a/s/l/threat model?
Andrew Nesbitt
• Andrew Nesbitt
The Infosec Phrasebook
Package management and open source metadata expert. Building Ecosyste.ms, open datasets and tools for critical open source infrastructure.
Andrew Nesbitt
• Andrew Nesbitt
a/s/l/threat model?
Andrew Nesbitt
• Andrew Nesbitt
Releases, advisories, and articles from across the package management world
Andrew Nesbitt
• Andrew Nesbitt
uBlock Origin for composer install
Andrew Nesbitt
• Andrew Nesbitt
printMessageForCodingAgents()
Andrew Nesbitt
• Andrew Nesbitt
brew install pip install poetry add pdm add uv tool install conda
Andrew Nesbitt
• Andrew Nesbitt
CHAOSS metrics were calibrated for human-speed contribution
Andrew Nesbitt
• Andrew Nesbitt
Thank you Dr. Zizmor
Andrew Nesbitt
• Andrew Nesbitt
TUF, in-toto, and Sigstore only look pointless while nothing is on fire
Andrew Nesbitt
• Andrew Nesbitt
Releases, advisories, and articles from across the package management world
Andrew Nesbitt
• Andrew Nesbitt
A survey of unused-dependency detectors
Andrew Nesbitt
• Andrew Nesbitt
Intended status: Best Current Practice.
Andrew Nesbitt
• Andrew Nesbitt
How your dependencies became Bernies
Andrew Nesbitt
• Andrew Nesbitt
apt install -t unstable, but make it your whole personality
Andrew Nesbitt
• Andrew Nesbitt
Don't automatically reach for PageRank on dependency graphs
Andrew Nesbitt
• Andrew Nesbitt
An independent benchmark of the ecosyste.ms Python fund
Andrew Nesbitt
• Andrew Nesbitt
How curl's disclosure policy filtered an AI scanner's findings at source
Andrew Nesbitt
• Andrew Nesbitt
A lightweight multi-ecosystem caching package proxy
Andrew Nesbitt
• Andrew Nesbitt
The cards do not lie.
Andrew Nesbitt
• Andrew Nesbitt
The streetlight effect in project-health scoring
Andrew Nesbitt
• Andrew Nesbitt
Which of your dependencies are wearing sunglasses
Andrew Nesbitt
• Andrew Nesbitt
The next metaphor after free-as-in-puppy
Andrew Nesbitt
• Andrew Nesbitt
The riskiest projects in open source, scored a decade early
Andrew Nesbitt
• Andrew Nesbitt
The non-CVE half of package manager security
Andrew Nesbitt
• Andrew Nesbitt
Recurring weakness classes in package managers
Andrew Nesbitt
• Andrew Nesbitt
Giving dependencies the same treatment the fork got
Andrew Nesbitt
• Andrew Nesbitt
What to do when upstream ghosts you