A PHP developer scanned 1554 Packagist projects and found that 229 (roughly 15%) include unnecessary polyfill or compatibility packages despite requiring a PHP version where those packages are no longer needed. The post raises questions about how carefully developers vet their dependencies, drawing parallels to recent NPM supply-chain attacks. The author sent PRs to all affected projects and reflects on whether the convenience of package managers has made developers too passive about what code they pull in.
Sort: