Lighting the Ledger for PHP
Composer 2.9 delivered new CLI security improvements this week, but the bigger story for the PHP ecosystem is the work now underway on Packagist.org. With support from the Sovereign Tech Agency, the PHP Foundation, and Private Packagist, the team is building a transparency log aimed at strengthening PHP’s supply chain. Given the scale of Packagist today, introducing systematic visibility into package activity has become a practical necessity.
The transparency log will surface security-relevant events through a web interface and an API. That includes changes to package ownership, source URLs, maintainers, version releases or removals, and updates to underlying git tags, along with account security actions such as two-factor authentication status changes and password resets. Making these events publicly accessible gives researchers, companies, and tool builders the data they need to monitor dependency changes, spot suspicious patterns, and investigate incidents more effectively.
Implementation has begun, with features rolling out incrementally. This work aligns with the OpenSSF guidance for secure package repositories and moves the PHP ecosystem closer to stronger, audit-ready supply chain practices. Looking ahead, the team is also preparing a new model for organizational package ownership, set to address long-standing issues with shared accounts and improve security for both companies and open-source projects.
EVENT
- Heading to DrupalCon Asia 2025? Don't Miss the Magic of Nara
- Community, Code, and Columbia Gorge Views: PNW Drupal Summit 2025 Recap
- Drupal in a Day: Scaling Drupal Education from University Classrooms to Global Camps
- Rachael Censuales Debuts as a Speaker at DrupalCamp Italy 2025
- Drupal Association Invites Global Support for DrupalCamp Burkina Faso 2026
- Stanford WebCamp 2026 Seeks Volunteers Ahead of Spring Conference
- DrupalCon Chicago 2026 Sponsorships Now Open with Tiered Packages and Summit Add‑Ons
- Salim Lakhani to Demo Drupal Forge at Fox Valley Drupal Meetup on Nov 19
ORGANIZATION NEWS
- Drupal.org Relaunches Industry Pages to Showcase Sector-Specific Impact
- Dripyard Prepares Premium Themes for Drupal Canvas Ahead of Stable Release
TRAINING
DRUPAL COMMUNITY
TUTORIALS
We acknowledge that there are more stories to share. However, due to selection constraints, we must pause further exploration for now. To get timely updates, follow us on LinkedIn, Twitter, Bluesky, and Facebook. You can also join us on Drupal Slack at #thedroptimes.
Thank you.
Sincerely,
Alka Elizabeth,
Sub-editor,
The DropTimes.
