Flávio Heleno · @flavioheleno
33 followers · 120 posts · Server phpc.social

Hey, I'm looking for feedback on Kahu.app - a dependency monitoring system that tracks API/Extensions usage and alerts you when malicious behavior is found. It also has a safeguard engine that allows you to write custom rules to what you *don't* want libs accessing

#php #security #saas #packagist #composer

Last updated 1 year ago

Lennart Hengstmengel · @lhengstmengel
155 followers · 792 posts · Server mastodon.nl

People always say "do not release on Fridays after 4 o' clock" but I did it anyway: v1.0.0 of my mastodon api client library is out! 🎉

If you are a PHP developer and want to do anything with the Mastodon API, then this is for you!

github.com/vazaha-nl/mastodon-

#release #packagist #api #mastodon #developer #php

Last updated 1 year ago

Ben Ramsey :elephpant_rainbow: · @ramsey
3176 followers · 6543 posts · Server phpc.social

I’m okay with this decision because I want and to succeed, but, damn, just can’t get first class support anywhere.

github.com/github/roadmap/issu

#packagist #privatepackagist #php

Last updated 1 year ago

ITSEC News · @itsecbot
1282 followers · 34975 posts · Server schleuss.online

PHP Packagist supply chain poisoned by hacker “looking for a job” - I pwned you! Gizza job! You know it makes sense! nakedsecurity.sophos.com/2023/

#php #packagist #supplychain #vulnerability

Last updated 1 year ago

Victor van Liederen · @victor
1 followers · 5 posts · Server phpc.social

🚨 Breaking news: A researcher (neskafe3v1) hijacked 14 popular packages to get a job! 😲 With one of them reaching 500M+ installs, it's a bold move, to say the least. Does this display creativity or recklessness? 🤔 Let's discuss! 💬

#packagist #php #infosec #jobhunt #codingethics

Last updated 1 year ago

Axel Libori Roch · @alibori
3 followers · 12 posts · Server phpc.social

Greetings!

I'm happy to share with everyone my new dev package to make efortless the coding process of a Laravel application with a DDD approach 🔥

Thanks again to @spatie_be fort the great -skeleton-laravel

Happy to read your feedback also!

github.com/alibori/laravel-ddd

#laravel #package #php #packagist #development

Last updated 1 year ago

Iain Cuthbertson · @bigcalm
76 followers · 358 posts · Server mendeddrum.org

A bit part of my job is ensuring sustainability of actions. That is, making sure that a development environment or a deployment works now and in the future.

Composer is wonderful to bring dependencies together, but it relies upon public repos staying public and available.

How do you ensure that a project will always work with 3rd party repos?

Please boost for coverage :)

#php #composer #packagist

Last updated 1 year ago

Axel Libori Roch · @alibori
3 followers · 10 posts · Server phpc.social

Greetings!

I really love learning about Laravel package development and the infinite possibilities it brings 😊

This one is a try to make easier to have in mind the current state of a project's board.

github.com/alibori/laravel-jir

#jira #laravel #php #packagist

Last updated 1 year ago

Axel Libori Roch · @alibori
2 followers · 8 posts · Server phpc.social

Happy to share my first public Laravel package 😊
It's not a great one but is my first. Great learnings from @freekmurze and courses!
Thanks a lot!

github.com/alibori/laravel-fil

#spatie #laravel #php #packagist

Last updated 1 year ago

Ben Ramsey :elephpant_rainbow: · @ramsey
2993 followers · 4822 posts · Server phpc.social

You can now add your security policy to your `composer.json`, and it'll display a link on

github.com/composer/packagist/

github.com/composer/composer/p

#packagist #composer

Last updated 1 year ago

Symfony Station :symfony: · @symfonystation
522 followers · 2541 posts · Server phpc.social
Inautilo · @inautilo
88 followers · 181 posts · Server mastodon.social
Abivia · @abivia
10 followers · 43 posts · Server fosstodon.org

Just noticed that Ledger has cracked the 1,000 install mark on ! While that's obviously far less than 1,000 individual projects using the package, it's still one heck of a milestone. packagist.org/packages/abivia/

#packagist

Last updated 2 years ago

Jules · @julesbl
24 followers · 79 posts · Server mastodon.me.uk
Philippe Gerber · @phphil
19 followers · 15 posts · Server phpc.social

I wonder if you could take stats from about the most used packages and cross-reference this with the number of open issues on .

What you'd get is a list of widely-used projects that could use some help, no?

#github #php #packagist

Last updated 2 years ago

husimo 🦊 · @husimo
30 followers · 304 posts · Server mstdn.fr
Jesus M. Gonzalez-Barahona · @jgbarah
204 followers · 6428 posts · Server floss.social

RT @tom_mens
Our paper on practices in package dependency networks (, , , ) has been accepted in IEEE TSE!
doi.org/10.1109/TSE.2021.31122
A @secoassist collaboration with @AlexandreDecan, @a_zerou, @oniroi
Contact me by e-mail if you need an electronic copy

#rubygems #packagist #npm #cargo #backporting

Last updated 3 years ago

Fork Awesome · @forkawesome
237 followers · 15 posts · Server floss.social

We need some help with and .

Could someone help review a pull request that updates `composer.json` for packagist.org?

github.com/ForkAwesome/Fork-Aw

( tooted by shine )

#composer #packagist #PHP

Last updated 3 years ago

ITSEC News · @itsecbot
738 followers · 32490 posts · Server schleuss.online

PHP community sidesteps its third supply chain attack in three years - Third time lucky! (The first two times were lucky, too, luckily.) nakedsecurity.sophos.com/2021/

#php #composer #packagist #supplychain #vulnerability

Last updated 3 years ago

Sand Fox · @sandfox
22 followers · 97 posts · Server qoto.org