home.social

#composerphp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #composerphp, aggregated by home.social.

  1. RE: phpc.social/@packagist/1165668

    If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc

  2. Three months of Private Packagist updates: Malware filter list support is already in place, ahead of Composer 2.10's release next week. Flagged versions show warning banners on package pages and are marked in the version list. Permissions views on package level, better background job & sync visibility, and a narrower GitLab OAuth scope (read_api).

    blog.packagist.com/whats-new-i

    #php #phpc #composerphp

  3. We hope you enjoyed @glaubinix talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday in Verona, Italy!

    Slides at glaubinix.github.io/talks/2026

    #php #phpc #phpday #composerphp #supplychainsecurity #malware

  4. We hope you enjoyed @glaubinix talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday in Verona, Italy!

    Slides at glaubinix.github.io/talks/2026

    #php #phpc #phpday #composerphp #supplychainsecurity #malware

  5. We hope you enjoyed @glaubinix talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday in Verona, Italy!

    Slides at glaubinix.github.io/talks/2026

    #php #phpc #phpday #composerphp #supplychainsecurity #malware

  6. We hope you enjoyed @glaubinix talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday in Verona, Italy!

    Slides at glaubinix.github.io/talks/2026

    #php #phpc #phpday #composerphp #supplychainsecurity #malware

  7. We hope you enjoyed @glaubinix talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday in Verona, Italy!

    Slides at glaubinix.github.io/talks/2026

    #php #phpc #phpday #composerphp #supplychainsecurity #malware

  8. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  9. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  10. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  11. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  12. UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc

  13. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  14. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  15. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  16. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  17. RE: social.lfx.dev/@openssf/116527

    Open infrastructure isn't free. 🌱

    Packagist/Composer signed a joint
    OpenSSF letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries.

    Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.

    #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability

  18. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  19. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  20. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  21. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev

  22. Fuck it, I'm going to make a store for Laravel Packages, per-package licensing, and quality commitment (no $49 shit that is barely two classes).

    Really. Fuck it.

    #PHP #ComposerPHP #Programming #Laravel #Coding #Code #Store #Marketplace #SoftwareDevelopment #WebDevelopment #WebDev