只读仓库超时本质是git克隆卡死,需配github token、改用https地址、调低git连接超时(如git config --global core.sshcommand "ssh -o connecttimeout=10"),并避免--prefer-source;composer自身timeout对此无效。

只读仓库超时本质是 Git 克隆卡死,不是网络不通
Composer 遇到 git@ 或 https://github.com/xxx 类私有/只读仓库时,超时往往发生在 Cloning into '/path/to/vendor/xxx' 阶段。这不是 packagist 下载慢的问题,而是 Git 协议层连接失败或响应迟缓——比如 SSH 连接被防火墙拦截、GitHub API 限流、或未配 Token 导致 https://api.github.com 请求 403 后重试耗尽超时。
- 先确认卡点:加
-v运行composer install,看最后输出是否停在Cloning或Downloading https://api.github.com/ - 若卡在 SSH(
git@github.com:),优先改用 HTTPS:把composer.json中的仓库地址从"git@github.com:user/repo.git"换成"https://github.com/user/repo.git" - 若卡在 HTTPS 克隆,大概率是 GitHub API 调用失败——必须配 GitHub Token,否则每秒限流 60 次,匿名请求极易超时
GitHub Token 必须配,且权限要对
没 Token 时,Composer 会反复调用 https://api.github.com/repos/user/repo 获取最新 commit 和 ZIP 包地址,但匿名请求很快被限流,导致等待超时。Token 不仅提速,更是绕过限流的关键。
- 生成 Token:GitHub → Settings → Developer settings → Personal access tokens → Generate new token → 勾选
repo权限(public_repo不够) - 写入全局认证文件:
~/.composer/auth.json,内容为:{"github-oauth": {"github.com": "ghp_xxx..."}} - 注意:Token 是明文存本地的,别提交到 Git;CI 环境应通过 secret 注入,而非硬编码
Git 层超时参数要单独调,Composer 的 timeout 不管用
COMPOSER_PROCESS_TIMEOUT 和 --timeout 只控制 Composer 主进程总耗时,对底层 git clone 子进程完全无效。Git 自己有独立超时机制,必须单独配置。
围绕关键发现、作用机制、临床相关性及研究局限性展开讨论。适用于撰写或优化任何生物医学论文的“讨论(Discussion)”部分——包括结果解读、与既往文献关联、阐释意外发现、界定研究局限性,以及撰写结论。当用户输入以下任一指令时也会自动触发该功能: - “write my discussion” - “help me discuss my findings” - “how do I compare to prior studies” - “write the limitations par
- 设 Git 全局连接超时:
git config --global core.sshCommand "ssh -o ConnectTimeout=10 -o ServerAliveInterval=30" - 禁用 Git 的长连接探测(某些内网环境会卡住):
git config --global core.sshCommand "ssh -o ConnectTimeout=5 -o ServerAliveInterval=0" - 强制 Git 走 HTTPS 并跳过证书验证(仅调试用,不推荐生产):
git config --global http.sslVerify false
只读仓库慎用 --prefer-source
--prefer-source 强制走 Git 克隆,哪怕包本身提供 ZIP 分发(--prefer-dist)。对只读仓库来说,这等于主动放弃最快路径,把所有压力都压到 Git 协议上——尤其在 CI 环境无 SSH key、无 Token、DNS 不稳时,基本必超时。
- 默认用
--prefer-dist(下 ZIP),它走 HTTP,受 Composer 的http.timeout控制,也走镜像源(如果仓库支持) - 只在需要调试源码或 patch 修改时才临时加
--prefer-source,且务必配合 Token 和 Git 超时配置 - 检查
composer.json是否硬编码了"preferred-install": "source",这种全局设置在只读场景下风险极高
真正卡住的从来不是 Composer,是 Git 和 GitHub API 的组合延迟。调高 Composer 超时只是掩耳盗铃;盯住 Cloning 日志、配好 Token、调低 Git 的 ConnectTimeout,三者缺一不可。










