Answer
The most reliable way to keep dev dependencies out of CI vendor trees while preserving them for local work is to run composer install with the --no-dev flag in the CI environment. This can be done automatically by setting the environment variable COMPOSER_FLAGS=--no-dev (or by invoking composer install --no-dev directly in your CI script).
Explanation
What config.platform-dev does: It controls which PHP platform packages Composer pretends to have installed; it does not affect the require-dev section. Changing it to false therefore does not skip dev dependencies.
How --no-dev works: When Composer sees this flag it ignores every package listed under require-dev in composer.json and does not write them to composer.lock or install them. The autoloader is generated only from production classes.
Why an environment variable is useful: By exporting COMPOSER_FLAGS=--no-dev on the CI runner, every composer install (or composer update) call inherits the flag without touching the repository configuration. Local developers keep their usual workflow because the variable is absent in their shells.
Steps for a typical CI pipeline
- Ensure the CI environment defines
COMPOSER_FLAGS=--no-dev (e.g., in the pipeline YAML or as a secret).
- Run the standard Composer command:
composer install --prefer-dist --optimize-autoloader
The flag from COMPOSER_FLAGS is appended automatically.
- If your CI jobs need testing tools (PHPUnit, CodeSniffer, etc.), add a separate step after the main install:
composer require --dev phpunit/phpunit squizlabs/php_codesniffer
or run composer install --dev in an isolated stage.
Considerations & missing detail
The only factor that could change this recommendation is whether your CI pipeline must execute tests that depend on dev‑only packages. If those tests are essential and cannot be moved to the require section, you will need a dedicated dev‑install step as shown above. Please confirm: Does your CI need to run any test or tooling that relies on packages listed under require-dev?