Packagist turns 15, with more than 200 billion package installs 🎉 How Composer and Packagist started, 15 years of milestones, recent growth, and our plans for supply chain security and funding. blog.packagist.com/15-years-of... #php #phpc #composerphp
We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general. #php #phpc #composerphp
🎉We already have our next #SymfonyCon stop for you!✨ 💜Get ready for: Warsaw, Poland 2026! Where the very first SymfonyCon took place back in 2013 💙 🎟️Get your tickets: live.symfony.com Don’t miss the chance to connect with the Symfony community again ! 🎊 #Symfony
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
Composer and Packagist are critical shared infrastructure for the PHP ecosystem, serving billions of package installs a year. The new sponsorship program spreads the cost of running them beyond a single company, and we're glad to be one of the launch sponsors!
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure. blog.packagist.com/announcing-... #php #phpc #composerphp
Package managers support our world's infrastructure, but those who build them have more work on their plate then ever. Companies who rely on this work for their revenue should give something back. It's in these companies' interest to keep this tech sustainable.
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure. blog.packagist.com/announcing-... #php #phpc #composerphp
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure. blog.packagist.com/announcing-... #php #phpc #composerphp
We're excited to announce @upsun.com is now sponsoring #composerphp & Packagist maintenance, ops and development! They have a long history in the #PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours. blog.packagist.com/securing-ou... #php #phpc #composerphp #github #githubactions #zizmor
Securing our GitHub Actions workflows with zizmor
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened
blog.packagist.com
We’re sponsoring Meet Magento Germany on Oct 22, 2026 in Mainz, Germany. Come meet our founder @naderman.de to talk software supply chain security and answer your questions. Tickets available, CFP open: de.meet-magento.com/ #meetmagento #magento #meetmagentode #adobecommerce
Meet Magento Germany 2026
Meet Magento Germany: the conference for Magento, Hyvä, and Adobe Commerce. Discover insights, experts, and networking. Get your ticket now.
de.meet-magento.com
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
If you're curious about what our Ecosystem Security Team has been up to the past month, you're in luck! Volker Dusch has provided an update in our recent blog post. thephp.foundation/blog/2026/0... #php #phpc #phpsecurity
You can now join the PHP Ambassador Program if you want to help improve the perception of PHP in spaces outside our bubble. Help us help the community tell the real story of modern PHP development! #php #phpc Read more: thephp.foundation/blog/2026/0...
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
opensourcesecurity.io
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide... Thanks @jetbrains.com for a great online event! Videos soon! Follow blog.packagist.com for updates. #php #phpc #composerphp #supplychainsecurity
naderman.de
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
blog.packagist.com
Looking forward to talking about Composer and Packagist Supply Chain Security in 2026 at the JetBrains PHPverse 2026 on June 9 - Join us for a free virtual event bringing together developers, ideas, and energy from across the PHP ecosystem. #PHPverse2026 jb.gg/3ldzpb
JetBrains PHPverse 2026 – Bringing the PHP Community Together
Join us for a free virtual event bringing together developers, ideas, and energy from across the ecosystem. Enjoy insightful talks, exciting announcements, and a look at the future of PHP development.
jb.gg
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
blog.packagist.com
⛔ Composer policies block flagged malware, but only on 2.10. A project disabling the policy, or a CI image running an old Composer, still installs flagged versions. Private Packagist now blocks these at the repository, for all versions. blog.packagist.com/blocking-mal... #php #phpc #composerphp
Blocking Malware Downloads for Every Composer Version in Private Packagist
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, and the recent post on closing Composer's download fallback paths. Co...
blog.packagist.com
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
blog.packagist.com
Today we published our Impact and Transparency Report for 2025. We are incredibly grateful for our sponsors, partners, contractors, & individual financial contributors for without them, none of our work would be possible. thephp.foundation/blog/2026/05... #php #opensource
The PHP Foundation Impact and Transparency Report 2025
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
thephp.foundation
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
blog.packagist.com
Our team is passionate about creating a community-led space at Tek (and beyond). @packagist.com is another 2026 partner and is made up of people just as invested in our community as we are, bringing us great tools from people who understand PHP. Thanks from Chicago, team! 🐘🧡
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
github.com
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
blog.packagist.com
We hope you enjoyed @glaubinix.bsky.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor phpday in Verona, Italy! Slides at glaubinix.github.io/talks/2026-0... #php #phpc #phpday #composerphp
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
blog.packagist.com
Open infrastructure isn't free. 🌱 Packagist/Composer signed a joint @openssf.org letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries. #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability
Open Infrastructure Is Not Free Part II 10 trillion open source package downloads in 2026. Still running on donations and volunteers. AI is accelerating attacks. The Sustaining Package Registries WG is here to help. openssf.org/blog/2026/05... #PreserveOpenSource