# Packagist and Composer security with Jordi Boggiano Page: https://stenobird.com/podcast/open-source-security-518991/packagist-and-composer-security-with-jordi-boggiano Text version: https://stenobird.com/podcast/open-source-security-518991/packagist-and-composer-security-with-jordi-boggiano.md Podcast: [Open Source Security](https://stenobird.com/podcast/open-source-security-518991) Published: 2026-06-22T00:00:00+00:00 Episode link: https://opensourcesecuritypodcast.libsyn.com/packagist-and-composer-security-with-jordi-boggiano Audio file: https://traffic.libsyn.com/secure/opensourcesecuritypodcast/2026-06-packagist-security-jordi.mp3?dest-id=542864 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/packagist-and-composer-security-with-jordi-boggiano Duration seconds: 2088 ## Resource Josh welcomes Jordi Boggiano the lead maintainer of Composer and Packagist to explain the truckload of security features they've recently added. Packagist is the PHP package registry, Composer is the dependency manager for PHP. Recently the people behind these projects have added a number of security features that will improve the security of the entire ecosystem. Jordi explains it all to us and gives a glimpse of what's coming next. The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2026/2026-06-packagist-security-jordi ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/open-source-security-518991/episodes/packagist-and-composer-security-with-jordi-boggiano/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/open-source-security-518991/packagist-and-composer-security-with-jordi-boggiano.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.