What changed
On October 7, 2026 the PHP Foundation released PHP Installer for Extensions (PIE) 1.5. The installer can now install multiple extension packages in one command, filter configuration flags to the relevant packages, and use --select for unattended project installs. The release adds pie search, pie check-build-tools, --no-dev for project extension installation, and more control over download URL methods. Its attestation library was substantially reworked to support Sigstore verification independently of GitHub's trusted root, with 131 conformance tests passing, five skipped and four expected failures. PIE is the PHP Foundation-backed replacement for deprecated PECL.
Why it matters
PHP operators often build containers or deployment images with several native extensions, where manual prompts and one-package-at-a-time scripts complicate reproducibility. PIE 1.5 lowers that friction and gives maintainers a more explicit path for discovering, selecting and checking extension dependencies. The attestation work improves verification of PIE's own distribution/update path; it does not imply that every third-party PHP extension has been audited or is signed.
Multi-package installation reaches normal deployment scripts
The same pie install invocation can now request multiple extension packages, and configure flags are assigned to the relevant extension. This helps Dockerfile and image provisioning workflows, though conflicting shared configure options can still cause an install to fail.
Unattended project installs become more deliberate
The --select option allows package choices for missing extensions in noninteractive project installs; --no-dev skips development-only extensions. Teams can avoid a prompt blocking CI while keeping package selection explicit.
Build checks and package discovery are first-class
The release adds pie search for extension packages and pie check-build-tools to check prerequisite compilation tooling before attempting installation.
Attestation verification is stronger but has a defined scope
PIE's Sigstore attestation library passed 131 conformance tests and can work with roots beyond GitHub's built-in certificate. This strengthens authenticity checking for PIE itself; extension package provenance still requires separate scrutiny.