Happy to be back and talk about Ecosystem Security.
Delighted to see @Tideways@phpc.social amongst the sponsors again :)
👋 Hi, I'm a software engineering and management human interested in growing systems, developer experience, shipping, PHP performance, and more beautiful software things.
PHP 8.5 Release Manager. PHP Ecosystem Security Team Lead
Working @Tideways@phpc.social.
Gaming enthusiast. He/Him.
Happy to be back and talk about Ecosystem Security.
Delighted to see @Tideways@phpc.social amongst the sponsors again :)
Slides for my talk at the #PHP Developer Days in Dresden:
https://speakerdeck.com/edorian/securing-php-in-the-llm-age
Thank you very much for having me and for the feedback so far!
If there is anything the Ecosystem Security Team at The PHP Foundation can do for you, please get in touch: volker@thephp.foundation
In @Tideways@phpc.social News:
With #PHP 8.6 having its own branch and first RC release now, we've released our extension with 8.6 support.
So if you're using #Tideways to test the performance of upcoming releases or track bugs with it, you're good to go!
Even if you don't: Try out the Release Candidate.
The best time to fix bugs is before the final release :)
Today someone asked how to do Python "execute if primary file" approach in PHP.
if __name__ == "__main__":
main()
The first two ideas:
if (get_included_files()[0] === __FILE__) {
main();
}
Which seems the most natural/stable.
Other ideas:
if (realpath($_SERVER['SCRIPT_FILENAME']) === __FILE__) {
main();
}
&
if (realpath($argv[0]) === __FILE__) {
main();
}
For /some/ reason, nobody seemed to like my suggestion of
if (!debug_backtrace()) {
main();
}
Delighted to have Daniel help out. It's a lot of diligent and fiddly work that I'm very happy to hand off to someone I trust.
The best piece of writing on building and growing #PHP applications I've read in many years.
Released by @kore@chaos.social, who's writing and insights I've always valued.
Available starting at 0€ and full of learnings I've made the hard way in the last 20 years.
A must read for individuals building, and for teams that want to understand each other better.
As Software development accelerates, this is more important than ever.
I don't usually recommend things. This one is special
Voting for the PHP 8.6 Release Mangers as ended today.
Congratulations to @mbeccati@phpc.social and @joepferguson@phpc.social
You can read my announcement and see the voting tally here:
https://news-web.php.net/php.internals/130645
Enjoy shipping @php@fosstodon.org !
Sebastian wrote a fantastic piece for the foundation blog around the ecosystem security efforts:
https://thephp.foundation/blog/2026/08/19/so-you-received-a-security-report-now-what/
I'd be delighted to hear from you folks what you think we should add to make this a more permanent resource and to hear if this is helpful to you.
Looked at our deployment stats at @Tideways@phpc.social for the last year.
Today we did our 555th deployments in the last 13 months.
That's around 2.5 deployments per working day 🥳
Last week Sebastian merged a #[DataProvider] feature I wanted since ... PHP 4? That is finally possible now. 🥳
https://github.com/sebastianbergmann/phpunit/pull/6526
Should ship in 13.1, in April.
Then say hi to:
#[DataProviderClosure(self::callableProvider(...))]
Inline closures as well!
I'm delighted. One of my goals with the two 8.5 RFCs [1][2] on the matter was to enable exactly this.
[1]: https://wiki.php.net/rfc/closures_in_const_expr
[2]: First Class Callables in constant expressions (FCC) https://wiki.php.net/rfc/first_class_callable_syntax
I think Erased is the most common, especially in compiled languages.
Rust and C++ don't erase types at all. Really not sure what you're thinking of here.
Typescript I wouldn't called "compiled" in that sense. Java does though.
--
Changing PHP to advertise a couple (commerical) tools to make types work is also something unprecedented.
Introducing syntax that does nothing and then later break projects that use it by giving it behavior is also an approach we tried to avoid.
@flowcontrol@phpc.social The Elephpant now arrived at the TidewaysHQ in @beberlei@phpc.social's hands :)
Tried a lot of different options, but #iTerm is still by far my favorite terminal experience.
There's an option for everything I want, all use-cases are covered and everything is easily discoverable with a search.
It's a delight how a tool can stay so simple and yet be so powerful over so many years.
Giving a small talk about how #PHP8_5 came together from an RM perspective today at the IPC pre event.
Highlighting the contributors and reviewers behind the changes and how the work of individuals and that of the foundation shape PHP.
https://devm.io/live-events/modern-php-in-practice/#fullstack
Edit: Just figured out that's paid access event 😓 , unclear if that will be freely available later on.
@brendt For transitive dependencies I never cared. Especially not about the SF ones as they're managed, security-wise, for all I care.
And otherwise composer replaces seems like a good choice.
Given PHP can be build without so many exptensions sadly dropping these polyfills is not an option for most libaries that want to provide DX.
I don't think dropping these for is sensible for most libraries.
@dantleech For final reasons and some other details this doesn't work.
But it's not far off with the underlying infra