Private Packagist
  • Home
  • Packagist.com
  • About
Tagged

dependencies

A collection of 3 posts

Closing Composer's download fallback paths in Private Packagist
supplychain

Closing Composer's download fallback paths in Private Packagist

This is the next post in our supply chain security series, following the supply chain security update and the Composer 2.10 release. Each post in this series covers a specific Composer behavior worth understanding, and a Private Packagist feature we are introducing on top of it. Today: How Composer&

  • Nils Adermann
Nils Adermann Jun 1, 2026 • 8 min read
composer

Composer 2.7 and CVE-2024-24821: Code execution and possible privilege escalation

Please immediately update Composer to version 2.7.0 or 2.2.23 (composer.phar self-update). The new releases includes fixes for a code execution and possible privilege escalation via InstalledVersions.php or installed.php vulnerability (CVE-2024-24821) reported by Ed Cradock. The vulnerability does not impact packagist.

  • Nils Adermann
Nils Adermann Feb 8, 2024 • 3 min read
Private Packagist

Introducing: Update Review

As of today, when you update your dependencies in a pull request, Private Packagist comments with all composer.lock changes displayed in a clear and easy to scan table. This feature is immediately available to all our customers at no additional cost. We love it! With the Private Packagist Update

  • Stephan Vock
  • Nils Adermann
Stephan Vock, Nils Adermann Dec 2, 2021 • 4 min read
Private Packagist
  • About
  • Terms
  • Privacy
  • Imprint