Are Composer and Packagist also vulnerable to package unpublishing and hijacking? | Hacker News Reader