Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

packagist

@packagist@phpc.social
mastodon 4.7.3
  • Open on phpc.social

PHP Package Repository for #ComposerPHP (https://getcomposer.org). See https://packagist.org for open source, https://packagist.com for private packages.

0 Followers
0 Following
25 Posts
Joined October 31, 2022
Open post
packagist @packagist@phpc.social
· 1w ago
Boosted by @dansup@mastodon.social
Packagist turns 15 🎉 On September 27, 2011, monolog/monolog became package ID 1. Today Packagist lists more than 469,000 packages, and Composer has installed packages from it more than 200 billion times. Our anniversary post covers how it all started, 15 years of milestones, the growth we've seen in 2026, and what comes next for supply chain security and funding. https://blog.packagist.com/15-years-of-packagist-over-200-billion-package-installs/ #php #phpc #composerphp #opensource
15 years of Packagist: Over 200 billion package installs
Private Packagist

15 years of Packagist: Over 200 billion package installs

On September 27th, 2011, Jordi submitted monolog/monolog to Packagist.org, it got package ID 1. Fifteen years later, Packagist.org lists more than 469,000 packages with over 5.8 million versions, and Composer has installed packages from it more than 200 billion times. Monolog alone has passed one

47
0
44
0
Open post
packagist @packagist@phpc.social
· 2mo ago
Composer & Packagist now have a formal sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia. Our costs are primarily staff: operations, support, emergency response, maintenance and development. We ask enterprises profiting from the PHP ecosystem to pay their fair share to keep our shared critical infrastructure available to all PHP developers. https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/ #php #phpc #composerphp
Announcing the Composer & Packagist Sponsorship Program
Private Packagist

Announcing the Composer & Packagist Sponsorship Program

Today we are launching a formal sponsorship program for Composer and Packagist.org, together with new public sponsor pages on packagist.org/sponsor and getcomposer.org/sponsor. We want to start by thanking the companies who are on board at launch: Private Packagist, Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways,

33
4
34
3
Open post
packagist @packagist@phpc.social
· 3mo ago
📌 Stable versions on Packagist are now immutable. Once a version is published, the git commit it points to can no longer change. Retags are blocked and deleted versions are now marked with a reason and recoverable, if unmodified. Every change is recorded on the package's public transparency log. All details on our blog: https://blog.packagist.com/immutable-versions-on-packagist/ #php #phpc #composerphp
Immutable Versions on Packagist
Private Packagist

Immutable Versions on Packagist

This is the next post in our supply chain security series, following the supply chain security update and the Composer 2.10 release. Each post in this series covers a specific behavior worth understanding, and a change we are making on top of it. Today: Stable version metadata on Packagist.

47
0
50
1
Open post
packagist @packagist@phpc.social
· 2mo ago
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈 Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way: https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/ #php #phpc #composerphp #github #githubactions #supplychainsecurity
Securing our GitHub Actions workflows with zizmor
Private Packagist

Securing our GitHub Actions workflows with zizmor

This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we hardened

9
0
9
1
Open post
packagist @packagist@phpc.social
· 4mo ago

🔒 An update on Composer & Packagist supply chain security:

Covering what's in place today, what ships this week with Composer 2.10 (dependency policies, stable version immutability), what's coming next (mandatory MFA, minimum-release-age policy, organizational package ownership), and the long-term direction toward immutable artifacts with SLSA provenance and sigstore attestations.

If you maintain PHP packages, please enable MFA now.

https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #phpc #composerphp

blog.packagist.com
19
2
27
1
Open post
packagist @packagist@phpc.social
· 4mo ago

We hope you enjoyed @glaubinix@phpc.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor @phpday@phpc.social in Verona, Italy!

Slides at https://glaubinix.github.io/talks/2026-05-15-Composer-2-10-Malware-Filtering.html

#php #phpc #phpday #composerphp #supplychainsecurity #malware

glaubinix.github.io
15
1
9
0
Open post
packagist @packagist@phpc.social
· 4mo ago

⛔ Composer dependency policies block flagged malware by default, but only on 2.10. A project disabling the policy, or a CI image running Composer 2.4, still installs flagged versions normally until we can manually pull it from Packagist.

Private Packagist now refuses to serve dist files for malware-flagged versions at the repository level, regardless of the Composer version requesting them. Enabled by default for new and existing organizations.

https://blog.packagist.com/blocking-malware-downloads-for-every-composer-version-in-private-packagist/

#php #phpc #composerphp

blog.packagist.com
10
0
14
0
Open post
packagist @packagist@phpc.social
· 4mo ago
Replying to
UPDATE: GitHub has rolled back their change to GitHub Actions tokens. It is no longer necessary to immediately disable GitHub Actions. We now have a few days to get the entire PHP ecosystem updated to safe Composer versions, before a new rollout of the new token format is attempted. GitHub is also looking into improving their secrets masking. Ideally a new rollout will not lead to any leaked credentials, even if they are accidentally exposed in logs. #php #composerphp #phpc
11
0
12
0
Open post
packagist @packagist@phpc.social
· 5mo ago
Boosted by @dansup@mastodon.social
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on Packagist.org and Private Packagist. Details on our blog: https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/ #php #phpc #composerphp
Composer 2.9.6 fixes Perforce Driver Command Injection Vulnerabilities (CVE-2026-40261, CVE-2026-40176)
Private Packagist

Composer 2.9.6 fixes Perforce Driver Command Injection Vulnerabilities (CVE-2026-40261, CVE-2026-40176)

Please immediately update Composer to version 2.9.6 or 2.2.27 (LTS) by running composer.phar self-update. The new releases include fixes for two command injection security vulnerabilities in the Perforce VCS driver, that also affected users without Perforce and not actively using the driver. CVE-2026-

15
0
22
0
Open post
packagist @packagist@phpc.social
· 4mo ago

The Composer CLI is part of your supply chain. Older versions miss the protections shipped in 2.10 (dependency policies, malware feed integration, source fallback off by default) and carry known client-side CVEs.

Private Packagist customers can now enforce which Composer client versions are allowed to talk to their Composer repository, with a clear upgrade message shown in the developer's terminal when an outdated client tries to connect.

https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/
#php #phpc #composerphp

blog.packagist.com
8
0
7
0
Open post
packagist @packagist@phpc.social
· 10mo ago

RE: @thephpf@phpc.social

Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation! Check out this summary on all the work completed in 2025. So much more could be accomplished, if more businesses relying on PHP contributed too. Sign up as a sponsor and help moving PHP forward!

phpc.social
39
0
29
0
Open post
packagist @packagist@phpc.social
· 12mo ago

Together with PyPI, Maven Central, crates.io and other major package registries we signed a statement on sustainable open source infrastructure.

3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs.

Our Blog: https://blog.packagist.com/a-call-for-sustainable-open-source-infrastructure/
Open Letter: https://openssf.org/blog/2025/09/23/open-infrastructure-is-not-free-a-joint-statement-on-sustainable-stewardship/

#phpc #php #supplychainsecurity #opensourcesustainability

phpc.social
49
1
54
0
Open post
packagist @packagist@phpc.social
· 4mo ago

RE: @packagist@phpc.social

If you haven't updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They've improved secret masking to cover this Composer issue, but you're safer if you update. #composerphp #php #phpc

phpc.social
7
1
20
0
Open post
packagist @packagist@phpc.social
· 4mo ago

Three months of Private Packagist updates: Malware filter list support is already in place, ahead of Composer 2.10's release next week. Flagged versions show warning banners on package pages and are marked in the version list. Permissions views on package level, better background job & sync visibility, and a narrower GitLab OAuth scope (read_api).

https://blog.packagist.com/whats-new-in-private-packagist-may-2026-update/

#php #phpc #composerphp

blog.packagist.com
7
0
11
0
Open post
packagist @packagist@phpc.social
· 4mo ago

🛡️ Blog: How Composer's download fallback behavior can silently override security decisions at the repository side, and what we are doing about it.
If Private Packagist refuses to serve a malware-flagged version, Composer can fall back to the original GitHub URL, or even clone from source. Two new Private Packagist options close both fallback paths, regardless of the Composer version your developers and CI happen to be running.
https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/
#php #phpc #composerphp

blog.packagist.com
5
0
10
0
Open post
packagist @packagist@phpc.social
· 10mo ago

After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist org to strengthen PHP supply chain security, funded by the Sovereign Tech Agency with help of the PHP Foundation and Private Packagist. #php #phpc #composerphp

More detail about what we're working on can be viewed on our blog at https://blog.packagist.com/strengthening-php-supply-chain-security-with-a-transparency-log-for-packagist-org/

phpc.social
26
0
22
0
Open post
packagist @packagist@phpc.social
· 6mo ago

Private Packagist is a member of the @opensourcepledge@fosstodon.org & gave over $4k/FTE in 2025 to #opensource maintainers. Have your company join too! https://blog.packagist.com/private-packagist-2025-contributions-for-the-open-source-pledge/ - Reach out if you want to be a launch partner for our Composer&Packagist.org sponsorship program! #composerphp #php #phpc

phpc.social
9
0
11
0
Open post
packagist @packagist@phpc.social
· 6mo ago
Replying to
The Algolia search was restored quickly yesterday (thanks!) The bot traffic, that picked up after the JS library upgrade last week, is under control too now. So we hope we don't run into this again.
4
0
1
0
Open post
packagist @packagist@phpc.social
· 10mo ago

In Amsterdam next week and part of a group underrepresented at tech confs, or can't afford a ticket? Private Packagist is sponsoring @symfony@phpc.social Con (Nov 27th/28th) and we have a ticket to give away: Reply your favorite PHP8.5 feature to win #php #phpc #symfony #symfonycon

phpc.social
7
2
25
0
Open post
packagist @packagist@phpc.social
· 10mo ago

New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how dependencies cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. https://blog.packagist.com/whats-new-in-private-packagist-november-update/ #php #phpc #composerphp

blog.packagist.com
4
0
9
0
Open post
packagist @packagist@phpc.social
· 8mo ago

🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal https://blog.packagist.com/whats-new-in-private-packagist-february-2026-update/ #composerphp #php #phpc

blog.packagist.com
2
0
5
0
Open post
packagist @packagist@phpc.social
· 12mo ago

Bitbucket Cloud is retiring app passwords in favor of API tokens. If you're using Private Packagist with Bitbucket Cloud, migrate now to avoid future disruptions.

This blog post explains it step-by-step: https://blog.packagist.com/bitbucket-deprecated-app-passwords/

#php #composerphp #phpc #privatepackagist #bitbucket

blog.packagist.com
3
0
1
0
Open post
packagist @packagist@phpc.social
· 2mo ago
We're excited to announce @upsun@mastodon.social is now sponsoring Composer & Packagist maintenance, operations and development! Upsun is a great platform to run PHP applications and they have a long history in the PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem. If your company wants to still become a launch partner for our sponsorship program this week, reach out to sponsoring@packagist.org. #php #phpc #composerphp
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:56:34 UTC