A comprehensive review of Composer and Packagist's supply chain security posture in 2025–2026, following real attacks on PHP packages like intercom/intercom-php and laravel-lang. Covers Composer 2.9's automatic security advisory blocking, Composer 2.10's new Dependency Policy Framework with malware filtering at install time, and Packagist's immutable version metadata launched July 7, 2026. Compares PHP's approach against npm, PyPI, RubyGems, crates.io, and Maven Central across defensive defaults, cryptographic provenance, and identity verification. Highlights Packagist's unique position as the only major package registry operated by a European (German) entity, funded partly by the Sovereign Tech Agency. Identifies remaining gaps — mandatory MFA, Trusted Publishing via OIDC, Sigstore attestations, SLSA provenance — and evaluates the published roadmap's technical coherence and funding constraints.

31m read timeFrom phpunit.expert
Post cover image
Table of contents
Early design decisionsDefensive defaults: Composer 2.9 and 2.10Immutable versions on PackagistServer-side or client-side?Who owns our supply chain?What we can be grateful forLearning from other ecosystemsFour observations on the roadmapConclusion
10.5K Impressions1 Comment