[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fN3ORmfqXw35P-D7ZYnWutbF4wy3CDCI1hYWyA0dBMyk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":46},"efdd01f2-6541-4630-9e20-22db1a7dd169","sustaining-open-source-infrastructure-to-combat-supply-chain-risk","2d0be3b3-b752-4835-b8ab-24fcd1a5b36d","Sustaining Open-Source Infrastructure to Combat Supply Chain Risk","Critical open-source tools like Composer and Packagist underpin millions of PHP applications globally, yet their security and maintenance have historically relied on volunteer effort with limited funding. Supply chain attacks targeting package repositories and dependency managers have surged, making unsupported infrastructure a high-value target for adversaries seeking to compromise downstream consumers at scale. Without sustained investment in maintenance and emergency response capabilities, vulnerabilities in these foundational tools can propagate silently into thousands of production environments. Socket's sponsorship highlights a broader industry lesson: organizations that depend on open-source ecosystems bear a shared responsibility to fund their security posture, not just consume their output.","**Immediate actions:**\n- Audit all third-party open-source dependencies in your PHP projects using a software composition analysis (SCA) tool.\n- Subscribe to security advisories for Composer and Packagist to receive timely notifications of vulnerabilities or compromised packages.\n\n**Long-term improvements:**\n- Establish a formal open-source dependency policy that mandates vetting, pinning, and periodic review of all external packages.\n- Contribute to or financially sponsor the open-source projects your organization critically depends on to help fund their security maintenance.\n- Integrate supply chain security checks (e.g., provenance verification, integrity hashing) into your CI\u002FCD pipeline as a mandatory gate.\n\n**Detection measures:**\n- Implement continuous monitoring of your dependency tree for newly disclosed vulnerabilities or unexpected package modifications.\n- Use tools like Socket Security or similar to detect malicious behavior patterns in open-source packages before they reach production.",[12,13,14,15,16,17,18,19],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management Practices","NIST CSF ID.SC-2: Suppliers and third-party partners are identified and prioritized","NIST CSF ID.SC-4: Suppliers are routinely assessed using audits and test results","SLSA Framework: Supply-chain Levels for Software Artifacts","GDPR Article 32: Security of processing (relevant where PHP apps handle personal data)","SSDF (NIST SP 800-218): Protect Software practice PS.3","published","2026-07-31T10:21:13.237917+00:00","2026-07-31T10:21:12.973+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fsocket-sponsoring-composer-and-packagist?utm_medium=feed","socket-is-sponsoring-composer-and-packagist-67faea","Socket Is Sponsoring Composer and Packagist",[28,34,40],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":41,"name":42,"slug":43,"description":44,"color":45},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]