Sign in

Nils Adermann

@naderman.de
822 followers 240 following 149 posts

Co-Founder of @packagist.com / packagist.com and Co-Creator of #composerphp - he/him - @naderman@phpc.social

PostsRepliesMedia
Reposted by Nils Adermann
Packagist @packagist.com · 29/09/2026
Packagist turns 15, with more than 200 billion package installs 🎉 How Composer and Packagist started, 15 years of milestones, recent growth, and our plans for supply chain security and funding. blog.packagist.com/15-years-of... #php #phpc #composerphp
054
Reposted by Nils Adermann
Packagist @packagist.com · 24/09/2026
We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general. #php #phpc #composerphp
021
Reposted by Nils Adermann
Matt Hodges @matthodges.bsky.social · 19/09/2026
Very quick and dirty Jev test for hiring bias. One resume for a Wall Street job; asked whether the applicant should get a first-round interview. 76 evaluations, changing only the first name. 19 of each: White-associated men/women, Black-associated men/women. console.typesafe.ai/playground?s...
19475116
Nils Adermann @naderman.de · 17/09/2026
Takeaway from a brief AI doom tangent at dinner: Gustav Mahler is known for saying "When the world ends, I'll move to Vienna. Everything happens 50 years later there" Vienna School of Agentic Engineering goal to ward off the apocalypse for 50 years? 🤣
010
Reposted by Nils Adermann
The PHP Foundation @thephpf.bsky.social · 02/09/2026
Digital sovereignty is written in PHP. 🐘 Germany's €108M federal CMS migration, 770 EU Commission sites, 300,000 users on Nextcloud. In our latest post we examine PHP in the public sector and the funding gap that exists. thephp.foundation/blog/2026/0...
Image of the Earth at night, focused on Europe, showing the lights from the cities below. Image is from Insaanu Studio via Unsplash.
0117
Nils Adermann @naderman.de · 01/09/2026
reminded once more that if you train models on annoying human behavior, you get annoying AI behavior 🤦
Claude (Bot) commenting on a PR: "Out of scope for this PR, but the n..."
040
Reposted by Nils Adermann
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Reposted by Nils Adermann
Open Source Pledge ⇌ @opensourcepledge.com · 31/07/2026
Package managers support our world's infrastructure, but those who build them have more work on their plate then ever. Companies who rely on this work for their revenue should give something back. It's in these companies' interest to keep this tech sustainable.
1104
Nils Adermann @naderman.de · 31/07/2026
We launched our sponsorship program as a step toward more distributed funding of critical open source infrastructure. Long term we want to move from sponsorships to regular service subscriptions paid from engineering budgets. Two partners deserve a special mention: #php #phpc #composerphp
111
Reposted by Nils Adermann
Packagist @packagist.com · 30/07/2026
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure. blog.packagist.com/announcing-... #php #phpc #composerphp
1136
Reposted by Nils Adermann
Packagist @packagist.com · 23/07/2026
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours. blog.packagist.com/securing-ou... #php #phpc #composerphp #github #githubactions #zizmor
blog.packagist.com
Securing our GitHub Actions workflows with zizmor
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened
084
Nils Adermann @naderman.de · 14/07/2026
So I'm trying to contact a bunch of enterprises with SDKs on packagist to help with sponsorships. But what I'm finding instead is that their SDKs are mostly owned by ex-employee accounts with private email addresses or bouncing corporate emails. 😵‍💫
070
Reposted by Nils Adermann
Packagist @packagist.com · 07/07/2026
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
01110
Reposted by Nils Adermann
The PHP Foundation @thephpf.bsky.social · 23/06/2026
If you're curious about what our Ecosystem Security Team has been up to the past month, you're in luck! Volker Dusch has provided an update in our recent blog post. thephp.foundation/blog/2026/0... #php #phpc #phpsecurity
Photo of a laptop keyboard in dim light.
053
Reposted by Nils Adermann
Josh Bressers @josh.bressers.name · 22/06/2026
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
opensourcesecurity.io
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
045
Nils Adermann @naderman.de · 16/06/2026
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide... Thanks @jetbrains.com for a great online event! Videos soon! Follow blog.packagist.com for updates. #php #phpc #composerphp #supplychainsecurity
naderman.de
054
Reposted by Nils Adermann
Packagist @packagist.com · 12/06/2026
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
blog.packagist.com
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
143
Nils Adermann @naderman.de · 09/06/2026
Live now, free online conference #PHPVerse2026! Join us now! #php #phpc
031
Nils Adermann @naderman.de · 08/06/2026
Looking forward to talking about Composer and Packagist Supply Chain Security in 2026 at the JetBrains PHPverse 2026 on June 9 - Join us for a free virtual event bringing together developers, ideas, and energy from across the PHP ecosystem. #PHPverse2026 jb.gg/3ldzpb
jb.gg
JetBrains PHPverse 2026 – Bringing the PHP Community Together
Join us for a free virtual event bringing together developers, ideas, and energy from across the ecosystem. Enjoy insightful talks, exciting announcements, and a look at the future of PHP development.
071
Reposted by Nils Adermann
Packagist @packagist.com · 04/06/2026
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
blog.packagist.com
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
064
Reposted by Nils Adermann
Packagist @packagist.com · 02/06/2026
⛔ Composer policies block flagged malware, but only on 2.10. A project disabling the policy, or a CI image running an old Composer, still installs flagged versions. Private Packagist now blocks these at the repository, for all versions. blog.packagist.com/blocking-mal... #php #phpc #composerphp
blog.packagist.com
Blocking Malware Downloads for Every Composer Version in Private Packagist
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, and the recent post on closing Composer's download fallback paths. Co...
042
Reposted by Nils Adermann
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Reposted by Nils Adermann
Andrew Nesbitt @andrewnez.bsky.social · 29/05/2026
Composer's dependency policies nesbitt.io/2026/05/29/c...
nesbitt.io
Composer’s dependency policies
uBlock Origin for composer install
031
Reposted by Nils Adermann
Jordi Boggiano @seld.be · 29/05/2026
I realized I was never going to get to adding zizmor to all my repos so I made a claude skill to let it do the grunt work. You can use it too, if it helps more busy/lazy people to secure their GitHub repos I am glad! See github.com/Seldaek/zizm...
github.com
GitHub - Seldaek/zizmorify: Agent skill to harden GitHub Actions by adding zizmor to your CI and fix existing workflow errors
Agent skill to harden GitHub Actions by adding zizmor to your CI and fix existing workflow errors - Seldaek/zizmorify
021
Reposted by Nils Adermann
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by Nils Adermann
The PHP Foundation @thephpf.bsky.social · 27/05/2026
Today we published our Impact and Transparency Report for 2025. We are incredibly grateful for our sponsors, partners, contractors, & individual financial contributors for without them, none of our work would be possible. thephp.foundation/blog/2026/05... #php #opensource
thephp.foundation
The PHP Foundation Impact and Transparency Report 2025
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
096
Reposted by Nils Adermann
Packagist @packagist.com · 27/05/2026
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
blog.packagist.com
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
1912
Nils Adermann @naderman.de · 26/05/2026
This pressure @seld.be and I can certainly relate to. 😵‍💫 Here's hoping we'll figure out a better way forward soon.
Friday, May 22nd
seldaek 11:35PM
Ok.. Caught up with everything again
seldaek 11:36 PM
Really not enjoying this acceleration of everything very much.
- 3 replies Last reply 3 days ago
seldaek 11:38 PM
We're off tomorrow to [redacted] It's 30 degrees too, so my
plan is to actually try and enjoy two days off for real for once. | hope no drama gets in the way. And please let's
not start huge discussions on slack either (sweat emoji)
Enjoy the weekend too! Crazy times for real..
naderman 11:47 PM
thank you, you too
Saturday, May 23rd
naderman 12:24 AM:
Damn this one is kind of bad https:/packagist.slack.com/archives/CO9TI[redacted]
250
Reposted by Nils Adermann
Fabien Potencier @fabien.potencier.org · 24/05/2026
As an OSS maintainer, my new rule is that anything a frontier model can find with some reasonable effort is a 0-day. Hence why I'm now shipping security releases on public holidays.
2175
Reposted by Nils Adermann
Packagist @packagist.com · 20/05/2026
We recommend you change the default permissions for GitHub Actions GITHUB_TOKENs to read only. Explicitly grant elevated permissions only where strictly necessary. Use zizmor to analyze your GitHub Actions: github.com/zizmorcore/z... see also: phpunit.expert/articles/har...
Workflow permissions setting screen in GitHub with "Read repository contents and packages permissions" selected rather than "Read and write permissions"
044
Reposted by Nils Adermann
Jordi Boggiano @seld.be · 20/05/2026
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
076
Reposted by Nils Adermann
Packagist @packagist.com · 20/05/2026
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
169
Reposted by Nils Adermann
Packagist @packagist.com · 18/05/2026
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
034
Reposted by Nils Adermann
Packagist @packagist.com · 15/05/2026
We hope you enjoyed @glaubinix.bsky.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor phpday in Verona, Italy! Slides at glaubinix.github.io/talks/2026-0... #php #phpc #phpday #composerphp
Stephan Vock in front of a slide saying "Composer Says No" subtitle "Malware Filtering in 2.10"
053
Reposted by Nils Adermann
Packagist @packagist.com · 13/05/2026
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
blog.packagist.com
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
178
Nils Adermann @naderman.de · 06/05/2026
Open infrastructure isn't free. 🌱 Packagist/Composer signed a joint @openssf.org letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries. #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability
1119
Reposted by Nils Adermann
Packagist @packagist.com · 14/04/2026
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: blog.packagist.com/composer-2-9... #php #phpc #composerphp
packagist.org
Packagist.org
The PHP Package Repository
039
Reposted by Nils Adermann
Ahmad Nassri @ahmadnassri.com · 01/04/2026
⚠️ If you're running local mcp servers, you need to do the following: 1. Individually "install" packages you want to use, within a specified directory: (e.g. $HOME/mcp) creating a lockfile 2. Add: "--include-workspace-root --workspace $HOME/mcp --no --offline" to EVERY npx call
293
Reposted by Nils Adermann
Ian Coldwater 🧊🚫 @lookitup.baby · 01/04/2026
I don’t think I realized I had any latent Challenger trauma until right about now My kid’s like “neat!” and I’m like 🫣
1712577174
Reposted by Nils Adermann
Jordi Boggiano @seld.be · 01/04/2026
We need your help to test Composer 2.10. Expect a final release next week, now is the time to try it out and flag any issue you find! github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC1 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC1 Running comp...
047
Reposted by Nils Adermann
Gergely Orosz @gergely.pragmaticengineer.com · 27/03/2026
If you use GitHub (especially if you pay for it!!) consider doing this *immediately* Settings -> Privacy -> Disallow GitHub to train their models on your code. GitHub opted *everyone* into training. No matter if you pay for the service (like I do). WTH github.com/settings/cop...
8820471488
Reposted by Nils Adermann
Packagist @packagist.com · 18/03/2026
Private Packagist is a member of the @opensourcepledge.com & gave over $4k/FTE in 2025 to #opensource maintainers. Have your company join too! blog.packagist.com/private-pack... - Reach out if you want to be a launch partner for our Composer&Packagist.org sponsorship program! #composerphp #php #phpc
blog.packagist.com
Private Packagist 2025 contributions for the Open Source Pledge
This is now our third year as a member of the Open Source Pledge. Private Packagist subscriptions help fund not only the development of Composer and Packagist.org, but also the open source dependencie...
173
Nils Adermann @naderman.de · 18/03/2026
One of my takeaways from @foss-backstage.de was @andrewnez.bsky.social saying relative download stats for packages closely resemble stats of open source dependents, so closed source dependency use matches open source dependency use: We can distribute funding fairly w/o analyzing closed source use.
140
Nils Adermann @naderman.de · 16/03/2026
Enjoying the CRA workshop at @foss-backstage.de - that feels a lot like some absurdist comedy show 🙈
Slide saying "The Autonomy of EU Law" with a venn diagram showing how Belgian legal person, us legal person and German legal person are all separate concepts with the CRA defining a legal person in a way that only partially overlaps with each of these
110
Reposted by Nils Adermann
Lena Reinhard (she/they) @lenareinhard.com · 15/03/2026
I don't think we've talked enough about this login trend using OTPs (one-time passwords) sent via email. My ADHD brain has enough problems staying on task as-is, I don't need you, authentication designer, over here making me open the distraction circus that is my inbox to dig up a six-figure code
484
Nils Adermann @naderman.de · 16/03/2026
Meet me at @foss-backstage.de today and tomorrow in Berlin! Let's talk about sustainable software package repository operation, supply chain security in open source and @thephpf.bsky.social
040
Nils Adermann @naderman.de · 14/03/2026
Excited to see my aunt Ines put together a website for her art and upcoming exhibitions 🎉 www.ines-kettenburg.de
031
Reposted by Nils Adermann
Les-Tilleuls.coop @les-tilleuls.coop · 13/03/2026
We're very excited to attend and speak at Dutch PHP Conference this week, and to see FrankenPHP mentioned in one of the opening keynotes! Don't miss our colleagues' talks (Alexandre Daubois & Vincent Amstoutz) scheduled today. Feel free to reach out to them!
Always bet on PHP
032
Reposted by Nils Adermann
Neighbourhoodie @bsky.neighbourhood.ie · 13/03/2026
Only the weekend stands between us and @foss-backstage.de! Neighbourhoodie’s @janl.bsky.narrativ.es will present work we’ve done with @sovereign.tech support over 2.5 years. Catch him on Monday at 12:10 in the auditorium, “security” topic track. 🎟️ Tickets (incl. remote) are still available
26.foss-backstage.de
2.5 Years of STA Bug Resilience: how we helped a lot of FOSS
Between major updates for Log4J, substantially increasing test coverage for SystemD, updating hundreds of CVE reports at NIST for Yocto and providing a new infrastructure-as-code solution for PHP, wor...
043
Reposted by Nils Adermann
The PHP Foundation @thephpf.bsky.social · 06/03/2026
For those who don't know our new Executive Director, Elizabeth Barron, she's written an introductory post on The PHP Foundation Blog that shares a bit about her background, her vision for the future, and how you can share your own PHP thoughts with her. #php #phpc thephp.foundation/blog/2026/03...
thephp.foundation
Working Together on the Future of PHP
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
073