Socket has become a launch sponsor of the new Composer and Packagist sponsorship program, joining seven other companies to help fund PHP's package registry infrastructure. The post explains why Socket chose to sponsor: a year of collaborative incident response on supply chain attacks including the Mini Shai-Hulud cross-registry attack, malicious Composer packages hiding install hooks, and the Laravel-Lang backdoor. Packagist is expanding funding beyond its own Private Packagist product for the first time. The team is also building proactive defenses: immutable stable versions, a public transparency log, a unified dependency policy in Composer 2.10, and upcoming features like mandatory MFA, organizational package ownership, and signed build provenance.