composer / composer/packagist

Security -- how are malicious or insecure Packagist packages reported

Open
#335 6 comments 1 reaction 0 assignees View on GitHub
Dominant language
PHP
Stars
1.8k
Forks
488
Avg merge
2d 21h
Merged PRs (30d)
32

Description

Not so much an issue with the packagist code, so perhaps not the ideal place for voicing this concern, but the main issue I have with Packagist is that it is so _open_ which is both _good_ and _bad_.

Say I'd discover that some person is sneaking in backdoors or purposely or not introducing exploits, how do I make sure the package is taken offline as soon as possible? If there _is_ an existing procedure it should be much, much more apparant. Probably it should have a prominent place on the Packagist home page.

It's not stopping me from using Composer and Packagist right now but if this bites me in the ass despite the uncomfortable feeling I am communicating right now I'll probably never forgive myself :p I am seriously considering abandoning the use of Packagist packages because of this concern.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Review whether Packagist already has a security-reporting procedure and how the homepage presents support information; done means users can find a clear, prominent way to report malicious or insecure packages.

Written by the indexing model from the issue text.

Assessment

Tech stack
php
Domain
documentation, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.