New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours. blog.packagist.com/securing-ou... #php #phpc #composerphp #github #githubactions #zizmor
Securing our GitHub Actions workflows with zizmor
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened
blog.packagist.com
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide... Thanks @jetbrains.com for a great online event! Videos soon! Follow blog.packagist.com for updates. #php #phpc #composerphp #supplychainsecurity
naderman.de
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
blog.packagist.com
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
blog.packagist.com
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
blog.packagist.com
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
github.com
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
blog.packagist.com
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
blog.packagist.com
Open infrastructure isn't free. 🌱 Packagist/Composer signed a joint @openssf.org letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries. #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability
Open Infrastructure Is Not Free Part II 10 trillion open source package downloads in 2026. Still running on donations and volunteers. AI is accelerating attacks. The Sustaining Package Registries WG is here to help. openssf.org/blog/2026/05... #PreserveOpenSource
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: blog.packagist.com/composer-2-9... #php #phpc #composerphp
Packagist.org
The PHP Package Repository
packagist.org
🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-in... #composerphp #php #phpc
What's New in Private Packagist, February 2026 Update
Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights f...
blog.packagist.com
Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!
Thanks to our sponsors for supporting The PHP Foundation in 2025! Together we helped ship PHP 8.5, released PIE 1.0, supported FrankenPHP, launched the PHP MCP SDK, secured a 2nd STA investment for Streams, and much more. Please consider sponsoring PHP in 2026 🙏💜 thephp.foundation/blog/2025/12...
After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org
The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...
blog.packagist.com
Would you like to attend #APIPlatformCon 2025 in Lille on Sep 18/19 or online? Private Packagist is sponsoring: 4 tickets to give away! Part of a group underrepresented at tech conferences, or can't afford a ticket? Repost and reply favorite PHP package(s) #php #composerphp #phpc
August update: dependency usage tracking across your packages, automatic GitLab token rotation, and Conductor improvements with custom labels and smarter PR handling blog.packagist.com/whats-new-in... #php #composer #composerphp #phpc
What’s New in Private Packagist, August Update
We've been busy improving Private Packagist over the past few months with a focus on package discovery, user experience improvements, and improved security monitoring tools. Here are the most signific...
blog.packagist.com
🚨 Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025. Act now, upgrade to Composer 2! Last resort: check out Private Packagist extended 1.x support if you really cannot migrate right now. blog.packagist.com/packagist-or...
Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025
With the deadline drawing near, we’d like to remind you that we are discontinuing Composer 1.x support on Packagist.org soon. We're extending our original timeline by one month to give teams additiona...
blog.packagist.com
Meet @igorbenko.bsky.social and me at IPC in Berlin today & tomorrow at our @packagist.com booth. 👋 Would love to chat about Composer, supply chain security, dependencies, or show you our new tool Conductor! Don't forget to pick up a Composer sticker 😉 #php #phpc #composerphp #ipc #ipc2025
We're excited to introduce you to 🧑✈️Conductor! Automatic dependency update PRs with Composer for PHP projects - Security fixes patched in minutes - Continuous updates without the hassle - all running in your own CI env! Early access waitlist: packagist.com/features/con... #composerphp #php #phpc
Conductor - Automatic dependency updates for Composer
Automatic dependency updates for Composer - tailor made for PHP. Grouped and scheduled in ways that just make sense for PHP projects.
packagist.com