This is the next post in our supply chain security series, following the supply chain security update , the Composer 2.10 release , and the recent post on closing Composer’s download fallback paths . Composer 2.10’s dependency policy framework is a substantial step forward for PHP supply