Sign in

Nils Adermann

@naderman.de
822 followers 240 following 149 posts

Co-Founder of @packagist.com / packagist.com and Co-Creator of #composerphp - he/him - @naderman@phpc.social

PostsRepliesMedia
Reposted by Nils Adermann
Packagist @packagist.com · 29/09/2026
Packagist turns 15, with more than 200 billion package installs 🎉 How Composer and Packagist started, 15 years of milestones, recent growth, and our plans for supply chain security and funding. blog.packagist.com/15-years-of... #php #phpc #composerphp
064
Reposted by Nils Adermann
Packagist @packagist.com · 24/09/2026
We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general. #php #phpc #composerphp
021
Reposted by Nils Adermann
Matt Hodges @matthodges.bsky.social · 19/09/2026
Very quick and dirty Jev test for hiring bias. One resume for a Wall Street job; asked whether the applicant should get a first-round interview. 76 evaluations, changing only the first name. 19 of each: White-associated men/women, Black-associated men/women. console.typesafe.ai/playground?s...
19475116
Nils Adermann @naderman.de · 17/09/2026
Takeaway from a brief AI doom tangent at dinner: Gustav Mahler is known for saying "When the world ends, I'll move to Vienna. Everything happens 50 years later there" Vienna School of Agentic Engineering goal to ward off the apocalypse for 50 years? 🤣
010
Reposted by Nils Adermann
The PHP Foundation @thephpf.bsky.social · 02/09/2026
Digital sovereignty is written in PHP. 🐘 Germany's €108M federal CMS migration, 770 EU Commission sites, 300,000 users on Nextcloud. In our latest post we examine PHP in the public sector and the funding gap that exists. thephp.foundation/blog/2026/0...
Image of the Earth at night, focused on Europe, showing the lights from the cities below. Image is from Insaanu Studio via Unsplash.
0117
Nils Adermann @naderman.de · 01/09/2026
Cc @trodrigues.net cause apparently there was a typo 🙈
100
Nils Adermann @naderman.de · 01/09/2026
Who is up for 12 lunch at dot tea bar and then co-working from Foley tomorrow? @seidt.quest @conniehwong.bsky.social @lstoll.net @chown.de @rkh.cool @felixge.de @trodigues.net @justine.cool @pudo.org @powen.net @rmehner.bsky.social @agento.bsky.social
630
Nils Adermann @naderman.de · 01/09/2026
reminded once more that if you train models on annoying human behavior, you get annoying AI behavior 🤦
Claude (Bot) commenting on a PR: "Out of scope for this PR, but the n..."
040
Reposted by Nils Adermann
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Nils Adermann @naderman.de · 26/08/2026
Ugh sorry didn't get a bsky notification. We were at Chay Umi Vegan, got Auto in corrected. Now at Foley.
100
Nils Adermann @naderman.de · 26/08/2026
@agento.bsky.social we're just at chat umi across the street for lunch first now. Foley food options are still very limited/unclear
200
Nils Adermann @naderman.de · 26/08/2026
We'll check it out and see if it could be a permanent replacement 😁
120
Nils Adermann @naderman.de · 26/08/2026
So @seidt.quest and @conniehwong.bsky.social suggested we try Foley on Schönhauser Allee as an alternative. Who is up for joining today? @lstoll.net @chown.de @rkh.cool @felixge.de @trodigues.net @justine.cool @pudo.org @powen.net @rmehner.bsky.social @agento.bsky.social
400
Reposted by Nils Adermann
Open Source Pledge ⇌ @opensourcepledge.com · 31/07/2026
Package managers support our world's infrastructure, but those who build them have more work on their plate then ever. Companies who rely on this work for their revenue should give something back. It's in these companies' interest to keep this tech sustainable.
1104
Nils Adermann @naderman.de · 31/07/2026
Thanks to @brianfox.bsky.social and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring us, even though one of their products competes with our Private Packagist. The infrastructure underneath is shared, we fund it together.
010
Nils Adermann @naderman.de · 31/07/2026
Credit to @aikidosecurity.bsky.social: They stepped up before we even had a program to offer, right when we realized how much security work was ahead of us, offered the funding we needed without hesitation, and got us onto this path in the first place.
110
Nils Adermann @naderman.de · 31/07/2026
We launched our sponsorship program as a step toward more distributed funding of critical open source infrastructure. Long term we want to move from sponsorships to regular service subscriptions paid from engineering budgets. Two partners deserve a special mention: #php #phpc #composerphp
111
Reposted by Nils Adermann
Packagist @packagist.com · 30/07/2026
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure. blog.packagist.com/announcing-... #php #phpc #composerphp
1136
Reposted by Nils Adermann
Packagist @packagist.com · 23/07/2026
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours. blog.packagist.com/securing-ou... #php #phpc #composerphp #github #githubactions #zizmor
blog.packagist.com
Securing our GitHub Actions workflows with zizmor
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened
084
Nils Adermann @naderman.de · 14/07/2026
So I'm trying to contact a bunch of enterprises with SDKs on packagist to help with sponsorships. But what I'm finding instead is that their SDKs are mostly owned by ex-employee accounts with private email addresses or bouncing corporate emails. 😵‍💫
070
Reposted by Nils Adermann
Packagist @packagist.com · 07/07/2026
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
01110
Reposted by Nils Adermann
The PHP Foundation @thephpf.bsky.social · 23/06/2026
If you're curious about what our Ecosystem Security Team has been up to the past month, you're in luck! Volker Dusch has provided an update in our recent blog post. thephp.foundation/blog/2026/0... #php #phpc #phpsecurity
Photo of a laptop keyboard in dim light.
053
Reposted by Nils Adermann
Josh Bressers @josh.bressers.name · 22/06/2026
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
opensourcesecurity.io
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
046
Nils Adermann @naderman.de · 16/06/2026
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide... Thanks @jetbrains.com for a great online event! Videos soon! Follow blog.packagist.com for updates. #php #phpc #composerphp #supplychainsecurity
naderman.de
054
Reposted by Nils Adermann
Packagist @packagist.com · 12/06/2026
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
blog.packagist.com
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
143
Nils Adermann @naderman.de · 09/06/2026
Live now, free online conference #PHPVerse2026! Join us now! #php #phpc
031
Nils Adermann @naderman.de · 08/06/2026
Looking forward to talking about Composer and Packagist Supply Chain Security in 2026 at the JetBrains PHPverse 2026 on June 9 - Join us for a free virtual event bringing together developers, ideas, and energy from across the PHP ecosystem. #PHPverse2026 jb.gg/3ldzpb
jb.gg
JetBrains PHPverse 2026 – Bringing the PHP Community Together
Join us for a free virtual event bringing together developers, ideas, and energy from across the ecosystem. Enjoy insightful talks, exciting announcements, and a look at the future of PHP development.
071
Reposted by Nils Adermann
Packagist @packagist.com · 04/06/2026
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
blog.packagist.com
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
064
Reposted by Nils Adermann
Packagist @packagist.com · 02/06/2026
⛔ Composer policies block flagged malware, but only on 2.10. A project disabling the policy, or a CI image running an old Composer, still installs flagged versions. Private Packagist now blocks these at the repository, for all versions. blog.packagist.com/blocking-mal... #php #phpc #composerphp
blog.packagist.com
Blocking Malware Downloads for Every Composer Version in Private Packagist
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, and the recent post on closing Composer's download fallback paths. Co...
042
Reposted by Nils Adermann
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Reposted by Nils Adermann
Andrew Nesbitt @andrewnez.bsky.social · 29/05/2026
Composer's dependency policies nesbitt.io/2026/05/29/c...
nesbitt.io
Composer’s dependency policies
uBlock Origin for composer install
031
Reposted by Nils Adermann
Jordi Boggiano @seld.be · 29/05/2026
I realized I was never going to get to adding zizmor to all my repos so I made a claude skill to let it do the grunt work. You can use it too, if it helps more busy/lazy people to secure their GitHub repos I am glad! See github.com/Seldaek/zizm...
github.com
GitHub - Seldaek/zizmorify: Agent skill to harden GitHub Actions by adding zizmor to your CI and fix existing workflow errors
Agent skill to harden GitHub Actions by adding zizmor to your CI and fix existing workflow errors - Seldaek/zizmorify
021
Reposted by Nils Adermann
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by Nils Adermann
The PHP Foundation @thephpf.bsky.social · 27/05/2026
Today we published our Impact and Transparency Report for 2025. We are incredibly grateful for our sponsors, partners, contractors, & individual financial contributors for without them, none of our work would be possible. thephp.foundation/blog/2026/05... #php #opensource
thephp.foundation
The PHP Foundation Impact and Transparency Report 2025
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
096
Reposted by Nils Adermann
Packagist @packagist.com · 27/05/2026
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
blog.packagist.com
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
1912
Nils Adermann @naderman.de · 26/05/2026
This pressure @seld.be and I can certainly relate to. 😵‍💫 Here's hoping we'll figure out a better way forward soon.
Friday, May 22nd
seldaek 11:35PM
Ok.. Caught up with everything again
seldaek 11:36 PM
Really not enjoying this acceleration of everything very much.
- 3 replies Last reply 3 days ago
seldaek 11:38 PM
We're off tomorrow to [redacted] It's 30 degrees too, so my
plan is to actually try and enjoy two days off for real for once. | hope no drama gets in the way. And please let's
not start huge discussions on slack either (sweat emoji)
Enjoy the weekend too! Crazy times for real..
naderman 11:47 PM
thank you, you too
Saturday, May 23rd
naderman 12:24 AM:
Damn this one is kind of bad https:/packagist.slack.com/archives/CO9TI[redacted]
250
Nils Adermann @naderman.de · 26/05/2026
I see, makes sense, thanks!
000
Nils Adermann @naderman.de · 25/05/2026
Not sure I follow? If you think it's urgent to release the patches and disclose details, release without a CVE id. If it's not urgent enough to release without a CVE id, why tell everyone they'd have to be ready to patch their software on a holiday? Processes with hard dependency on CVE id?
140
Nils Adermann @naderman.de · 25/05/2026
I can see accepted practice is out the window when suddenly anyone can (a) easily immediately build an exploit for any vuln and (b) anyone can quickly find the vulns. But if any vuln can now also be found by an LLM and we treat any vuln with such alarm, we'll collectively burn out very soon.
120
Nils Adermann @naderman.de · 25/05/2026
Accepted practice used to be: either a vuln is undisclosed, so you ship a patch at a planned/announced patch date, which you announce, or if it is disclosed, then you disclose workarounds/warning publicly if active exploitation is occurring, or disclose as soon as you can publish a patch.
110
Nils Adermann @naderman.de · 25/05/2026
The opposite view is: By announcing the 0-day without patches, which you have no knowledge of exploitation of yet, you are significantly increasing the risk of exploitation, cause an LLM still needs to be prompted to look in the right project, and before this announcement, who would have done that?
110
Nils Adermann @naderman.de · 25/05/2026
The point is, you didn't screw anyone over. The vuln is public, it's a 0-day, so you're not disclosing any info that isn't already public. You publish the patch as quickly as you can. All you can do is provide a patch and advice as quickly as possible.
140
Nils Adermann @naderman.de · 25/05/2026
I appreciate it for deps of tools and services I run, cause I can follow this and react quickly. I'd rather be safe from attacks on these. At the same time, I see people already struggle with updates. I'm not sure how sustainable this will be when every dep releases security updates twice a week.
100
Nils Adermann @naderman.de · 25/05/2026
It's one way to react to this new reality, where any vulns a regular LLM can find when simply asked to look for vulns. You can consider them a 0-day, cause anyone can just go ask an LLM now and find the exact same issue.
110
Reposted by Nils Adermann
Fabien Potencier @fabien.potencier.org · 24/05/2026
As an OSS maintainer, my new rule is that anything a frontier model can find with some reasonable effort is a 0-day. Hence why I'm now shipping security releases on public holidays.
2175
Reposted by Nils Adermann
Packagist @packagist.com · 20/05/2026
We recommend you change the default permissions for GitHub Actions GITHUB_TOKENs to read only. Explicitly grant elevated permissions only where strictly necessary. Use zizmor to analyze your GitHub Actions: github.com/zizmorcore/z... see also: phpunit.expert/articles/har...
Workflow permissions setting screen in GitHub with "Read repository contents and packages permissions" selected rather than "Read and write permissions"
044
Reposted by Nils Adermann
Jordi Boggiano @seld.be · 20/05/2026
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
076
Reposted by Nils Adermann
Packagist @packagist.com · 20/05/2026
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
169
Reposted by Nils Adermann
Packagist @packagist.com · 18/05/2026
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
034
Reposted by Nils Adermann
Packagist @packagist.com · 15/05/2026
We hope you enjoyed @glaubinix.bsky.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor phpday in Verona, Italy! Slides at glaubinix.github.io/talks/2026-0... #php #phpc #phpday #composerphp
Stephan Vock in front of a slide saying "Composer Says No" subtitle "Malware Filtering in 2.10"
053