Sign in

igorbenko.bsky.social

@igorbenko.bsky.social
19 followers 54 following 0 posts

Dev at Packagist Conductors

PostsRepliesMedia
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 23/07/2026
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours. blog.packagist.com/securing-ou... #php #phpc #composerphp #github #githubactions #zizmor
blog.packagist.com
Securing our GitHub Actions workflows with zizmor
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened
084
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 07/07/2026
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
01110
Reposted by @igorbenko.bsky.social
Nils Adermann @naderman.de · 16/06/2026
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide... Thanks @jetbrains.com for a great online event! Videos soon! Follow blog.packagist.com for updates. #php #phpc #composerphp #supplychainsecurity
naderman.de
054
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 12/06/2026
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
blog.packagist.com
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
143
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 04/06/2026
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
blog.packagist.com
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
064
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 27/05/2026
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
blog.packagist.com
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
1912
Reposted by @igorbenko.bsky.social
Jordi Boggiano @seld.be · 20/05/2026
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
076
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 20/05/2026
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
169
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 18/05/2026
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
034
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 13/05/2026
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
blog.packagist.com
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
178
Reposted by @igorbenko.bsky.social
Nils Adermann @naderman.de · 06/05/2026
Open infrastructure isn't free. 🌱 Packagist/Composer signed a joint @openssf.org letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries. #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability
1119
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 14/04/2026
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: blog.packagist.com/composer-2-9... #php #phpc #composerphp
packagist.org
Packagist.org
The PHP Package Repository
039
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 09/02/2026
🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-in... #composerphp #php #phpc
blog.packagist.com
What's New in Private Packagist, February 2026 Update
Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights f...
053
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 03/12/2025
Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!
1277
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 14/11/2025
After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp
blog.packagist.com
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org
The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...
0167
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 03/09/2025
Would you like to attend #APIPlatformCon 2025 in Lille on Sep 18/19 or online? Private Packagist is sponsoring: 4 tickets to give away! Part of a group underrepresented at tech conferences, or can't afford a ticket? Repost and reply favorite PHP package(s) #php #composerphp #phpc
Badge saying API Platform Conference 2025, Lille (France) & Online - Private Packagist is a wonderful Silver Sponsor and the Private Packagist elephant logo is shown on the right.
145
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 01/09/2025
August update: dependency usage tracking across your packages, automatic GitLab token rotation, and Conductor improvements with custom labels and smarter PR handling blog.packagist.com/whats-new-in... #php #composer #composerphp #phpc
blog.packagist.com
What’s New in Private Packagist, August Update
We've been busy improving Private Packagist over the past few months with a focus on package discovery, user experience improvements, and improved security monitoring tools. Here are the most signific...
023
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 04/07/2025
🚨 Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025. Act now, upgrade to Composer 2! Last resort: check out Private Packagist extended 1.x support if you really cannot migrate right now. blog.packagist.com/packagist-or...
blog.packagist.com
Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025
With the deadline drawing near, we’d like to remind you that we are discontinuing Composer 1.x support on Packagist.org soon. We're extending our original timeline by one month to give teams additiona...
049
Reposted by @igorbenko.bsky.social
Nils Adermann @naderman.de · 03/06/2025
Meet @igorbenko.bsky.social and me at IPC in Berlin today & tomorrow at our @packagist.com booth. 👋 Would love to chat about Composer, supply chain security, dependencies, or show you our new tool Conductor! Don't forget to pick up a Composer sticker 😉 #php #phpc #composerphp #ipc #ipc2025
Igor Benko and Nils Adermann in Private Packagist T-shirts in front of a Private Packagist booth
063
Reposted by @igorbenko.bsky.social
Packagist @packagist.com · 04/12/2024
We're excited to introduce you to 🧑‍✈️Conductor! Automatic dependency update PRs with Composer for PHP projects - Security fixes patched in minutes - Continuous updates without the hassle - all running in your own CI env! Early access waitlist: packagist.com/features/con... #composerphp #php #phpc
packagist.com
Conductor - Automatic dependency updates for Composer
Automatic dependency updates for Composer - tailor made for PHP. Grouped and scheduled in ways that just make sense for PHP projects.
24219