Jordi Boggiano's Avatar

Jordi Boggiano

@seld.be

Co-Founder of @packagist.com – Dev at teamup.com – #ComposerPHP lead – Wandering Belgian – OSS Wishlist: https://seld.be/wishlist aka Seldaek

341
Followers
125
Following
9
Posts
07.08.2023
Joined
Posts Following

Latest posts by Jordi Boggiano @seld.be

Yeah most likely connected. Anyway i saw your email and security report already just didn't get to handle it yet..

05.03.2026 19:27 👍 1 🔁 0 💬 1 📌 0
Preview
What's New in Private Packagist, February 2026 Update Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights f...

🚀 Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-in... #composerphp #php #phpc

09.02.2026 16:28 👍 5 🔁 3 💬 0 📌 0

Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation!

Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!

03.12.2025 15:38 👍 27 🔁 7 💬 1 📌 1
Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.

Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.

Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.

Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.

Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist.com booth was busy throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026! #php #composerphp

01.12.2025 14:57 👍 9 🔁 3 💬 1 📌 0
Preview
What’s New in Private Packagist, November Update We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure a...

New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how deps cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-in... #php #phpc #composerphp

18.11.2025 09:35 👍 2 🔁 3 💬 0 📌 0
Preview
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...

After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp

14.11.2025 15:35 👍 17 🔁 7 💬 0 📌 0
Preview
Composer 2.9 Release We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...

Composer 2.9 is here! 🚀 It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more!

blog.packagist.com/composer-2-9/
#composerphp #phpc #PHP

13.11.2025 10:22 👍 14 🔁 8 💬 0 📌 0
Preview
Release 2.9.0-RC1 · composer/composer Composer 2.9 is ready for a release, and we need your help to test it and report any regression. Please try it out! Running composer self-update --preview will get you the 2.9.0-RC1 Running compos...

Composer 2.9 is coming, and there's an RC to try out! We need your help and feedback github.com/composer/com... #composerphp #phpc

07.11.2025 15:39 👍 6 🔁 4 💬 0 📌 0

🚨 Warning to #PHP package maintainers: We did not email you to change your passwords & 2FA. Emails asking you to update your credentials are a phishing attempt. We had the phishing site & domain taken down. If you got the email and entered your credentials, please contact us. #phpc

20.09.2025 15:32 👍 25 🔁 40 💬 0 📌 0

Together with PyPI, Maven Central, cratesio and other major package registries we signed a statement on sustainable open source infrastructure.
3B+ installs/month and evolving #composerphp and packagist.org requires sharing the costs.
#phpc #php

23.09.2025 13:42 👍 16 🔁 8 💬 1 📌 1
Packagist The PHP Package Repository

The era of Composer v1 finally comes to an end, long live Composer v2! 👑 Today packagist.org support for v1 metadata has been shut down as announced last year. blog.packagist.com/packagist-or... #composerphp #phpc #php

01.09.2025 08:28 👍 11 🔁 6 💬 1 📌 0
Preview
What’s New in Private Packagist, August Update We've been busy improving Private Packagist over the past few months with a focus on package discovery, user experience improvements, and improved security monitoring tools. Here are the most signific...

August update: dependency usage tracking across your packages, automatic GitLab token rotation, and Conductor improvements with custom labels and smarter PR handling blog.packagist.com/whats-new-in... #php #composer #composerphp #phpc

01.09.2025 08:19 👍 2 🔁 3 💬 0 📌 0
Preview
Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025 With the deadline drawing near, we’d like to remind you that we are discontinuing Composer 1.x support on Packagist.org soon. We're extending our original timeline by one month to give teams additiona...

🚨 Packagist.org shutdown of Composer 1.x support postponed to September 1st, 2025. Act now, upgrade to Composer 2! Last resort: check out Private Packagist extended 1.x support if you really cannot migrate right now. blog.packagist.com/packagist-or...

04.07.2025 07:56 👍 4 🔁 9 💬 0 📌 0

I will be at WordCamp Europe today talking about Composer and dependency management. Find me if you want to chat about @packagist.com!

06.06.2025 07:04 👍 1 🔁 0 💬 0 📌 0

I expected more from the AI model too tbh.. Do ping if you're in town tho!

23.03.2025 22:15 👍 2 🔁 0 💬 0 📌 0

You're lucky I cannot seem to ai-gen an image of you roasting marshmallows with your flintstone-lit farts.

23.03.2025 22:08 👍 1 🔁 0 💬 1 📌 0
Post image

Definitely the cork, it makes sure you don't let out any extra gas too, another sustainability win.

23.03.2025 21:59 👍 1 🔁 0 💬 1 📌 0

She must've thought the rage against the sewing machine sweater means you're a big crochet guy

23.03.2025 21:50 👍 1 🔁 0 💬 1 📌 0
Preview
[RFC] Modern Compression (zstd, brotli) - Externals #externals - Opening PHP's #internals to the outside

Let's add modern compression formats to PHP!

The new RFC for natively integrating Zstandard and Brotli proposed by @seld.be and myself would significantly improve Composer and asset pre-compression by @symfony.com AssetMapper.

18.02.2025 11:05 👍 17 🔁 8 💬 0 📌 0
Two people on stools at a table in front of a Private Packagist and a Conductor banner as well as a big screen.

Two people on stools at a table in front of a Private Packagist and a Conductor banner as well as a big screen.

Stop by our @packagist.com booth at #LaraconEU and have a chat about Composer, Packagist, Conductor or anything else relating to dependency management and supply chain security! #Laravel #Laracon

03.02.2025 08:28 👍 16 🔁 5 💬 1 📌 1
Post image

Got our #SymfonyCon tickets for next year already

06.12.2024 17:03 👍 16 🔁 1 💬 0 📌 0
Team photo in front of Symfony Logo

Team photo in front of Symfony Logo

Meet our team at #SymfomyCon Vienna! We'd love to chat about how you manage your Composer dependencies, your questions around supply chain security, Private Packagist or our upcoming product Conductor! #symfony #php #composerphp

06.12.2024 09:57 👍 15 🔁 2 💬 1 📌 0
Preview
Conductor - Automatic dependency updates for Composer Automatic dependency updates for Composer - tailor made for PHP. Grouped and scheduled in ways that just make sense for PHP projects.

We're excited to introduce you to 🧑‍✈️Conductor! Automatic dependency update PRs with Composer for PHP projects - Security fixes patched in minutes - Continuous updates without the hassle - all running in your own CI env!

Early access waitlist: packagist.com/features/con...

#composerphp #php #phpc

04.12.2024 15:14 👍 42 🔁 19 💬 2 📌 2
Video thumbnail

➡️ The PHP manual has learned a new trick, you can now run the code right in the browser!

🥳 Thanks to @soyuka for the implementation!

#php #documentation

03.12.2024 10:52 👍 158 🔁 67 💬 9 📌 7