#composerphp — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #composerphp, aggregated by home.social.
-
Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.
That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.
-
Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.
That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.
-
Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.
That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.
-
Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.
That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.
-
Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.
That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.
-
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.
Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.
https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/
-
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.
Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.
https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/
-
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.
Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.
https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/
-
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.
Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.
https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/
-
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.
Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.
https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/
-
RE: https://phpc.social/@OndrejMirtes/116991095416961297
I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵💫
-
RE: https://phpc.social/@OndrejMirtes/116991095416961297
I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵💫
-
RE: https://phpc.social/@OndrejMirtes/116991095416961297
I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵💫
-
RE: https://phpc.social/@OndrejMirtes/116991095416961297
I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵💫
-
RE: https://phpc.social/@OndrejMirtes/116991095416961297
I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵💫
-
We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].
-
We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].
-
We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].
-
We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].
-
We're excited to announce @upsun is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
If your company wants to still become a launch partner for our sponsorship program this week, reach out to [email protected].
-
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/#php #phpc #composerphp #github #githubactions #supplychainsecurity
-
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/#php #phpc #composerphp #github #githubactions #supplychainsecurity
-
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/#php #phpc #composerphp #github #githubactions #supplychainsecurity
-
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/#php #phpc #composerphp #github #githubactions #supplychainsecurity
-
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/#php #phpc #composerphp #github #githubactions #supplychainsecurity
-
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.
All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/
-
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.
All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/
-
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.
All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/
-
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.
All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/
-
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.
All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/
-
The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf
Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!
Follow https://blog.packagist.com for updates on supply chain security.
-
The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf
Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!
Follow https://blog.packagist.com for updates on supply chain security.
-
The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf
Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!
Follow https://blog.packagist.com for updates on supply chain security.
-
The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf
Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!
Follow https://blog.packagist.com for updates on supply chain security.
-
The last weeks have been busy: Here are my slides on Composer & Packagist Supply Chain Security in 2026 from #PHPVerse last week: https://naderman.de/slippy/slides/2026-06-09-PHPVerse-Composer-and-Packagist-Supply-Chain-Security-in-2026.pdf
Thank you to @jetbrains for organizing a fantastic online event with thousands of simultaneous live viewers again! Video recordings will be published soon as well!
Follow https://blog.packagist.com for updates on supply chain security.
-
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.
https://blog.packagist.com/restricting-composer-plugins-across-your-organization/
#php #phpc #composerphp -
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.
https://blog.packagist.com/restricting-composer-plugins-across-your-organization/
#php #phpc #composerphp -
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.
https://blog.packagist.com/restricting-composer-plugins-across-your-organization/
#php #phpc #composerphp -
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.
https://blog.packagist.com/restricting-composer-plugins-across-your-organization/
#php #phpc #composerphp -
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins.
https://blog.packagist.com/restricting-composer-plugins-across-your-organization/
#php #phpc #composerphp -
The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.
Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.
https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/
#php #phpc #composerphp -
The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.
Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.
https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/
#php #phpc #composerphp -
The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.
Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.
https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/
#php #phpc #composerphp -
The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.
Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.
https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/
#php #phpc #composerphp -
The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.
Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.
https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/
#php #phpc #composerphp -
⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.
Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.
-
⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.
Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.
-
⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.
Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.
-
⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.
Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.
-
⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.
Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.
-
🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/
#php #phpc #composerphp -
🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/
#php #phpc #composerphp -
🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/
#php #phpc #composerphp -
🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/
#php #phpc #composerphp -
🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/
#php #phpc #composerphp -
🔒 An update on Composer & Packagist supply chain security:
Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.
If you maintain PHP packages, please enable MFA now.
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #phpc #composerphp -
🔒 An update on Composer & Packagist supply chain security:
Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.
If you maintain PHP packages, please enable MFA now.
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #phpc #composerphp -
🔒 An update on Composer & Packagist supply chain security:
Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.
If you maintain PHP packages, please enable MFA now.
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #phpc #composerphp -
🔒 An update on Composer & Packagist supply chain security:
Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.
If you maintain PHP packages, please enable MFA now.
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #phpc #composerphp -
🔒 An update on Composer & Packagist supply chain security:
Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.
If you maintain PHP packages, please enable MFA now.
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #phpc #composerphp