🔗 An Update on Composer & Packagist Supply Chain Security
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #security #composer #packagist #supplychain
https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/
#php #security #composer #packagist #supplychain

An Update on Composer & Packagist Supply Chain Security
The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via taken-over GitHub accounts and stolen access tokens that let attackers publish new tags on packages they had