such as ^2.4 in composer.json. Fewer candidate versions means a smaller problem for the solver.
Terminal
composer self-update
COMPOSER_MEMORY_LIMIT=-1 composer update vendor/package --with-all-dependencies
# on production servers
composer install --no-dev --optimize-autoloader How to stop it happening again
- Run composer update locally or in CI and commit composer.lock
- Use composer install on servers, never a full composer update
- Keep Composer itself up to date with composer self-update
- Use caret version constraints rather than * in composer.json