Security -- how are malicious or insecure Packagist packages reported
- Dominant language
- PHP
- Stars
- 1.8k
- Forks
- 488
- Avg merge
- 2d 21h
- Merged PRs (30d)
- 32
Description
Not so much an issue with the packagist code, so perhaps not the ideal place for voicing this concern, but the main issue I have with Packagist is that it is so _open_ which is both _good_ and _bad_.
Say I'd discover that some person is sneaking in backdoors or purposely or not introducing exploits, how do I make sure the package is taken offline as soon as possible? If there _is_ an existing procedure it should be much, much more apparant. Probably it should have a prominent place on the Packagist home page.
It's not stopping me from using Composer and Packagist right now but if this bites me in the ass despite the uncomfortable feeling I am communicating right now I'll probably never forgive myself :p I am seriously considering abandoning the use of Packagist packages because of this concern.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no files, tests, or entry points. Review whether Packagist already has a security-reporting procedure and how the homepage presents support information; done means users can find a clear, prominent way to report malicious or insecure packages.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- documentation, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100