Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Volker Dusch (Edorian)

@edorian@phpc.social
mastodon 4.7.3
  • Open on phpc.social

👋 Hi, I'm a software engineering and management human interested in growing systems, developer experience, shipping, PHP performance, and more beautiful software things.

PHP 8.5 Release Manager. PHP Ecosystem Security Team Lead

Working @Tideways@phpc.social.

Gaming enthusiast. He/Him.

395 Followers
158 Following
50 Posts
Joined May 03, 2022
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 1w ago

Hello #PHP #Dresden,

Happy to be back and talk about Ecosystem Security.

Delighted to see @Tideways@phpc.social amongst the sponsors again :)

phpc.social

PHP Community on Mastodon

11
0
1
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 1w ago

Slides for my talk at the #PHP Developer Days in Dresden:

https://speakerdeck.com/edorian/securing-php-in-the-llm-age

Thank you very much for having me and for the feedback so far!

If there is anything the Ecosystem Security Team at The PHP Foundation can do for you, please get in touch: volker@thephp.foundation

#phpdd

phpc.social

PHP Community on Mastodon

10
0
8
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 1w ago

In @Tideways@phpc.social News:

With #PHP 8.6 having its own branch and first RC release now, we've released our extension with 8.6 support.

So if you're using #Tideways to test the performance of upcoming releases or track bugs with it, you're good to go!

Even if you don't: Try out the Release Candidate.
The best time to fix bugs is before the final release :)

https://www.php.net/archive/2026.php#2026-09-24-1

#php86

phpc.social

PHP Community on Mastodon

4
0
6
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 3w ago

Today someone asked how to do Python "execute if primary file" approach in PHP.

if __name__ == "__main__":
main()

The first two ideas:

if (get_included_files()[0] === __FILE__) {
main();
}

Which seems the most natural/stable.

Other ideas:

if (realpath($_SERVER['SCRIPT_FILENAME']) === __FILE__) {
main();
}

&

if (realpath($argv[0]) === __FILE__) {
main();
}

For /some/ reason, nobody seemed to like my suggestion of

if (!debug_backtrace()) {
main();
}

#php #fun

phpc.social

PHP Community on Mastodon

10
0
3
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 4w ago

RE: @thephpf@phpc.social

Delighted to have Daniel help out. It's a lot of diligent and fiddly work that I'm very happy to hand off to someone I trust.

phpc.social
6
0
1
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 1mo ago

With #factorio getting its final patch we wanted to finish off the last achievements before going back into modded runs.

Space Age in under 30 hours 🥳 on the first attempt.

https://factorio.com/galaxy/Sulfur%20IV:%20Delta4-2.B4V1

phpc.social
8
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
8.6 is coming together nicely. So many improvements; looking forward to upgrading.
9
0
2
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
Replying to
@brzuchal@phpc.social random inital feedback as you asked: syntax feels very far away from how the rest of PHP looks set[1,2,3]; would be closer to arrays, otherwise they could be just classes
4
4
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
RE: https://phpc.social/@packagist/116969590453454422 In the two month I'm doing security scans of PHP projects ( https://thephp.foundation/blog/2026/05/18/announcing-ecosystem-security-team/ ) I've come across multiple repositories with issues in their GitHub Actions. All fixed now. The issues allowed attackers to ship a new releases with arbitrary, hostile code. No required interactions from the project authors. Zizmor reported these issues. It also reports a lot of issues, read the story from the Packagist folks to learn about checking and hardening your GHA More reading: https://phpunit.expert/articles/hardening-github-actions-workflows.html
Open quoted post
Quoting
packagist
@packagist@phpc.social
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈 Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way: https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/ #php #phpc #composerphp #github #githubactions #supplychainsecurity
Open quoted post
phpc.social

packagist: "CI/CD pipelines are a prime target for supply cha…" - PHP Community on Mastodon

4
1
2
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 5mo ago

RE: @kore@chaos.social

The best piece of writing on building and growing #PHP applications I've read in many years.

Released by @kore@chaos.social, who's writing and insights I've always valued.

Available starting at 0€ and full of learnings I've made the hard way in the last 20 years.

A must read for individuals building, and for teams that want to understand each other better.
As Software development accelerates, this is more important than ever.

I don't usually recommend things. This one is special

https://codethatships.com/

chaos.social
14
0
12
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 5mo ago

Voting for the PHP 8.6 Release Mangers as ended today.

Congratulations to @mbeccati@phpc.social and @joepferguson@phpc.social

You can read my announcement and see the voting tally here:
https://news-web.php.net/php.internals/130645

Enjoy shipping @php@fosstodon.org !

#php #php86

news-web.php.net
13
1
7
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 1mo ago

Sebastian wrote a fantastic piece for the foundation blog around the ecosystem security efforts:

https://thephp.foundation/blog/2026/08/19/so-you-received-a-security-report-now-what/

I'd be delighted to hear from you folks what you think we should add to make this a more permanent resource and to hear if this is helpful to you.

#php #security

thephp.foundation
1
0
4
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago

> Shrink PHPStan baseline
> 312 lines removed

We have a GHA that shrinks the #PHPStan baseline every Saturday.

Coming in on Monday there's a PR waiting that removes all fixed issues from the baseline. It's always nice to see what got sorted out during last weeks changes.

phpc.social
9
2
4
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 5mo ago

Looked at our deployment stats at @Tideways@phpc.social for the last year.

Today we did our 555th deployments in the last 13 months.

That's around 2.5 deployments per working day 🥳

8
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
Replying to
@andrewnez@mastodon.social How gracious that you get to keep hosting their content
1
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Delighted with the applications we got for the #PHP 8.6 Release Mangers (RMs) so far. There are still a couple of days left to apply as well.
7
0
1
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 7mo ago

Last week Sebastian merged a #[DataProvider] feature I wanted since ... PHP 4? That is finally possible now. 🥳

https://github.com/sebastianbergmann/phpunit/pull/6526

Should ship in 13.1, in April.

Then say hi to:

#[DataProviderClosure(self::callableProvider(...))]

Inline closures as well!

I'm delighted. One of my goals with the two 8.5 RFCs [1][2] on the matter was to enable exactly this.

[1]: https://wiki.php.net/rfc/closures_in_const_expr

[2]: First Class Callables in constant expressions (FCC) https://wiki.php.net/rfc/first_class_callable_syntax

#PHP #PHPUnit #FCC

github.com
8
1
6
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
Replying to
@sebastian@phpc.social impressive change log
1
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
Replying to
@naderman@phpc.social I feel we have the same issue already with projects shipping phars where there is no insight into their dependencies (and less tooling in general)?
1
5
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
Replying to
@Girgias@phpc.social Train, Munich... (Me thinking: 😢 DB again...) ÖBB: Oh! Not it! Sorry to hear, funny plot twist though
1
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 4mo ago
Replying to
@Girgias@phpc.social entering
2
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
In a couple hours I'll be speaking about PHP Performance at the Manychat office in Barcelona: https://www.meetup.com/barcelona-php-talks/events/313617620/ Thank you for sponsoring the PHP Foundation Manychat :)
meetup.com
3
0
1
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 4mo ago
Replying to
@ramsey@phpc.social I'm more worried about the language presenting types where they are not enforced and the issues and bugs around that. People will always complain, but we shouldn't break how types work, and then make more BC issues when we potentially enforce some of these types in the future. Starting with the bits that work within the language and going iteratively forward would be my preferred approach. So the current RFC isn't what I'd vote for.
2
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 4mo ago
Replying to

@Crell@phpc.social

I think Erased is the most common, especially in compiled languages.

Rust and C++ don't erase types at all. Really not sure what you're thinking of here.

Typescript I wouldn't called "compiled" in that sense. Java does though.

--

Changing PHP to advertise a couple (commerical) tools to make types work is also something unprecedented.

Introducing syntax that does nothing and then later break projects that use it by giving it behavior is also an approach we tried to avoid.

2
3
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago

@flowcontrol@phpc.social The Elephpant now arrived at the TidewaysHQ in @beberlei@phpc.social's hands :)

3
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago

Less than 2 weeks to go to apply as a Release Manager for #PHP 8.6

https://news-web.php.net/php.internals/130240

phpc.social

PHP Community on Mastodon

3
0
9
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 5mo ago

Tried a lot of different options, but #iTerm is still by far my favorite terminal experience.

There's an option for everything I want, all use-cases are covered and everything is easily discoverable with a search.

It's a delight how a tool can stay so simple and yet be so powerful over so many years.

phpc.social
2
0
1
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Replying to
@flowcontrol@phpc.social Best wishes <3
2
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago

Giving a small talk about how #PHP8_5 came together from an RM perspective today at the IPC pre event.

Highlighting the contributors and reviewers behind the changes and how the work of individuals and that of the foundation shape PHP.

https://devm.io/live-events/modern-php-in-practice/#fullstack

Edit: Just figured out that's paid access event 😓 , unclear if that will be freely available later on.

phpc.social
2
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Replying to

@brendt For transitive dependencies I never cared. Especially not about the SF ones as they're managed, security-wise, for all I care.

And otherwise composer replaces seems like a good choice.

Given PHP can be build without so many exptensions sadly dropping these polyfills is not an option for most libaries that want to provide DX.

I don't think dropping these for is sensible for most libraries.

2
5
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Replying to
@asgrim@phpc.social major outages 2016-2018. Unclear how that goes to 100% https://hn.algolia.com/?dateEnd=1545696000&dateRange=custom&dateStart=1456531200&page=0&prefix=true&query=github%20outage&sort=byPopularity&type=story And the data showing ~100 min downtime per month also seems to add up all services? Or some alternative data for "only 90% availability" numbers: https://mrshu.github.io/github-statuses/ Just, things have been on fire before Azure as well.
hn.algolia.com
2
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 4mo ago
Replying to
@brendt@phpc.social Is there anyone that actually thinks this would change something fundamental for the ecosystem? I'm deeply confused why you'd call this a "masterpiece" and I'm trying very hard to take this seriously, but it's hard. We have like 10 implementation of exactly this for many years now. And PHP has decided it doesn't want to be Python orJavaScript where you have to reimplement each type check that actually matters again at runtime or just hope for the best. What am I missing?
1
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 4mo ago
Replying to
@brendt@phpc.social We already have generics in PHP in syntax that do nothing at runtime, for years. If we want PHP to not be language with runtime type checks but have type-hoping like with elevated comments we could have done this for years. I don't see this RFC as adding new above minimal sugar. Sure it would appease the shallow and uncurious social media hype cycle, but it wouldn't change anything about how PHP works or written, except blocking us from every having proper type checking again.
1
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 5mo ago
Replying to
@beberlei@phpc.social BetterReflection? Otherwise the PHPStan types
1
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Replying to
@brendt I'd love to make chunk of bundled-but-optional PHP extensions non-optional. If you're interested in a RFC on that, I'd be happy to collaborate in figuring that out :)
1
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 7mo ago
Replying to
@dantleech 😅 I actually didn't know or think to check
1
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
RE: https://phpc.social/@sebastian/117001358342074524 Sebastian also wrote some words on the issue with pipes in php-parser, that I've discussed with some of you.
Open quoted post
Quoting
Sebastian Bergmann :phpunit:
@sebastian@phpc.social
A security vulnerability in PHPCSUtils revealed an eval() call in a static analysis tool. Why disable_functions cannot reach eval(), and what a switch in the PHP engine to disable it could look like: https://phpunit.expert/articles/when-static-analysis-runs-your-code.html?ref=mastodon
Open quoted post
phpc.social

Sebastian Bergmann :phpunit:: "A security vulnerability in PHPCSUtils revealed a…" - PHP Community on Mastodon

0
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 3mo ago
RE: https://phpc.social/@packagist/116879040486226971 Fantastic work
Open quoted post
Quoting
packagist
@packagist@phpc.social
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log. All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/ #php #phpc #composerphp
Open quoted post
phpc.social
0
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
Replying to
@paulca@mastodon.social hurray
0
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 1w ago
Replying to
@Synchro@phpc.social Hey Marcus. I'm Volker from the Ecosystem Security team at the PHP foundation ( https://thephp.foundation/blog/2026/05/18/announcing-ecosystem-security-team/ ) Is there something I can help with? The current delays for CVEs sadly are 5-10 weeks. If there's something I can do to help, feel to email, discord or DM me here. Depending on the specifics and what you want to achieve there are ways to get this done, or for me to reach out for help. Also available if you want to just talk things through.
Announcing the Ecosystem Security Team at The PHP Foundation
thephp.foundation

Announcing the Ecosystem Security Team at The PHP Foundation

The PHP Foundation — Supporting, Advancing, and Developing the PHP Language

0
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 3mo ago
Replying to
@rowan_m@mastodon.social beautiful
0
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Replying to
@derickr (☞ ͡° ͜ʖ ͡°)☞ (No)
0
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 7mo ago
Replying to

@dantleech For final reasons and some other details this doesn't work.

But it's not far off with the underlying infra

0
2
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 3mo ago
Replying to
@rowan_m@mastodon.social as long as one does not look at the sauce
0
0
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Replying to
@brendt it means that potentially all composer requirements are met but the application isn't working, right? Or am I missing something there
0
3
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 5mo ago
Replying to
@klimpong Very philosophical question. Code changes going to production? A different binary/archive reaching 1-n servers facing user traffic?
0
1
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 6mo ago
Replying to
@asgrim@phpc.social Tested the @Tideways@phpc.social CI with the upgraded runner. All green 👍
0
2
0
0
Open post
Volker Dusch (Edorian) @edorian@phpc.social
· 2mo ago
RE: https://phpc.social/@packagist/117008833006861501 🎉 @Tideways@phpc.social mentioned
Open quoted post
Quoting
packagist
@packagist@phpc.social
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia. Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers. https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/ #php #phpc #composerphp
Open quoted post
phpc.social
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:59:53 UTC