Access Composer changelog updates through our uniform API. Same JSON structure across all sources — no adapter-specific parsing needed.
GET https://watchchangelog.com/api/v1/entries?source=composer.releases{
"source": "composer.releases",
"vendor": "Composer",
"id": "tag:github.com,2008:Repository/1864363/2.10.2",
"published_at": "2026-07-08T08:24:36.000Z",
"title": "2.10.2",
"url": "https://github.com/composer/composer/releases/tag/2.10.2",
"summary": "Security: Validate package names ( GHSA-499r-g7pc-vmp9 / CVE-2026-59948 ) Security: Validate package bin paths against path traversal ( GHSA-gjfg-22fp-rrxx / CVE-2026-59946 ) Security: Sanitize URL-embedded usernames/token in verbose output ( GHSA-g6xq-892h-64w3 / CVE-2026-59947 ) Security: Only follow HTTP redirects from HTTP responses ( #12948 ) Security: Prevent phar metadata unserialization on unsafe PHP versions ( #12946 ) Security: Sanitize JSON parse errors in http responses to avoid leaking response body data ( #12959 ) Added warning output in self-update command when using a soon-to-be EOL version ( #12920 ) Added download retry when a GitHub codeload URL returns a 400 ( #12962 ) Fixed audit command to output the audit result to stdout ( #12904 ) Fixed backspace characters being output to non-decorated output ( #12925 ) Fixed security advisory blocking causing issues with xdebug enabled ( #12935 ) Fixed provider packages hiding suggestions for the package they provide themselves ( #12933 ) Fixed security advisory blocking causing issues with xdebug enabled ( #12935 ) Full Changelog : 2.10.1...2.10.2",
"tags": [
"Composer",
"composer.releases",
"package-manager",
"php",
"open-source"
]
}Sign up to access the full changelog API. All public sources are free — no credit card required.
Sign Up Free →+2 more
+2 more
+2 more
+2 more
+2 more
+2 more