Composer and Packagist Supply Chain Security in 2026 | Nils Adermann | PHPverse 2026

Опубликовано: 08 Август 2026
на канале: PHP Annotated
583
19

You can already register for next year's PHPverse: https://lp.jetbrains.com/phpverse-202...

Recent attacks on PHP packages via compromised GitHub accounts have forced a hard look at supply chain security with Composer and Packagist. Nils will cover what Packagist has shipped in response: transparency log, malware detection, Composer 2.10 dependency policies, version immutability, and the work still ahead: mandatory MFA, organizational controls, immutable artifacts, and build provenance. Along the way, he’ll explore the infrastructure powering it all and the funding side of running critical open-source infrastructure – where the money comes from today, and what it takes to keep this kind of work going.

#php #oss #webdev #programming #coding