cd /news/ai-policy/socket-is-sponsoring-composer-and-pa… · home topics ai-policy article
[ARTICLE · art-81563] src=socket.dev ↗ pub= topic=ai-policy verified=true sentiment=↑ positive

Socket Is Sponsoring Composer and Packagist

Socket, a software supply chain security company, is a launch sponsor of the new Composer and Packagist sponsorship program announced by Nils Adermann and Jordi Boggiano, the maintainers of PHP's package infrastructure. The program, which includes eight launch sponsors, aims to fund around-the-clock operations, publisher support, emergency response, and maintenance for Packagist, which has faced increased supply chain attacks and regulatory pressures. Socket has worked with the Packagist team on several security incidents, including the Mini Shai-Hulud attack and the Laravel-Lang backdoor.

read2 min views1 publishedJul 31, 2026
Socket Is Sponsoring Composer and Packagist
Image: Socket (auto-discovered)

Socket is a launch sponsor of the new Composer and Packagist sponsorship program, announced today by Nils Adermann, Jordi Boggiano, and the team that keeps PHP's package infrastructure running.

Like many other widely used open source registries, Packagist has been under mounting pressure to sustain critical infrastructure as the demands on it grow.

"Usage keeps rising, supply chain attacks have increased in both frequency and sophistication, regulatory and compliance requirements around software supply chains are expanding, and AI accelerates both legitimate consumption and attacks," Packagist founders Adermann and Boggiano said.

For the first time, Packagist is expanding its funding beyond Private Packagist, the maintainers' own commercial product, which has covered most of the cost along with donated infrastructure. The new sponsorship program brings in companies that build on the registry to help cover the cost, and Socket is one of eight launch sponsors. The money funds the work that keeps Packagist running: around-the-clock operations, publisher support, emergency response to attacks, ongoing maintenance, and the engineering behind new supply chain defenses.

## What working with the Packagist team looks like[#](#What-working-with-the-Packagist-team-looks-like)

Over the past year, we have worked alongside this team through several supply chain attacks. When we find a malicious package on Packagist, we report it, and the team moves fast. When Mini Shai-Hulud jumped from PyPI to npm to Packagist through intercom/intercom-php

, we worked through the incident with them in real time to remediate the attack. They were just as responsive working through reports on other attacks, including eight Composer packages hiding an install hook in package.json and the Laravel-Lang backdoor that landed across more than 700 versions.

That kind of dedicated vigilance comes from a small group who genuinely care about the health and security of the PHP ecosystem and answer when it needs them, nights and weekends included. We have seen it firsthand working together to make this ecosystem safer, and it is a big part of why we wanted to back their work publicly.

Supporting the future of Packagist# #

The team is not just responding to attacks, they are building defenses into the registry. In recent months they made stable versions on Packagist.org immutable, built out a public transparency log of changes to packages, and shipped a unified dependency policy framework in Composer 2.10. Still ahead: mandatory MFA, organizational package ownership, and signed build provenance for what you install.

Registries are stewards of work the community created, and the Packagist team has been exemplary and diligent in that role. We are happy to support their work, and we encourage every company that builds on Packagist to do the same.

── more in #ai-policy 4 stories · sorted by recency
── more on @socket 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/socket-is-sponsoring…] indexed:0 read:2min 2026-07-31 ·