Editor's Pick | Vol. 3 | Issue. 46

Lighting the Ledger for PHP

Lighting the Ledger for PHP

Composer 2.9 delivered new CLI security improvements this week, but the bigger story for the PHP ecosystem is the work now underway on Packagist.org. With support from the Sovereign Tech Agency, the PHP Foundation, and Private Packagist, the team is building a transparency log aimed at strengthening PHP’s supply chain. Given the scale of Packagist today, introducing systematic visibility into package activity has become a practical necessity.

The transparency log will surface security-relevant events through a web interface and an API. That includes changes to package ownership, source URLs, maintainers, version releases or removals, and updates to underlying git tags, along with account security actions such as two-factor authentication status changes and password resets. Making these events publicly accessible gives researchers, companies, and tool builders the data they need to monitor dependency changes, spot suspicious patterns, and investigate incidents more effectively.

Implementation has begun, with features rolling out incrementally. This work aligns with the OpenSSF guidance for secure package repositories and moves the PHP ecosystem closer to stronger, audit-ready supply chain practices. Looking ahead, the team is also preparing a new model for organizational package ownership, set to address long-standing issues with shared accounts and improve security for both companies and open-source projects.

EVENT

ORGANIZATION NEWS

TRAINING

DRUPAL COMMUNITY

TUTORIALS

We acknowledge that there are more stories to share. However, due to selection constraints, we must pause further exploration for now. To get timely updates, follow us on LinkedIn, Twitter, Bluesky, and Facebook. You can also join us on Drupal Slack at #thedroptimes.

Thank you. 

Sincerely, 
Alka Elizabeth, 
Sub-editor, 
The DropTimes.