#ComposerPHP

2026-03-09

New release of github.com/joachim-n/drupal-co, the Composer template for working on #Drupal core issues. Thanks to @rkoller and rfay for their help! #ComposerPHP

github.com/ghostwriterghostwriter@phpc.social
2026-03-04

How do users report a composer package that is distributing a Remote Access Trojan (RAT) on packagist for removal/warning?

eg.

intel.aikido.dev/packages/pack

packagist.org/packages/nhattua

Payload: gitlab.com/nhattuanbl/lara-hel

#PHP #ComposerPHP

2026-03-02

Loved the very engaged audience of a thousand people at #LaraconEU 2026 in Amsterdam today at my "Composer Deep Dive" talk! Proud to sponsor the event with Private Packagist / @packagist - Find me and chat about package management or @thephpf ! Slides: naderman.de/slippy/slides/2026 #laravel #laracon #php #composerphp

Nils Adermann wearing a blue Private Packagist hoodie and yellow Private Packagist t-shirt on stage next to a lectern pointing at a slide, photographed across backs of audience heads.Sign with community sponsor logos at Laracon EU Amsterdam including Private PackagistNils Adermann taking a selfie from the balcony above the Laracon EU crowd with Nuno Maduro on a large screen talking to the audience.Laracon EU audience facing the stage
2026-03-01

Just arrived in Amsterdam for #LaraconEU - my talk "Composer Deep Dive" is tomorrow afternoon at 2:30pm! Hope to talk to as many of you about #composerphp @packagist and @thephpf! #laravel #php #laracon

2026-02-25

Excited to speak at #symfony user group Berlin tonight! #sfugberlin #composerphp

Full audience at c-base at the Symfony User Group Opening
2026-02-09

🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-i #composerphp #php #phpc

2025-12-01

Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist booth was busy with discussions throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026!

Slides: naderman.de/slippy/slides/2025

#php #composerphp

Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.
2025-11-27

Projects using #composerphp "autoload-files" in their composer.json will see some speedup when analzed with #phpstan, starting with the next phpstan release.

2025-11-18

New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how dependencies cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-i #php #phpc #composerphp

2025-11-14

After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist org to strengthen PHP supply chain security, funded by the Sovereign Tech Agency with help of the PHP Foundation and Private Packagist. #php #phpc #composerphp

More detail about what we're working on can be viewed on our blog at blog.packagist.com/strengtheni

Jordi Boggianoseldaek
2025-11-13

Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more!

Read the full announcement: blog.packagist.com/composer-2-

Jordi Boggianoseldaek
2025-11-07

Composer 2.9 is coming, and there's an RC to try out! We need your help and feedback github.com/composer/composer/r

2025-09-26

Bitbucket Cloud is retiring app passwords in favor of API tokens. If you're using Private Packagist with Bitbucket Cloud, migrate now to avoid future disruptions.

This blog post explains it step-by-step: blog.packagist.com/bitbucket-d

#php #composerphp #phpc #privatepackagist #bitbucket

Marcus Jaschenmjaschen
2025-09-24

Caching in CI/CD sollte eingesetzt werden, wann immer es geht.

Das hilft nicht nur, die Infrastrukturkosten niedrig zu halten, sondern verkürzt auch eigenen Build-Zeiten mitunter erheblich.

Für GitHub-/Gitea-kompatible Workflows gibt es actions/cache, welches trivial einzurichten ist.

blog.packagist.com/a-call-for-

github.com/actions/cache

github.com/actions/cache/blob/

2025-09-23

Together with PyPI, Maven Central, crates.io and other major package registries we signed a statement on sustainable open source infrastructure.

3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs.

Our Blog: blog.packagist.com/a-call-for-
Open Letter: openssf.org/blog/2025/09/23/op

#phpc #php #supplychainsecurity #opensourcesustainability

2025-09-20

🚨 Warning to PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc #composerphp

2025-09-19

🚨 PSA for #PHP package maintainers: DO NOT REPLACE tags! If you messed up a release simply do another. No matter how quickly you notice a mistake, automatic tools already pulled the original tag, triggered automatic updates. Users will never know you recreated the tag and use the broken state. #phpc #composerphp

2025-09-18

Had a great time presenting Composer Best Practices for 2025 at #APIPlatformCon in Lille this morning. Meet me at our booth, I'd love to hear all about how you work with #composerphp! Slides at naderman.de/slippy/slides/2025

#php #phpc #supplychainsecurity #symfony #apiplatform

Nils Adermann behind a lectern on stage at API PlatformCon receiving a birthday cake while the audience claps. The slide on stage asks "Questions / Feedback?" and points to Private Packagist.
2025-09-03

Would you like to attend #APIPlatformCon 2025 in Lille, France on September 18th & 19th or watch online? Private Packagist is sponsoring the event, and we have 4 tickets to give away! If you are part of a group, that is underrepresented at typical tech conferences, or can't afford a ticket, boost this post and comment with your favorite PHP package(s) - We'll pick a winner by the end of the week! #php #composerphp #phpc

Badge saying API Platform Conference 2025, Lille (France) & Online - Private Packagist is a wonderful Silver Sponsor and the Private Packagist elephant logo is shown on the right.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst