Sign in

glaubinix.bsky.social

@glaubinix.bsky.social
28 followers 64 following 7 posts
PostsRepliesMedia
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 07/07/2026
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
01110
Reposted by @glaubinix.bsky.social
Josh Bressers @josh.bressers.name · 22/06/2026
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
opensourcesecurity.io
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
046
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 04/06/2026
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
blog.packagist.com
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
064
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 02/06/2026
⛔ Composer policies block flagged malware, but only on 2.10. A project disabling the policy, or a CI image running an old Composer, still installs flagged versions. Private Packagist now blocks these at the repository, for all versions. blog.packagist.com/blocking-mal... #php #phpc #composerphp
blog.packagist.com
Blocking Malware Downloads for Every Composer Version in Private Packagist
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, and the recent post on closing Composer's download fallback paths. Co...
042
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Reposted by @glaubinix.bsky.social
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 27/05/2026
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
blog.packagist.com
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
1912
Reposted by @glaubinix.bsky.social
Jordi Boggiano @seld.be · 20/05/2026
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
076
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 20/05/2026
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
169
Reposted by @glaubinix.bsky.social
The PHP Foundation @thephpf.bsky.social · 18/05/2026
Announcing the Ecosystem Security Team at The PHP Foundation! Thanks to a grant from Alpha-Omega at @linuxfoundation.org, this effort will improve security across the entire PHP ecosystem. The amazing @edorian.bsky.social will be filling this role.✨ thephp.foundation/blog/2026/05... #php #security
thephp.foundation
Announcing the Ecosystem Security Team at The PHP Foundation
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
097
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 18/05/2026
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
034
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 15/05/2026
We hope you enjoyed @glaubinix.bsky.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor phpday in Verona, Italy! Slides at glaubinix.github.io/talks/2026-0... #php #phpc #phpday #composerphp
Stephan Vock in front of a slide saying "Composer Says No" subtitle "Malware Filtering in 2.10"
053
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 13/05/2026
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
blog.packagist.com
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
178
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 14/04/2026
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: blog.packagist.com/composer-2-9... #php #phpc #composerphp
packagist.org
Packagist.org
The PHP Package Repository
039
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 02/04/2026
Search on Packagist is currently unavailable due to large amounts of bot traffic that @algolia.bsky.social did not filter out. They now blocked packagist. UI search and the search API are affected. We are looking into temp workarounds till Algolia resolves our support request from yesterday.
202
Reposted by @glaubinix.bsky.social
Jordi Boggiano @seld.be · 01/04/2026
We need your help to test Composer 2.10. Expect a final release next week, now is the time to try it out and flag any issue you find! github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC1 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC1 Running comp...
047
Reposted by @glaubinix.bsky.social
Derick Rethans @derickr.phpc.social.ap.brid.gy · 30/03/2026
Whoop! PHP London is meeting again next week: meetu.ps/e/PXrS6/2XF6m/i #php #london #elephpants #meetup
meetup.com
PHP London Social - April, Thu, Apr 9, 2026, 6:30 PM | Meetup
PHP London Pub Social – April 9th, Jack Horner, Tottenham Court Road Join us for an informal PHP London pub social at the Jack Horner on Tottenham Court Road! We've got a
056
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 21/11/2025
In Amsterdam next week and part of a group underrepresented at tech confs, or can't afford a ticket? Private Packagist is sponsoring #SymfonyCon (Nov 27th/28th) and we have a ticket to give away: Reply your favorite PHP8.5 feature to win #php #phpc #symfony @symfony.com
066
Reposted by @glaubinix.bsky.social
Jordi Boggiano @seld.be · 13/11/2025
Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more! blog.packagist.com/composer-2-9/ #composerphp #phpc #PHP
blog.packagist.com
Composer 2.9 Release
We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...
0148
Reposted by @glaubinix.bsky.social
Jordi Boggiano @seld.be · 07/11/2025
Composer 2.9 is coming, and there's an RC to try out! We need your help and feedback github.com/composer/com... #composerphp #phpc
github.com
Release 2.9.0-RC1 · composer/composer
Composer 2.9 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.9.0-RC1 Running compos...
064
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 20/09/2025
🚨 Warning to #PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc
02540
Reposted by @glaubinix.bsky.social
Nils Adermann @naderman.de · 19/09/2025
🚨 PSA for #PHP package maintainers: DO NOT REPLACE tags! If you messed up a release simply do another. No matter how quickly you notice a mistake, automatic tools already pulled the original tag, triggered automatic updates. Users will never know you recreated the tag and use the broken state. #phpc
0912
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 03/09/2025
Would you like to attend #APIPlatformCon 2025 in Lille on Sep 18/19 or online? Private Packagist is sponsoring: 4 tickets to give away! Part of a group underrepresented at tech conferences, or can't afford a ticket? Repost and reply favorite PHP package(s) #php #composerphp #phpc
Badge saying API Platform Conference 2025, Lille (France) & Online - Private Packagist is a wonderful Silver Sponsor and the Private Packagist elephant logo is shown on the right.
145
Reposted by @glaubinix.bsky.social
🥧 asgrim 🇺🇦 @asgrim.dev · 27/07/2025
The Online Safety Act is terrible for privacy. This is not just about pornography, it has wide over-reach into all our digital lives. It is authoritarian, and literally embodies parts of an Orwellian 1984 - except this is reality, not just a dystopian novel. petition.parliament.uk/petitions/72...
petition.parliament.uk
Petition: Repeal the Online Safety Act
We want the Government to repeal the Online Safety act.
054
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 04/07/2025
🚨 Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025. Act now, upgrade to Composer 2! Last resort: check out Private Packagist extended 1.x support if you really cannot migrate right now. blog.packagist.com/packagist-or...
blog.packagist.com
Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025
With the deadline drawing near, we’d like to remind you that we are discontinuing Composer 1.x support on Packagist.org soon. We're extending our original timeline by one month to give teams additiona...
049
Reposted by @glaubinix.bsky.social
🥧 asgrim 🇺🇦 @asgrim.dev · 01/07/2025
Hey folks 👋 , I'm available to hire! 💼 Part time, ~4h/day ⏳ Happy to work remote EU/UK/US ✅ I am a software team leader, Java/PHP/Rust/C/etc 🧑‍💼 Experience in avionics/finance/insurance/education/gov If you would like to talk more and see how I can help your team succeed, DM me and lets chat! 💬
046
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 13/05/2025
May update: Progress on Conductor, expiring API credentials, stronger account protection, improved user profile/settings UX & performance boosts! Details: blog.packagist.com/whats-new-in... #php #composer #composerphp #phpc
blog.packagist.com
What’s New in Private Packagist, May Update
Private Packagist has been evolving steadily over the past three months with a focus on API improvements, enhanced security, and refined user experience. Let's dive into the significant updates that h...
042
Reposted by @glaubinix.bsky.social
Pauline Vos @pauline-vos.nl · 04/03/2025
Alright, I’ve decided I’m leaving my job. Officially looking for work! Me: software engineer, >10 years industry experience. Backend heavy but exp across the stack from infra to FE. Experience leading teams. PHP, Rust, Go, TS, good at learning new stacks/langs! Shares super appreciated ❤️
34033
Reposted by @glaubinix.bsky.social
Nils Adermann @naderman.de · 03/02/2025
Stop by our @packagist.com booth at #LaraconEU and have a chat about Composer, Packagist, Conductor or anything else relating to dependency management and supply chain security! #Laravel #Laracon
Two people on stools at a table in front of a Private Packagist and a Conductor banner as well as a big screen.
1165
Reposted by @glaubinix.bsky.social
Derick Rethans @derickr.phpc.social.ap.brid.gy · 31/01/2025
I have been playing around with running PHP through WASM, mostly to see how we can enable more extensions for the one that runs in the PHP documentation. Following up from our latest @thephpf developers meeting, where we discussed improving the @php website, I […] [Original post on phpc.social]
0188
Reposted by @glaubinix.bsky.social
Packagist @packagist.com · 04/12/2024
We're excited to introduce you to 🧑‍✈️Conductor! Automatic dependency update PRs with Composer for PHP projects - Security fixes patched in minutes - Continuous updates without the hassle - all running in your own CI env! Early access waitlist: packagist.com/features/con... #composerphp #php #phpc
packagist.com
Conductor - Automatic dependency updates for Composer
Automatic dependency updates for Composer - tailor made for PHP. Grouped and scheduled in ways that just make sense for PHP projects.
24219