Composer cache on Mac: safe to delete?
Where it is
~/Library/Caches/composer~/.composer/cache
What it is
Composer, the PHP dependency manager, caches downloaded package archives, git clones used for source installs, and Packagist repository metadata so repeat installs can skip the network. Newer versions on macOS use ~/Library/Caches/composer, while older setups keep the cache inside ~/.composer.
Why it gets so big
Every version of every package you've installed is kept, along with repository metadata. Composer garbage-collects old files from time to time, but frameworks with many dependencies still fill it.
Is it safe to delete?
Yes. Your projects' vendor folders are unaffected, and Composer downloads anything it needs again on the next install or update. Composer's own clear-cache command does the same thing.
Tip
Leave the rest of ~/.composer alone: it can hold your global auth.json and globally installed tools.
See how much space it uses
du -sh "$HOME/Library/Caches/composer" "$HOME/.composer/cache" 2>/dev/nullClean it with the tool’s own command
composer clear-cacheDelete it by hand
Run in Terminal. Deleting cannot be undone, so check the paths first.
rm -rf "$HOME/Library/Caches/composer"/*
rm -rf "$HOME/.composer/cache"/*