Advertisement · 728 × 90

Posts by Jordi Boggiano

Preview
Packagist.org The PHP Package Repository

🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: blog.packagist.com/composer-2-9... #php #phpc #composerphp

3 days ago 3 9 0 0
Preview
Release 2.10.0-RC1 · composer/composer Composer 2.10 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.10.0-RC1 Running comp...

We need your help to test Composer 2.10. Expect a final release next week, now is the time to try it out and flag any issue you find! github.com/composer/com... #composerphp #phpc

2 weeks ago 4 7 0 0
Preview
Private Packagist 2025 contributions for the Open Source Pledge This is now our third year as a member of the Open Source Pledge. Private Packagist subscriptions help fund not only the development of Composer and Packagist.org, but also the open source dependencie...

Private Packagist is a member of the @opensourcepledge.com & gave over $4k/FTE in 2025 to #opensource maintainers. Have your company join too! blog.packagist.com/private-pack... - Reach out if you want to be a launch partner for our Composer&Packagist.org sponsorship program! #composerphp #php #phpc

4 weeks ago 7 3 1 1

Yeah most likely connected. Anyway i saw your email and security report already just didn't get to handle it yet..

1 month ago 1 0 1 0
Preview
What's New in Private Packagist, February 2026 Update Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights f...

🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-in... #composerphp #php #phpc

2 months ago 5 3 0 0

Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation!

Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!

4 months ago 27 7 1 1
Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.

Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.

Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.

Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.

Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist.com booth was busy throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026! #php #composerphp

4 months ago 9 3 1 0
Advertisement
Preview
What’s New in Private Packagist, November Update We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure a...

New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how deps cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-in... #php #phpc #composerphp

4 months ago 2 3 0 0
Preview
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...

After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp

5 months ago 17 7 0 0
Preview
Composer 2.9 Release We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...

Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more!

blog.packagist.com/composer-2-9/
#composerphp #phpc #PHP

5 months ago 14 8 0 0
Preview
Release 2.9.0-RC1 · composer/composer Composer 2.9 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.9.0-RC1 Running compos...

Composer 2.9 is coming, and there's an RC to try out! We need your help and feedback github.com/composer/com... #composerphp #phpc

5 months ago 6 4 0 0

🚨 Warning to #PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc

6 months ago 25 40 0 0

Together with PyPI, Maven Central, cratesio and other major package registries we signed a statement on sustainable open source infrastructure.
3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs.
#phpc #php

6 months ago 16 8 1 1
Packagist The PHP Package Repository

The era of Composer v1 finally comes to an end, long live Composer v2! 👑 Today packagist.org support for v1 metadata has been shut down as announced last year. blog.packagist.com/packagist-or... #composerphp #phpc #php

7 months ago 11 6 1 0
Preview
What’s New in Private Packagist, August Update We've been busy improving Private Packagist over the past few months with a focus on package discovery, user experience improvements, and improved security monitoring tools. Here are the most signific...

August update: dependency usage tracking across your packages, automatic GitLab token rotation, and Conductor improvements with custom labels and smarter PR handling blog.packagist.com/whats-new-in... #php #composer #composerphp #phpc

7 months ago 2 3 0 0
Preview
Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025 With the deadline drawing near, we’d like to remind you that we are discontinuing Composer 1.x support on Packagist.org soon. We're extending our original timeline by one month to give teams additiona...

🚨 Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025. Act now, upgrade to Composer 2! Last resort: check out Private Packagist extended 1.x support if you really cannot migrate right now. blog.packagist.com/packagist-or...

9 months ago 4 9 0 0

I will be at WordCamp Europe today talking about Composer and dependency management. Find me if you want to chat about @packagist.com!

10 months ago 1 0 0 0
Advertisement

I expected more from the AI model too tbh.. Do ping if you're in town tho!

1 year ago 2 0 0 0

You're lucky I cannot seem to ai-gen an image of you roasting marshmallows with your flintstone-lit farts.

1 year ago 1 0 1 0
Post image

Definitely the cork, it makes sure you don't let out any extra gas too, another sustainability win.

1 year ago 1 0 1 0

She must've thought the rage against the sewing machine sweater means you're a big crochet guy

1 year ago 1 0 1 0
Preview
[RFC] Modern Compression (zstd, brotli) - Externals #externals - Opening PHP's #internals to the outside

Let's add modern compression formats to PHP!

The new RFC for natively integrating Zstandard and Brotli proposed by @seld.be and myself would significantly improve Composer and asset pre-compression by @symfony.com AssetMapper.

1 year ago 17 8 0 0
Two people on stools at a table in front of a Private Packagist and a Conductor banner as well as a big screen.

Two people on stools at a table in front of a Private Packagist and a Conductor banner as well as a big screen.

Stop by our @packagist.com booth at #LaraconEU and have a chat about Composer, Packagist, Conductor or anything else relating to dependency management and supply chain security! #Laravel #Laracon

1 year ago 16 5 1 1
Post image

Got our #SymfonyCon tickets for next year already

1 year ago 16 1 0 0
Advertisement
Team photo in front of Symfony Logo

Team photo in front of Symfony Logo

Meet our team at #SymfomyCon Vienna! We'd love to chat about how you manage your Composer dependencies, your questions around supply chain security, Private Packagist or our upcoming product Conductor! #symfony #php #composerphp

1 year ago 15 2 1 0
Preview
Conductor - Automatic dependency updates for Composer Automatic dependency updates for Composer - tailor made for PHP. Grouped and scheduled in ways that just make sense for PHP projects.

We're excited to introduce you to 🧑‍✈️Conductor! Automatic dependency update PRs with Composer for PHP projects - Security fixes patched in minutes - Continuous updates without the hassle - all running in your own CI env!

Early access waitlist: packagist.com/features/con...

#composerphp #php #phpc

1 year ago 42 19 2 2
Video

➡️ The PHP manual has learned a new trick, you can now run the code right in the browser!

🥳 Thanks to @soyuka for the implementation!

#php #documentation

1 year ago 158 67 9 7