Skip to content

Package Manager Security in 2025: What's Next?

Avatar of Nils Adermann Nils Adermann

Package managers are critical infrastructure—and prime targets for supply chain attacks. This talk examines recent security incidents across npm, PyPI, and other ecosystems to understand what threats apply to Composer and Packagist.

We'll explore emerging security standards including SLSA, trusted publishing, build provenance attestations, and reproducible builds. You'll learn how GitHub Actions has become an attack vector, what organizations like OpenSSF and its Package Repository Working Group are doing, which improvements other language packaging ecosystems recently introduced and how two new projects funded by Germany's Sovereign Tech Agency will improve security for the PHP ecosystem.

Whether you maintain packages or just run composer install, you'll gain practical insights into supply chain security threats and the tools being built to address them.

Delivered in English
Room:
Track SensioLabs

Friday, November 28, 2025 at 14:30 PM – 15:05 PM