Investing in security

Written on 2026-05-19

Join over 14k subscribers on my mailing list. I write about PHP news, share programming content from across the web, keep you up to date about what's happening on this blog, my work on Tempest, and more.

You can subscribe by sending an email to brendt@stitcher.io.

Hi

It hasn't been long since I wrote my post about Dependency Hygiene; and many things happened since then. First, there was a side-chain attack on a popular PHP package, which was luckily caught very soon after the affected version got published. Then there was a change at GitHub that caused Composer to print out GitHub access tokens in public action logs. As far as we know, the bug hasn't been exploited and was quickly fixed.

There's also good news, though: the PHP Foundation just announced they have gotten a grant from the Linux Foundation which allows them to pay a full-time employee to work on ecosystem security.

All these things show that PHP definitely isn't immune to malicious attackers, but also that the community is very serious about it. I'm currently working on some more content and interviews about these happenings, and I'll keep you posted about them soon.

From the feed

In other news, here are some of the things that caught my eye for the past weeks:

That's all I have today, have a good week!

Brent

Join over 14k subscribers on my mailing list. I write about PHP news, share programming content from across the web, keep you up to date about what's happening on this blog, my work on Tempest, and more.

You can subscribe by sending an email to brendt@stitcher.io.

Noticed a tpyo? You can submit a PR to fix it.
Home RSS Newsletter Discord © 2026 stitcher.io Login