It Wasn’t Your Code – Understanding Supply Chain Failures
By Eric Mann
I ran `composer update` on a side project a few weeks back and watched a few dozen packages move. I manually reviewed maybe three of them. The rest I waved through, because that is what we all do. The lock file said the hashes matched what Packagist served, the tests passed, and I had other work to ship. by Eric Mann
This article was originally published in the July 2026 issue of PHP Architect magazine. To read the complete article please subscribe or purchase the complete issue.



Leave a comment
Use the form below to leave a comment: