home.social

#composerphp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #composerphp, aggregated by home.social.

fetched live
  1. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  2. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  3. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  4. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  5. Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.

    That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.

    #php #phpc #composerphp

  6. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  7. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  8. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  9. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  10. Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.

    Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.

    blog.packagist.com/announcing-

    #php #phpc #composerphp

  11. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  12. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  13. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  14. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  15. RE: phpc.social/@OndrejMirtes/1169

    I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵‍💫

  16. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  17. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  18. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  19. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  20. We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.

    If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].

    #php #phpc #composerphp

  21. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  22. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  23. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  24. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  25. CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

    Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
    blog.packagist.com/securing-ou

    #php #phpc #composerphp #github #githubactions #supplychainsecurity

  26. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  27. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  28. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  29. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  30. 📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.

    All details on our blog: blog.packagist.com/immutable-v

    #php #phpc #composerphp

  31. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  32. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  33. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  34. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  35. The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: naderman.de/slippy/slides/2026

    Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!

    Follow blog.packagist.com for updates on supply chain security.

    #php #phpc #composerphp #supplychainsecurity

  36. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  37. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  38. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  39. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  40. 🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.

    blog.packagist.com/restricting
    #php #phpc #composerphp

  41. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  42. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  43. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  44. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  45. The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

    Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

    blog.packagist.com/enforce-a-s
    #php #phpc #composerphp

  46. ⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.

    Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.

    blog.packagist.com/blocking-ma

    #php #phpc #composerphp

  47. ⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.

    Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.

    blog.packagist.com/blocking-ma

    #php #phpc #composerphp

  48. ⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.

    Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.

    blog.packagist.com/blocking-ma

    #php #phpc #composerphp

  49. ⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.

    Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.

    blog.packagist.com/blocking-ma

    #php #phpc #composerphp

  50. ⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.

    Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.

    blog.packagist.com/blocking-ma

    #php #phpc #composerphp

  51. 🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
    If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
    blog.packagist.com/closing-com
    #php #phpc #composerphp

  52. 🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
    If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
    blog.packagist.com/closing-com
    #php #phpc #composerphp

  53. 🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
    If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
    blog.packagist.com/closing-com
    #php #phpc #composerphp

  54. 🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
    If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
    blog.packagist.com/closing-com
    #php #phpc #composerphp

  55. 🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
    If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
    blog.packagist.com/closing-com
    #php #phpc #composerphp

  56. 🔒 An update on Composer & Packagist supply chain security:

    Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.

    If you maintain PHP packages, please enable MFA now.

    blog.packagist.com/an-update-o
    #php #phpc #composerphp

  57. 🔒 An update on Composer & Packagist supply chain security:

    Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.

    If you maintain PHP packages, please enable MFA now.

    blog.packagist.com/an-update-o
    #php #phpc #composerphp

  58. 🔒 An update on Composer & Packagist supply chain security:

    Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.

    If you maintain PHP packages, please enable MFA now.

    blog.packagist.com/an-update-o
    #php #phpc #composerphp

  59. 🔒 An update on Composer & Packagist supply chain security:

    Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.

    If you maintain PHP packages, please enable MFA now.

    blog.packagist.com/an-update-o
    #php #phpc #composerphp

  60. 🔒 An update on Composer & Packagist supply chain security:

    Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.

    If you maintain PHP packages, please enable MFA now.

    blog.packagist.com/an-update-o
    #php #phpc #composerphp