{"record":{"id":"9134904a56288e18","repo":"composer/composer","slug":"advisory-for-name-could-not-be-loaded-as-a-full","errorCode":null,"errorMessage":"Advisory for ${name} could not be loaded as a full advisory from ${getRepoName()}\n${var_export($data, true)}","messagePattern":"Advisory for (.+?) could not be loaded as a full advisory from (.+?)\n(.+?)","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"src/Composer/Repository/ComposerRepository.php","lineNumber":727,"sourceCode":"        // respect available-package-patterns / available-packages directives from the repo\n        if ($this->hasAvailablePackageList) {\n            foreach ($packageConstraintMap as $name => $constraint) {\n                if (!$this->lazyProvidersRepoContains(strtolower($name))) {\n                    unset($packageConstraintMap[$name]);\n                }\n            }\n        }\n\n        $parser = new VersionParser();\n        /**\n         * @param array<mixed> $data\n         * @param string $name\n         * @return ($allowPartialAdvisories is false ? SecurityAdvisory|null : PartialSecurityAdvisory|SecurityAdvisory|null)\n         */\n        $create = function (array $data, string $name) use ($parser, $allowPartialAdvisories, &$packageConstraintMap): ?PartialSecurityAdvisory {\n            $advisory = PartialSecurityAdvisory::create($name, $data, $parser);\n            if (!$allowPartialAdvisories && !$advisory instanceof SecurityAdvisory) {\n                throw new \\RuntimeException('Advisory for '.$name.' could not be loaded as a full advisory from '.$this->getRepoName() . PHP_EOL . var_export($data, true));\n            }\n            if (!$advisory->affectedVersions->matches($packageConstraintMap[$name])) {\n                return null;\n            }\n\n            return $advisory;\n        };\n\n        if ($this->securityAdvisoryConfig['metadata'] && ($allowPartialAdvisories || $apiUrl === null)) {\n            $promises = [];\n            foreach ($packageConstraintMap as $name => $constraint) {\n                $name = strtolower($name);\n\n                // skip platform packages, root package and composer-plugin-api\n                if (PlatformRepository::isPlatformPackage($name) || '__root__' === $name) {\n                    continue;\n                }\n","sourceCodeStart":709,"sourceCodeEnd":745,"githubUrl":"https://github.com/composer/composer/blob/c435d285c9120efdca35696769c72ea9fdcc0466/src/Composer/Repository/ComposerRepository.php#L709-L745","documentation":"Thrown inside the advisory-creation closure during security advisory fetching when a remote advisory cannot be hydrated into a full SecurityAdvisory and partial advisories are not allowed. The data dump is included to aid diagnosis. This signals the upstream repository returned incomplete or malformed advisory data.","triggerScenarios":"When $allowPartialAdvisories is false (the caller requires full advisories) and PartialSecurityAdvisory::create returns only a PartialSecurityAdvisory (missing required fields like patches, sources, or proper linking). The check at line 726 triggers.","commonSituations":"A custom/private packagist-like server returning advisory payloads missing required fields. Composer run with strict advisory settings against a repo whose advisory schema is incomplete. Version skew between Composer and the advisory feed.","solutions":["Inspect the var_export dump in the error to see which fields are missing.","If you control the advisory feed, ensure it returns all fields required for a full SecurityAdvisory.","If you cannot fix the feed, allow partial advisories via the appropriate audit option/config so the loader degrades gracefully.","Verify you are running a Composer version compatible with the feed's advisory schema."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n    $advisories = $repo->getSecurityAdvisories($packages, false);\n} catch (\\RuntimeException $e) {\n    if (str_contains($e->getMessage(), 'could not be loaded as a full advisory')) { /* retry with allowPartialAdvisories=true, or report upstream */ }\n    else { throw $e; }\n}","preventionTips":["Ensure your advisory feed returns all fields required by SecurityAdvisory.","Keep Composer updated to match the feed's schema version.","Allow partial advisories if you can tolerate degraded output."],"tags":["advisories","security","repository","remote-data"],"backgroundTag":null,"analyzedSha":"c435d285c9120efdca35696769c72ea9fdcc0466","analyzedAt":"2026-08-07T18:58:23.525Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}