Key details

  1. PIE 1.5 released October 7, 2026.
  2. PIE is the PHP Foundation-backed extension installer replacing deprecated PECL.
  3. pie install now accepts multiple extension packages.
  4. --select enables unattended package choice in PHP projects.
  5. pie search, pie check-build-tools and --no-dev add discovery and automation controls.
  6. The reworked Sigstore verification library passed 131 conformance tests, with five skipped and four expected failures.
  7. Multi-extension installs can still fail when extensions share conflicting configure options.

What builders should take away

  1. Review Docker and CI scripts that install multiple extensions separately; batch them only after testing configure-option compatibility.
  2. Use explicit unattended package selection to avoid CI prompting or unexpected package choices.
  3. Run build-tool preflight checks in minimal images before compilation.
  4. Distinguish verified PIE installer artifacts from the security and provenance of each installed extension.

What changed

On October 7, 2026 the PHP Foundation released PHP Installer for Extensions (PIE) 1.5. The installer can now install multiple extension packages in one command, filter configuration flags to the relevant packages, and use --select for unattended project installs. The release adds pie search, pie check-build-tools, --no-dev for project extension installation, and more control over download URL methods. Its attestation library was substantially reworked to support Sigstore verification independently of GitHub's trusted root, with 131 conformance tests passing, five skipped and four expected failures. PIE is the PHP Foundation-backed replacement for deprecated PECL.

Why it matters

PHP operators often build containers or deployment images with several native extensions, where manual prompts and one-package-at-a-time scripts complicate reproducibility. PIE 1.5 lowers that friction and gives maintainers a more explicit path for discovering, selecting and checking extension dependencies. The attestation work improves verification of PIE's own distribution/update path; it does not imply that every third-party PHP extension has been audited or is signed.

Multi-package installation reaches normal deployment scripts

The same pie install invocation can now request multiple extension packages, and configure flags are assigned to the relevant extension. This helps Dockerfile and image provisioning workflows, though conflicting shared configure options can still cause an install to fail.

Unattended project installs become more deliberate

The --select option allows package choices for missing extensions in noninteractive project installs; --no-dev skips development-only extensions. Teams can avoid a prompt blocking CI while keeping package selection explicit.

Build checks and package discovery are first-class

The release adds pie search for extension packages and pie check-build-tools to check prerequisite compilation tooling before attempting installation.

Attestation verification is stronger but has a defined scope

PIE's Sigstore attestation library passed 131 conformance tests and can work with roots beyond GitHub's built-in certificate. This strengthens authenticity checking for PIE itself; extension package provenance still requires separate scrutiny.

What to watch next

  • Adoption of PIE across PHP distribution images and hosting panels.
  • Support for more PECL extension edge cases and Windows binaries.
  • Whether more extension publishers adopt independently verifiable attestations.

Still unclear

  • The release does not establish ecosystem-wide PIE adoption or universal PECL compatibility.
  • Multi-extension installs still have known configure-option conflicts.
  • Sigstore attestation conformance for PIE's verification library does not certify every extension package.

Sources

Direct reading behind this dossier.

2 sources
PIE 1.5 Released
PHP Foundation primary

Primary release details for multi-package installs, unattended selection, helper commands and attestation tests.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment