Ecosyste.ms: Packages

An open API service providing package, version and dependency metadata of many open source software ecosystems and registries.

Top 0.1% on packagist.org
Top 0.1% downloads on packagist.org
Top 0.1% dependent packages on packagist.org
Top 0.1% dependent repos on packagist.org
Top 0.1% forks on packagist.org
Top 0.1% docker downloads on packagist.org

packagist.org : composer/composer

Composer helps you declare, manage and install dependencies of PHP projects. It ensures you have the right stack everywhere.

Registry - Source - Homepage - JSON
purl: pkg:composer/composer/composer
Keywords: package, dependency, autoload, composer, dependency-manager, hacktoberfest, package-manager, packages, php
License: MIT
Latest release: 10 days ago
First release: about 12 years ago
Namespace: composer
Dependent packages: 2,463
Dependent repositories: 35,414
Downloads: 131,015,635 total
Stars: 28,274 on GitHub
Forks: 4,460 on GitHub
Docker dependents: 228
Docker downloads: 57,082,479
See more repository details: repos.ecosyste.ms
Funding links: https://packagist.com, https://github.com/composer, https://tidelift.com/funding/github/packagist/composer/composer, https://github.com/sponsors/composer
Last synced: 9 days ago

High
GSA_kwCzR0hTQS03YzZwLTg0OGotd2g1aM4AA5KP
Composer code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php
Ecosystems: packagist
Packages: composer/composer
Source: github
Published: 3 months ago
High
GSA_kwCzR0hTQS1mcnFnLTdnMzgtNmdjZs0WJQ
Improper escaping of command arguments on Windows leading to command injection
Ecosystems: packagist
Packages: composer/composer
Source: github
Published: over 2 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg1aDgtcGM2aC1qdnZ4
Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial
Ecosystems: packagist
Packages: composer/composer
Source: github
Published: about 3 years ago
High
GSA_kwCzR0hTQS1qbTZtLTQ2MzItMzZoZs4AA2Jg
Composer Remote Code Execution vulnerability via web-accessible composer.phar
Ecosystems: packagist
Packages: composer/composer
Source: github
Published: 8 months ago
High
GSA_kwCzR0hTQS03MjVtLXc4MzItcTk3M84AA1_U
Composer allows cache poisoning from other projects built on the same host
Ecosystems: packagist
Packages: composer/composer
Source: github
Published: 8 months ago
High
GSA_kwCzR0hTQS14N2NyLTZxcjYtMmhoNs0_nA
Missing input validation can lead to command execution in composer
Ecosystems: packagist
Packages: composer/composer
Source: github
Published: about 2 years ago