It Wasn’t Your Code – Understanding Supply Chain Failures

By Eric Mann

I ran `composer update` on a side project a few weeks back and watched a few dozen packages move. I manually reviewed maybe three of them. The rest I waved through, because that is what we all do. The lock file said the hashes matched what Packagist served, the tests passed, and I had other work to ship. by Eric Mann

This article was originally published in the July 2026 issue of PHP Architect magazine. To read the complete article please subscribe or purchase the complete issue.

Leave a comment

Use the form below to leave a comment: