home.social

#composerphp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #composerphp, aggregated by home.social.

  1. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  2. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  3. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  4. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  5. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  6. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  7. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  8. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  9. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  10. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  11. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  12. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  13. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  14. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  15. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  16. Fed up with Composer not allowing per-package authentication (it forces per-host authentication).

    So I made a plugin.

    github.com/Laragear/MultiAuth

    Haven't tested it yet on prod, but it *should* work. If not, welp, I'm testing it today on a project.

    #PHP #Programming #ComposerPHP #Coding #Code #SoftwareDevelopment #WebDevelopment

  17. Fed up with Composer not allowing per-package authentication (it forces per-host authentication).

    So I made a plugin.

    github.com/Laragear/MultiAuth

    Haven't tested it yet on prod, but it *should* work. If not, welp, I'm testing it today on a project.

    #PHP #Programming #ComposerPHP #Coding #Code #SoftwareDevelopment #WebDevelopment

  18. Fed up with Composer not allowing per-package authentication (it forces per-host authentication).

    So I made a plugin.

    github.com/Laragear/MultiAuth

    Haven't tested it yet on prod, but it *should* work. If not, welp, I'm testing it today on a project.

    #PHP #Programming #ComposerPHP #Coding #Code #SoftwareDevelopment #WebDevelopment

  19. Fed up with Composer not allowing per-package authentication (it forces per-host authentication).

    So I made a plugin.

    github.com/Laragear/MultiAuth

    Haven't tested it yet on prod, but it *should* work. If not, welp, I'm testing it today on a project.

    #PHP #Programming #ComposerPHP #Coding #Code #SoftwareDevelopment #WebDevelopment

  20. Fed up with Composer not allowing per-package authentication (it forces per-host authentication).

    So I made a plugin.

    github.com/Laragear/MultiAuth

    Haven't tested it yet on prod, but it *should* work. If not, welp, I'm testing it today on a project.

    #PHP #Programming #ComposerPHP #Coding #Code #SoftwareDevelopment #WebDevelopment

  21. My "free stack" for Laragear packages from now onwards, until a better solution is done:

    1. Sell in Gumroad
    2. Zapier to KeyGen.sh to create the license
    3. Zapier an email with the license
    4. Dev uses KeyGen to download the package

    This is the only way that allows me to sell and receive payouts in my country (Chile).

    #PHP #Programming #Laravel #Laragear #Composer #ComposerPHP #Gumroad #Zapier #KeyGenSH #KeyGen #SoftwareDevelopment #WebDevelopment #WebDev

  22. My "free stack" for Laragear packages from now onwards, until a better solution is done:

    1. Sell in Gumroad
    2. Zapier to KeyGen.sh to create the license
    3. Zapier an email with the license
    4. Dev uses KeyGen to download the package

    This is the only way that allows me to sell and receive payouts in my country (Chile).

    #PHP #Programming #Laravel #Laragear #Composer #ComposerPHP #Gumroad #Zapier #KeyGenSH #KeyGen #SoftwareDevelopment #WebDevelopment #WebDev