#phpc
18 posts · Last used 8d
Boosted by @dansup@mastodon.social
Packagist turns 15 🎉
On September 27, 2011, monolog/monolog became package ID 1. Today Packagist lists more than 469,000 packages, and Composer has installed packages from it more than 200 billion times.
Our anniversary post covers how it all started, 15 years of milestones, the growth we've seen in 2026, and what comes next for supply chain security and funding.
https://blog.packagist.com/15-years-of-packagist-over-200-billion-package-installs/
#php #phpc #composerphp #opensource
PHP conference and user group organisers, please read! https://thephp.foundation/blog/2026/09/28/kicking-off-the-community-events-coalition-sig/
@ian@phpc.social @mbeccati@phpc.social @dragonbe@phpc.social @eric@phparch.social @phpc@phpc.social @DaveLiddament@phpc.social @SecondeJ@phpc.social and probably loads more I can't think of atm, please spread the word!
#php #phpc #phpconferences #phpug #phpusergroups #phpmeetups #phpx #community #phpcommunity
Community events are the lifeblood of the PHP ecosystem and how we build trust in an ever-changing world. We are very happy to announce the launch of the Community Events Coalition SIG to help keep these crucial pieces of our community thriving. Read more: https://thephp.foundation/blog/2026/09/28/kicking-off-the-community-events-coalition-sig/
#php #phpc #opensourceevents
Replying to
Thanks to Brian Fox and Sonatype: a key role in the Sustaining Package Registries Working Group as steward of Maven Central, and now sponsoring Composer & Packagist even though one of their products competes with our own Private Packagist. The infrastructure underneath both our products is shared, and we need to fund it together.
That is where this needs to be heading: every major beneficiary contributing, like any other critical infrastructure they budget for.
#php #phpc #composerphp
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia.
Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers.
https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/
#php #phpc #composerphp
We're excited to announce @upsun@mastodon.social is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.
If your company wants to still become a launch partner for our sponsorship program this week, reach out to sponsoring@packagist.org.
#php #phpc #composerphp
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/
#php #phpc #composerphp #github #githubactions #supplychainsecurity
Boosted by @welcome@friends.deko.cloud
Hey #phpc 👋 New here. I'm a PHP dev — mostly legacy CodeIgniter & Laravel work — and I tinker with dev tooling and app security. Glad to be on a more community-driven corner of the web. Looking forward to learning from you all.
#PHP #introduction
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log.
All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/
#php #phpc #composerphp
Does PHP really need asynchronous programming in its core, or should it continue focusing on its proven synchronous execution model?
#php #phpc #async #asynchronous
If you're curious about what our Ecosystem Security Team has been up to the past month, you're in luck! @edorian@phpc.social has provided an update in our recent blog post. https://thephp.foundation/blog/2026/06/23/one-month-of-ecosystem-security-engineering/ #php #phpc #phpsecurity
In our latest blog post, Foundation contractor @shivammathur@phpc.social digs into the details of providing support for PHP builds on Windows and why this is such an important piece of the work we do. 🚀 https://thephp.foundation/blog/2026/06/26/maintaining-php-build-infrastructure-for-windows-tooling-for-builds-and-security-updates/ #php #phpc #windows #security
Building a more accessible PHP ecosystem is something The PHP Foundation cares a great deal about. We are honored to share this post from guest blogger @menelion@dragonscave.space about what it's like to be a visually impaired PHP developer, learning and coding PHP. 💙 #php #accessibility #phpchttps://thephp.foundation/blog/2026/06/16/php-through-a-screen-reader-small-syntax-choices-that-matter/
Get ready to elevate your ecommerce game!
Join us on April 30th at the Sylius Meetup in Mannheim, where Sebastian Langer will introduce the Laioutr platform and its powerful #Sylius connector. 🤝 Learn how to build digital experiences that are faster, better, and more efficient.
Sign up now: https://www.meetup.com/phpug-rhein-neckar/events/312782219/
#phpugmrn #rheinneckarrocks #phpc #sylius
Boosted by @dansup@mastodon.social
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on Packagist.org and Private Packagist. Details on our blog: https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/ #php #phpc #composerphp
For those who don't know our new Executive Director, Elizabeth Barron, she's written an introductory post on The PHP Foundation Blog that shares a bit about her background, her vision for the future, and how you can share your own PHP thoughts with her. She wants to hear from you!
#phpc #php
Read more: https://thephp.foundation/blog/2026/03/05/working-together-on-the-future-of-php/
Very much looking forward to returning to the @dutchphpconference@mastodon.social next month 🇳🇱 - I'll be talking about 🥧 PIE of course! :)
Hopefully I'll see some of you there, if you are, mark yourself as coming on the @roave@mastodon.social Discord too: https://discord.gg/roave?event=1461623085638877300
#php #phpc #phppie #pie
You've seen all posts










