packagist
PHP Package Repository for #ComposerPHP (https://getcomposer.org). See https://packagist.org for open source, https://packagist.com for private packages.
🔒 An update on Composer & Packagist supply chain security:
Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.
If you maintain PHP packages, please enable MFA now.
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #phpc #composerphp
We hope you enjoyed @glaubinix@phpc.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday@phpc.social in Verona, Italy!
Slides at https://glaubinix.github.io/talks/2026-05-15-Composer-2-10-Malware-Filtering.html
#php #phpc #phpday #composerphp #supplychainsecurity #malware
⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.
Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.
The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.
Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.
https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/
#php #phpc #composerphp
Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on all the work completed in 2025. So much more could be accomplished, if more businesses relying on PHP contributed too. Sign up as a sponsor and help moving PHP forward!
Together with PyPI, Maven Central, crates.io and other major package registries we signed a statement on sustainable open source infrastructure.
3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs.
Our Blog: https://blog.packagist.com/a-call-for-sustainable-open-source-infrastructure/
Open Letter: https://openssf.org/blog/2025/09/23/open-infrastructure-is-not-free-a-joint-statement-on-sustainable-stewardship/
If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc
Three months of Private Packagist updates: Malware filter list support is already in place, ahead of Composer 2.10's release next week. Flagged versions show warning banners on package pages and are marked in the version list. Permissions views on package level, better background job & sync visibility, and a narrower GitLab OAuth scope (read_api).
https://blog.packagist.com/whats-new-in-private-packagist-may-2026-update/
🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/
#php #phpc #composerphp
After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist org to strengthen PHP supply chain security, funded by the Sovereign Tech Agency with help of the PHP Foundation and Private Packagist. #php #phpc #composerphp
More detail about what we're working on can be viewed on our blog at https://blog.packagist.com/strengthening-php-supply-chain-security-with-a-transparency-log-for-packagist-org/
Private Packagist is a member of the @opensourcepledge@fosstodon.org & gave over $4k/FTE in 2025 to #opensource maintainers. Have your company join too! https://blog.packagist.com/private-packagist-2025-contributions-for-the-open-source-pledge/ - Reach out if you want to be a launch partner for our Composer&Packagist.org sponsorship program! #composerphp #php #phpc
In Amsterdam next week and part of a group underrepresented at tech confs, or can't afford a ticket? Private Packagist is sponsoring @symfony@phpc.social Con (Nov 27th/28th) and we have a ticket to give away: Reply your favorite PHP8.5 feature to win #php #phpc #symfony #symfonycon
New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how dependencies cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. https://blog.packagist.com/whats-new-in-private-packagist-november-update/ #php #phpc #composerphp
🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal https://blog.packagist.com/whats-new-in-private-packagist-february-2026-update/ #composerphp #php #phpc
Bitbucket Cloud is retiring app passwords in favor of API tokens. If you're using Private Packagist with Bitbucket Cloud, migrate now to avoid future disruptions.
This blog post explains it step-by-step: https://blog.packagist.com/bitbucket-deprecated-app-passwords/




