๐—ง๐—ต๐—ฒ ๐——๐—ฎ๐—ป๐—ด๐—ฒ๐—ฟ๐—ผ๐˜‚๐—ฆ ๐—ง๐—ฟ๐˜‚๐˜๐—ต ๐—”๐—ฏ๐—ผ๐˜‚๐˜ ๐—–๐—ผ๐—บ๐—ฝ๐—ผ๐—ฒ๐—ฟ ๐—จ๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ You use Composer to manage your PHP projects. But do you know the risks of running Composer update? A recent incident with Laravel-Lang packages shows that supply chain attacks are a real threat. The attack used malicious packages to steal credentials from your machine. This is not just about SQL injection or XSS. This is about your development process being compromised.

To protect yourself:

Some key takeaways:

Source: https://dev.to/tegos/composer-update-is-not-safe-anymore-2bcf