Drata might be a bit more popular than Private Packagist. We know about 7 links to it since March 2021 and only 7 links to Private Packagist. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
I was told in another forum to look at Private Packagist... But how is that different? Instead of installing packages from packagist.org.. You pay to Packagist.com to do the same thing? You just download from packagist.com cloud instead of packagist.org? Source: about 3 years ago
We have a private Satis instance. Our ITSec team reviews all packages before we add them to Satis. Packagist.com is available for us but the CI-CD servers can reach only the private Satis. Source: about 3 years ago
Https://packagist.com maybe tell them about a local packagist install. Source: about 3 years ago
"[MANAGER] requested this to be done in PHP. You as IT will know that most modern programming and scripting languages work only with packaging software properly. Composer sends requests (majority of cases) to packagist.com and to github.com. It will add thousands of hours to do everything that composer does manually. Please sign here to authorize the usage of 4000 hours and the possible delay of 4000 hours.... Source: about 3 years ago
Another downside that only really exists with non-PHP boilerplates is getting updates isn'T as easy. With PHP we're able to use packagist.com and make our code available via composer. Other languages don't have this so SaaS Pegasus provides zip downloads and Gravity provides access to a GitHub repo. This means you have to apply bug fixes yourself. With Parthenon, you do composer update and you'll get the latest... Source: over 3 years ago
Have you had opportunity to apply any of the compliance automation tools like Drata in your work? Have you found them to be useful? Source: over 2 years ago
Have you got any experience from services like Drata (https://drata.com/)? Source: over 2 years ago
Have a chat with the folks at https://drata.com/. Thier discovery and automated evidence gathering platform is pretty cool. Prepare for sticker shock though. Getting through any compliance process is a $30k ish annual expense. Source: almost 3 years ago
Compliance tools like Vanta and Drata integrate with the major cloud providers and allow you to automatically monitor whether compliance criteria are being met. Because these tools can plug directly into the cloud provider APIs, they are able to pull relevant data automatically and send alerts when something is misconfigured. - Source: dev.to / about 3 years ago
Even if your organization has the practices down, you will still need to spend time maintaining and collecting evidence of compliance. Therefore, itโs beneficial to invest in automated software tools like Vanta or Drata that can speed up the evidence collection process. These tools help manage and record evidence of compliance practices via continuous monitoring of the applicationโs infrastructure and business... - Source: dev.to / over 3 years ago
Satis - Satis is a simple static Composer repository generator
Vanta - Automate compliance, simplify security.
Sonatype Nexus Repository - The world's only repository manager with FREE support for popular formats.
Secureframe - Get enterprise ready with SOC 2 and ISO 27001 compliance
Packagist - The PHP Package Repository
Sprinto - SOC 2 security compliance for SaaS