composer/composer
packagist
pkg:composer/composer/composer
217 Dependabot PRs
21 days ago
128 repositories
4 repositories
Security Advisories
Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
Composer code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php
Composer Remote Code Execution vulnerability via web-accessible composer.phar
Missing input validation can lead to command execution in composer
Composer allows cache poisoning from other projects built on the same host
Recent PRs (filtered by: Patch PRs )
Bump composer/composer from 2.9.5 to 2.9.8 in /composer/helpers/v2 in the prod-dependencies group across 1 directory
JaclynCodes/dependabot-core #121
Bump composer/composer from 2.9.5 to 2.9.7
WyriHaximus/php-async-test-utilities #370
Bump composer/composer from 2.9.5 to 2.9.7
WyriHaximus/php-psr-3-context-logger #86
chore(deps-dev): bump composer/composer from 2.9.5 to 2.9.7 in the composer group across 1 directory
NguyenThanhPhucne/open_crm #10
Bump composer/composer from 2.9.5 to 2.9.7
acquia/cli #1982
build(deps): bump composer/composer from 2.9.5 to 2.9.6 in /composer/helpers/v2
dependabot/dependabot-core #14719
chore(deps-dev): bump composer/composer from 2.9.5 to 2.9.7
UN-OCHA/response-site #1088
Bump the composer group across 1 directory with 2 updates
Bump the composer group across 1 directory with 2 updates
EncoreDigitalGroup/laravel-stripe #90
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-tile-stitcher #44
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-psr-3-callable-throwable-logger #75
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-broadcast #329
Bump composer/composer from 2.9.2 to 2.9.3
WyriHaximus/php-monolog-formatted-psr-handler #88
Bump composer/composer from 2.9.2 to 2.9.3 in /streetcode
Bump composer/composer from 2.9.1 to 2.9.3
librenms/librenms #18726
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3
UN-OCHA/drupal-starterkit #243
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3
UN-OCHA/unocha-site #732
chore(deps): bump composer/composer from 2.9.2 to 2.9.3 in the composer group across 1 directory
dfo-osdt/osp #1315
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3
UN-OCHA/common-design-site #591
Bump composer/composer from 2.9.2 to 2.9.3 in /build
unb-libraries/datasets.lib.unb.ca #94
Bump composer/composer from 2.9.2 to 2.9.3
phpro/grumphp #1202
chore(deps-dev): bump composer/composer from 2.9.2 to 2.9.3 in /tools
Bump composer/composer from 2.9.2 to 2.9.3 in the composer group across 1 directory
build(deps): bump composer/composer from 2.9.2 to 2.9.3
ilios/ilios #6766
Bump composer/composer from 2.9.2 to 2.9.3
cweagans/composer-patches #671
Bump composer/composer from 2.9.1 to 2.9.3 in /tests/Composer/__fixtures__
statamic/cms #13408
Bump composer/composer from 2.2.12 to 2.2.24 in /tests/Composer/__fixtures__
oshkoshbagoshh/aj_statamic_cms #3
chore(deps-dev): bump composer/composer from 2.9.1 to 2.9.2
netz98/n98-magerun #1630
Bump the composer group across 1 directory with 9 updates
Bump composer/composer from 1.10.23 to 1.10.27 in /tests/Fake/fake-app
chore(deps): bump composer/composer from 2.8.11 to 2.8.12
demos-europe/demosplan-core #5292
Bump composer/composer from 2.8.11 to 2.8.12
EncoreDigitalGroup/PHPGenesis #162
Bump composer/composer from 2.8.11 to 2.8.12
EncoreDigitalGroup/stdlib #128
(chore): Bump the composer group with 5 updates
yardinternet/wp-user-roles #65
Bump composer/composer from 2.8.11 to 2.8.12
roots/wordpress-packager #1187
Bump composer/composer from 2.8.11 to 2.8.12 in the minor-patch group
composer/satis #1042
build(deps): bump composer/composer from 2.8.11 to 2.8.12
ilios/ilios #6521
Bump composer/composer from 2.8.11 to 2.8.12
rajeshreeputra/composer-patches #63
Bump composer/composer from 2.8.11 to 2.8.12
madewithlove/semver #1068
Bump composer/composer from 2.8.11 to 2.8.12
cweagans/composer-patches #644
build(deps-dev): bump composer/composer from 2.8.11 to 2.8.12
guanguans/laravel-skeleton #1507
Package Details
| Name: | composer/composer |
| Ecosystem: | packagist |
| PURL Type: | composer |
| Package URL: | pkg:composer/composer/composer |
| JSON API: | View JSON |
Security Advisories
Package Information
Composer helps you declare, manage and install dependencies of PHP projects. It ensures you have the right stack everywhere.
| Repository: | https://github.com/composer/composer |
| Homepage: | https://getcomposer.org/ |
| Latest Release: |
2.8.9
about 1 year ago |
| Dependent Repos: | 35,414 |
| Dependent Packages: | 2,610 |
| Downloads: | 162,035,323 |
| Ranking: | Top 0.0479% by dependent repos Top 0.0457% by downloads Top 0.0156% by dependent pkgs |