News

Postmortem of PHP Core compromise continues

Published
Postmortem of PHP Core compromise continues image

The investigation of how a couple of git accounts of some prominent PHP Core developers was compromised is still ongoing. PHP internals contributor Sara Golemon took some time to join a panel of other PHP community members to discuss the current status of the investigation and what information they have.

Sara shared that there is no reason to be concerned about any of the official releases of PHP. The PHP Internals team caught this security breach before being merged into any of the release branches.

Some actions the PHP Internals team is considering moving forward are requiring signed commits for pull requests and requiring two-factor authentication for any core contributors.

You can watch the entire panel below:

Eric Van Johnson photo

CTO of DiegoDev Group, LLC. Podcaster at PHPUgly.com. Monthly contributor to php[architect] magazine and host of their podcast php[podcast].

Filed in

Sponsored

laravelcloud logo
Laravel Cloud

Easily create and manage your servers and deploy your Laravel applications in seconds.

Visit Laravel Cloud

The latest

View all →
CPX: The Composer Package Executor for PHP image

CPX: The Composer Package Executor for PHP

Read article
Laravel AI SDK Adds Human-in-the-Loop Tool Approval image

Laravel AI SDK Adds Human-in-the-Loop Tool Approval

Read article
Pest 5 Released With Test Impact Analysis, Agent Verification, and Evals image

Pest 5 Released With Test Impact Analysis, Agent Verification, and Evals

Read article
Queue-SQL: Run Mass Deletes and Updates Across Parallel Queue Jobs image

Queue-SQL: Run Mass Deletes and Updates Across Parallel Queue Jobs

Read article
Blade Formatting in Laravel Pint image

Blade Formatting in Laravel Pint

Read article
Inertia DevTools Is Now on the Chrome Web Store image

Inertia DevTools Is Now on the Chrome Web Store

Read article