Co-Founder of Packagist / https://packagist.com and Co-Creator of #composerphp - he/him
Nils Adermann
@naderman@phpc.social
phpc.social
Replying to
@naderman@phpc.social
Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.
That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.
#php #phpc #composerphp
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.
Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.
https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/
#php #phpc #composerphp
Nils Adermann
@naderman@phpc.social
Co-Founder of Packagist / https://packagist.com and Co-Creator of #composerphp - he/him
phpc.social
RE: https://phpc.social/@OndrejMirtes/116991095416961297
I both love and hate this: Has #composerphp now reached python wheel levels and we soon need analysis tools to figure out which C libraries containing which CVEs exactly were compiled into which extensions shipping inside which #php phar files in Composer packages? 😵💫
Quoting
Announcing PHPStan Turbo! Native PHP extension (PHP 8.3+) written in C++ that makes running PHPStan 10-30 % faster.
The best part: If you update to PHPStan 2.2.6, you get it automatically. It ships with pre-built binaries for all the usual combos of OS:architecture:PHP.
We're excited to announce @upsun@mastodon.social is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
If your company wants to still become a launch partner for our sponsorship program this week, reach out to sponsoring@packagist.org.
#php #phpc #composerphp
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/
#php #phpc #composerphp #github #githubactions #supplychainsecurity
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.
All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/
#php #phpc #composerphp
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on Packagist.org and Private Packagist. Details on our blog: https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/ #php #phpc #composerphp
You've seen all posts