Sign in

Emma Irwin

@sunnydeveloper.mastodon.social.ap.brid.gy
17 followers 2 following 148 posts

Open Everything, #Canada sunnydeveloper.com #DigitalSovereignty #EthicalOpenAI 🌉 bridged from ⁂ mastodon.social/@sunnydeveloper, follow @ap.brid.gy to interact

PostsRepliesMedia
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 30/09/2026
When I first starting talking about #AI #Alignment in the context of OSS communities - asking "Alignment with WHICH humans?" I was told I didn't really understand the topic area, that alignment with humans is a purely an ML problem for engineers(silly woman). Two years later, many more people […]
mastodon.social
Original post on mastodon.social
112
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 29/09/2026
Disturbing on so many levels - including that the company who built, and profits from this technology, is still allowed to operate AND is solely responsible for fixing the problems they are creating. www.motherjones.com/media/2026/09/c…
motherjones.com
ChatGPT Helped Tumbler Ridge Shooter Focus on Guns, Tactics, and Terror
Editor’s note: This story discusses suicide and extreme violence. Also read part 1, part 2, and part 3 of our investigation into AI chatbots and violence. In June 2025, Jesse Van Rootselaar received an email notification from OpenAI. Van Rootselaar had been using ChatGPT to discuss committing potential acts of violence—including a mass shooting at […]
100
Reposted by Emma Irwin
Laurie Voss @seldo.alpaca.gold.ap.brid.gy · 27/09/2026
Good thing all this unauthorized computer access is somehow not illegal and magically nobody is criminally liable for it or it would be really expensive and professionally damaging! www.axios.com/2026/09/26/openai-ant…
213
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 27/09/2026
A product made by a rich tech company coached a youth to commit mass murder at their school. That company is still operating and - get this, it's on us to create laws making this a crime. And it's on those same rich tech companies to monitor and fix themselves. Absolute insanity […]
mastodon.social
Original post on mastodon.social
010
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 27/09/2026
RE: mastodon.gamedev.place/@jonikorpi/1… Efforts to combat abuse help everyone.
mastodon.gamedev.place
010
Reposted by Emma Irwin
🇨🇦 Dianne S @dfs-comedy.mastodon.social.ap.brid.gy · 26/09/2026
@sunnydeveloper That's a great article! I've written on this topic too. May I link to your article from mine? dianne.skoll.ca/writings/sovereignt…
dianne.skoll.ca
🇨🇦 Dianne Skoll's Web Site - Stuff I've Written - Duke
101
Reposted by Emma Irwin
🇨🇦 Dianne S @dfs-comedy.mastodon.social.ap.brid.gy · 26/09/2026
The Government of Canada needs to get it's ass in gear and be serious about digital sovereignty. The Netherlands is showing the way. dawo.community/en/about-dawo
dawo.community
About DAWO - DAWO.community
What DAWO is, why digital autonomy matters and which goals the community pursues.
102
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 24/09/2026
My trail camera was noticed by our #bear last night. Someone it wasn't harmed! #trailcam #BC
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 19/09/2026
I needed to buy a notebook today. Many I saw - clearly used #AI generated images (kittens, flowers, unicorns etc)... are people buying such products? It had the same feel as a pawn store - like, you're pretty sure something is stolen, but it looks OK.
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 13/09/2026
I've moved Open Source Wishlist (oss-wishlist.com) to a stand alone teaching tool. It uses Ecosyste.ms metadata for critical OSS projects to help identify risk, intervention, and expertise required to mitigate that risk. It lives as evidence that - sustainability is an accountability and funding […]
mastodon.social
Original post on mastodon.social
035
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 10/09/2026
"Saddle Lake Cree Nation is asserting its Treaty rights and jurisdiction to provide safe refuge for those seeking and providing gender-affirming care." bsky.app/profile/thebreakdownab.bsk… #Alberta #Canada #transrightdarehumanrights
011
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 09/09/2026
#Canada can manage a ton of risk associated with dependency on US tech, by investing in #opensource projects and expertise - but right now the scope of strategy is narrow to AI infrastructure and government itself. I submitted recommendations to Canada's pre-budget consultations - and wrote up […]
mastodon.social
Original post on mastodon.social
021
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 05/09/2026
Aside from loving my #Roomba for vacuuming, I also love that I can clean and fix it myself. This one I bought during the pandemic and its still humming - new filter, brush and spinner thingy today. #rightorepair
Bottom view of Rooba, with  clean brush, catch,  and filter
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 04/09/2026
Using (#Canadian) GEM for streaming recently and LOVE Land and Sea gem.cbc.ca/land-and-sea-network
gem.cbc.ca
Land and Sea Network | Shows | CBC Gem
For more than thirty years Land and Sea has brought you stories from people who live off the land and the sea. We cover issues that affect people in rural communities which ultimately affect those in cities as well. We bring you stories from those who celebrate life living close to nature, who promote and protect their culture and traditional ways of doing things. There are stories of success and sometime failures that portray the unique way Atlantic Canadians deal with the challenges and pleasures of living on the east coast.
000
Reposted by Emma Irwin
Kumar McMillan @kumarvibe.mastodon.social.ap.brid.gy · 30/08/2026
View from the descent of #BeinnAchaladair ⛰️ #Scotland ☀️ #SilentSunday
View towards Achaladair Farm, hills lit up by dramatic evening sun, tall mountains in the background. It’s a 5x zoom on iPhone which is why it looks a little glitchy.
136
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 02/09/2026
Why do people expect me to have voicemail? Like, SMS, email isn't enough? I refuse.
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 02/09/2026
#Schnauzers cuddling #cute #dogsofmastodon
2 Schnauzers , both brown, one smaller fan the other  - cuddling
1102
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 31/08/2026
Policy is one engine through which OSS communities can influence model builders and the AI economy. Collectively stating and enforcing values has huge potential to shift the power balance. CHAOSS AI Alignment Working Group has an early set of metrics for Open Source Communities. I decided to […]
mastodon.social
Original post on mastodon.social
051
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 29/08/2026
'Responsible Use ' for #Debian policy seems to be purely focused on output. "standards of quality, correctness, maintainability, and legal compliance' Sad to see big projects missing the opportunity to influence (and lead) standads of responsibility like openness of model, #environment impact […]
mastodon.social
Original post on mastodon.social
032
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 29/08/2026
Back from some time in nature, wading through things - looks like I'll be presenting ' Power Back to Open Communities ' at a Victoria AI Conference in October, which is cool they're open to my ethical focus.
010
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 27/08/2026
Hike up to the #crash site of 1945 WWII bomber #Tofino #BeautifulBritishColumbia
Side view of crashed 1945 WWII bomber wing  and body  - with heavy damage and lots of grafitttiView from atop WWII crashed bomber, recognizable ad cockpit, smashed, lots of graffiti.
000
Reposted by Emma Irwin
Brandy Zadrozny @brandyzadrozny.bsky.social · 25/08/2026
If Dolly's passing leaves a final lesson for these times, I think it's that you can and should live your life in a way that makes people sad when you leave the world.
10770108
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 25/08/2026
As much as there is a rallying cry for #DigitalSovereignty in #Canada - there are no dollars to fund efficiency and speed. The government, and private industry must invest in the resources and labour required to create the conditions. That means learning from Europe's Sovereign Tech fund and […]
mastodon.social
Original post on mastodon.social
010
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 24/08/2026
RE: mamot.fr/@pluralistic/1171526241041… This is fairly accurate, while #Canada is largely focused on AI sovereignty, the foundational technology of universities, businesses and non profits depend on USA tech. I wrote about how higher can lead and contributed to BC Gov […]
mastodon.social
Original post on mastodon.social
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 20/08/2026
Brandywine Falls - Like something from a dream #waterfall #Canada #BeautifulBritishColumbia
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 18/08/2026
I've worked in #tech forever, but I live in a small town - no uber, no skip the dishes and I have no clue on city norms: are people really just walking around with Meta glasses on?
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 18/08/2026
Made it out to the #Whistler train wreck, which was so worth it (went early to avoid crowds) #beautifulbritishcolumbia […] [Original post on mastodon.social]
Graffitied train car, on a high cliff overlooking a blue river. Brown schnauzer in foreground.Schnauzer overlooking blue, blue river below
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 11/08/2026
The island is absolutely bonkers busy with tourists and those leaving smokey areas. Never seen ferries or traffic like this. #vancouverisland #Climatechange
001
Reposted by Emma Irwin
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 11/08/2026
Something I've been working on recently to improve testing around dependencies: github.com/alpha-omega-security/hyr… Reuses a lot of pieces of git-pkgs and scrutineer
github.com
GitHub - alpha-omega-security/hyrum: Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness.
Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness. - alpha-omega-security/hyrum
011
Reposted by Emma Irwin
Mike Gifford, CPWA @mgifford.mastodon.social.ap.brid.gy · 09/08/2026
At #FOSSY & the AI panel that is happening now. The conversation of unionization came up so thought to mention @beep 's book You Deserve a Tech Union ethanmarcotte.com/books/you-deserve…
ethanmarcotte.com
You Deserve a Tech Union — Ethan Marcotte
Read this page on ethanmarcotte.com
001
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 09/08/2026
Slides from our FOSSY Talk: "AI depends on #OpenSource to function, both as a technical dependency and as a source of data. Model builders who consume the output of our labour MUST also be aligned with the values, norms and governance of those communities. Our hypothesis, being that AI builders […]
mastodon.social
Original post on mastodon.social
020
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 07/08/2026
I love the framing that fixing your own devices is the dopamine hit youth need. #FOSSY2026 #RightToRepair #Canada
000
Reposted by Emma Irwin
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 06/08/2026
A year of AI disclosure in critical packages: nesbitt.io/2026/08/06/a-year-of-ai-…
nesbitt.io
A year of AI disclosure in critical packages
Stephen O’Grady’s RedMonk analysis of who is writing open source code looked at commits to fifteen large projects during the first half of 2026 and counted two forms of declared AI involvement: a known autonomous agent as the commit author, or a known AI identity in a `Co-Authored-By` trailer. The result was under one percent, framed as a floor. I ran a wider version of the same measurement over the packages.ecosyste.ms critical set: 5,682 GitHub repositories behind the most-depended-on packages across sixteen registries, using the CHAOSS disclosure library to detect four kinds of explicit signal instead of two. Over the same six months the rate was 4.13%. Over the year ending 29 July 2026 it was 2.93% (17,279 of 589,798 non-merge commits), rising from 0.48% last August to 5.32% this July. These are counts of commits where someone left an explicit marker in git metadata. Undeclared use is not measured, and a commit is one unit regardless of whether it changed one line or ten thousand. ## Sample selection versus detector choice Running my scanner against RedMonk’s fifteen repositories with only their two signals found 94 matches in 23,346 first-half commits including merges, or 0.40%, against RedMonk’s “~24K commits” and a match count “in the dozens”. Excluding merges leaves 17,323 commits and the same 94 matches, or 0.54%; `espressif/esp-idf` and `openssl/openssl` supply 71 of them, matching RedMonk’s reported 73% concentration in two projects. sample and signals | commits | marked | share ---|---|---|--- RedMonk 15, agent author or known AI co-author | 17,323 | 94 | 0.54% RedMonk 15, all validated disclosure signals | 17,323 | 182 | 1.05% Critical GitHub set, agent author or known AI co-author | 308,354 | 11,002 | 3.57% Critical GitHub set, all validated disclosure signals | 308,354 | 12,720 | 4.13% Adding the two extra signal types moved the rate by about half a percentage point on either sample. Changing the sample moved it by three points. RedMonk’s fifteen were chosen by contributor-base size with, in O’Grady’s words, a deliberate bias towards C; the critical package set is whatever sits at the top of each registry’s dependency graph, which pulls in a lot of smaller, newer, company-run repositories. ## What I counted The critical snapshot contained 8,605 packages, with repository URLs and metadata pulled from the same package cache I built for Weekend at Bernie’s. Merging packages that share a repository, following renames, restricting to GitHub, and dropping malformed URLs left 5,707 candidates. 5,682 cloned successfully; the other 25 were deleted or private. 3,533 had at least one non-merge commit in the year ending 29 July 2026. Each repository was cloned bare with a tree filter and a shallow date boundary, streamed through the disclosure library, and deleted. The full pass transferred about 1 GB and the retained checkpoint is 16 MB of per-repository summaries and matched commit SHAs. Rename following checks GitHub’s stable repository ID as well as the redirect. The npm package `base` still lists `node-base/base` as its repository. GitHub reused the org name, so that path now redirects to the Base blockchain monorepo, which would have contributed 3,135 commits and 273 AI signals to a nine-year-old npm utility. The ID check excluded it. Every non-merge commit was checked for: * a known AI agent as author or committer * a known AI identity in `Co-Authored-By` * an `Assisted-By` trailer naming an AI tool or model * a tool-specific attribution format that disclosure supports Merges are excluded so projects that squash, rebase, or merge count on the same basis. Commits are bucketed by committer time, when the change landed on the current branch. Mentions of tool names in ordinary commit prose are ignored. `Assisted-By` values are validated because the trailer is also used for people: raw matches included `Assisted-By: Daniel Stenberg` and `Assisted-By: Automated Tooling, Human Reviewed.` The clones did not fetch `refs/notes/ai`, so declarations recorded as git notes are absent. ## Over the year The monthly rate passed 3% in February and 5% in March, then held between 4.58% and 5.32% through July. Counting repositories instead of commits, a signal appeared in 41 of the 1,734 repositories with commits in August 2025 (2.4%) and 276 of 1,793 in July 2026 (15.4%). Of the 17,279 findings, 4,625 carry only an autonomous-agent identity, 12,628 carry only a declared-assistance signal, and 26 carry both. Declared assistance went from 0.08% of commits in August to 4.92% in July. Agent authorship started at 0.40% and ended at 0.41%, peaking at 1.33% in between; 4,613 of those commits have GitHub Copilot’s agent as author, 38 have Devin’s, and Claude, Cursor, Codex, and Amazon Q account for 25 between them. Copilot agent commits reached 745 in March across 85 repositories and fell to 208 across 35 in July, with individual projects running the agent in short bursts: `pycqa/isort` had 49 in March and none after, `azure/azure-sdk-for-net` had 275 in February and 28 in March. The February and March step in the total is Claude Code `Co-Authored-By` trailers. Those went from 97 commits in December to 325, 753, and 2,037 over the following three months, and from 39 distinct repositories to 190. Cursor’s co-author trailers rose from 1 to 48 over the same months and Copilot’s from 1 to 2, so the step is specific to one tool rather than a general change in disclosure practice. Anthropic released Claude Opus 4.6 on 5 February and Sonnet 4.6 on 17 February; March is the first full month with both available. The findings carry 231 distinct declared tool strings across 17,392 occurrences. Grouping them by client family, and separately by model or provider where no client is named: declared as | occurrences | share ---|---|--- Claude Code | 9,974 | 57.35% GitHub Copilot | 4,857 | 27.93% Cursor | 773 | 4.44% Codex | 236 | 1.36% OpenCode | 69 | 0.40% Claude or Anthropic (model only) | 1,135 | 6.53% OpenAI or GPT (model only) | 118 | 0.68% Gemini or Google (model only) | 70 | 0.40% The raw declared strings are in the summary JSON; the grouping is mine and a value naming two clients counts in both. At the repository level, 687 of the 3,533 active repositories recorded at least one signal over the year, so the median active repository’s rate is zero. The ten repositories with the most findings account for 40.8% of the total and the top hundred for 84.9%. ## By ecosystem `go-git` shows what the extra detectors add in one repository: 269 of its 731 commits carry a validated signal, 12 of which match RedMonk’s narrow rules. The rest are `Assisted-By` trailers and tool attributions. Nine of the sixteen ecosystems had at least 30,000 commits in the window: package ecosystem | commits | validated share | repositories | with instructions ---|---|---|---|--- NuGet | 41,523 | 6.84% | 74 | 40.54% npm | 87,357 | 3.72% | 1,578 | 3.11% RubyGems | 40,889 | 3.59% | 670 | 6.12% Conda | 144,227 | 3.31% | 264 | 12.12% Go | 34,117 | 3.07% | 545 | 5.87% PyPI | 124,641 | 2.57% | 451 | 12.42% Cargo | 30,620 | 1.96% | 570 | 2.46% Packagist | 37,267 | 1.73% | 547 | 10.24% Maven | 100,539 | 1.60% | 273 | 16.12% The other seven, from CocoaPods at 13,581 commits down to Julia at 682, are in the summary JSON. Julia’s 51 findings in 682 commits give it the highest rate in the set at 7.47%, on the smallest sample. NuGet’s 6.84% is a Microsoft deployment. Repositories under `aspnet`, `azure`, `azuread`, `dotnet`, `microsoft`, and `nuget` supplied 2,716 of the 2,842 NuGet findings (95.6%), and 2,634 of those are autonomous-agent identities. Remove those owners and NuGet falls to 126 findings in 14,283 commits, or 0.88%, below Maven. I have only run that owner exclusion for NuGet; the per-repository CSV has what’s needed to do it for the others. ## Instruction files A separate pass over the same 5,682 default-branch heads checked for committed instructions to coding agents: `AGENTS.md`, `CLAUDE.md`, `GEMINI.md`, and the documented Copilot, Cursor, Cline, Windsurf, and Continue rule paths. 353 repositories (6.21%) have at least one, holding 1,091 files between them. A file’s presence records that someone set up guidance for an agent; it attributes nothing to any commit. instruction type | repositories | share of scanned repositories | files ---|---|---|--- `AGENTS.md` | 240 | 4.22% | 571 `CLAUDE.md` | 204 | 3.59% | 340 GitHub Copilot instructions | 84 | 1.48% | 154 Cursor rules | 11 | 0.19% | 14 `GEMINI.md` | 8 | 0.14% | 8 Cline rules | 1 | 0.02% | 4 Windsurf rules | 0 | 0% | 0 Continue rules | 0 | 0% | 0 Each repository is counted once, in the month its earliest surviving instruction file was added, so Cypress with 118 files counts the same as a project with one. Only files present on current heads are visible, so anything added and later deleted is absent from the timeline. 228 of the 353 repositories also have a disclosed commit in the year. 94 of those added their earliest instruction file before their first disclosed commit, 98 added it after, and 36 on the same day; the median gap is zero. The other 125 have an instruction file and no disclosed commit in the window. ## Data The scanner and report generator are at andrew/critical-ai-scan. The summary JSON has the overall, monthly, ecosystem, signal, tool, and leading-repository counts. The repository CSV has one row per successful scan with the exact default-branch head used, so individual cases can be checked without recloning. The instruction-file report lists every matched path with its category and the commit that added it.
002
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 05/08/2026
It makes me bonkers frustrated to see the same names, over and over declaring the definition of openness in their selected silos- if regular people don't feel empowered, in control and included it's not open. Open is a commodity no - it seems like to advance the democratization of technology in […]
mastodon.social
Original post on mastodon.social
020
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 04/08/2026
#Bunny checking out our #wildlifecamera
010
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 02/08/2026
I #thrifted this today. I have another silver egg cup with a chicken, which means I am, officially, now a #collector of antique #silverware with birds on top.
A tarnished silver platter platter cover, with a seagull on top. Very fancy looking
100
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 02/08/2026
Our #bear came back today! Same guy, we must be neighbors :) #VancouverIsland #wildlifecam
100
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 02/08/2026
Does anyone know the date for #FOSDEM this year. I know it's usually the 1st weekend in February but someome also suggested it could fall on the 31st January weekend. Hard to find info .... #FOSS #opensource
020
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 30/07/2026
My town has talented folks victoriabuzz.com/2026/07/portrait-o…
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 30/07/2026
@avilewis we really need the NDP right now bsky.app/profile/rachelgilmore.bsky… if you could please challenge Carney silence on Alberta stripping Healthcare from trans youth, and altogether looking to privatize Healthcare? Don't be shy to stand up for trans […]
mastodon.social
Original post on mastodon.social
010
Reposted by Emma Irwin
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 28/07/2026
Why npm Dependency Trees Are So Big nesbitt.io/2026/07/28/why-npm-depen…
nesbitt.io
Why npm Dependency Trees Are So Big
Every major release of Rails sets off a wave of releases across the rest of the gem ecosystem. An application that tries to upgrade runs `bundle update rails` and Bundler refuses, because some gem in the tree only allows activesupport up to the previous major. The error names the gem, an issue gets filed on its tracker, and a maintainer who had nothing to do with the Rails release widens a version range and ships. Multiply that across every gem with a Rails constraint and the upgrade arrives as dozens of small releases from maintainers who mostly don’t know each other, each responding to errors their own users are hitting. Bundler refuses because it picks one version of every gem for the entire application. Every constraint in every gem is a claim on that shared choice, and finding a set of versions that satisfies all of them at once is NP-complete in the general case. Sometimes no set exists, and Bundler refuses to install, listing the gems whose constraints collided. That makes every constraint a cost that other people pay: a gem that pins a dependency tightly will block someone’s upgrade and get issues filed about it, so gem authors keep dependency lists short and ranges wide. All of it runs through the conflict error, which names the packages whose constraints disagree, so the problem reaches the maintainers who can fix it. That error has no equivalent in npm, which starts with the runtime. Ruby loads one copy of each gem per process, Python keys imported modules by name, and a JVM classpath resolves each class name once. You can get a second version into any of them if you work at it, but one version per program is the working assumption, so their package managers all resolve each library to a single version, and disagreements have to be settled somewhere. JavaScript module loading keys on file paths, not package names: two copies of the same package in different `node_modules` directories are just two different files, and Node’s module resolution loads whichever copy sits closest to the code requiring it. A resolver on top of that runtime could still pick one shared version per package and error when constraints can’t agree, but when two packages want different versions of a shared dependency, npm gives each its own copy. Ordinary dependency resolution has no conflict error in it at all: whatever constraints the packages in your tree declare, install succeeds. Which means a constraint in npm costs its author nothing: a library can pin an exact version of everything it uses and no downstream install will ever fail because of it. Your choice of range never collides with anyone else’s, so there is no occasion to talk to another maintainer about what you both should support, and no prompt to look at what your tree has accumulated. A dependency on a ten-line package is as free as any other too, which is the condition the micro-package habit needed. The costs show up elsewhere: npm’s dependency network was already the largest and fastest growing of the seven ecosystems Decan, Mens and Grosjean measured in 2017, and installing an average npm package means trusting 79 other packages and 39 maintainers. Every duplicated copy gets installed, bundled, and added to the surface you have to audit, so everyone pays a little of it and nothing like the Rails upgrade wave follows. Two copies of the same package do break things when the package holds module-level state: each copy gets its own singletons, and `instanceof` checks fail when an object from one copy reaches the other. The famous case is React, where two Reacts in one app break hooks, so a component library has to run against the application’s copy. `peerDependencies` exists for that case: a declaration that this package must share one version with the rest of the tree rather than getting its own. For years npm only warned when peer ranges couldn’t agree. When npm 7 started enforcing them, the resulting `ERESOLVE` errors were unpopular enough that npm added `--legacy-peer-deps`, a flag for turning the conflicts back off. Cargo runs both designs at once, and within a semver-compatible range it behaves like Bundler: every crate that depends on `bitflags` 1.x shares a single version. If the requirements can’t unify, say one crate pins `=1.2.3` while another needs a later patch, the resolver backtracks and errors rather than take two copies. Incompatible ranges get the npm treatment: 1.x and 2.x of the same crate coexist in one build with no error. And because a caret requirement on a 0.x crate only spans that minor, every 0.x minor is its own compatibility range, which puts a large share of the crate ecosystem on the npm side of the line. Rust’s coordination culture lives on the strict side, where foundational crates sit on the same major for years because a breaking release would split the single version every dependent has to share. serde has been on 1.x since 2017. When a crate that far down the stack does have to break compatibility, there’s the semver trick, where the outgoing major gets one final release that depends on the new major and re-exports its types, so the resolver treats the two as one while the migration rolls through, a contortion maintainers only accept under real pressure. On the loose side of the line, a demo web service at Tweede golf came to 141 crates, with base64, socket2, syn and time each present in two incompatible major versions, and Armin Ronacher counts a basic Rocket web project at 172 crates. Run `cargo tree --duplicates` in any sizeable project: every incompatible version it lists was resolved the way npm resolves everything. Dependency trees grow to the size their resolver permits: where every package must share one version, constraints put costs on other people, and those costs get maintainers talking to each other. npm settles every disagreement with another copy instead, and each copy makes the tree bigger.
005
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 24/07/2026
This is so well done. What resonated msot for me was "we're losing trust in each other". I would add, and in organizations and companies that continue to ignore that fact. New leaders emerge in the ecosystem... blog.codeberg.org/protecting-our-fl… #foss #opensource
blog.codeberg.org
Protecting our FLOSS commons from LLMs — Codeberg News
.codeberg-design ul { padding-left: revert !important; } In Brief: Two...
020
Reposted by Emma Irwin
David Scott Moyer @farbel.mas.to.ap.brid.gy · 21/07/2026
#transrights #harrypotter
Trans lives matter more than Harry Potter
1113
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 22/07/2026
To be on X is to ignore the harm being actively, boldly and loudly done by its owner. A mission means, taking a stand. No stand, no mission. #FireFox
012
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 19/07/2026
Hockey has a lot to teach soccer about the kindness that is sudden-death overtime.
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 16/07/2026
Well done contrast of the Prime Minister's announcement of his intention to miss Canada's carbon goals ("too expensive") set against the monsterous Ontario fire. #Canada #Climatechange
001
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 15/07/2026
RE: mastodon.social/@sadiedoreen/116920… They were just in Victoria at the Phillips Backyard. I hadnt heard of them before but omg! Now I'm listening.
mastodon.social
000
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 14/07/2026
Many #AI policies now define expected and unacceptable behavior - traditionally the role of a Code of Conduct. I decided to look into how these safe participation policies are evolving (or fragmenting) safety, and whether new AI safety tools and policies meet established ecosystem standards for […]
mastodon.social
Original post on mastodon.social
132
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 13/07/2026
We are a group of experts in #opensource, open education, software ethics, engineering, community building, incident response and more - looking to collaborate with an individual, organization or team ~ building #openmodels/#openweights ~ and interested in creating alignment with the open source […]
mastodon.social
Original post on mastodon.social
022
Emma Irwin @sunnydeveloper.mastodon.social.ap.brid.gy · 04/07/2026
Go 🇨🇦 🍁 Canada!
000