P

Packagist / Composer Blog

P
Packagist / Composer Blog Dev Tools

Announcing the Composer & Packagist Sponsorship Program

Today we are launching a formal sponsorship program for Composer and Packagist.org, together with new public sponsor pages on packagist.org/sponsor and getcomposer.org/sponsor.We want to start by thanking the companies who are on board at launch: Private Packagist, Aikido, AWS, Socket, Bunny, Upsun, Sonatype, Tideways

P
Packagist / Composer Blog Dev Tools

Securing our GitHub Actions workflows with zizmor

This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release and immutable version metadata on Packagist.org. The earlier posts covered Composer behavior, changes to Packagist.org, and Private Packagist features. Today we’ll cover how we

P
Packagist / Composer Blog Dev Tools

Immutable Versions on Packagist

This is the next post in our supply chain security series, following the supply chain security update and the Composer 2.10 release. Each post in this series covers a specific behavior worth understanding, and a change we are making on top of it.Today: Stable version metadata on Packagist.

P
Packagist / Composer Blog Dev Tools

Restricting Composer plugins across your organization

This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, blocking malware downloads for every Composer version, and enforcing a safe Composer version across your organization.Composer plugins are a powerful

P
Packagist / Composer Blog Dev Tools

Enforce a safe Composer version across your organization

This is the next post in our supply chain security series, following the supply chain security update, the Composer 2.10 release, closing Composer's download fallback paths, and blocking malware downloads for every Composer version.While the protections we have shipped try their best to cover older Composer

P
Packagist / Composer Blog Dev Tools v2.10

Composer 2.10 Release

We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of security advisories, abandoned packages, and now malware. Fast detection of malware for packages published on Packagist.org is provided by Aikido

P
Packagist / Composer Blog Dev Tools

An update on Composer & Packagist supply chain security

The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via taken-over GitHub accounts and stolen access tokens that let attackers publish new tags on packages

P
Packagist / Composer Blog Dev Tools

What's new in Private Packagist, May 2026 Update

Over the past three months, we've shipped updates focused on security, integrations with code hosting platforms, and usability improvements throughout Private Packagist. Here's a rundown of the most notable changes.Support for malware filter listsWe've added support for malware filter lists to help

P
Packagist / Composer Blog Dev Tools

What's New in Private Packagist, February 2026 Update

Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights from our latest round of product improvements.Redesigned Login and Registration FlowWe've completely reworked the authentication experience to make login and

P
Packagist / Composer Blog Dev Tools

What’s New in Private Packagist, November 2025 Update

We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure artifact deployment, and enhanced security and audit controls. Here are the highlights from our latest round of product improvements.

P
Packagist / Composer Blog Dev Tools v2.9

Composer 2.9 Release

We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more.Automatic Security BlockingComposer now automatically blocks updates to packages with known security advisories. This protection is enabled by default and prevents you from accidentally updating

P
Packagist / Composer Blog Dev Tools

Bitbucket deprecated App Passwords

Bitbucket announced that they deprecated app passwords in favor of their new API token system. This change affects organizations using Private Packagist with Bitbucket Cloud (bitbucket.org) workspace synchronizations. Bitbucket app passwords will stop working entirely on June 9th, 2026.Bitbucket's app passwords provided limited functionality and security