Skip to content

Composer & Packagist Supply Chain Security: Report from the trenches

Avatar of Nils Adermann Nils Adermann

At Symfony 2025 we asked “Package Manager Security in 2025: What’s Next?” and outlined our long term supply chain security strategy. Reality caught up with us fast!

The PHP ecosystem has been hit by the same class of supply chain attacks that has repeatedly hit npm and PyPI: taken-over GitHub accounts and stolen access tokens used to publish malicious tags on packages the attackers had no legitimate access to. This talk walks through what we changed across Composer and Packagist in response, and what is still in flight.

Our response came in two phases. First, detection: the Aikido malware feed integrated into Packagist.org, a public transparency log that helped analyze attacks. Then the prevention work: Composer 2.10's unified dependency policy framework covering malware, advisories, and abandoned packages, stable version immutability on Packagist.org so tagged releases can no longer be silently rewritten. We’ll look at more recent changes like Composer 2.11’s minimum-release-age configuration, maintainer security posture and MFA status publication on Packagist, and the new organization level ownership and controls over open-source packages on Packagist.org.

We’ll provide concrete tips and best practices for keeping your own supply chain secure, and give an outlook into what we have planned for 2027.

Delivered in English

Date/time to be announced