Private Packagist
  • Home
  • Packagist.com
  • About
Tagged

supplychain

A collection of 3 posts

supplychain

Closing Composer's Download Fallback Paths in Private Packagist

This is the next post in our supply chain security series, following the supply chain security update and the Composer 2.10 release. Each post in this series covers a specific Composer behavior worth understanding, and a Private Packagist feature we are introducing on top of it. Today: How Composer&

  • Nils Adermann
Nils Adermann Jun 1, 2026 • 7 min read
Composer 2.10 Release
composer

Composer 2.10 Release

We are excited to announce the release of Composer 2.10.0, introducing native malware filtering and consolidated future-proof customizable dependency policy configuration to control the handling of security advisories, abandoned packages, and now malware. Fast detection of malware for packages published on Packagist.org is provided by Aikido. This

  • Stephan Vock
  • Nils Adermann
Stephan Vock, Nils Adermann May 28, 2026 • 7 min read
composer

An Update on Composer & Packagist Supply Chain Security

The last months, and even more so the last weeks, saw an increasing amount of software supply chain attacks targeting open-source ecosystems. A handful of these have hit the PHP ecosystem too, via taken-over GitHub accounts and stolen access tokens that let attackers publish new tags on packages they had

  • Nils Adermann
  • Igor Benko
Nils Adermann, Igor Benko May 27, 2026 • 12 min read
Private Packagist
  • About
  • Terms
  • Privacy
  • Imprint