Sign in

Andrew Nesbitt

@andrewnez.bsky.social
1.1K followers 167 following 267 posts

Working on mapping the world of open source software ecosyste.ms and empowering developers with octobox.io Mostly posting on mastodon.social/@andrewnez

PostsRepliesMedia
Andrew Nesbitt @andrewnez.bsky.social · 10h
git-pkgs v0.21.0 is out: fail CI on high/critical vulnerabilities with --fail-on high, get changelogs starting at your installed version, and see every dependency occurrence in outdated reports. Plus fixes for vulnerability reports across branches. github.com/git-pkgs/git...
github.com
Release v0.21.0 · git-pkgs/git-pkgs
Add git pkgs vulns scan --fail-on high to fail CI for high or critical findings. The command writes the complete text, JSON, or SARIF report before exiting 1. --severity filters the report independ...
020
Andrew Nesbitt @andrewnez.bsky.social · 01/10/2026
brief v0.14.0 is out: CITATION.cff and CodeMeta metadata, source manifest paths for dependencies, better Ruby/Python/Rust project detection, TinyGo support, and compact npm lockfile fixes. github.com/git-pkgs/bri...
github.com
Release v0.14.0 · git-pkgs/brief
Changelog 5f53947 Add and align CI security and dependency automation 8e75365 Apply gopls modernize fixes (#192) 73f926f Bump github.com/git-pkgs/archives from 0.7.0 to 0.7.1 (#191) e635e97 Bump g...
010
Andrew Nesbitt @andrewnez.bsky.social · 01/10/2026
git-pkgs proxy v0.9.0 is out with npm audit support, version denylists and multiple Debian archives. It fixes NuGet cooldown enforcement and concurrent download failures, and refreshes SPDX license data. github.com/git-pkgs/pro...
github.com
Release v0.9.0 · git-pkgs/proxy
Changelog c1f420a Add and align CI security and dependency automation 73a9863 Assert omitted Helm releases are not downloadable 8d3dacf Bump azure/setup-helm from 4.3.1 to 5.0.1 (#332) f0580d9 Bum...
010
Andrew Nesbitt @andrewnez.bsky.social · 01/10/2026
Software Heritage Identifiers nesbitt.io/2026/10/01/s... cc @softwareheritage.org
nesbitt.io
Software Heritage Identifiers
Notes from CodeCommons: SWHIDs, the SWH archive, and connecting both to package metadata.
021
Reposted by Andrew Nesbitt
Seth Larson @sethmlarson.dev · 30/09/2026
I've just published 10 blog posts detailing the #Python Language Summit 2026. The Language Summit was held in Kraków, Poland and included discussions about free-threading, #Rust, garbage collectors, and type annotations. Please enjoy and thank you for your patience: blog.python.org/2026/09/lang...
Group photo of the attendees of the 2026 Python Language Summit. Notably, Larry Hastings is laying flat on the ground with his eyes closed.
2107
Andrew Nesbitt @andrewnez.bsky.social · 27/09/2026
Luarocks having a a bad day: luarocks.org/security-inc... Don't sleep on TUF: nesbitt.io/2026/05/24/s...
luarocks.org
Security Incident September 2026 - LuaRocks
131
Andrew Nesbitt @andrewnez.bsky.social · 26/09/2026
This Week in Package Management: 26 September 2026 nesbitt.io/2026/09/26/t...
nesbitt.io
This Week in Package Management: 26 September 2026
Releases, advisories, and articles from across the package management world
250
Andrew Nesbitt @andrewnez.bsky.social · 24/09/2026
Package Manager Sandboxing nesbitt.io/2026/09/24/p...
nesbitt.io
Package Manager Sandboxing
A survey of sandbox usage across package manager clients.
010
Reposted by Andrew Nesbitt
Software Stewardship Lab @stewardshiplab.org · 23/09/2026
The Stewardship Lab has joined the @rustfoundation.org as an Associate Member! 🎉️ To support the Foundation in its mission of stewarding the Rust programming language, we're working to improve software supply chain security and developer education across the Rust ecosystem.
Software Stewardship Lab × Rust Foundation
052
Reposted by Andrew Nesbitt
The Rust Foundation @rustfoundation.org · 23/09/2026
We're excited to welcome four new members to the Rust Foundation: Silver Members: @codspeed.io, Haevek, and Perplexity Associate Member: @stewardshiplab.org Thanks to these orgs for investing in the health and stewardship of #rustlang! rustfoundation.org/media/rust-f...
071
Andrew Nesbitt @andrewnez.bsky.social · 22/09/2026
I fucked up the publish dates, so two blog posts live today: nesbitt.io/2026/09/22/p... nesbitt.io/2026/09/22/u...
nesbitt.io
Package Manager Threat Model, Revisited
Path traversal via a manifest field appeared in eight of ten package managers audited and thirty-three times in four months of everyone else’s advisories.
030
Reposted by Andrew Nesbitt
Miranda Heath @mirandaheath.website · 20/09/2026
Super excited to be a speaker at @viteconf.org this year, where I'll be talking about burnout in OSS and why we should care about it 🔥 viteconf.org/tickets/t/YB...
viteconf.org
Miranda's ViteConf 2026 mission credential
Miranda is on a connect mission for ViteConf 2026. Create your own credential.
0205
Reposted by Andrew Nesbitt
daniel wraith @danielroe.dev · 19/09/2026
don't be nice.
roe.dev
Don't be nice
Sometimes, it's more important to be good than it is to be nice.
41734250
Andrew Nesbitt @andrewnez.bsky.social · 19/09/2026
This Week in Package Management: 19 September 2026 nesbitt.io/2026/09/19/t...
nesbitt.io
This Week in Package Management: 19 September 2026
Releases, advisories, and articles from across the package management world
040
Reposted by Andrew Nesbitt
Rust Language @rust-lang.org · 17/09/2026
⚠️ We believe that there is an ongoing campaign targeting owners of popular crates and rust-lang team members that is attempting to compromise devices and accounts in order to use them to publish malware. See our blog post for details: blog.rust-lang.org/2026/09/17/t...
blog.rust-lang.org
Be alert: targeted attacks on prominent Rustaceans | Rust Blog
Empowering everyone to build reliable and efficient software.
122090
Andrew Nesbitt @andrewnez.bsky.social · 17/09/2026
Good Morning, Your Toaster Is Compromised nesbitt.io/2026/09/17/g...
nesbitt.io
Good Morning, Your Toaster Is Compromised
Rise & Grind goes live to the software supply chain.
081
Andrew Nesbitt @andrewnez.bsky.social · 15/09/2026
Shadowing the Standard Library nesbitt.io/2026/09/15/s...
nesbitt.io
Shadowing the Standard Library
export PYTHONSAFEPATH=1
020
Reposted by Andrew Nesbitt
Mike McQuaid @mikemcquaid.com · 13/09/2026
Today, I’m proud to announce Homebrew 7.0.0. The most significant changes since 6.0.0 are faster installations, stronger sandboxing, native macOS app, vulnerability checks, advisory database, end of macOS 10.15 support and Intel Macs to Tier 3.
brew.sh
7.0.0
Today, I’m proud to announce Homebrew 7.0.0. The most significant changes since 6.0.0 are faster installations and upgrades, stronger sandboxing, a native macOS app, built-in vulnerability checks and an advisory database, the end of macOS 10.15 support and Intel Macs moving to Tier 3.
523226
Reposted by Andrew Nesbitt
Ruby Central @rubycentral.org · 12/09/2026
The RubyGems team has published an update on the May spam-publishing campaign on rubygems.org, following recent reporting from The Wall Street Journal and research from Nightingale Collective. buff.ly/qU21FCK
rubygems.org
RubyGems.org | your community gem host
266,249,669,118
455
Andrew Nesbitt @andrewnez.bsky.social · 12/09/2026
This Week in Package Management: 5 September 2026 nesbitt.io/2026/09/05/t...
nesbitt.io
This Week in Package Management: 5 September 2026
Releases, advisories, and articles from across the package management world
001
Andrew Nesbitt @andrewnez.bsky.social · 10/09/2026
Package Manager Trends nesbitt.io/2026/09/10/p...
nesbitt.io
Package Manager Trends
min-release-age, minimum-release-age, -Zmin-publish-age, cooldown.
030
Andrew Nesbitt @andrewnez.bsky.social · 08/09/2026
nesbitt.io/2026/09/08/w...
nesbitt.io
What’s new in git-pkgs
Small Go modules for people who build package-manager tooling.
010
Reposted by Andrew Nesbitt
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 06/09/2026
Dogs
Felix and Basil - black mini and toy poodles
032
Reposted by Andrew Nesbitt
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 06/09/2026
A little weekend experiment: github.com/git-pkgs/git-spdx
github.com
GitHub - git-pkgs/git-spdx: Scan Git history for detected SPDX license changes
Scan Git history for detected SPDX license changes - git-pkgs/git-spdx
011
Reposted by Andrew Nesbitt
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 07/09/2026
I’m in print!
Photo of c’t magazine featuring an interview with me about software supply chain security (in German)
2102
Reposted by Andrew Nesbitt
Josh Bressers @josh.bressers.name · 07/09/2026
I had a chat with Jaya Baloo from AISLE about why they seem to be finding vulnerabilities even when the new fancy tools aren't finding anything The answer is unsurprisingly "engineering" Jaya has a ton of interesting insight, including how to work with open source projects and what's coming next
opensourcesecurity.io
Finding difficult vulnerabilities with Jaya Baloo from AISLE
Josh chats with Jaya Baloo from AISLE about their vulnerability scanner. If you follow open source vulnerabilities AISLE is a name you’ve seen popping up recently. They have a vulnerability scanner th...
001
Andrew Nesbitt @andrewnez.bsky.social · 05/09/2026
This Week in Package Management: 5 September 2026 nesbitt.io/2026/09/05/t...
nesbitt.io
This Week in Package Management: 5 September 2026
Releases, advisories, and articles from across the package management world
020
Andrew Nesbitt @andrewnez.bsky.social · 04/09/2026
How much should you trust your OSS data? nesbitt.io/2026/09/04/h...
nesbitt.io
How much should you trust your OSS data?
Every second, open source shapes our software, yet our view of this ecosystem is surprisingly opaque. How much can you really trust OSS data?
010
Reposted by Andrew Nesbitt
Nathan Hruby @nathanhruby.bsky.social · 04/09/2026
Tired: compromise a package Wired: compromise a registry Inspired: goat farming
001
Andrew Nesbitt @andrewnez.bsky.social · 03/09/2026
Oh look, I'm on the google open source blog: opensource.googleblog.com/2026/09/how-...
opensource.googleblog.com
How much should you trust your OSS data?
Every second, open source shapes our software, yet our view of this ecosystem is surprisingly opaque. How much can you really trust OSS data?
050
Reposted by Andrew Nesbitt
Anil Madhavapeddy @anil.recoil.org · 23/08/2026
I've had to respond to multiple OSS security issues recently and the wild thing is that agents can now generate exploits just on the *rumour* of a bug. This throws security embargoes out the window, as the fix is less important than the knowledge of its existence anil.recoil.org/notes/rumour...
anil.recoil.org
Just a rumour of a bug is enough to find a security exploit these days
Thinking through how the conventional OSS security embargoes no longer buy us time, and what open source maintainers might do instead to respond
57222
Andrew Nesbitt @andrewnez.bsky.social · 01/09/2026
Git Submodules as a Package Manager nesbitt.io/2026/09/01/g...
nesbitt.io
Git Submodules as a Package Manager
.gitmodules is a manifest and the gitlink is a lockfile entry.
150
Reposted by Andrew Nesbitt
Josh Bressers @josh.bressers.name · 31/08/2026
I had a chat with Erik Möller from @sovereign.tech about what they're doing in the universe of funding open source Eric breaks down what they're doing, how it works, and how you can apply for funding. We even learn about some similar projects happening in the EU
opensourcesecurity.io
Sovereign Tech Agency with Erik Möller
Episode Links Erik’s LinkedIn Sovereign Tech Agency Meet the First Sovereign Tech Standards Cohort Incident Report: unsanctioned agent behaviour during cyber testing STA on Mastodon This episode is al...
022
Andrew Nesbitt @andrewnez.bsky.social · 29/08/2026
This Week in Package Management: 29 August 2026 nesbitt.io/2026/08/29/t...
nesbitt.io
This Week in Package Management: 29 August 2026
Releases, advisories, and articles from across the package management world
030
Reposted by Andrew Nesbitt
Andrew Nesbitt @andrewnez.bsky.social · 28/08/2026
Now Hiring: Senior Open Source Maintainer nesbitt.io/2026/08/28/n...
nesbitt.io
Now Hiring: Senior Open Source Maintainer
A rare opportunity to make a real impact in a fast-paced, high-visibility role.
78817
Reposted by Andrew Nesbitt
Packagist @packagist.com · 28/08/2026
New in Private Packagist, August '26 update: Organization-wide supply chain security controls, MFA enforcement for CLI access, GitLab subgroup sync, artifact packages for suborgs via API, and more complete audit logging. blog.packagist.com/whats-new-i... #php #phpc #composerphp
045
Andrew Nesbitt @andrewnez.bsky.social · 28/08/2026
Now Hiring: Senior Open Source Maintainer nesbitt.io/2026/08/28/n...
nesbitt.io
Now Hiring: Senior Open Source Maintainer
A rare opportunity to make a real impact in a fast-paced, high-visibility role.
78817
Andrew Nesbitt @andrewnez.bsky.social · 27/08/2026
Bazel Module Versions Aren't SemVer nesbitt.io/2026/08/27/b...
nesbitt.io
Bazel Module Versions Aren’t SemVer
According to strict SemVer, protobuf’s latest Bazel release is from 2022.
010
Reposted by Andrew Nesbitt
thattommyhall @thattommyhall.com · 27/08/2026
Multi Page Webapps were actually ok
183
Andrew Nesbitt @andrewnez.bsky.social · 25/08/2026
Hardening the Override Flag nesbitt.io/2026/08/25/h...
nesbitt.io
Hardening the Override Flag
export PIP_BREAK_SYSTEM_PACKAGES=1
020
Reposted by Andrew Nesbitt
Dr. Dawn Foster @geekygirldawn.bsky.social · 25/08/2026
Improving open source project security and increasing diverse leadership can help a project become more sustainable over time, but when a project has reached the end, it can be responsibly sunsetted, instead abandoned. Here's part 2 of my Practitioner Guide series: fastwonderblog.com/2026/08/25/p...
fastwonderblog.com
Part 2: Additional Sustainability Topics From the CHAOSS Practitioner Guides | Fast Wonder
033
Andrew Nesbitt @andrewnez.bsky.social · 22/08/2026
This Week in Package Management: 22 August 2026 nesbitt.io/2026/08/22/t...
nesbitt.io
This Week in Package Management: 22 August 2026
Releases, advisories, and articles from across the package management world
040
Andrew Nesbitt @andrewnez.bsky.social · 21/08/2026
Two-Factor Authentication Across Package Registries nesbitt.io/2026/08/18/t...
nesbitt.io
Two-Factor Authentication Across Package Registries
Something you have, something you know, and someone else's OAuth.
130
Reposted by Andrew Nesbitt
Rust Language @rust-lang.org · 20/08/2026
⚠️ A few hours ago, a malicious crate was discovered on crates.​io which spread as a dependency of `arrayref` and some other crates, likely due to compromised credentials. The affected versions have been deleted. For details and how to see if you are impacted, see: blog.rust-lang.org/2026/08/20/s...
blog.rust-lang.org
Supply chain attack on arrayref | Rust Blog
Empowering everyone to build reliable and efficient software.
119481
Andrew Nesbitt @andrewnez.bsky.social · 20/08/2026
Issues in the Repo - refs/bugs, refs/notes, refs/heads/ticgit, or a directory full of YAML. nesbitt.io/2026/08/20/i...
nesbitt.io
Issues in the Repo
refs/bugs, refs/notes, refs/heads/ticgit, or a directory full of YAML.
131
Reposted by Andrew Nesbitt
Seth Larson @sethmlarson.dev · 18/08/2026
A neat security vulnerability in Python caused by str.lower(). Also includes lots of RFCs so I’m having a good time :) sethmlarson.dev/when-str-low... #security #python #idna
sethmlarson.dev
When str.lower() is a security vulnerability in Python
Some internet standards only support ASCII characters, but the world uses much more than the Latin alphabet. Thus, a mapping from Unicode to ASCII for use in domain names is required. NamePrep was...
0208
Reposted by Andrew Nesbitt
Josh Bressers @josh.bressers.name · 17/08/2026
I had a chat with Erin Schnabel and Rob Nalen about a sustainability project between @commonhaus.org and HeroDevs The idea is to bring together the EOL business model from HeroDevs and use that to help further some of the Commonhaus software catalog
opensourcesecurity.io
Maintaining EOL Open Source with Commonhaus and HeroDevs
Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the Open Source Sustainability Initiative is a clever...
032
Reposted by Andrew Nesbitt
James @43081j.com · 17/08/2026
i've written up some thoughts about AI in the open source world, and more importantly, why humanity is important. its a bit wordy and doomy but this is an important topic right now. there is still a lot of good in the OSS world at least ❤️
43081j.com
Humanity in Open Source
Thoughts on how the open source world is changing in the AI era, not always for the better.
109535
Andrew Nesbitt @andrewnez.bsky.social · 15/08/2026
This Week in Package Management: 15 August 2026 nesbitt.io/2026/08/15/t...
nesbitt.io
This Week in Package Management: 15 August 2026
Releases, advisories, and articles from across the package management world
051