Socket has become a launch sponsor of the new Composer and Packagist sponsorship program, joining seven other companies to help fund PHP's package registry infrastructure. The post explains why Socket chose to sponsor: a year of collaborative incident response on supply chain attacks including the Mini Shai-Hulud cross-registry attack, malicious Composer packages hiding install hooks, and the Laravel-Lang backdoor. Packagist is expanding funding beyond its own Private Packagist product for the first time. The team is also building proactive defenses: immutable stable versions, a public transparency log, a unified dependency policy in Composer 2.10, and upcoming features like mandatory MFA, organizational package ownership, and signed build provenance.

3m read timeFrom socket.dev
Post cover image
Table of contents
What working with the Packagist team looks like #Supporting the future of Packagist #
741 Impressions