Ever found yourself accidentally merging changes to the public API of a PHP package and regretting it later? I made a GitHub Action to help prevent that.
I realized I was never going to get to adding zizmor to all my repos so I made a claude skill to let it do the grunt work.
You can use it too, if it helps more busy/lazy people to secure their GitHub repos I am glad!
See github.com/Seldaek/zizmor…
We recommend you change the default permissions for GitHub Actions GITHUB_TOKENs to read-only. Grant elevated permissions only where necessary. Use zizmor to analyze your GitHub Actions: github.com/zizmorcore/ziz… see also: phpunit.expert/articles/harde…
Composer 2.10 is out.
Native malware filtering via @AikidoSecurity, enabled by default on @packagist. Plus a unified config.policy framework, deprecated source fallback, and wildcards in --with.
#php#phpc#composerphp
It took us a bit longer than expected but after over a month of discussions and rewrites, Composer 2.10 RC2 is now available for testing with a new policy config and detected malware now blocked by default on install. github.com/composer/compo…#composerphp#phpc