Packagist
packagist.com
Packagist
@packagist.com
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging.

blog.packagist.com/whats-new-i...

#php #phpc #composerphp
August 28, 2026 at 11:51 AM
Reposted by Packagist
Composer and Packagist are critical shared infrastructure for the PHP ecosystem, serving billions of package installs a year.

The new sponsorship program spreads the cost of running them beyond a single company, and we're glad to be one of the launch sponsors!
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure.

blog.packagist.com/announcing-...

#php #phpc #composerphp
August 11, 2026 at 9:43 AM
Reposted by Packagist
Package managers support our world's infrastructure, but those who build them have more work on their plate then ever. Companies who rely on this work for their revenue should give something back. It's in these companies' interest to keep this tech sustainable.
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure.

blog.packagist.com/announcing-...

#php #phpc #composerphp
July 31, 2026 at 2:05 PM
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure.

blog.packagist.com/announcing-...

#php #phpc #composerphp
July 30, 2026 at 12:05 PM
We're excited to announce @upsun.com is now sponsoring #composerphp & Packagist maintenance, ops and development! They have a long history in the #PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
July 28, 2026 at 12:04 PM
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours.

blog.packagist.com/securing-ou...

#php #phpc #composerphp #github #githubactions #zizmor
Securing our GitHub Actions workflows with zizmor
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened
blog.packagist.com
July 23, 2026 at 1:45 PM
We’re sponsoring Meet Magento Germany on Oct 22, 2026 in Mainz, Germany. Come meet our founder @naderman.de to talk software supply chain security and answer your questions.

Tickets available, CFP open: de.meet-magento.com/

#meetmagento #magento #meetmagentode #adobecommerce
Meet Magento Germany 2026
Meet Magento Germany: the conference for Magento, Hyvä, and Adobe Commerce. Discover insights, experts, and networking. Get your ticket now.
de.meet-magento.com
July 14, 2026 at 1:21 PM
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable.
blog.packagist.com/immutable-v...
#php #phpc #composerphp
July 7, 2026 at 1:57 PM
Reposted by Packagist
If you're curious about what our Ecosystem Security Team has been up to the past month, you're in luck! Volker Dusch has provided an update in our recent blog post. thephp.foundation/blog/2026/0... #php #phpc #phpsecurity
June 23, 2026 at 11:35 AM
Reposted by Packagist
You can now join the PHP Ambassador Program if you want to help improve the perception of PHP in spaces outside our bubble. Help us help the community tell the real story of modern PHP development! #php #phpc Read more: thephp.foundation/blog/2026/0...
June 19, 2026 at 3:17 PM
Reposted by Packagist
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future

The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
opensourcesecurity.io
June 22, 2026 at 2:15 PM
Reposted by Packagist
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide...

Thanks @jetbrains.com for a great online event! Videos soon!
Follow blog.packagist.com for updates.

#php #phpc #composerphp #supplychainsecurity
naderman.de
June 16, 2026 at 11:39 AM
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
blog.packagist.com
June 12, 2026 at 10:56 AM
Reposted by Packagist
Live now, free online conference #PHPVerse2026! Join us now!

#php #phpc
June 9, 2026 at 11:15 AM
Reposted by Packagist
Looking forward to talking about Composer and Packagist Supply Chain Security in 2026 at the JetBrains PHPverse 2026 on June 9 - Join us for a free virtual event bringing together developers, ideas, and energy from across the PHP ecosystem. #PHPverse2026 jb.gg/3ldzpb
JetBrains PHPverse 2026 – Bringing the PHP Community Together
Join us for a free virtual event bringing together developers, ideas, and energy from across the ecosystem. Enjoy insightful talks, exciting announcements, and a look at the future of PHP development.
jb.gg
June 8, 2026 at 10:30 AM
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own.
Private Packagist customers can now enforce which Composer versions are allowed to use their repository.

blog.packagist.com/enforce-a-sa...
#php #phpc #composerphp
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
blog.packagist.com
June 4, 2026 at 12:20 PM
⛔ Composer policies block flagged malware, but only on 2.10. A project disabling the policy, or a CI image running an old Composer, still installs flagged versions.
Private Packagist now blocks these at the repository, for all versions.
blog.packagist.com/blocking-mal...
#php #phpc #composerphp
Blocking Malware Downloads for Every Composer Version in Private Packagist
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, and the recent post on closing Composer's download fallback paths. Co...
blog.packagist.com
June 2, 2026 at 3:25 PM
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone.
Two new Private Packagist options close it off.
blog.packagist.com/closing-comp...
#php #phpc #composerphp
June 1, 2026 at 7:44 AM
Reposted by Packagist
📦 Composer 2.10 is out.

Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated.

blog.packagist.com/composer-2-1...

#php #phpc #composerphp
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
blog.packagist.com
May 28, 2026 at 11:16 AM
Reposted by Packagist
Today we published our Impact and Transparency Report for 2025. We are incredibly grateful for our sponsors, partners, contractors, & individual financial contributors for without them, none of our work would be possible. thephp.foundation/blog/2026/05...
#php #opensource
The PHP Foundation Impact and Transparency Report 2025
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
thephp.foundation
May 27, 2026 at 7:50 PM
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next.

If you maintain PHP packages, enable MFA now.

blog.packagist.com/an-update-on...

#php #phpc #composerphp #supplychainsecurity
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
blog.packagist.com
May 27, 2026 at 3:18 PM
Reposted by Packagist
Our team is passionate about creating a community-led space at Tek (and beyond). @packagist.com is another 2026 partner and is made up of people just as invested in our community as we are, bringing us great tools from people who understand PHP. Thanks from Chicago, team! 🐘🧡
May 21, 2026 at 6:03 AM
Reposted by Packagist
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
github.com
May 20, 2026 at 1:54 PM
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
May 20, 2026 at 11:04 AM
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes.
blog.packagist.com/whats-new-in...
#php #phpc #composerphp
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
blog.packagist.com
May 18, 2026 at 12:39 PM