Socket @socket.dev · Feb 17

PHP developers can now: • Browse any Composer package’s security score & dependency insights • Generate SBOMs from composer.lock & composer.json • Detect malware, typosquatting, backdoors, and other risks with AI-powered analysis Learn more → socket.dev/blog/introdu...

3 likes 2 replies

?

Replies

Socket · Feb 17

The PHP ecosystem is massive, and so are the potential supply chain risks. Today’s launch brings best-in-class package security to Packagist and Composer workflows. We’re excited for the PHP community to try it and share feedback!

@mrdanack.bsky.social · Feb 18

I should probably just tell my OCD to shut up, but ....is it possible to see what the scores are based on? danack/datatype