Sign in

Philipp Scheit

@pscheit.bsky.social
32 followers 40 following 182 posts

developer, entrepreneur, and open source enthusiast pscheit.de

PostsRepliesMedia
Reposted by Philipp Scheit
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Philipp Scheit @pscheit.bsky.social · 30/07/2026
upload speed is a tenth of scaleways performance and a 1/20th of bunny.net upload performance. I can highly not recommend. Moving everything to scaleway now
100
Philipp Scheit @pscheit.bsky.social · 30/07/2026
is so slow.. There are no batch endpoints implemented, so you really have to do 1 api call for each file (it feels like it). The management UI does not allow you to delete any files and fails randomly. I dont trust the quota / billing with this product at all, and its not transparent.
100
Philipp Scheit @pscheit.bsky.social · 30/07/2026
Dont use Hetzner S3 storage. I used a lot of cloud products professionally, but this thing is off the charts. Bucket creation is eventually consistant. The rate limiting is SHARED, so that its totally random when you get rate limited. Deleting buckets with files in it takes an hour, cause API
100
Philipp Scheit @pscheit.bsky.social · 05/07/2026
Ich finde 35 eur Nenngeld für Turniere mit Spiralsystem für 2 Spiele U10 zu viel Geld. Seht ihr das auch so? #tennis
000
Philipp Scheit @pscheit.bsky.social · 03/07/2026
I want to read those, too. Please! :)
000
Philipp Scheit @pscheit.bsky.social · 03/07/2026
Someone raising kid(s) with ambitions to become "pro" in their sport? Would love to compare notes!
000
Reposted by Philipp Scheit
Jordi Boggiano @seld.be · 04/06/2026
Ever found yourself accidentally merging changes to the public API of a PHP package and regretting it later? I made a GitHub Action to help prevent that. seld.be/notes/surfac...
seld.be
Making public API surfaces changes more visible in open source libraries | Jordi's Ramblings
...
002
Philipp Scheit @pscheit.bsky.social · 04/06/2026
Team is on a release-rage-supply-chain-security-week :D Go Team!
010
Reposted by Philipp Scheit
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Reposted by Philipp Scheit
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by Philipp Scheit
Packagist @packagist.com · 13/05/2026
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
blog.packagist.com
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
178
Philipp Scheit @pscheit.bsky.social · 09/05/2026
So.. been in bed since tuesday, I think I derserve now to drop this infect/cold/whatever!
000
Philipp Scheit @pscheit.bsky.social · 02/03/2026
yeah but, whats the solution?
100
Philipp Scheit @pscheit.bsky.social · 02/03/2026
Why do i keep teaching Claude things in a session. I need to stop that.. Or talk to humans from time to time, lol Today I messaged a customer and wanted to write "Cloud" but typoed "Claud"
000
Philipp Scheit @pscheit.bsky.social · 01/02/2026
why?
100
Philipp Scheit @pscheit.bsky.social · 01/02/2026
Unlocks a lot of magic. I can now stlil decide to move one bounded context out of my repo into it's own app. But this only needs to happen when I feel "this repo gets too big". It has become the perfect tradeoff for me: not so many repos, not so big repos (and slow CI pipelines because of that)
000
Philipp Scheit @pscheit.bsky.social · 01/02/2026
e.g. if you dont have to build Rest-APIs but instead you just call an interface (port) from the other bounded context, living the same repo.. Things get so much faster! Share the dtos that are arguments to this call, they can be later be json request bodies. One repo -> several bounded contexts
100
Philipp Scheit @pscheit.bsky.social · 01/02/2026
10 years later.. finally understand HOW to actually use the hexagonal architecture. If you are noob like me definitely start with installing deptrac and just "think hard" about what it says. I am really unlocking a new way to protoype my "medium services" architecture
100
Philipp Scheit @pscheit.bsky.social · 18/01/2026
so you think i can stop this hanging build , where the last output was 44days ago? 😬
000
Philipp Scheit @pscheit.bsky.social · 13/12/2025
Doing printing things
010
Philipp Scheit @pscheit.bsky.social · 13/12/2025
oh lol :D thanks. I was looking on the page for a broken link now xD haha yeah, should probably learn how to typo this :) hahaha, Thanks
000
Philipp Scheit @pscheit.bsky.social · 13/12/2025
Finally diving into the core parts of our webapp: yaymeories.com has become yayphotobooks.com Parts i did not touch for a year. There is so much code rot! You get better, php gets better, symfony gets better, you learn new libraries (like Valinor). So much fun to change it!
yaymeories.com
000
Reposted by Philipp Scheit
Nils Adermann @naderman.de · 03/12/2025
Fascinating evening organized by the @sovereign.tech in Berlin tonight: Presenting their #SovereignTechFellowship program which funds individual open source maintainers of our digital infrastructure with public money.
051
Philipp Scheit @pscheit.bsky.social · 04/12/2025
The flow is more like: the AI TRIES to code, i lecture it. It says "oh thats valuable insights" it forgets... So now the flow is "oh this is valuable insights" "ok lets write a blog post" at least have the blog post now to reference the next time :D
000
Reposted by Philipp Scheit
Packagist @packagist.com · 03/12/2025
Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!
1277
Philipp Scheit @pscheit.bsky.social · 02/12/2025
I like the starting on dev.to. a) I can finally use claude to create my posts, review them in dev.to and publish them there b) Just started to post yesterday and got already two meaningful interactions: dev.to/pscheit/tric...
dev.to
DEV Community
A space to discuss and keep up software development and manage your software career
000
Philipp Scheit @pscheit.bsky.social · 01/12/2025
So a new personal site (pscheit.de) cries for new articles, right? So I went ahead and I quickly drafted something for you: dev.to/pscheit/the-... Defeat to the lazy lurk!
pscheit.de
Philipp Scheit - Developer, entrepreneur, open source enthusiast
Developer, entrepreneur, and open source enthusiast.
010
Philipp Scheit @pscheit.bsky.social · 01/12/2025
Finally, finally updated my personal page, haha. This was SOOO overdue pscheit.de
000
Reposted by Philipp Scheit
Nils Adermann @naderman.de · 01/12/2025
Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist.com booth was busy throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026! #php #composerphp
Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.
193
Reposted by Philipp Scheit
Symfony @symfony.com · 28/11/2025
💥 Shoutout to our Gold Sponsor: @PrivatePackagist! 🥇 Thanks for fueling innovation and supporting #SymfonyCon Amsterdam 2025! 🚀💛 👏 You rock! #PHP #Symfony #Sponsor
082
Philipp Scheit @pscheit.bsky.social · 20/11/2025
Oh cool! This was needed :)
010
Philipp Scheit @pscheit.bsky.social · 20/11/2025
Cash-in November! :)
010
Philipp Scheit @pscheit.bsky.social · 20/11/2025
Oooh. 😊 You are very welcome! I use it in all my projects and this was long overdue :)) Thanks for maintaining that library!
010
Philipp Scheit @pscheit.bsky.social · 18/11/2025
I am so tired... Tested an deactivated encharge flow for an hour... :facepalm:
010
Reposted by Philipp Scheit
Packagist @packagist.com · 18/11/2025
New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how deps cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What’s New in Private Packagist, November Update
We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure a...
023
Philipp Scheit @pscheit.bsky.social · 15/11/2025
I spent days making this work for our customers, which sometimes even fail at this step 1: yaymemories.com/en/trial
110
Reposted by Philipp Scheit
Packagist @packagist.com · 14/11/2025
After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp
blog.packagist.com
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org
The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...
0167
Reposted by Philipp Scheit
Jordi Boggiano @seld.be · 13/11/2025
Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more! blog.packagist.com/composer-2-9/ #composerphp #phpc #PHP
blog.packagist.com
Composer 2.9 Release
We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...
0148
Philipp Scheit @pscheit.bsky.social · 01/11/2025
do you feel like you reached a point where you let it do its thing alone and the outcome is pretty okay? I am still working on that. There needs to be still a lot of manual reviews and intervention. Sometimes it just "starts to cheat" the tests it has written and e.g. hardcodes product ids
000
Philipp Scheit @pscheit.bsky.social · 01/11/2025
I think it even offers a wider range of solutions as before. Things that were very fast but cumbersome to maintain are currently possible. E.g. super fast, simple code, that is hard to maintain. Tests with lots of data, where the fixtures are hard to generate. Now its possible
000
Philipp Scheit @pscheit.bsky.social · 26/10/2025
Yes, it was hard work to get there. And it's nothing like you imagined vibe-coding. I iterated my CLAUDE.md and Skills for months, learned, read. Definitely not something easy. But imho totally worth it. Looking forward into the future with this.
010
Philipp Scheit @pscheit.bsky.social · 26/10/2025
Someone told me lately, that the typing speed is not relevant - and that's why they wouldn't see the need for AI. 97 files 3406 lines added 1892 lines removed All TDD, all DDD, in one day. Semi interactive build with Claude and Claude-Skills.
100
Philipp Scheit @pscheit.bsky.social · 25/10/2025
Claudes most annoying sentences: These failures are unrelated to my changes. You're absolutely right
000
Philipp Scheit @pscheit.bsky.social · 25/10/2025
After 5 years DDD I finally get to understand BoundedContexts in practice. This was a crazy journey!
000
Philipp Scheit @pscheit.bsky.social · 18/10/2025
Hard to tell what you want to accomplilsh. What do you mean by dynamically added classes?
100
Philipp Scheit @pscheit.bsky.social · 18/10/2025
Yeah, but you see the problem right? When you add 8 entities, how much code do you need to get this done? (in Laravel)
100
Philipp Scheit @pscheit.bsky.social · 18/10/2025
Hehe, have you ever "copied code from another project" the TDD style? Teaching this to Claude right now.. Never thought that this is something special I do. You still begin with an empty class and see what you need to copy - line by line - improve it along the way.
000
Philipp Scheit @pscheit.bsky.social · 15/10/2025
I still have troubles to teach Claude to write useful phpunit tests. I have to hand hold a lot there.
000
Philipp Scheit @pscheit.bsky.social · 15/10/2025
oh you store it in an entity. Well not sure than how to do this with laravel. But would prefer to not write a Cast*Thing for every object I want to embed in an object.
110