April 2nd, 2021

Postmortem of PHP Core compromise continues

The investigation of how a couple of git accounts of some prominent PHP Core developers was compromised is still ongoing. PHP internals contributor Sara Golemon took some time to join a panel of other PHP community members to discuss the current status of the investigation and what information they have.

Sara shared that there is no reason to be concerned about any of the official releases of PHP. The PHP Internals team caught this security breach before being merged into any of the release branches.

Some actions the PHP Internals team is considering moving forward are requiring signed commits for pull requests and requiring two-factor authentication for any core contributors.

You can watch the entire panel below:

Eric Van Johnson

CTO of DiegoDev Group, LLC. Podcaster at Monthly contributor to php[architect] magazine and host of their podcast php[podcast].