Packages
NPM
https://verdaccio.org/docs/what-is-verdaccio https://cheatsheetseries.owasp.org/cheatsheets/NPM_Security_Cheat_Sheet.html#6-use-a-local-npm-proxy
PHP
https://cheatsheetseries.owasp.org/cheatsheets/PHP_Configuration_Cheat_Sheet.html https://snuffleupagus.readthedocs.io/
https://github.com/fabpot/local-php-security-checker
Standards, helpers etc
squizlabs/php_codesnifferpheromone/phpcs-security-auditdealerdirect/phpcodesniffer-composer-installerslevomat/coding-standardphpstan/phpstan- https://phpstan.org/phpstan/phpstan-deprecation-rulesspaze/phpstan-disallowed-calls