Private Packagist is a member of the @opensourcepledge & gave over $4k/FTE in 2025 to #opensource maintainers. Have your company join too! https://blog.packagist.com/private-packagist-2025-contributions-for-the-open-source-pledge/ - Reach out if you want to be a launch partner for our Composer&Packagist.org sponsorship program! #composerphp #php #phpc
Private Packagist 2025 contributions for the Open Source Pledge

This is now our third year as a member of the Open Source Pledge. Private Packagist subscriptions help fund not only the development of Composer and Packagist.org, but also the open source dependencies we rely on to build and run our commercial product. In 2025, we contributed a total

Private Packagist
New release of https://github.com/joachim-n/drupal-core-development-project, the Composer template for working on #Drupal core issues. Thanks to @rkoller and rfay for their help! #ComposerPHP

How do users report a composer package that is distributing a Remote Access Trojan (RAT) on packagist for removal/warning?

eg.

https://intel.aikido.dev/packages/packagist/nhattuanbl/lara-helper

https://packagist.org/packages/nhattuanbl/lara-helper

Payload: https://gitlab.com/nhattuanbl/lara-helper/-/blob/master/src/helper.php

#PHP #ComposerPHP

nhattuanbl/lara-helper - Packagist package security analysis

Just some helper functions & commands for Laravel Latest: 5.5.1. No known vulnerabilities.

Loved the very engaged audience of a thousand people at #LaraconEU 2026 in Amsterdam today at my "Composer Deep Dive" talk! Proud to sponsor the event with Private Packagist / @packagist - Find me and chat about package management or @thephpf ! Slides: https://naderman.de/slippy/slides/2026-03-02-Laracon-EU-2026-Composer-Deep-Dive.pdf #laravel #laracon #php #composerphp
Just arrived in Amsterdam for #LaraconEU - my talk "Composer Deep Dive" is tomorrow afternoon at 2:30pm! Hope to talk to as many of you about #composerphp @packagist and @thephpf! #laravel #php #laracon
Excited to speak at #symfony user group Berlin tonight! #sfugberlin #composerphp
πŸš€ Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal https://blog.packagist.com/whats-new-in-private-packagist-february-2026-update/ #composerphp #php #phpc
What's New in Private Packagist, February 2026 Update

Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights from our latest round of product improvements. Redesigned Login and Registration Flow We've completely reworked the authentication experience to make login and registration more

Private Packagist

Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist booth was busy with discussions throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026!

Slides: https://naderman.de/slippy/slides/2025-11-28-SymfonyCon-Amsterdam-2025-Package-Manager-Security-in-2025-Whats-Next.pdf

#php #composerphp

Projects using #composerphp "autoload-files" in their composer.json will see some speedup when analzed with #phpstan, starting with the next phpstan release.