Sign in

Jordi Boggiano

@seld.be
362 followers 128 following 14 posts

Co-Founder of @packagist.com – Dev at teamup.com – #ComposerPHP lead – Wandering Belgian aka Seldaek

PostsRepliesMedia
Reposted by Jordi Boggiano
Packagist @packagist.com · 29/09/2026
Packagist turns 15, with more than 200 billion package installs 🎉 How Composer and Packagist started, 15 years of milestones, recent growth, and our plans for supply chain security and funding. blog.packagist.com/15-years-of... #php #phpc #composerphp
064
Reposted by Jordi Boggiano
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Reposted by Jordi Boggiano
Packagist @packagist.com · 30/07/2026
Composer & Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure. blog.packagist.com/announcing-... #php #phpc #composerphp
1136
Reposted by Jordi Boggiano
Packagist @packagist.com · 07/07/2026
📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable. blog.packagist.com/immutable-v... #php #phpc #composerphp
01110
Reposted by Jordi Boggiano
Josh Bressers @josh.bressers.name · 22/06/2026
I had a chat with Jordi Boggiano from Packagist about a heap of security features they recently added and adding in the future The security of the public package repositories is a hot topic right now, Packagist is doing some really interesting things to improve their security
opensourcesecurity.io
Packagist and Composer security with Jordi Boggiano
Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they’ve recently added. Packagist is the PHP package registry, Composer is the ...
046
Reposted by Jordi Boggiano
Nils Adermann @naderman.de · 16/06/2026
Busy times: Here are my slides on Composer & Packagist Supply Chain Security from #PHPVerse: naderman.de/slippy/slide... Thanks @jetbrains.com for a great online event! Videos soon! Follow blog.packagist.com for updates. #php #phpc #composerphp #supplychainsecurity
naderman.de
054
Reposted by Jordi Boggiano
Packagist @packagist.com · 12/06/2026
🧩 Composer plugins are powerful, but execute code during install & update. Composer prompts to allow a plugin, but a distracted "yes" or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. blog.packagist.com/restricting-... #php #phpc #composerphp
blog.packagist.com
Restricting Composer plugins across your organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads...
143
Reposted by Jordi Boggiano
Packagist @packagist.com · 04/06/2026
The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own. Private Packagist customers can now enforce which Composer versions are allowed to use their repository. blog.packagist.com/enforce-a-sa... #php #phpc #composerphp
blog.packagist.com
Enforce a Safe Composer Version Across Your Organization
This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downl...
064
Jordi Boggiano @seld.be · 04/06/2026
Ever found yourself accidentally merging changes to the public API of a PHP package and regretting it later? I made a GitHub Action to help prevent that. seld.be/notes/surfac...
seld.be
Making public API surfaces changes more visible in open source libraries | Jordi's Ramblings
...
002
Reposted by Jordi Boggiano
Packagist @packagist.com · 01/06/2026
🛡️ Composer's download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone. Two new Private Packagist options close it off. blog.packagist.com/closing-comp... #php #phpc #composerphp
035
Jordi Boggiano @seld.be · 29/05/2026
I realized I was never going to get to adding zizmor to all my repos so I made a claude skill to let it do the grunt work. You can use it too, if it helps more busy/lazy people to secure their GitHub repos I am glad! See github.com/Seldaek/zizm...
github.com
GitHub - Seldaek/zizmorify: Agent skill to harden GitHub Actions by adding zizmor to your CI and fix existing workflow errors
Agent skill to harden GitHub Actions by adding zizmor to your CI and fix existing workflow errors - Seldaek/zizmorify
021
Jordi Boggiano @seld.be · 28/05/2026
📦 Composer 2.10 is out. Native malware filtering via @aikidosecurity.bsky.social (enabled by default on Packagist), a unified config.policy framework for advisories/abandoned/malware, and source fallback now deprecated. blog.packagist.com/composer-2-1... #php #phpc #composerphp
blog.packagist.com
Composer 2.10 Release
We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of se...
01710
Reposted by Jordi Boggiano
Packagist @packagist.com · 27/05/2026
🔒 An update on Composer & Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what's next. If you maintain PHP packages, enable MFA now. blog.packagist.com/an-update-on... #php #phpc #composerphp #supplychainsecurity
blog.packagist.com
An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via tak...
1912
Jordi Boggiano @seld.be · 20/05/2026
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC2 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC2 Running comp...
076
Reposted by Jordi Boggiano
Packagist @packagist.com · 20/05/2026
We recommend you change the default permissions for GitHub Actions GITHUB_TOKENs to read only. Explicitly grant elevated permissions only where strictly necessary. Use zizmor to analyze your GitHub Actions: github.com/zizmorcore/z... see also: phpunit.expert/articles/har...
Workflow permissions setting screen in GitHub with "Read repository contents and packages permissions" selected rather than "Read and write permissions"
044
Reposted by Jordi Boggiano
Packagist @packagist.com · 20/05/2026
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
169
Reposted by Jordi Boggiano
Packagist @packagist.com · 18/05/2026
Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10's release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What's New in Private Packagist, May 2026 Update
Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most n...
034
Reposted by Jordi Boggiano
Packagist @packagist.com · 13/05/2026
UPDATE: GitHub has rolled back their change to GitHub Actions tokens, no longer necessary to immediately disable GitHub Actions. We now have a few days to get the PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. #php #composerphp #phpc
022
Reposted by Jordi Boggiano
Packagist @packagist.com · 13/05/2026
🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages. Update now or disable affected workflows. blog.packagist.com/composer-2-9... #composerphp #phpc #php
blog.packagist.com
Composer 2.9.8 and 2.2.28 fix GitHub Actions token disclosure in error messages
Please immediately update Composer to version 2.9.8 or 2.2.28 (LTS) by running composer.phar self-update. The new releases fix a vulnerability where Composer leaks the full contents of GitHub Actions ...
178
Reposted by Jordi Boggiano
Nils Adermann @naderman.de · 06/05/2026
Packagist needs to finance staff, not just hardware and bandwidth. Contact me if your company's interested in joining our sponsorship program for its launch this month while we work on long term solutions.
025
Reposted by Jordi Boggiano
Nils Adermann @naderman.de · 06/05/2026
Open infrastructure isn't free. 🌱 Packagist/Composer signed a joint @openssf.org letter with PyPI, crates, Maven, CPAN, etc on real cost of running package registries. #php #phpc #composerphp #softwaresupplychain #PreserveOpenSource #FreeSoftwareIsntFree #OpenSource #Sustainability
1119
Reposted by Jordi Boggiano
Packagist @packagist.com · 14/04/2026
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: blog.packagist.com/composer-2-9... #php #phpc #composerphp
packagist.org
Packagist.org
The PHP Package Repository
039
Jordi Boggiano @seld.be · 01/04/2026
We need your help to test Composer 2.10. Expect a final release next week, now is the time to try it out and flag any issue you find! github.com/composer/com... #composerphp #phpc
github.com
Release 2.10.0-RC1 · composer/composer
Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC1 Running comp...
047
Reposted by Jordi Boggiano
Packagist @packagist.com · 18/03/2026
Private Packagist is a member of the @opensourcepledge.com & gave over $4k/FTE in 2025 to #opensource maintainers. Have your company join too! blog.packagist.com/private-pack... - Reach out if you want to be a launch partner for our Composer&Packagist.org sponsorship program! #composerphp #php #phpc
blog.packagist.com
Private Packagist 2025 contributions for the Open Source Pledge
This is now our third year as a member of the Open Source Pledge. Private Packagist subscriptions help fund not only the development of Composer and Packagist.org, but also the open source dependencie...
173
Reposted by Jordi Boggiano
Packagist @packagist.com · 09/02/2026
🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-in... #composerphp #php #phpc
blog.packagist.com
What's New in Private Packagist, February 2026 Update
Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights f...
053
Reposted by Jordi Boggiano
Packagist @packagist.com · 03/12/2025
Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!
1277
Reposted by Jordi Boggiano
Nils Adermann @naderman.de · 01/12/2025
Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist.com booth was busy throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026! #php #composerphp
Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.
193
Reposted by Jordi Boggiano
Packagist @packagist.com · 18/11/2025
New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how deps cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-in... #php #phpc #composerphp
blog.packagist.com
What’s New in Private Packagist, November Update
We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure a...
023
Reposted by Jordi Boggiano
Packagist @packagist.com · 14/11/2025
After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp
blog.packagist.com
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org
The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...
0167
Jordi Boggiano @seld.be · 13/11/2025
Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more! blog.packagist.com/composer-2-9/ #composerphp #phpc #PHP
blog.packagist.com
Composer 2.9 Release
We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...
0148
Jordi Boggiano @seld.be · 07/11/2025
Composer 2.9 is coming, and there's an RC to try out! We need your help and feedback github.com/composer/com... #composerphp #phpc
github.com
Release 2.9.0-RC1 · composer/composer
Composer 2.9 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.9.0-RC1 Running compos...
064
Reposted by Jordi Boggiano
Packagist @packagist.com · 20/09/2025
🚨 Warning to #PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc
02540
Reposted by Jordi Boggiano
Packagist @packagist.com · 23/09/2025
Together with PyPI, Maven Central, cratesio and other major package registries we signed a statement on sustainable open source infrastructure. 3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs. #phpc #php
1168
Reposted by Jordi Boggiano
Packagist @packagist.com · 01/09/2025
The era of Composer v1 finally comes to an end, long live Composer v2! 👑 Today packagist.org support for v1 metadata has been shut down as announced last year. blog.packagist.com/packagist-or... #composerphp #phpc #php
packagist.org
Packagist
The PHP Package Repository
1116
Reposted by Jordi Boggiano
Packagist @packagist.com · 01/09/2025
August update: dependency usage tracking across your packages, automatic GitLab token rotation, and Conductor improvements with custom labels and smarter PR handling blog.packagist.com/whats-new-in... #php #composer #composerphp #phpc
blog.packagist.com
What’s New in Private Packagist, August Update
We've been busy improving Private Packagist over the past few months with a focus on package discovery, user experience improvements, and improved security monitoring tools. Here are the most signific...
023
Reposted by Jordi Boggiano
Packagist @packagist.com · 04/07/2025
🚨 Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025. Act now, upgrade to Composer 2! Last resort: check out Private Packagist extended 1.x support if you really cannot migrate right now. blog.packagist.com/packagist-or...
blog.packagist.com
Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025
With the deadline drawing near, we’d like to remind you that we are discontinuing Composer 1.x support on Packagist.org soon. We're extending our original timeline by one month to give teams additiona...
049
Jordi Boggiano @seld.be · 06/06/2025
I will be at WordCamp Europe today talking about Composer and dependency management. Find me if you want to chat about @packagist.com!
010
Reposted by Jordi Boggiano
Kévin Dunglas @dunglas.dev · 18/02/2025
Let's add modern compression formats to PHP! The new RFC for natively integrating Zstandard and Brotli proposed by @seld.be and myself would significantly improve Composer and asset pre-compression by @symfony.com AssetMapper.
externals.io
[RFC] Modern Compression (zstd, brotli) - Externals
#externals - Opening PHP's #internals to the outside
0178
Reposted by Jordi Boggiano
Nils Adermann @naderman.de · 03/02/2025
Stop by our @packagist.com booth at #LaraconEU and have a chat about Composer, Packagist, Conductor or anything else relating to dependency management and supply chain security! #Laravel #Laracon
Two people on stools at a table in front of a Private Packagist and a Conductor banner as well as a big screen.
1165
Jordi Boggiano @seld.be · 06/12/2024
Got our #SymfonyCon tickets for next year already
0161
Reposted by Jordi Boggiano
Packagist @packagist.com · 06/12/2024
Meet our team at #SymfomyCon Vienna! We'd love to chat about how you manage your Composer dependencies, your questions around supply chain security, Private Packagist or our upcoming product Conductor! #symfony #php #composerphp
Team photo in front of Symfony Logo
1152
Reposted by Jordi Boggiano
Packagist @packagist.com · 04/12/2024
We're excited to introduce you to 🧑‍✈️Conductor! Automatic dependency update PRs with Composer for PHP projects - Security fixes patched in minutes - Continuous updates without the hassle - all running in your own CI env! Early access waitlist: packagist.com/features/con... #composerphp #php #phpc
packagist.com
Conductor - Automatic dependency updates for Composer
Automatic dependency updates for Composer - tailor made for PHP. Grouped and scheduled in ways that just make sense for PHP projects.
24219
Reposted by Jordi Boggiano
Derick Rethans @derickr.phpc.social.ap.brid.gy · 03/12/2024
➡️ The PHP manual has learned a new trick, you can now run the code right in the browser! 🥳 Thanks to @soyuka for the implementation! #php #documentation
915767