PHP Foundation Community Hour Podcast 2026.10.08
🎙️ PHP Foundation Community Hour – October 8, 2026
Hosts: Elizabeth Barron & James Titcumb
James tells the story of how he fell into open source, breaks down what Pie actually does, celebrates the 1.5 release, and shares real advice for anyone nervous about making their first contribution.
🌱 How James Got Into Open Source
James traced his open source journey back many years to a set of Zend Framework 1 helper classes he found useful enough to publish, back when he wasn’t even sure GitHub existed yet. From there he built a little tool to deploy code from Git over SSH at a previous employer, replacing a hand-upload process that he knew had to be modernized.
Things really took off when he joined Roave, where contributing was actively encouraged and he was surrounded by prolific maintainers like Marco working on Doctrine, alongside in-house libraries such as Security Advisories and Better Reflection. Having a supportive employer early on made all the difference, letting him do the work during the day instead of squeezing it into nights and weekends.
Elizabeth reflected that this is a common on-ramp into open source: scratch your own itch, put it out there, and hope it helps someone with the same problem. She emphasized how much employer support, team mentorship, and a genuine culture of open source help newcomers find their footing.
🥧 What Pie Is and Why It Exists
James explained that Pie came about because the infrastructure around PECL and PEAR is simply aging, with very few people who know the code base well enough to maintain it. The PHP Foundation approached him to overhaul that tooling, applying the hard-won lessons of Composer — which he agrees is arguably the best package manager for any language.
Under the hood, Pie is really a very fancy wrapper around four commands — phpize, configure, make, and make install — plus a lot of dependency management and making sure you get the right package for your specific PHP install, something PECL never really did. Thanks to the Packagist team setting up an extensions area, Pie plugs into Composer’s source code to get that dependency resolution for free.
A key distinction is that you aren’t installing extensions for a project the way you do with Composer packages — you’re installing them for a particular PHP install. Pie manages this in a dedicated Pie home directory, keeping each of your many PHP versions and their extensions sorted out. James’s bigger goal has evolved from simply replacing PECL to making installing an extension as frictionless as installing a PHP package.
🧩 Democratizing Extensions and the Windows Challenge
Moving off PECL’s centralized repository and onto Packagist means literally anyone can now submit an extension, the same way they publish PHP packages. James noted that when problems come up there are usually three kinds of fixes: improving something in Pi, writing better documentation, or working with an extension author who hasn’t configured their composer.json correctly.
Because extensions have unique needs, the Composer team added new Pi-specific options to specify configure flags, supported platforms, and architectures — concepts Composer never had since it only ever dealt with pure PHP code. A Windows-only library extension is useless on macOS or Linux, and a systemd-dependent one is useless on Windows, so that categorization matters.
The most common friction point James sees is Windows extensions. Unlike PECL, which auto-compiled DLLs from uploaded source, the Pie ecosystem requires authors to build the DLL themselves — handled through a GitHub Action called PHP Windows Builder, which Shivam worked on. For security reasons Pie deliberately can’t just download and run arbitrary binaries on people’s systems.
🚀 The 1.5 Release
Elizabeth congratulated James on shipping 1.5, a significant release that pulled together several large, closely-related requests. A lot of it grew from working with the author of the mlocati Docker PHP extension installer, mapping out everything Pie does on a whiteboard to see where changes could unlock multiple features at once.
The big internal change was fixing how Pie handles locking, bringing it much closer to how Composer manages its own lock file. That one improvement enabled installing multiple extensions at once, making a reinstall of an already-installed extension a no-op, installing reproducibly from a lock file, and the long-requested Pie upgrade command that bumps all your Pie extensions in one go.
The other massive chunk of work was the attestation library. It started as a bare-bones OpenSSL-based verification of GitHub attestation certificates — written with help from Tim Düsterhus so people could verify Pi’s authenticity without needing the gh CLI. For 1.5, James ran it against the Sigstore conformance test suite and filled in a huge number of gaps, bringing it close to full conformance on the verification side. That opens the door to the Composer team’s stated interest in authenticating PHP packages down the line.
💬 Advice for New Contributors
Asked what he’d tell his past self, James kept it simple: just get involved, and always assume good intent. If a maintainer doesn’t respond within a day they’re probably just busy — not ignoring you — and lengthy back-and-forth on a pull request usually reflects a maintainer trying to keep the project maintainable, not nitpicking.
He encouraged everyone to open a discussion before sending a PR so effort doesn’t get duplicated — a lesson learned after early contributions collided with work he already had in progress. To help with that, he adds a “maintainer investigating” label to issues he’s actively working on, and leans on issue and PR templates to steer people in the right direction.
Elizabeth added that newer coders can find it intimidating to put their work out publicly on GitHub forever, and that both sides benefit from a little grace and a shared social contract. James closed by stressing that the single most helpful contribution is feedback — report even the small things you worked around, because eliminating that friction saves the next developer the same headache, as happened with a recent PCRE2 compile fix on macOS.
Links from the show:
- Pie(php/pie) — GitHub repository, issues & discussions
- PHP Windows Builder GitHub Action
- Packagist Extensions
- Composer
- attestation library
- Introduction to PIE
Host:
Elizabeth Barron
- Mastodon: @elizabeth@fosstodon.org
- LinkedIn: elizabethn
James Titcumb
- Mastodon: @asgrim@phpc.social
Streams:
📬 Connect & Hire
Looking to hire PHP developers? Email support@phparch.com – Joe and the team are available for consulting, infrastructure work, Ansible playbooks, and code review.
Music Provided by Epidemic Sound
https://www.epidemicsound.com/
🎯 Join Us Live Next Week
Got feedback? Join us on Discord at discord.phparch.com
Listen
Podcast (episodes): Play in new window | Download | Subscribe
| Air date | October 8, 2026 |
|---|---|
| Hosted by | Elizabeth Barron, James Titcumb |
| Guest(s) | James Titcumb |


