Sign in

Philipp Scheit

@pscheit.bsky.social
32 followers 40 following 182 posts

developer, entrepreneur, and open source enthusiast pscheit.de

PostsRepliesMedia
Reposted by Philipp Scheit
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Philipp Scheit @pscheit.bsky.social · 30/07/2026
Dont use Hetzner S3 storage. I used a lot of cloud products professionally, but this thing is off the charts. Bucket creation is eventually consistant. The rate limiting is SHARED, so that its totally random when you get rate limited. Deleting buckets with files in it takes an hour, cause API
100
Philipp Scheit @pscheit.bsky.social · 05/07/2026
Ich finde 35 eur Nenngeld für Turniere mit Spiralsystem für 2 Spiele U10 zu viel Geld. Seht ihr das auch so? #tennis
000
Philipp Scheit @pscheit.bsky.social · 03/07/2026
Someone raising kid(s) with ambitions to become "pro" in their sport? Would love to compare notes!
000
Reposted by Philipp Scheit
Jordi Boggiano @seld.be · 04/06/2026
Ever found yourself accidentally merging changes to the public API of a PHP package and regretting it later? I made a GitHub Action to help prevent that. seld.be/notes/surfac...
seld.be
Making public API surfaces changes more visible in open source libraries | Jordi's Ramblings
...
002
Philipp Scheit @pscheit.bsky.social · 04/06/2026
Team is on a release-rage-supply-chain-security-week :D Go Team!
010
Reposted by Philipp Scheit
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Reposted by Philipp Scheit
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by Philipp Scheit
Packagist @packagist.com · 13/05/2026
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
blog.packagist.com
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
178
Philipp Scheit @pscheit.bsky.social · 09/05/2026
So.. been in bed since tuesday, I think I derserve now to drop this infect/cold/whatever!
000
Philipp Scheit @pscheit.bsky.social · 02/03/2026
Why do i keep teaching Claude things in a session. I need to stop that.. Or talk to humans from time to time, lol Today I messaged a customer and wanted to write "Cloud" but typoed "Claud"
000
Philipp Scheit @pscheit.bsky.social · 01/02/2026
10 years later.. finally understand HOW to actually use the hexagonal architecture. If you are noob like me definitely start with installing deptrac and just "think hard" about what it says. I am really unlocking a new way to protoype my "medium services" architecture
100
Philipp Scheit @pscheit.bsky.social · 18/01/2026
so you think i can stop this hanging build , where the last output was 44days ago? 😬
000
Philipp Scheit @pscheit.bsky.social · 13/12/2025
Doing printing things
010
Philipp Scheit @pscheit.bsky.social · 13/12/2025
Finally diving into the core parts of our webapp: yaymeories.com has become yayphotobooks.com Parts i did not touch for a year. There is so much code rot! You get better, php gets better, symfony gets better, you learn new libraries (like Valinor). So much fun to change it!
yaymeories.com
000
Reposted by Philipp Scheit
Nils Adermann @naderman.de · 03/12/2025
Fascinating evening organized by the @sovereign.tech in Berlin tonight: Presenting their #SovereignTechFellowship program which funds individual open source maintainers of our digital infrastructure with public money.
051
Reposted by Philipp Scheit
Packagist @packagist.com · 03/12/2025
Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!
1277
Philipp Scheit @pscheit.bsky.social · 02/12/2025
I like the starting on dev.to. a) I can finally use claude to create my posts, review them in dev.to and publish them there b) Just started to post yesterday and got already two meaningful interactions: dev.to/pscheit/tric...
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
000
Philipp Scheit @pscheit.bsky.social · 01/12/2025
So a new personal site (pscheit.de) cries for new articles, right? So I went ahead and I quickly drafted something for you: dev.to/pscheit/the-... Defeat to the lazy lurk!
pscheit.de
Philipp Scheit - Developer, entrepreneur, open source enthusiast
Developer, entrepreneur, and open source enthusiast.
010
Philipp Scheit @pscheit.bsky.social · 01/12/2025
Finally, finally updated my personal page, haha. This was SOOO overdue pscheit.de
000
Reposted by Philipp Scheit
Nils Adermann @naderman.de · 01/12/2025
Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist.com booth was busy throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026! #php #composerphp
Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.
193
Reposted by Philipp Scheit
Symfony @symfony.com · 28/11/2025
💥 Shoutout to our Gold Sponsor: @PrivatePackagist! 🥇 Thanks for fueling innovation and supporting #SymfonyCon Amsterdam 2025! 🚀💛 👏 You rock! #PHP #Symfony #Sponsor
082
Philipp Scheit @pscheit.bsky.social · 18/11/2025
I am so tired... Tested an deactivated encharge flow for an hour... :facepalm:
010
Reposted by Philipp Scheit
Packagist @packagist.com · 18/11/2025
New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how deps cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What’s New in Private Packagist, November Update
We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure a...
023
Reposted by Philipp Scheit
Packagist @packagist.com · 14/11/2025
After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp
blog.packagist.com
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org
The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...
0167
Reposted by Philipp Scheit
Jordi Boggiano @seld.be · 13/11/2025
Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more! blog.packagist.com/composer-2-9/ #composerphp #phpc #PHP
blog.packagist.com
Composer 2.9 Release
We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...
0148
Philipp Scheit @pscheit.bsky.social · 26/10/2025
Someone told me lately, that the typing speed is not relevant - and that's why they wouldn't see the need for AI. 97 files 3406 lines added 1892 lines removed All TDD, all DDD, in one day. Semi interactive build with Claude and Claude-Skills.
100
Philipp Scheit @pscheit.bsky.social · 25/10/2025
Claudes most annoying sentences: These failures are unrelated to my changes. You're absolutely right
000
Philipp Scheit @pscheit.bsky.social · 25/10/2025
After 5 years DDD I finally get to understand BoundedContexts in practice. This was a crazy journey!
000
Philipp Scheit @pscheit.bsky.social · 18/10/2025
Hehe, have you ever "copied code from another project" the TDD style? Teaching this to Claude right now.. Never thought that this is something special I do. You still begin with an empty class and see what you need to copy - line by line - improve it along the way.
000
Philipp Scheit @pscheit.bsky.social · 15/10/2025
MIch wundert nix mehr, der Klassenlehrer so: Bitte geben Sie Ihrem Kind nach Möglichkeit einen Löffel, ein Schälchen und eine Küchenreibe mit.
000
Philipp Scheit @pscheit.bsky.social · 13/10/2025
Does someone know why Claude thinks i am "You are absolutely right!" Maybe I am but not all the time? Feels like its just brabbling along with whatever shit I come up with? Is it because it wouldn't do "what i want"? So its baked in? "Always trust the user"? how is this done scientifically?
110
Philipp Scheit @pscheit.bsky.social · 03/10/2025
I am gonna teach you real TDD! If you like it or not.. Claude: 🫢 It's getting there.. it's getting there. I just have to reject the code now and just write "TDD" then Claude usually knows whats up :D "Oh right, i did not see the test failing FIRST, let me run it..."
000
Reposted by Philipp Scheit
Packagist @packagist.com · 26/09/2025
Bitbucket Cloud is retiring app passwords in favor of API tokens. If you're using Private Packagist with Bitbucket Cloud, migrate now to avoid future disruptions. Our blog post explains it step-by-step: blog.packagist.com/bitbucket-de... #php #composerphp #phpc #privatepackagist #bitbucket
blog.packagist.com
Bitbucket deprecated App Passwords
Bitbucket announced that they deprecated app passwords in favor of their new API token system. This change affects organizations using Private Packagist with Bitbucket Cloud (bitbucket.org) workspace ...
002
Reposted by Philipp Scheit
Packagist @packagist.com · 23/09/2025
Together with PyPI, Maven Central, cratesio and other major package registries we signed a statement on sustainable open source infrastructure. 3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs. #phpc #php
1168
Philipp Scheit @pscheit.bsky.social · 16/09/2025
Its called the 1,2,3 rule 1 thing will go wrong (at least) 2 trips to the hardware store / team manager 3 times as long as you planned :)
000
Philipp Scheit @pscheit.bsky.social · 16/09/2025
Könnt ihr hier: a) mir sagen warum die Schnittstelle obsolete ist, und was man anstelle dessen nutzen soll? (spoiler: ich weiß es schon ...) b) den Cookie banner wegclicken? www.bzst.de/DE/Unternehm... Man beachte: das ist eine OFFIZIELLE Seite unseres Landes #digitalisierung-ist-neuland
bzst.de
Weitere Informationen zur Schnittstelle
000
Philipp Scheit @pscheit.bsky.social · 06/08/2025
Someone doing eventsourcing with #PHP ? Do you use a framework?
000
Philipp Scheit @pscheit.bsky.social · 06/08/2025
I remember failing hard when figuring this out, and now Claude did fail hard at it again - i am not alone. The filter_query[username][is]=my-user-name returns all stories. It becomes clear when you read the docs but boy. This is unintuitive! @storyblok.com
200
Reposted by Philipp Scheit
lerrrgan @lerrrgan.bsky.social · 01/08/2025
Good morning / happy Friday
A woman is reading a book titled “how to stay humble when you’re always right about everything”.
0544
Philipp Scheit @pscheit.bsky.social · 01/08/2025
I love startups. "Any chance you can bump up my pre-order? The kids are waiting desparately for it" "yeah sure, I put your shipping label on the top of the stack" fasttracktennis.eu
fasttracktennis.eu
FastTrackTennis
-the ultimate training tool -the ultimate ball machine -for all levels (beginner to advanced) -no picking up balls and up to 1200 hits per hour
000
Philipp Scheit @pscheit.bsky.social · 31/07/2025
Wer von euch Knallköppen hat eigentlich die eVatR Rest-Api die "neue" API vom bff gebaut? Ich muss ja nur diese YAML posten... api.evatr.vies.bzst.de/api-docs
api.evatr.vies.bzst.de
000
Reposted by Philipp Scheit
Nils Adermann @naderman.de · 25/06/2025
What's a time tracking process that works for you? I regularly for get to end or switch what I'm tracking, despite it being pretty easy and on web as well as my phone. What tools do you prefer and how did you fix this problem? Are there analogue devices that help keep this present at all times?
601
Reposted by Philipp Scheit
Nils Adermann @naderman.de · 28/07/2025
Arrived in Denver for #Laracon - look forward to meeting everyone at our @packagist.com booth! Would love to talk to everyone about how you use Composer, handle updates and apply security patches, or anything else relating to dependency management! #laraconus #laravel #phpc
092
Philipp Scheit @pscheit.bsky.social · 29/07/2025
The worst thing you can do as a support agent: Don't be able to tell the kind of customer you are talking with. If you are missing MRR, CLTV, how many contracts they have, Number of Orders, company size, etc... You will likely think twice if you send the default answer to them?
010
Philipp Scheit @pscheit.bsky.social · 29/07/2025
Uh, be careful on discogs.com this seems to be a new scam, almost fell for it. The scammy user starts an order, then cancels it and sends this message, as it looks like it came from discogs. Even the url mentions discogs. But thats a scam, dont click the link. Discogs removed the user.
010
Philipp Scheit @pscheit.bsky.social · 27/07/2025
So Claude was trained on the behaviour of a lot of developers. Is this the reason it goes like: oh the test fails... this is likely do to the test setup and states: "Successfully changed everything" :D
000
Philipp Scheit @pscheit.bsky.social · 16/07/2025
www.youtube.com/watch?v=hOKu... This is still a masterpiece
youtube.com
Somebody That I Used To Know - Pentatonix (Gotye cover)
YouTube video by Pentatonix
000
Philipp Scheit @pscheit.bsky.social · 13/07/2025
Best feature I added to my CRM this year :
000
Philipp Scheit @pscheit.bsky.social · 10/07/2025
I am so tired of not sleeping anymore. It's like not understanding your body anymore, which wants to solve problems, when there is really not the right time for it.
000