composer/composer
packagist
pkg:composer/composer/composer
217 Dependabot PRs
21 days ago
128 repositories
4 repositories
Security Advisories
Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
Composer code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php
Composer Remote Code Execution vulnerability via web-accessible composer.phar
Missing input validation can lead to command execution in composer
Composer allows cache poisoning from other projects built on the same host
Recent PRs
Bump composer/composer from 2.9.5 to 2.10.0 in /html
Bump the composer group across 1 directory with 18 updates
HandyKnox/mautic-marketing #21
Bump the composer group across 1 directory with 17 updates
dporkka/mautic #16
Bump the composer group across 1 directory with 12 updates
HandyKnox/mautic-marketing #15
Bump the composer group across 1 directory with 8 updates
Bump composer/composer from 2.9.5 to 2.9.8 in /composer/helpers/v2 in the prod-dependencies group across 1 directory
JaclynCodes/dependabot-core #121
Bump the composer group across 1 directory with 6 updates
acquia/drupal-recommended-project #915
Bump the composer group across 1 directory with 7 updates
Bump the composer group across 1 directory with 7 updates
Bump composer/composer from 2.9.5 to 2.9.7
WyriHaximus/php-async-test-utilities #370
Bump composer/composer from 2.9.5 to 2.9.7
WyriHaximus/php-psr-3-context-logger #86
chore(deps-dev): bump composer/composer from 2.9.5 to 2.9.7 in the composer group across 1 directory
NguyenThanhPhucne/open_crm #10
Bump composer/composer from 2.9.5 to 2.9.7
acquia/cli #1982
build(deps): bump composer/composer from 2.9.5 to 2.9.6 in /composer/helpers/v2
dependabot/dependabot-core #14719
chore(deps-dev): bump composer/composer from 2.9.5 to 2.9.7
UN-OCHA/response-site #1088
Bump the composer group across 1 directory with 2 updates
Bump the composer group across 1 directory with 2 updates
EncoreDigitalGroup/laravel-stripe #90
Bump the composer group across 1 directory with 6 updates
acquia/drupal-recommended-project #906
composer(deps): bump the production-dependencies group with 54 updates
pivvenit/wordpress-readonly #33
Bump composer/composer from 2.8.6 to 2.9.5
acquia/orca #685
Bump composer/composer from 2.8.9 to 2.9.4 in /composer/helpers/v2 in the prod-dependencies group across 1 directory
JaclynCodes/dependabot-core #10
Bump the composer group across 1 directory with 2 updates
Bump the composer group across 1 directory with 2 updates
acquia/drupal-recommended-project #891
Bump the composer group across 1 directory with 2 updates
Bump composer/composer from 2.8.10 to 2.9.4 in /composer/helpers/v2 in the prod-dependencies group across 1 directory
Alexsio274ltd/dependabot-core #49
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-tile-stitcher #44
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-psr-3-callable-throwable-logger #75
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-broadcast #329
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-monolog-formatted-psr-handler #88
Bump composer/composer from 2.9.2 to 2.9.3 in /streetcode
Bump composer/composer from 2.9.1 to 2.9.3
librenms/librenms #18726
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3
UN-OCHA/drupal-starterkit #243
chore(deps): bump composer/composer from 2.9.2 to 2.9.3 in the composer group across 1 directory
dfo-osdt/osp #1315
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3
UN-OCHA/unocha-site #732
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3
UN-OCHA/common-design-site #591
Bump composer/composer from 2.9.2 to 2.9.3 in /build
unb-libraries/datasets.lib.unb.ca #94
Bump composer/composer from 2.9.2 to 2.9.3
phpro/grumphp #1202
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3 in /tools
Bump composer/composer from 2.9.2 to 2.9.3 in the composer group across 1 directory
build(deps): bump composer/composer from 2.9.2 to 2.9.3
ilios/ilios #6766
Bump composer/composer from 2.9.2 to 2.9.3
cweagans/composer-patches #671
Bump composer/composer from 2.9.1 to 2.9.3 in /tests/Composer/__fixtures__
statamic/cms #13408
chore(deps-dev): bump composer/composer from 2.8.9 to 2.9.3
rtCamp/snapwp-helper #119
build(deps-dev): bump composer/composer from 2.8.8 to 2.9.3
ONLYOFFICE/onlyoffice-docspace-wordpress #54
Package Details
| Name: | composer/composer |
| Ecosystem: | packagist |
| PURL Type: | composer |
| Package URL: | pkg:composer/composer/composer |
| JSON API: | View JSON |
Security Advisories
Package Information
Composer helps you declare, manage and install dependencies of PHP projects. It ensures you have the right stack everywhere.
| Repository: | https://github.com/composer/composer |
| Homepage: | https://getcomposer.org/ |
| Latest Release: |
2.8.9
about 1 year ago |
| Dependent Repos: | 35,414 |
| Dependent Packages: | 2,610 |
| Downloads: | 162,035,323 |
| Ranking: | Top 0.0479% by dependent repos Top 0.0457% by downloads Top 0.0156% by dependent pkgs |