PSA: If you maintain composer packages via Packagist, be a good steward of the open web and take a moment to set up 2FA on your Packagist site.

I set mine up today.

https://blog.packagist.com/an-update-on-composer-packagist-supply-chain-security/