As a followup to
MDL-49840, where we switched from composer update to composer install, and started to use the composer.lock files as base for testing environments...
... it's needed to create a Job in the CI servers continuously comparing the current composer.lock with a new one, regenerated using composer update.
1) Decide about which changes to inform about (hashes, versions...). And its periodicity.
2) Decide about how to inform (only once, continuously until fixed...).
3) Implement it
- his should be also verifying that not local repository is ever distributed by error in the .lock file (see