🔒An update on Composer & Packagist supply chain security: what's in place, what ships this week with Composer 2.10 (dependency policies, immutable versions), and what comes next.
If you maintain PHP packages, enable MFA now!
#php#phpc#composerphp
As an OSS maintainer, my new rule is that anything a frontier model can find with some reasonable effort is a 0-day. Hence why I'm now shipping security releases on public holidays.
@chris__gilroy@GromNaN@Shyim97 Same models. LLMs can be more focus on new problems when "reasoning about" a version with some security issues already fixes. They can also build on the previous findings and sometimes find "incomplete fixes". I've also spent MANY hours steering my agent, that makes a difference.
During the last few weeks, the #Symfony core team has been hard at work fixing a long list of vulnerabilities for both #Symfony and #Twig. Today, we're publishing that work in the biggest security patch releases ever. Bare with us and wish us luck 🍀
Hola #Barcelona 👋🏖️
Join us for an exclusive #Symfony & #PHP#meetup 🍻 in the heart of the Eixample
📍 Carrer de Pau Claris, 194
📅 June 25 at 18:00
🎤 @derrabus Build Apps that Welcome Change
🎤 @chr_hertel Building on top of Symfony #AI
Sign up 👉 https://t.co/ql4BTRh4zz
We are aware of the recently disclosed https://t.co/DGtKxwwvN7 vulnerability (CVE-2026-31431) and want to assure our customers that Upsun systems are not affected.
The module targeted by this vulnerability is disabled in our platform. We run hardened Linux kernels in which we only enable the components required for our services, minimizing the attack surface. As such, there is no risk of exploitation, and no action is required on your part.
We remain committed to the security of our products and will continue to monitor for any developments. If you have any questions or concerns, please do not hesitate to contact our support team. ✨
@khatriafaz@fabpot@jeffrey_way@ashleyhindle@jon_bossenger Yes, it will be streamed on the PHP Annotated YouTube channel by @brendt_gd. Please register on the event landing page to receive a reminder closer to the stream date. You can also click “Notify me” directly on the stream page if that’s more convenient: https://t.co/1AiTFzJEWX
As an OSS maintainer, merging older maintained branches up can be challenging in case of conflicts. As agents are now good at following instructions and resolving conflicts, I've just created a SKILL for #symfony that automates most of the work (but keeping the human in the loop)
💻 Pour cette édition #Symfony_Live Paris 2026, Fabien Potencier (@fabpot) enchaîne deux talks ! ⚡
Cette session : "Développer un Coding Agent en PHP : dans les coulisses du "Harness"” !
#PHP#Symfony#TechEvent
My favorite activity when coding: remove code
My new favorite activity with my coding agents: let them remove code they generated 😂
Also, I like removing cruft from AGENTS.md or SKILLS.md files
Writing code is also about removing code 😀
🤖Fabien Potencier: Keynote à #Symfony_Live Paris 2026 !
“Développer un Coding Agent en PHP : dans les coulisses du 'Harness'”
Rendez-vous le 26 mars ! 👀✨
#Symfony#PHP#IA#CodingAgent https://t.co/FbHwtGnzif