Sign up

Andrew Nesbitt

Not verified No WebSub updates No webmention support Valid

Package management and open source metadata expert. Building Ecosyste.ms, open datasets and tools for critical open source infrastructure.

Author
Andrew Nesbitt
Generator
Jekyll
Public lists
davewiner/hackerNewsStars
Fetched

Andrew Nesbitt Valid
• Andrew Nesbitt

The Infosec Phrasebook

a/s/l/threat model?

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 30 May 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Composer’s dependency policies

uBlock Origin for composer install

Andrew Nesbitt Valid
• Andrew Nesbitt

Protestware for coding agents

printMessageForCodingAgents()

Andrew Nesbitt Valid
• Andrew Nesbitt

Package managers that package package managers

brew install pip install poetry add pdm add uv tool install conda

Andrew Nesbitt Valid
• Andrew Nesbitt

CHAOSS Metrics in 2026

CHAOSS metrics were calibrated for human-speed contribution

Andrew Nesbitt Valid
• Andrew Nesbitt

GitHub Actions security in Python packages

Thank you Dr. Zizmor

Andrew Nesbitt Valid
• Andrew Nesbitt

Signing is for the bad days

TUF, in-toto, and Sigstore only look pointless while nothing is on fire

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 23 May 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Dependency Pruning

A survey of unused-dependency detectors

Andrew Nesbitt Valid
• Andrew Nesbitt

RFC: Artificial Contributors to Open Source

Intended status: Best Current Practice.

Andrew Nesbitt Valid
• Andrew Nesbitt

Dumb Ways for an Open Source Project to Die

How your dependencies became Bernies

Andrew Nesbitt Valid
• Andrew Nesbitt

Language Registries Are Unstable by Default

apt install -t unstable, but make it your whole personality

Andrew Nesbitt Valid
• Andrew Nesbitt

Centrality is not vitality

Don't automatically reach for PageRank on dependency graphs

Andrew Nesbitt Valid
• Andrew Nesbitt

Showing Our Work

An independent benchmark of the ecosyste.ms Python fund

Andrew Nesbitt Valid
• Andrew Nesbitt

Not a Security Issue

How curl's disclosure policy filtered an AI scanner's findings at source

Andrew Nesbitt Valid
• Andrew Nesbitt

proxy

A lightweight multi-ecosystem caching package proxy

Andrew Nesbitt Valid
• Andrew Nesbitt

Madame Semver Will See You Now

The cards do not lie.

Andrew Nesbitt Valid
• Andrew Nesbitt

The Mismeasure of Open Source

The streetlight effect in project-health scoring

Andrew Nesbitt Valid
• Andrew Nesbitt

Weekend at Bernie’s

Which of your dependencies are wearing sunglasses

Andrew Nesbitt Valid
• Andrew Nesbitt

Free as in Tribbles

The next metaphor after free-as-in-puppy

Andrew Nesbitt Valid
• Andrew Nesbitt

Revisiting the 2015 Open Source Census

The riskiest projects in open source, scored a decade early

Andrew Nesbitt Valid
• Andrew Nesbitt

Package Manager Threat Models

The non-CVE half of package manager security

Andrew Nesbitt Valid
• Andrew Nesbitt

Package Manager CWEs

Recurring weakness classes in package managers

Andrew Nesbitt Valid
• Andrew Nesbitt

A GitHub for maintainers

Giving dependencies the same treatment the fork got

Andrew Nesbitt Valid
• Andrew Nesbitt

Patching and forking in package managers

What to do when upstream ghosts you