home.social

#composerphp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #composerphp, aggregated by home.social.

fetched live
  1. Packagist turns 15 🎉

    On September 27, 2011, monolog/monolog became package ID 1. Today Packagist lists more than 469,000 packages, and Composer has installed packages from it more than 200 billion times.

    Our anniversary post covers how it all started, 15 years of milestones, the growth we've seen in 2026, and what comes next for supply chain security and funding.

    blog.packagist.com/15-years-of

    #php #phpc #composerphp #opensource

  2. Packagist turns 15 🎉

    On September 27, 2011, monolog/monolog became package ID 1. Today Packagist lists more than 469,000 packages, and Composer has installed packages from it more than 200 billion times.

    Our anniversary post covers how it all started, 15 years of milestones, the growth we've seen in 2026, and what comes next for supply chain security and funding.

    blog.packagist.com/15-years-of

    #php #phpc #composerphp #opensource

  3. Packagist turns 15 🎉

    On September 27, 2011, monolog/monolog became package ID 1. Today Packagist lists more than 469,000 packages, and Composer has installed packages from it more than 200 billion times.

    Our anniversary post covers how it all started, 15 years of milestones, the growth we've seen in 2026, and what comes next for supply chain security and funding.

    blog.packagist.com/15-years-of

    #php #phpc #composerphp #opensource

  4. Packagist turns 15 🎉

    On September 27, 2011, monolog/monolog became package ID 1. Today Packagist lists more than 469,000 packages, and Composer has installed packages from it more than 200 billion times.

    Our anniversary post covers how it all started, 15 years of milestones, the growth we've seen in 2026, and what comes next for supply chain security and funding.

    blog.packagist.com/15-years-of

    #php #phpc #composerphp #opensource

  5. Packagist turns 15 🎉

    On September 27, 2011, monolog/monolog became package ID 1. Today Packagist lists more than 469,000 packages, and Composer has installed packages from it more than 200 billion times.

    Our anniversary post covers how it all started, 15 years of milestones, the growth we've seen in 2026, and what comes next for supply chain security and funding.

    blog.packagist.com/15-years-of

    #php #phpc #composerphp #opensource

  6. RE: mastodon.social/@symfony/11652

    We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general.

    #php #phpc #composerphp

  7. RE: mastodon.social/@symfony/11652

    We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general.

    #php #phpc #composerphp

  8. RE: mastodon.social/@symfony/11652

    We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general.

    #php #phpc #composerphp

  9. RE: mastodon.social/@symfony/11652

    We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general.

    #php #phpc #composerphp

  10. RE: mastodon.social/@symfony/11652

    We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general.

    #php #phpc #composerphp

  11. New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging.

    blog.packagist.com/whats-new-i

    #php #phpc #composerphp

  12. New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging.

    blog.packagist.com/whats-new-i

    #php #phpc #composerphp

  13. New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging.

    blog.packagist.com/whats-new-i

    #php #phpc #composerphp

  14. New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging.

    blog.packagist.com/whats-new-i

    #php #phpc #composerphp

  15. New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging.

    blog.packagist.com/whats-new-i

    #php #phpc #composerphp

  16. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  17. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  18. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  19. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  20. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  21. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  22. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  23. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  24. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  25. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  26. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  27. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  28. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  29. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  30. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  31. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  32. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  33. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  34. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  35. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  36. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  37. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  38. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  39. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  40. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  41. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  42. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  43. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  44. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  45. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  46. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  47. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  48. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  49. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  50. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  51. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  52. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  53. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  54. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  55. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  56. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  57. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  58. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  59. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  60. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp