Nils Adermann's Avatar

Nils Adermann

@naderman.de

Co-Founder of @packagist.com / http://packagist.com and Co-Creator of #composerphp - he/him - @naderman@phpc.social

791
Followers
234
Following
117
Posts
06.08.2023
Joined
Posts Following

Latest posts by Nils Adermann @naderman.de

Preview
Working Together on the Future of PHP The PHP Foundation β€” Supporting, Advancing, and Developing the PHP Language

For those who don't know our new Executive Director, Elizabeth Barron, she's written an introductory post on The PHP Foundation Blog that shares a bit about her background, her vision for the future, and how you can share your own PHP thoughts with her.

#php #phpc

thephp.foundation/blog/2026/03...

06.03.2026 19:30 πŸ‘ 5 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

Will take a look. Our Composer doesn't have a LinkedIn, at least nothing we control and that domain isn't ours sadly.

05.03.2026 19:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Finally got to meet @snipe.lol IRL at #LaraconEU! 😁

03.03.2026 13:52 πŸ‘ 6 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Nils Adermann wearing a blue Private Packagist hoodie and yellow Private Packagist t-shirt on stage next to a lectern pointing at a slide, photographed across backs of audience heads.

Nils Adermann wearing a blue Private Packagist hoodie and yellow Private Packagist t-shirt on stage next to a lectern pointing at a slide, photographed across backs of audience heads.

Laracon EU audience facing the stage

Laracon EU audience facing the stage

Nils Adermann taking a selfie from the balcony above the Laracon EU crowd with Nuno Maduro on a large screen talking to the audience.

Nils Adermann taking a selfie from the balcony above the Laracon EU crowd with Nuno Maduro on a large screen talking to the audience.

Sign with community sponsor logos at Laracon EU Amsterdam including Private Packagist

Sign with community sponsor logos at Laracon EU Amsterdam including Private Packagist

Loved the very engaged audience of a thousand people at #LaraconEU 2026 in Amsterdam today at my "Composer Deep Dive" talk! Proud to sponsor the event with Private Packagist /
@packagist.com - Find me and chat about package management or @thephpf.bsky.social! #laravel #laracon #php #composerphp

02.03.2026 14:58 πŸ‘ 11 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Just arrived in Amsterdam for #LaraconEU - my talk "Composer Deep Dive" is tomorrow afternoon at 2:30pm! Hope to talk to as many of you about #composerphp @packagist.com and @thephpf.bsky.social ! #laravel #php

01.03.2026 13:30 πŸ‘ 7 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0
Preview
Welcoming Elizabeth Barron as the New Executive Director of The PHP Foundation The PHP Foundation β€” Supporting, Advancing, and Developing the PHP Language

We’re excited to welcome Elizabeth Barron as the new Executive Director of The PHP Foundation! 🐘 πŸ’œ

Elizabeth brings PHP community roots, open-source governance experience from GitHub & CHAOSS, and a passion for making PHP thrive for decades to come.

thephp.foundation/blog/2026/02...

#php #phpc

27.02.2026 13:17 πŸ‘ 9 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Full audience at the c-base for the Symfony Usergroup Berlin Opening

Full audience at the c-base for the Symfony Usergroup Berlin Opening

Excited to speak at #symfony user group Berlin tonight! #sfugberlin #composerphp

25.02.2026 18:24 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Respectful Open Source Maintainer attention as a finite resource.

Treating Maintainer attention as a finite resource: nesbitt.io/2026/02/13/r...

13.02.2026 11:31 πŸ‘ 20 πŸ” 10 πŸ’¬ 0 πŸ“Œ 1
Preview
What's New in Private Packagist, February 2026 Update Private Packagist has continued to evolve over the past three months with significant improvements to authentication flows, security hardening, and notification capabilities. Here are the highlights f...

πŸš€ Private Packagist February update: Redesigned login flow, team member MFA resets for org owners, new Microsoft Teams Workflow notifications (old connectors deprecated), clickable composer search URLs in your terminal blog.packagist.com/whats-new-in... #composerphp #php #phpc

09.02.2026 16:28 πŸ‘ 5 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Package Management at FOSDEM 2026 Summary of package management talks from FOSDEM 2026, covering supply chain security, attestations, SBOMs, dependency resolution, and distribution packaging across multiple devrooms.

Everything package management at @fosdem.org 2026, most of the videos are online now: nesbitt.io/2026/02/04/p...

04.02.2026 16:49 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Incident Report: CVE-2024-YIKES A series of unfortunate events.

Incident Report: CVE-2024-YIKES

A series of unfortunate events

nesbitt.io/2026/02/03/i...

03.02.2026 10:21 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1

Postfach: β€žFrau P. ist seit 10 Jahren wohnungslos und bekommt endlich UnterstΓΌtzung durch Housing First. Doch jetzt droht Haft wegen Fahren ohne Ticket. Wird sie eingesperrt, gefΓ€hrdet das den Erhalt der Wohnung weil die Miete nicht mehr gezahlt wird. KΓΆnnt ihr was tun?β€œ

Das Gesetz muss weg. Punkt.

23.12.2025 09:13 πŸ‘ 252 πŸ” 75 πŸ’¬ 5 πŸ“Œ 1

Boo, surely you can pack more efficiently after some rose 😜

17.12.2025 08:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

cc @agento.bsky.social πŸ˜‰

17.12.2025 07:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
a christmas tree made out of pizza slices with a star on top ALT: a christmas tree made out of pizza slices with a star on top

There seemed to be some interest in once more this week. So calling you all for Wednesday Brewdog at noon tomorrow
@seidtgeist.com @lstoll.net @chown.de @rkh.cool @felixge.de @trodrigues.net @justine.cool @pudo.org @conniehwong.bsky.social @powen.net @rmehner.bsky.social

16.12.2025 21:30 πŸ‘ 3 πŸ” 0 πŸ’¬ 5 πŸ“Œ 0
Preview
a woman laying on a bed next to a pizza box that says pizza i love you on it ALT: a woman laying on a bed next to a pizza box that says pizza i love you on it

Who is joining for lunch one more time this year tomorrow at Brewdog Mitte at 12?
@seidtgeist.com @lds.li @chown.de @rkh.cool @felixge.de @trodrigues.net @justine.cool @pudo.org @conniehwong.bsky.social @powen.net

09.12.2025 19:23 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

I’m pleased to announce PromptVer, a new versioning scheme designed for the age of large language models.

nesbitt.io/2025/12/01/p...

01.12.2025 12:40 πŸ‘ 6 πŸ” 4 πŸ’¬ 0 πŸ“Œ 2
GitHub Actions Has a Package Manager, and It Might Be the Worst GitHub Actions has a package manager that ignores decades of supply chain security best practices: no lockfile, no integrity verification, no transitive pinning

The package manager in GitHub Actions might be the worst package manager in use today: nesbitt.io/2025/12/06/g...

07.12.2025 07:06 πŸ‘ 10 πŸ” 1 πŸ’¬ 0 πŸ“Œ 1

Fascinating evening organized by the @sovereign.tech in Berlin tonight: Presenting their #SovereignTechFellowship program which funds individual open source maintainers of our digital infrastructure with public money.

03.12.2025 21:49 πŸ‘ 5 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Proud to announce we just renewed our annual $18,000 sponsorship for the The PHP Foundation!

Check out this summary on the work completed in 2025. So much more could be accomplished, if all businesses using PHP contributed. Sign up as a sponsor and help moving PHP forward!

03.12.2025 15:38 πŸ‘ 27 πŸ” 7 πŸ’¬ 1 πŸ“Œ 1

who decided to call it Secret Santa when Nondisclosure Claus was right there

01.12.2025 22:55 πŸ‘ 3587 πŸ” 918 πŸ’¬ 26 πŸ“Œ 23

Check out the slides for my talk at
naderman.de/slippy/slide...

01.12.2025 14:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann in yellow Private Packagist t-shirt and blue hoodie presenting in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting on 2FA enforcement in package manager ecosystems in front of a crowd at SymfonyCon Amsterdam 2025.

Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.

Nils Adermann presenting at SymfonyCon Amsterdam 2025 on stage, discussing the npm Shai-Hulud Worm security incident. The slide shows details of the November 2024 supply chain attack that compromised 700+ packages and exposed credentials from 26k+ repositories through GitHub Actions code injection.

Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.

Conference attendees gathered around the Private Packagist booth at SymfonyCon Amsterdam 2025 having discussions.

Back from our annual #SymfonyCon trip! Great experience celebrating 20 years of #Symfony with its community in Amsterdam. The @packagist.com booth was busy throughout the event, and my package manager security outlook talk sparked good conversations. See you in Warsaw 2026! #php #composerphp

01.12.2025 14:57 πŸ‘ 9 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0

In Amsterdam next week and part of a group underrepresented at tech confs, or can't afford a ticket? Private Packagist is sponsoring #SymfonyCon (Nov 27th/28th) and we have a ticket to give away: Reply your favorite PHP8.5 feature to win #php #phpc #symfony @symfony.com

21.11.2025 21:52 πŸ‘ 6 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0
Post image

Really fun to play with Nano Banana Pro and have it visualize things. Here's the good old cube rule of food 😁

21.11.2025 08:37 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Tax information for GitHub Sponsors - GitHub Docs Sponsored developers and organizations must submit tax information to GitHub and are responsible for evaluating and paying their own taxes.

Great, @github.com giving open source maintainers wrong tax advice 🀦 docs.github.com/en/sponsors/... "In the EU and most other countries and regions, [...] B2B sales are not subject to tax."

20.11.2025 11:39 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
What’s New in Private Packagist, November Update We've shipped several important updates to Private Packagist over the past three months, including more insights on the package usage tracking page, the introduction of Trusted Publishing for secure a...

New in Private Packagist: Usage Tracking can now help prioritize security updates by showing how deps cascade through projects and where vulnerable versions are used. Trusted Publishing for GitHub Actions and better synchronization setup. blog.packagist.com/whats-new-in... #php #phpc #composerphp

18.11.2025 09:35 πŸ‘ 2 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Strengthening PHP Supply Chain Security with a Transparency Log for Packagist.org The release of Composer 2.9 this week introduced new security features on the Composer CLI client, which were funded by Private Packagist through service subscriptions. But in parallel, we are working...

After Composer 2.9 CLI security improvements, we're working on a transparency log for Packagist to strengthen PHP supply chain security, funded by the @sovereign.tech with help of the @thephpf.bsky.social and Private Packagist. Details at blog.packagist.com/strengthenin... #php #phpc #composerphp

14.11.2025 15:35 πŸ‘ 17 πŸ” 7 πŸ’¬ 0 πŸ“Œ 0
Preview
Composer 2.9 Release We are pleased to announce the release of Composer 2.9.0, bringing improvements to security, repository management from the CLI, and lots more. Automatic Security Blocking Composer now automaticall...

Composer 2.9 is here! πŸš€ It automatically blocks packages with known vulnerabilities, has a new repository command to manage repos from the CLI, and lots more!

blog.packagist.com/composer-2-9/
#composerphp #phpc #PHP

13.11.2025 10:22 πŸ‘ 14 πŸ” 8 πŸ’¬ 0 πŸ“Œ 0
Preview
The PHP Foundation is Seeking a New Executive Director The PHP Foundation β€” Supporting, Advancing, and Developing the PHP Language

The PHP Foundation is Seeking a New Executive Director! πŸ˜πŸ’œ

We're asking the PHP community to help find the right person for this role. If you know someone who would be an excellent fit, please encourage them to apply or reach out to us directly.

thephp.foundation/blog/2025/11... #phpc #php

10.11.2025 15:03 πŸ‘ 14 πŸ” 12 πŸ’¬ 0 πŸ“Œ 0