Sign up

Andrew Nesbitt

Not verified No WebSub updates No webmention support Valid

Package management and open source metadata expert. Building Ecosyste.ms, open datasets and tools for critical open source infrastructure.

Author
Andrew Nesbitt
Generator
Jekyll
Public lists
davewiner/hackerNewsStars
Fetched

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 25 July 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Interview with a Maintainer

Episode 214 of Green Squares.

Andrew Nesbitt Valid
• Andrew Nesbitt

Package Name Prefixes

django plugins, cloud SDKs, and 1,999 homework submissions.

Andrew Nesbitt Valid
• Andrew Nesbitt

–end-of-options

The git flag I assumed was an LLM hallucination

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 18 July 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Plumbing Homebrew into the vulnerability ecosystem

One command, six repos, three standards bodies, an advisory database, and a version comparator written in the wrong language.

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 11 July 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Package Management as Org Chart

Conway's Law applied to dependency management designs.

Andrew Nesbitt Valid
• Andrew Nesbitt

Unboxed: Zig

Zig's package manager: mechanics, categorisation, governance, threat model.

Andrew Nesbitt Valid
• Andrew Nesbitt

Content addressing in package managers

Names are for humans, hashes are for everything else

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 4 July 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

The CRA is not about open source

The CRA created an open-source steward role, then left maintenance unfunded.

Andrew Nesbitt Valid
• Andrew Nesbitt

Taking Roads and Bridges literally

Reflections on UN Open Source Week 2026

Andrew Nesbitt Valid
• Andrew Nesbitt

Unbundling the standard library

Batteries no longer included, available separately on aisle four

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 27 June 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Incident Report: CVE-2026-LGTM

A series of unfortunate agents.

Andrew Nesbitt Valid
• Andrew Nesbitt

Scrutineer: scanning open source without flooding maintainers

Finding the vulnerabilities is the easy part

Andrew Nesbitt Valid
• Andrew Nesbitt

Sunsetting a Package Manager

A frozen registry is the one place a package can never be patched again.

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 20 June 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Open Source vs the Invisible Hand

Ten million downloads a week, one maintainer, zero dollars.

Andrew Nesbitt Valid
• Andrew Nesbitt

How Open Source Projects Change Hands

There are fewer ways to leave your package than to kill it.

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 13 June 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Joint Guidance on Vulnerability Naming and Disclosure

Every named CVE now ships with a single-page site at .vuln.

Andrew Nesbitt Valid
• Andrew Nesbitt

What Happened to tea.xyz

Reading the tea leaves

Andrew Nesbitt Valid
• Andrew Nesbitt

Forms of Open Source Government

Open source has more forms of government than countries do.

Andrew Nesbitt Valid
• Andrew Nesbitt

Package Manager Patents

A reference list of patents and applications relevant to package manager design, with notes on prior art.

Andrew Nesbitt Valid
• Andrew Nesbitt

This Week in Package Management: 6 June 2026

Releases, advisories, and articles from across the package management world

Andrew Nesbitt Valid
• Andrew Nesbitt

Install-script allowlists

A survey of install-script allowlist mechanisms across package managers and language ecosystems.

Andrew Nesbitt Valid
• Andrew Nesbitt

gittuf - a signed log for git refs

Branch protection is a row in someone else's database

Andrew Nesbitt Valid
• Andrew Nesbitt

Skills Registry Threat Models

How long until we see a CVE filed against a markdown file?