Sign in

Packagist

@packagist.com
397 followers 3 following 44 posts
PostsRepliesMedia
Packagist @packagist.com · 29/09/2026
Packagist turns 15, with more than 200 billion package installs 🎉 How Composer and Packagist started, 15 years of milestones, recent growth, and our plans for supply chain security and funding. blog.packagist.com/15-years-of... #php #phpc #composerphp
064
Packagist @packagist.com · 24/09/2026
We're super excited for #SymfonyCon 2026 in Warsaw Nov 26-27 and happy to sponsor again! A must-go for anyone working with PHP and #Symfony. Great content, fantastic people. Now more than ever: educate yourself and keep up with ecosystem & tech in general. #php #phpc #composerphp
021
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Reposted by Packagist
bunny.net @bunny.net · 11/08/2026
Composer and Packagist are critical shared infrastructure for the PHP ecosystem, serving billions of package installs a year. The new sponsorship program spreads the cost of running them beyond a single company, and we're glad to be one of the launch sponsors!
041
Reposted by Packagist
Open Source Pledge ⇌ @opensourcepledge.com · 31/07/2026
Package managers support our world's infrastructure, but those who build them have more work on their plate then ever. Companies who rely on this work for their revenue should give something back. It's in these companies' interest to keep this tech sustainable.
1104
Packagist @packagist.com · 30/07/2026
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure. blog.packagist.com/announcing-... #php #phpc #composerphp
1136
Packagist @packagist.com · 28/07/2026
We're excited to announce @upsun.com is now sponsoring #composerphp & Packagist maintenance, ops and development! They have a long history in the #PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
112
Packagist @packagist.com · 23/07/2026
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours. blog.packagist.com/securing-ou... #php #phpc #composerphp #github #githubactions #zizmor
blog.packagist.com
Securing our GitHub Actions workflows with zizmor
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened
084
Packagist @packagist.com · 14/07/2026
We’re sponsoring Meet Magento Germany on Oct 22, 2026 in Mainz, Germany. Come meet our founder @naderman.de to talk software supply chain security and answer your questions. Tickets available, CFP open: de.meet-magento.com/ #meetmagento #magento #meetmagentode #adobecommerce
de.meet-magento.com
Meet Magento Germany 2026
Meet Magento Germany: the conference for Magento, Hyvä, and Adobe Commerce. Discover insights, experts, and networking. Get your ticket now.
010
Packagist @packagist.com · 07/07/2026
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
01110
Reposted by Packagist
The PHP Foundation @thephpf.bsky.social · 23/06/2026
If you're curious about what our Ecosystem Security Team has been up to the past month, you're in luck! Volker Dusch has provided an update in our recent blog post. thephp.foundation/blog/2026/0... #php #phpc #phpsecurity
Photo of a laptop keyboard in dim light.
053
Reposted by Packagist
The PHP Foundation @thephpf.bsky.social · 19/06/2026
You can now join the PHP Ambassador Program if you want to help improve the perception of PHP in spaces outside our bubble. Help us help the community tell the real story of modern PHP development! #php #phpc Read more: thephp.foundation/blog/2026/0...
044
Reposted by Packagist
Josh Bressers @josh.bressers.name · 22/06/2026
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
opensourcesecurity.io
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
046
Reposted by Packagist
Nils Adermann @naderman.de · 16/06/2026
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide... Thanks @jetbrains.com for a great online event! Videos soon! Follow blog.packagist.com for updates. #php #phpc #composerphp #supplychainsecurity
naderman.de
054
Packagist @packagist.com · 12/06/2026
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
blog.packagist.com
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
143
Reposted by Packagist
Nils Adermann @naderman.de · 09/06/2026
Live now, free online conference #PHPVerse2026! Join us now! #php #phpc
031
Reposted by Packagist
Nils Adermann @naderman.de · 08/06/2026
Looking forward to talking about Composer and Packagist Supply Chain Security in 2026 at the JetBrains PHPverse 2026 on June 9 - Join us for a free virtual event bringing together developers, ideas, and energy from across the PHP ecosystem. #PHPverse2026 jb.gg/3ldzpb
jb.gg
JetBrains PHPverse 2026 – Bringing the PHP Community Together
Join us for a free virtual event bringing together developers, ideas, and energy from across the ecosystem. Enjoy insightful talks, exciting announcements, and a look at the future of PHP development.
071
Packagist @packagist.com · 04/06/2026
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
blog.packagist.com
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
064
Packagist @packagist.com · 02/06/2026
⛔ Composer policies block flagged malware, but only on 2.10. A project disabling the policy, or a CI image running an old Composer, still installs flagged versions. Private Packagist now blocks these at the repository, for all versions. blog.packagist.com/blocking-mal... #php #phpc #composerphp
blog.packagist.com
Blocking Malware Downloads for Every Composer Version in Private Packagist
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, and the recent post on closing Composer's download fallback paths. Co...
042
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Reposted by Packagist
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by Packagist
The PHP Foundation @thephpf.bsky.social · 27/05/2026
Today we published our Impact and Transparency Report for 2025. We are incredibly grateful for our sponsors, partners, contractors, & individual financial contributors for without them, none of our work would be possible. thephp.foundation/blog/2026/05... #php #opensource
thephp.foundation
The PHP Foundation Impact and Transparency Report 2025
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
096
Packagist @packagist.com · 27/05/2026
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
blog.packagist.com
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
1912
Reposted by Packagist
PHP Architect @phparch.com · 21/05/2026
Our team is passionate about creating a community-led space at Tek (and beyond). @packagist.com is another 2026 partner and is made up of people just as invested in our community as we are, bringing us great tools from people who understand PHP. Thanks from Chicago, team! 🐘🧡
011
Reposted by Packagist
Jordi Boggiano @seld.be · 20/05/2026
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
076
Packagist @packagist.com · 20/05/2026
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
169
Packagist @packagist.com · 18/05/2026
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
034
Packagist @packagist.com · 15/05/2026
We hope you enjoyed @glaubinix.bsky.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor phpday in Verona, Italy! Slides at glaubinix.github.io/talks/2026-0... #php #phpc #phpday #composerphp
Stephan Vock in front of a slide saying "Composer Says No" subtitle "Malware Filtering in 2.10"
053
Packagist @packagist.com · 13/05/2026
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
blog.packagist.com
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
178
Reposted by Packagist
Nils Adermann @naderman.de · 06/05/2026
Open infrastructure isn't free. 🌱 Packagist/Composer signed a joint @openssf.org letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries. #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability
1119
Packagist @packagist.com · 14/04/2026
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: blog.packagist.com/composer-2-9... #php #phpc #composerphp
packagist.org
Packagist.org
The PHP Package Repository
039
Packagist @packagist.com · 02/04/2026
Search on Packagist is currently unavailable due to large amounts of bot traffic that @algolia.bsky.social did not filter out. They now blocked packagist. UI search and the search API are affected. We are looking into temp workarounds till Algolia resolves our support request from yesterday.
202
Reposted by Packagist
Jordi Boggiano @seld.be · 01/04/2026
We need your help to test Composer 2.10. Expect a final release next week, now is the time to try it out and flag any issue you find! github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC1 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC1 Running comp...
047
Packagist @packagist.com · 18/03/2026
Private Packagist is a member of the @opensourcepledge.com & gave over $4k/FTE in 2025 to #opensource maintainers. Have your company join too! blog.packagist.com/private-pack... - Reach out if you want to be a launch partner for our Composer&Packagist.org sponsorship program! #composerphp #php #phpc
blog.packagist.com
Private Packagist 2025 contributions for the Open Source Pledge
This is now our third year as a member of the Open Source Pledge. Private Packagist subscriptions help fund not only the development of Composer and Packagist.org, but also the open source dependencie...
173
Reposted by Packagist
Nils Adermann @naderman.de · 02/03/2026
Loved the very engaged audience of a thousand people at #LaraconEU 2026 in Amsterdam today at my "Composer Deep Dive" talk! Proud to sponsor the event with Private Packagist / @packagist.com - Find me and chat about package management or @thephpf.bsky.social! #laravel #laracon #php #composerphp
Nils Adermann wearing a blue Private Packagist hoodie and yellow Private Packagist t-shirt on stage next to a lectern pointing at a slide, photographed across backs of audience heads.Laracon EU audience facing the stageNils Adermann taking a selfie from the balcony above the Laracon EU crowd with Nuno Maduro on a large screen talking to the audience.Sign with community sponsor logos at Laracon EU Amsterdam including Private Packagist
0112
Reposted by Packagist
Nils Adermann @naderman.de · 01/03/2026
Just arrived in Amsterdam for #LaraconEU - my talk "Composer Deep Dive" is tomorrow afternoon at 2:30pm! Hope to talk to as many of you about #composerphp @packagist.com and @thephpf.bsky.social ! #laravel #php
271
Packagist @packagist.com · 09/02/2026
🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-in... #composerphp #php #phpc
blog.packagist.com
What's New in Private Packagist, February 2026 Update
Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights f...
053
Packagist @packagist.com · 03/12/2025
Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!
1277
Reposted by Packagist
Nils Adermann @naderman.de · 01/12/2025
Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist.com booth was busy throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026! #php #composerphp
Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.
193
Reposted by Packagist
Symfony @symfony.com · 28/11/2025
💥 Shoutout to our Gold Sponsor: @PrivatePackagist! 🥇 Thanks for fueling innovation and supporting #SymfonyCon Amsterdam 2025! 🚀💛 👏 You rock! #PHP #Symfony #Sponsor
082
Packagist @packagist.com · 21/11/2025
In Amsterdam next week and part of a group underrepresented at tech confs, or can't afford a ticket? Private Packagist is sponsoring #SymfonyCon (Nov 27th/28th) and we have a ticket to give away: Reply your favorite PHP8.5 feature to win #php #phpc #symfony @symfony.com
066
Reposted by Packagist
Romain Canon @romain-canon.com · 20/11/2025
And now @packagist.com 🔥 Thank you so much for sponsoring my work and placing trust in my humble contribution to the PHP ecosystem! 🙏
141
Packagist @packagist.com · 18/11/2025
New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how deps cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What’s New in Private Packagist, November Update
We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure a...
023
Packagist @packagist.com · 14/11/2025
After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp
blog.packagist.com
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org
The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...
0167
Reposted by Packagist
Jordi Boggiano @seld.be · 13/11/2025
Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more! blog.packagist.com/composer-2-9/ #composerphp #phpc #PHP
blog.packagist.com
Composer 2.9 Release
We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...
0148
Reposted by Packagist
The PHP Foundation @thephpf.bsky.social · 10/11/2025
The PHP Foundation is Seeking a New Executive Director! 🐘💜 We're asking the PHP community to help find the right person for this role. If you know someone who would be an excellent fit, please encourage them to apply or reach out to us directly. thephp.foundation/blog/2025/11... #phpc #php
thephp.foundation
The PHP Foundation is Seeking a New Executive Director
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
01412
Reposted by Packagist
Jordi Boggiano @seld.be · 07/11/2025
Composer 2.9 is coming, and there's an RC to try out! We need your help and feedback github.com/composer/com... #composerphp #phpc
github.com
Release 2.9.0-RC1 · composer/composer
Composer 2.9 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.9.0-RC1 Running compos...
064
Packagist @packagist.com · 26/09/2025
Bitbucket Cloud is retiring app passwords in favor of API tokens. If you're using Private Packagist with Bitbucket Cloud, migrate now to avoid future disruptions. Our blog post explains it step-by-step: blog.packagist.com/bitbucket-de... #php #composerphp #phpc #privatepackagist #bitbucket
blog.packagist.com
Bitbucket deprecated App Passwords
Bitbucket announced that they deprecated app passwords in favor of their new API token system. This change affects organizations using Private Packagist with Bitbucket Cloud (bitbucket.org) workspace ...
002
Packagist @packagist.com · 23/09/2025
Together with PyPI, Maven Central, cratesio and other major package registries we signed a statement on sustainable open source infrastructure. 3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs. #phpc #php
1168
Packagist @packagist.com · 20/09/2025
🚨 Warning to #PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc
02540