<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><link>https://bsky.app/profile/packagist.com</link><title>@packagist.com - Packagist</title><item><link>https://bsky.app/profile/packagist.com/post/3mu5cdkgutw2h</link><description>New in Private Packagist, August &#39;26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging.&#xA;&#xA;https://blog.packagist.com/whats-new-in-private-packagist-august-2026-update/&#xA;&#xA;#php #phpc #composerphp</description><pubDate>28 Aug 2026 11:51 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mu5cdkgutw2h</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mrufkuofud24</link><description>Composer &amp; Packagist now have a sponsorship program. Thank you to our launch sponsors 🤝 Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways, Datadog and Algolia help fund our shared infrastructure.&#xA;&#xA;https://blog.packagist.com/announcing-the-composer-packagist-sponsorship-program/&#xA;&#xA;#php #phpc #composerphp</description><pubDate>30 Jul 2026 12:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mrufkuofud24</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mrpem6tm3i2d</link><description>We&#39;re excited to announce @upsun.com is now sponsoring #composerphp &amp; Packagist maintenance, ops and development! They have a long history in the #PHP ecosystem. Their contribution helps us push forward with our work on improving supply chain security for the PHP ecosystem.</description><pubDate>28 Jul 2026 12:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mrpem6tm3i2d</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mrcxvhvan42d</link><description>CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with 🌈zizmor and wrote down how to do the same on yours.&#xA;&#xA;https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/&#xA;&#xA;#php #phpc #composerphp #github #githubactions #zizmor</description><pubDate>23 Jul 2026 13:45 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mrcxvhvan42d</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mqmcflfte624</link><description>We’re sponsoring Meet Magento Germany on Oct 22, 2026 in Mainz, Germany. Come meet our founder @naderman.de to talk software supply chain security and answer your questions.&#xA;&#xA;Tickets available, CFP open: de.meet-magento.com/&#xA;&#xA;#meetmagento #magento #meetmagentode #adobecommerce&#xA;https://de.meet-magento.com/</description><pubDate>14 Jul 2026 13:21 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mqmcflfte624</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mq2r43aq4n22</link><description>📌 Stable versions on Packagist are now immutable. Once published, the commit a version points to can no longer change. Retags are blocked, and deleted versions are tracked with a reason and recoverable.&#xA;https://blog.packagist.com/immutable-versions-on-packagist/&#xA;#php #phpc #composerphp</description><pubDate>07 Jul 2026 13:57 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mq2r43aq4n22</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mo3leilsjc24</link><description>🧩 Composer plugins are powerful, but execute code during install &amp; update. Composer prompts to allow a plugin, but a distracted &#34;yes&#34; or an AI agent on autopilot is all it takes. Private Packagist now has org-level allowlists for plugins. https://blog.packagist.com/restricting-composer-plugins-across-your-organization/ #php #phpc #composerphp</description><pubDate>12 Jun 2026 10:56 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mo3leilsjc24</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mnhmd3vrd226</link><description>The Composer CLI is part of your supply chain. Older versions miss the protections from 2.10 and have known CVEs of their own.&#xA;Private Packagist customers can now enforce which Composer versions are allowed to use their repository.&#xA;&#xA;https://blog.packagist.com/enforce-a-safe-composer-version-across-your-organization/&#xA;#php #phpc #composerphp</description><pubDate>04 Jun 2026 12:20 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mnhmd3vrd226</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mncvphwlz22z</link><description>⛔ Composer policies block flagged malware, but only on 2.10. A project disabling the policy, or a CI image running an old Composer, still installs flagged versions.&#xA;Private Packagist now blocks these at the repository, for all versions.&#xA;https://blog.packagist.com/blocking-malware-downloads-for-every-composer-version-in-private-packagist/&#xA;#php #phpc #composerphp</description><pubDate>02 Jun 2026 15:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mncvphwlz22z</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mn7lhv3pfk2f</link><description>🛡️ Composer&#39;s download fallback behavior can silently override security decisions at the repository side, falling back from a blocked Private Packagist URL to GitHub or a source clone.&#xA;Two new Private Packagist options close it off.&#xA;https://blog.packagist.com/closing-composers-download-fallback-paths-in-private-packagist/&#xA;#php #phpc #composerphp</description><pubDate>01 Jun 2026 07:44 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mn7lhv3pfk2f</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mmtsjt6ha22w</link><description>🔒 An update on Composer &amp; Packagist supply chain security: where we stand, what ships this week with Composer 2.10, what&#39;s next.&#xA;&#xA;If you maintain PHP packages, enable MFA now.&#xA;&#xA;https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/ &#xA;&#xA;#php #phpc #composerphp #supplychainsecurity</description><pubDate>27 May 2026 15:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mmtsjt6ha22w</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mmbr3gti2s22</link><description>If you haven&#39;t updated Composer to 2.9.8 or 2.2.28 (LTS), do so urgently! GitHub will restart the rollout of their new GitHub Actions tokens later today. They&#39;ve improved secret masking to cover this Composer issue, but you&#39;re safer if you update. #composerphp #php #phpc&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>20 May 2026 11:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mmbr3gti2s22</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mm4vgdhqls2y</link><description>Three-month Private Packagist recap: malware filter list support is already in place, ahead of Composer 2.10&#39;s release next week. Plus a new permissions tab, better job visibility, and narrower GitLab OAuth scopes.&#xA;https://blog.packagist.com/whats-new-in-private-packagist-may-2026-update/&#xA;#php #phpc #composerphp</description><pubDate>18 May 2026 12:38 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mm4vgdhqls2y</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mlvhkkhi5k2u</link><description>We hope you enjoyed @glaubinix.bsky.social talk on the malware filtering features in Composer 2.10 at phpday. Try them out on latest snapshots today. Appreciate early feedback! Proud to sponsor phpday in Verona, Italy!&#xA;&#xA;Slides at https://glaubinix.github.io/talks/2026-05-15-Composer-2-10-Malware-Filtering.html&#xA;&#xA;#php #phpc #phpday #composerphp</description><pubDate>15 May 2026 13:42 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mlvhkkhi5k2u</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mlq4qj6toc2b</link><description>🚨 Security advisory: Composer 2.9.8 and 2.2.28 fix a vulnerability leaking GitHub Actions GITHUB_TOKENs to job logs via error messages.&#xA;Update now or disable affected workflows.&#xA;https://blog.packagist.com/composer-2-9-8-and-2-2-28-fix-github-actions-token-disclosure-in-error-messages/ #composerphp #phpc #php</description><pubDate>13 May 2026 10:45 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mlq4qj6toc2b</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3mjh4zxgvfk2v</link><description>🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, command injection issues in the Perforce driver. Run composer self-update now. No exploits detected on Packagist.org and Private Packagist. Details: https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/ #php #phpc #composerphp&#xA;https://Packagist.org</description><pubDate>14 Apr 2026 10:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3mjh4zxgvfk2v</guid></item><item><link>https://bsky.app/profile/packagist.com/post/3miitkhpb4s2a</link><description>Search on Packagist is currently unavailable due to large amounts of bot traffic that @algolia.bsky.social did not filter out. They now blocked packagist. UI search and the search API are affected. We are looking into temp workarounds till Algolia resolves our support request from yesterday.</description><pubDate>02 Apr 2026 08:56 +0000</pubDate><guid isPermaLink="false">at://did:plc:mw4367k4mtpplhukvwn2ppd6/app.bsky.feed.post/3miitkhpb4s2a</guid></item></channel></rss>