Sign in

Thomas Sandmann

@thomas-sandmann.genomic.social.ap.brid.gy
51 followers 8 following 37 posts

Computational biologist, biotech, neurodegeneration, genomics, learning, R, python [bridged from genomic.social/@thomas_sandmann on the fediverse by fed.brid.gy ]

PostsRepliesMedia
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 01/10/2026
Oh, no! My R package {safespace} is in a broken state - won't someone (new to PRs) help me fix it??? I'm renewing my offer to guide newbies through the R package building / fixing / reviewing process during Hacktoberfest - see this post […]
fosstodon.org
Original post on fosstodon.org
059
Reposted by Thomas Sandmann
Julia Evans @b0rk.social.jvns.ca.ap.brid.gy · 21/09/2026
Are you interested in learning how to use Git for the first time? (or almost the first time) we're looking for Git beginners to give us feedback on a Git tutorial! The tutorial will be open source when it's released, so you'll be helping many future beginners! Sign up here […]
social.jvns.ca
Original post on social.jvns.ca
6673
Reposted by Thomas Sandmann
Christian Meesters @rupdecat.fediscience.org.ap.brid.gy · 13/09/2026
Dear Bubble, the far right is on the rise - not just in Germany. But that a Nazi party won an election in a German country state, 80 years after WWII, made the headline in many papers. And it concerns many of you. I have many friends and acquaintances […] [Original post on fediscience.org]
Protest sign, quoting an AfD member who wants to found a new SA to "clean up" society.
102
Reposted by Thomas Sandmann
Pottery by Osa @potterybyosa.mastodon.social.ap.brid.gy · 08/09/2026
Last night, my husband took me to see "A Life Illuminated" about Dr. Edith Widder, the first marine biologist to document deep ocean #bioluminescence. To me, the #film served as a reminder to leave room in our minds for the beautiful, magical things that exist in this life that we don't often […]
mastodon.social
Original post on mastodon.social
032
Reposted by Thomas Sandmann
vincentholst.bsky.social @vincentholst.bsky.social · 13/08/2026
In 2023, @nature.com published 'Papers and patents are becoming less disruptive over time', receiving world-wide media attention. Our Matters Arising, published after a 32 month delay (more on that soon), shows that the reported decline can largely be attributed to dataset artefacts. 🧵
The average CD_5 index per year for Web of Science. The original Park et al. decline (top curve) becomes essentially flat (bottom curve) when removing papers with CD_5=1. Those papers largely correspond to dataset artefacts.
9352173
Reposted by Thomas Sandmann
Niki @nikitonsky.mastodon.online.ap.brid.gy · 20/07/2026
I am looking for work! Clojure, or, maybe, something native, closer to the metal. RT for reach please 🙏 tonsky.me/blog/work-2026
tonsky.me
Looking for work
Hey, Niki here. This is a bit unusual. My sabbatical is coming to an end, and I am looking for a new opportunity. Full-time or contract, startup or research, remote or Berlin, individual contributor, ideally—tight team, ambitious product. I am a software engineer first and foremost with 20+ years of experience. I work on technically challenging products, foundational technology, dev tools. I’ve been doing Clojure and web recently, but I'm also very excited to explore closer-to-the-metal programming. I have an eye for design, user interfaces, UX, DX. I would love to work with a team that takes interface quality seriously. Or to work with graphics! I am pretty sure I am good at explaining stuff, including what we are building, why, why this way, why is it important, etc. For example. The overarching theme is to understand computers deeply, and then use that to make better and simpler software. If you care about that too, we might be a great match! # Recent work Instant DB is a US startup building a modern Firebase. I worked on the sync algorithm, performance, DX. A summary of my commit log. Roam Research is an OG personal knowledge manager. I worked on database optimization and a plugin system. At JetBrains, I developed a new Skia renderer for Fleet and Jetpack Compose Desktop. I’ve built many open-source libraries, including a database, a GUI toolkit, a Clojure dev environment, a React wrapper, a well-known font... More recently, Clojure+ gives you a taste of my approach to DX, and Fast EDN—to performance. I maintain several active projects — AlleKinos.de, Grumpy Website, this site. If you want to dive deeper, here’s the usual stuff: Projects / Talks / LinkedIn / GitHub # Why this post? It’s an attempt to reach beyond my immediate network. I’ve been doing Clojure for a long time, and now want to explore. If you are working on a compiler, a database, an IDE, a programming language or another technically ambitious product, touching graphics, typography, algorithms, low-level programming, and you think my experience can help, let’s talk: niki@tonsky.me.
21437
Reposted by Thomas Sandmann
Stephen Turner @stephenturner.us · 15/07/2026
Ten quick tips to SNIFF out sustainable and secure scientific software journals.plos.org/ploscompbiol... 🧬💻🧪
journals.plos.org
Ten quick tips to SNIFF out sustainable and secure scientific software
Modern computational biology depends heavily on open-source software tools, analysis pipelines, and containerized workflows developed and shared by the research community. While there is extensive gui...
22317
Reposted by Thomas Sandmann
Preston Maness ☭ @aspensmonster.tenforward.social.ap.brid.gy · 11/07/2026
And this bit in particular reminded me of Carl Sagan when he spoke about books in Cosmos: >Continuity is how a society talks to itself across time. It is how we remain connected to what we have done and what has been done for us. I can practically hear Sagan's voice: >What an astonishing […]
tenforward.social
Original post on tenforward.social
004
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 07/07/2026
A long shot, but the local opportunities seem a bit thin at the moment. I'm available for hire if you're looking for #rstats package development, maintenance, translation, etc... Need some help implementing a solution? Want to productionise a script into a robust package? Wish a third-party […]
fosstodon.org
Original post on fosstodon.org
049
Reposted by Thomas Sandmann
Grant McDermott @gmcd.bsky.social · 03/07/2026
𝐭𝐢𝐧𝐲𝐩𝐥𝐨𝐭 v0.7.0 now available on CRAN 🎉 This is big release, with loads of new features. Same tiny footprint, though ;-) Short highlight thread below, borrowing examples from our gallery: grantmcdermott.com/tinyplot/vig...
https://github.com/grantmcdermott/tinyplot/blob/main/vignettes/gallery_figs/bubble-quakes.Rhttps://github.com/grantmcdermott/tinyplot/blob/main/vignettes/gallery_figs/simpsons-paradox.Rhttps://github.com/grantmcdermott/tinyplot/blob/main/vignettes/gallery_figs/barplot-meat.Rhttps://github.com/grantmcdermott/tinyplot/blob/main/vignettes/gallery_figs/spineplot-titanic.R
48726
Reposted by Thomas Sandmann
D. Griffin Jones @dgriffinjones.tech.lgbt.ap.brid.gy · 30/06/2026
Welp… it’s my turn to #getfedihired: • Experienced writer, primarily in technology news/reviews/how-tos • Professional audio and video editing for podcasts, YouTube, shorts • 20+ years in graphic design • 8 years as a marketing director • Computer Science degree • Based in Ohio, prefer remote […]
tech.lgbt
Original post on tech.lgbt
1332
Reposted by Thomas Sandmann
Simon Willison @simon.fedi.simonwillison.net.ap.brid.gy · 22/06/2026
I just released the first release candidate for sqlite-utils v4, adding a migrations system (previously released independently as sqlite-migrate) and support for nested transactions: simonwillison.net/2026/Jun/21/sqlit…
simonwillison.net
sqlite-utils 4.0rc1 adds migrations and nested transactions
sqlite-utils is my combined Python library and CLI tool for working with SQLite databases. It provides an extensive set of higher-level operations on top of Python’s default sqlite3 package, including …
001
Reposted by Thomas Sandmann
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 19/06/2026
Drop #780 (2026-06-19): SSHHHH 🤫📝 Today's Drop discusses various useful SSH features and tips to improve automation and efficiency when using SSH. Key highlights include using BatchMode to avoid hanging connections, running local shell functions on remote hosts, maintaining sessions with […]
mastodon.social
Original post on mastodon.social
002
Reposted by Thomas Sandmann
Tom Stafford @tomstafford.mastodon.online.ap.brid.gy · 15/06/2026
TODAY: Listening to Richard McElreath "A Guerrilla Approach to Scientific Workflow" peercommunityin.org/pci-webinar-ser… Here's a dispiriting chart he shared from Serra-Garcia & Gneezy 2021 doi.org/10.1126/sciadv.abd1705 "Nonreplicable […] [Original post on mastodon.online]
Fig. 3 Yearly citation count by replicability.
The average yearly citation count per year for studies that were not replicated (according to P value of the replication) in each replication study [(A) for Nature/Science, (B) for Economics, and (C) for Psychology papers in replication markets] and for those that were replicated. The light gray area shows the year(s) in which the original studies were published, and the dark line shows the year in which the replication study was published.

Non-replicated papers increasingly cited above replicated
1208
Reposted by Thomas Sandmann
Stephen Turner @stephenturner.us · 11/06/2026
Ten simple rules for teaching data science: journals.plos.org/ploscompbiol... 🧪 With a checklist in the SI
0115
Reposted by Thomas Sandmann
hrbrmstr 🇺🇦 🇬🇱 🇨🇦🇧🇪 @hrbrmstr.mastodon.social.ap.brid.gy · 10/06/2026
With macOS 27 Apple also updated their `container` utility with a new `machine` command (that works on macOS 26 as well). It creates and manages lightweight Linux VMs (alpine/ubuntu/debian/perhaps more). I fired off a new blog post explaining it a bit, noting some "gotchas", and showcasing two […]
mastodon.social
Original post on mastodon.social
012
Reposted by Thomas Sandmann
@RonSupportsYou @ronsupportsyou.mastodon.social.ap.brid.gy · 06/06/2026
Sen. Raphael Warnock: "We’ve only been a democracy in a real sense since 1965. What we are witnessing in real time is an assault on those basic voting rights. I think that the Supreme Court has committed violence against the ways in which ordinary people can have a voice in our system" […]
mastodon.social
Original post on mastodon.social
0117
Reposted by Thomas Sandmann
Lisa Melton @lisamelton.mastodon.social.ap.brid.gy · 06/06/2026
Would you like to play a demo of my new game? Sure you would! store.steampowered.com/app/4377480/… It's called "Burn-9," a turn-based tactical visual novel. You're the operator directing a super soldier fighting for her life in a secret Antarctic military base. The demo is short […]
mastodon.social
Original post on mastodon.social
2636
Reposted by Thomas Sandmann
Dr. Doro (she/her) @ditsch42.troet.cafe.ap.brid.gy · 06/06/2026
I'm looking for a new job starting in October! I'm a physicist by training, did a PhD and postdoc in experimental quantum physics. My experience ranges over laser and vacuum technology, physics simulations, data analysis, environmental monitoring services, publication writing and much more. If […]
troet.cafe
Original post on troet.cafe
3351
Reposted by Thomas Sandmann
David Penfold :verified: @davep.infosec.exchange.ap.brid.gy · 06/06/2026
John Finnemore on the French horn/cor anglais: "I was idly wondering why the cor anglais has a French name meaning ‘English horn’, and the French horn has an English name meaning… well, ‘French horn’. I looked it up, even though I knew there would just be some reasonable but rather dull […]
infosec.exchange
Original post on infosec.exchange
1327228
Reposted by Thomas Sandmann
Tim Bray 🇨🇦 @timbray.cosocial.ca.ap.brid.gy · 05/06/2026
RE: mastodon.social/@gvwilson/116698825… The slides are excellent, I recommend reading them.
mastodon.social
004
Reposted by Thomas Sandmann
rOpenSci @handle.invalid · 29/05/2026
Meet Ezekiel Adebayo Ogundepo 🇳🇬 #MaintainerMonth Ezekiel is a data scientist with 10+ years of experience in interpreting and analyzing data in a fast-paced environment. As a rOpenSci Champion, Ezekiel worked on bulkreadr, an #RStats package to simplify and […] [Original post on hachyderm.io]
Ezekiel picture, Nigeria flag, social media accounts and personal website.
022
Reposted by Thomas Sandmann
rOpenSci @handle.invalid · 25/05/2026
👋 Meet Will Landau! 🇺🇸 Statistician and software developer. He maintains {targets} and several related packages to the targets ecosystem. Target is a pipeline toolkit that makes data analysis in R faster and fully reproducible by tracking dependencies and […] [Original post on hachyderm.io]
Will profile picture, github user and social media links
072
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 22/05/2026
I keep trying to use #rstats functions like table() and which() when I'm writing #python but those don't exist... until now jcarroll.com.au/2026/05/22/function… The rfuns package is live on pypi (my very first python package) and includes python-native functions with […]
fosstodon.org
Original post on fosstodon.org
083
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 21/05/2026
Linting prose around code with vale: jcarroll.xyz/2026/05/21/linting-pro…
jcarroll.xyz
Linting prose around code with vale
You may be familiar with the idea of linting for code, e.g. via {lintr} in R which “checks for adherence to a given style, identifying syntax errors and possible semantic issues.” It’s super helpful both for ensuring that your code meets your standards, but also when working in a team; no more arguing over nits in PRs about code style — it can be checked against your style guide rules automatically and enforced with tools like {styler}.
122
Reposted by Thomas Sandmann
rOpenSci @handle.invalid · 21/05/2026
👋 Today's highlight is Jeroen Ooms! 🇳🇱 Staff Research Engineer at rOpenSci, tidyverse team member, and project lead for R-universe. He also maintains {magick}, {pdftools}, and {gert} for rOpenSci. Find Jeroen at: 🐘 @jeroenooms 💻 github.com/jeroen 🌐 […] [Original post on hachyderm.io]
Jeroen picture, package list, personal website, GitHub user and mastodon account
051
Reposted by Thomas Sandmann
Clemens Schmid @clemensschmid.archaeo.social.ap.brid.gy · 19/05/2026
Positioning text labels in scatter plots is not always easy with #ggplot2, even with clever extensions like ggrepel. A new release of my #rstats package ggpointgrid aims to add another string to our bow here. To show what I mean I wrote a little blog post with […] [Original post on archaeo.social]
Example plot 2: Labels around a polygonExample plot 1: Labels on a lineExample plot 3: Labels on a grid around a point cloud
13610
Reposted by Thomas Sandmann
rOpenSci @handle.invalid · 19/05/2026
👋 Meet Jonathan Keane! Engineer at Posit, formerly at Ursa Computing, Voltron Data, and Socure. Jon maintains {dittodb} for rOpenSci: a package that makes testing database code easy by recording and replaying real database interactions, so tests run without […] [Original post on hachyderm.io]
Jon picture, bio, social media handles, Github user and package name.
063
Reposted by Thomas Sandmann
rOpenSci @handle.invalid · 18/05/2026
👋 Meet Mark Padgham! 🇩🇪 rOpenSci Software Review Lead and maintainer of {pkgcheck}. This package checks whether a package is ready for submission to our software peer review and is very useful for R package developers to check their own packages against our […] [Original post on hachyderm.io]
Mark headshot, German flag, personal website, github user and social media handle.
061
Reposted by Thomas Sandmann
rOpenSci @handle.invalid · 15/05/2026
👋 Meet Karl Broman! 🇺🇸 Professor of Biostatistics & Medical Informatics at UW–Madison and applied statistician working on statistical genomics. He maintains {chromer} and {aRxiv}. Both packages provide programmatic access to APIs: Chromosome Counts Database and […] [Original post on hachyderm.io]
Karl headshot, package list, pesonal website, github user and social media.
072
Reposted by Thomas Sandmann
Stephen Turner @stephenturner.us · 15/05/2026
anndataR improves interoperability between #Rstats and Python in single-cell transcriptomics academic.oup.com/bioinformati...
0103
Reposted by Thomas Sandmann
Diomidis Spinellis @coolsweng.mastodon.acm.org.ap.brid.gy · 07/05/2026
Today we launch a new run of the popular and award-winning free massive online course (MOOC) on the use of Unix Tools for data, software and production engineering. More than 7,500 learners enrolled on edX. Now, a further reason to follow the course is to […] [Original post on mastodon.acm.org]
002
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 04/05/2026
I've been looking into dbt for data engineering and wanted to flesh out what the similarities and differences were to just using {targets} - I learned lots about both of them! I wrote up my findings in this post […]
fosstodon.org
Original post on fosstodon.org
263
Reposted by Thomas Sandmann
Stephen Turner @stephenturner.us · 03/05/2026
Free and open-source images, icons, and tools for creating scientific illustrations doi.org/10.59350/5zt... 🧪
doi.org
Free and open-source images, icons, and tools for creating scientific illustrations
Phylopic, NIH Bioart, Bioicons, Scidraw, Open Science Art, Health Icons, Servier Medical Art, Biodiversity Heritage Library, the Noun Project, Segment Anything, Excalidraw, draw.io, Biographics
6406227
Reposted by Thomas Sandmann
Christopher Neugebauer @fedi.chrisjrn.fyi · 01/05/2026
This blog post from @pythonbynight captures so much of what we try to do at #NBPy: a tech conference about people, a schedule that gives presenters the time they need to tell their story, speakers who are just another part of the audience. I love that what we're trying to do shines through with […]
social.coop
Original post on social.coop
013
Reposted by Thomas Sandmann
Steve Bellovin @stevebellovin.infosec.exchange.ap.brid.gy · 30/04/2026
New book, released under a Creative Commons BY-NC-ND license: "Don't Get Hacked! Protecting Yourself at Home": www.cs.columbia.edu/~smb/homesec/in… Retoot for reach!
cs.columbia.edu
Don't Get Hacked!
339
Reposted by Thomas Sandmann
Paco Hope @paco.infosec.exchange.ap.brid.gy · 24/04/2026
"It's called _vibe plumbing_. I'm not even a plumber. Soon, all swimming pools will be done this way! Get onboard or get left behind." (a real life version of the 'vibe construction' comic from mandatoryrollercoaster.com). Photo taken from plumbers fails)
Photo of a very complicated swimming pool set up. It has multiple pumps and multiple filters and a rats nest of PVC tubing going all kinds of wacky different directions. Unlike my caption, which mocks AI, the photo appears to be dated 2017, so it seems like it might be real.
6472
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 24/04/2026
I've been keeping an eye on this since I first heard about it, and it looks like it now works! duckdb has a dplyr extension which can be installed - use dplyr code to slice and dice data within a duckdb session […] [Original post on fosstodon.org]
dplyr code running within a duckdb session
122
Reposted by Thomas Sandmann
Mark Ziemann 🇺🇦🌻🦩 @mdziemann.genomic.social.ap.brid.gy · 23/04/2026
Pleased to share with you our latest article "Ten common mistakes that could ruin your enrichment analysis", featuring Anusuiya Bora, Matthew McKenzie. This article condenses what we've learned about best practices in pathway enrichment analysis over the past 15 years. We hope you find it […]
genomic.social
Original post on genomic.social
003
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 18/04/2026
A bit of a long shot, but in the spirit of #fedihire I'm on the lookout for opportunities to contribute to R tooling. If your org could use some help developing or productionising an R package or some prototype R code, managing data access via databases or APIs, or translating between languages […]
fosstodon.org
Original post on fosstodon.org
020
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 14/04/2026
R/Pharma 2026 call for speakers is open until (approx) 02 May and we're once again running an APAC track for those not in North America/Europe timezones. Some of last year's sessions are available on YouTube www.youtube.com/rinpharma We're interested […] [Original post on fosstodon.org]
R/Pharma logo image
000
Reposted by Thomas Sandmann
Miguel de Icaza ᯅ🍉 @migueldeicaza.mastodon.social.ap.brid.gy · 06/04/2026
This is an amazing thread, holy shit.
2010
Reposted by Thomas Sandmann
Bastian Greshake Tzovaras @gedankenstuecke.scholar.social.ap.brid.gy · 04/04/2026
«Every hour you spend confused is an hour you spend building the infrastructure inside your own head that will eventually let you do original work. There is no shortcut through that process that doesn't leave you diminished on the other side.» The machines are fine. I'm worried about us […]
scholar.social
Original post on scholar.social
119
Reposted by Thomas Sandmann
Grant McDermott @gmcd.bsky.social · 01/04/2026
1. `tinyplot` v0.6.1 is out on CRAN. This release contains mostly bug fixes and internal optimizations. grantmcdermott.com/tinyplot/NEW... Who knew that base #rstats plotting could be this easy and feature-rich? P.S. Check out @zeileis.org's nice slides here: www.zeileis.org/papers/Psych...
tinyplot boxplot with jittered points
1195
Reposted by Thomas Sandmann
Jonathan Carroll @jonocarroll.fosstodon.org.ap.brid.gy · 31/03/2026
The latest issue of @rweekly is now live! rweekly.org/2026-W14.html Highlights: - 📊 Introducing ggauto: automating better charts by @nrennie - 🤖 Adding Alt Text in Quarto with Claude Code by @stephenturner.us - ☕ Using science to find the best decaf by @gdeejay.bsky.social As always […]
fosstodon.org
Original post on fosstodon.org
075
Reposted by Thomas Sandmann
Andrew Nesbitt @andrewnez.mastodon.social.ap.brid.gy · 29/03/2026
The Roles of Packages: nesbitt.io/2026/03/29/the-roles-of-…
nesbitt.io
The Roles of Packages
Greg Wilson’s recent post An E-Bike for the Mind reminded me of Jorma Sajaniemi’s work on the roles of variables. Sajaniemi found that just eleven roles cover nearly all variables in novice programs: stepper, most-wanted holder, gatherer, one-way flag, and so on. As Wilson puts it, types tell you about a variable’s state at rest while roles tell you about its state in motion. Once you learn the roles, you can look at unfamiliar code and immediately recognize the shape of the algorithm from how data flows through it. Every package in a registry plays a particular role, whether it’s a library your application calls, a tool your build pipeline runs, a daemon your infrastructure depends on, or a firmware blob that makes your hardware work. This holds across all kinds of package managers, from npm and RubyGems to Homebrew, apt, Helm, Terraform Registry, and OpenVSX, and the role tells you more about how a package fits into a system than the name or the README. Two packages in completely different domains, managed by completely different tools, can behave identically because they play the same role. ### Code execution **Application.** `neovim` and `ffmpeg` via Homebrew, `httpie` via pip, VS Code extensions via OpenVSX, desktop apps via Flatpak or Snap. Standalone programs distributed through a package manager, meant to be run directly rather than imported into other code. The package manager is acting as a software distribution channel rather than a dependency manager. System package managers like apt and Homebrew have always handled this role naturally, while language package managers treat it as an afterthought. Dev tooling like `eslint`, `prettier`, `rubocop`, and `cargo-edit` are applications too, but they live in a project’s manifest as dev dependencies rather than being installed globally, and no line of application code ever imports them. Some registries distinguish between library and binary packages, though most treat them identically. **Library.** The most common role by far: exports functions, classes, or modules that your code calls directly. Rails’ `ActiveSupport`, Python’s `requests`, Rust’s `serde`, Lodash, Guava. Your code depends on the library’s interface, you control when and how to invoke it, and the library knows nothing about your code. Some libraries bundle a broad surface area under one namespace (Lodash, Apache Commons, Boost), but that’s a property of the library rather than a different role. **Framework.** Inverts the library relationship: you write code that the framework calls. Rails, Django, Next.js, Spring Boot. The framework owns the execution lifecycle and your code fills in the blanks. Frameworks tend to be deep dependencies that are expensive to replace, because your code is shaped around their conventions rather than the other way around. **Plugin.** Extends another package and can’t function on its own, because it conforms to a host’s extension API. Babel plugins, ESLint rules, Jekyll plugins, Terraform providers, Rack middleware, webpack loaders, ActiveRecord database adapters. Some compose in a pipeline (Rack middleware), some transform files during a build (webpack loaders, Babel presets), and some implement a swappable backend interface (Faraday HTTP adapters, Rails cache backends), but in every case the relationship is the same: extending a host through a contract the host defines. A framework with a rich plugin ecosystem has a moat that a technically superior replacement can’t easily cross. **Wrapper.** An idiomatic interface to something written in a different language or running as an external service. `nokogiri` wraps libxml2, `pg` wraps libpq, and the AWS, Stripe, and Twilio SDKs wrap HTTP APIs. Wrappers carry an implicit second dependency on the thing being wrapped, not always declared in the package metadata. Native extension wrappers are the source of most “failed to build gem” errors because the system library might not be installed. **Polyfill.** Backports functionality from a newer version of a language or platform to an older one. `core-js` for JavaScript, `future` for Python 2/3 compatibility, `activesupport` core extensions for Ruby. Polyfills are supposed to disappear once you drop support for the older runtime, but in practice they linger for years because nobody audits minimum version requirements. The JavaScript ecosystem still carries enormous dependency trees from the ES5-to-ES6 transition, installed in projects targeting only modern browsers. ### Build and development **Compiler.** Transforms source code from one language or version to another. Babel, TypeScript (`tsc`), CoffeeScript, Sass, PostCSS. Dev dependencies that run at build time and produce output that replaces the input. The source code you write depends on the compiler, but the code your users run doesn’t. Similar to CLI tools in their dependency role, but they shape your source code more deeply because you write in the compiler’s input language.1 **Types.** Only type definitions, no runtime code. The `@types` scope on npm is the canonical example: `@types/node`, `@types/react`, thousands of others. These exist because TypeScript needs type information for packages written in JavaScript. The entire DefinitelyTyped project is a parallel registry of type-only packages that shadow real packages. Python has a similar pattern with `types-requests`, `types-PyYAML`, and stub packages for `mypy`. They vanish entirely from production builds. **Generator.** Scaffolds new projects or components, typically run once and never imported again. `create-react-app`, `yeoman` generators, `rails new`, `cargo-generate`. The generated output is the thing you maintain, not the generator itself. Some ecosystems install these globally, some use `npx`-style one-shot execution, and some bundle them into the framework CLI. The relationship between a generator and the code it produces is a dependency that no lockfile captures. ### Artefacts **Data.** Ships data rather than code: timezone databases (`tzdata`, `tzinfo-data`), Unicode character tables, country and currency lists, language detection models, word lists. Shared tool configurations (`eslint-config-airbnb`, `@tsconfig/recommended`) are data packages too, turning coding style decisions into installable dependencies with their own update and compatibility concerns. The package manager is being used as a distribution mechanism for datasets that need to be versioned and depended on just like code. Some of these are large enough that registries end up debating size limits. The IANA timezone database gets new releases when countries change their daylight saving rules, and every language ecosystem has its own repackaged copy. **Asset.** Non-code, non-data resources that a system or application needs to function. Fonts (`fonts-liberation`, `ttf-mscorefonts`), icon sets, SSL certificate bundles (`ca-certificates`), sound files, locale definitions. Resources that some other piece of software expects to find on disk, not code you call or structured data you query. System package managers handle these naturally, while language package managers mostly ignore them or push the problem to Docker and system-level provisioning. **Schema.** Defines the shape of data exchanged between systems, distributed as a shared dependency that both sides of a boundary rely on. Protobuf definition packages, OpenAPI specs, JSON Schema packages, GraphQL schema files, Avro schemas, AsyncAPI definitions. Language-agnostic interface definitions that get compiled into types and code for each consumer, distinct from type packages (which are language-specific and exist to satisfy a type checker). Both the producer and consumer of an API or message format depend on the same schema package, turning it into a coordination point where a version bump on one side forces a response on the other. **Meta.** Declares dependencies but contains little or no code of its own, pulling in a curated set of other packages when installed. The `rails` gem depends on `activerecord`, `actionpack`, `activesupport`, and the rest, but the gem itself is mostly a gemspec. Debian and other system package managers use meta-packages extensively for grouping (`build-essential`, `texlive-full`). In npm, packages like `react-scripts` bundle a whole toolchain behind a single dependency. Convenient, but they hide what you actually depend on, and auditing gets harder. ### Environment **Runtime.** The execution environment itself, treated as a versioned package. At the system level: Ruby in `.ruby-version`, Python in `.python-version`, Node.js in `engines`, managed by tools like `rbenv`, `pyenv`, `nvm`, `mise`, and `asdf`. At the package level, Electron embeds a browser runtime and `esbuild` ships platform-specific binaries as npm packages. The package manager or version manager becomes a distribution channel for the thing that runs your code, and a version mismatch here tends to produce errors from a layer that most tooling assumes is fixed. **Service.** Installs and manages a long-running daemon rather than linking code into your application: PostgreSQL, Redis, Nginx, Elasticsearch. In system package managers like apt and yum, installing a service package starts a background process and registers it with an init system. Your application depends on the service being available at runtime, but the relationship is over a network socket or IPC rather than a function call. **Driver.** Enables communication with hardware or provides low-level system capabilities. Firmware packages (`firmware-linux-nonfree`, `linux-firmware`), kernel modules, GPU drivers. Binary blobs or compiled modules that sit between the operating system and physical devices. Language package managers never touch this layer, but system package managers treat drivers as versioned dependencies like anything else, and getting the wrong version can make a machine unbootable. No other role on this list has that risk profile. **Infrastructure.** Declares the desired state of a system or environment rather than code that runs inside an application. Helm charts, Puppet modules, Ansible roles and collections, Chef cookbooks, Terraform modules, Salt formulas, Nix derivations. Distributed through their own registries (Puppet Forge, Ansible Galaxy, Terraform Registry, Artifact Hub), versioned, and depended on, but containing configuration and orchestration logic rather than application code. The relationships between infrastructure packages can be just as deep and tangled as in any language ecosystem, and the consequences of a bad version are often more severe because they affect running infrastructure rather than a build that fails locally. Middleware (Rack, Express, ASGI) is a plugin that composes in a pipeline. Loaders (webpack loaders, Babel presets) are plugins for build tools. Collections (Lodash, Apache Commons) are libraries with a broad API surface. Adapters (ActiveRecord database backends, Faraday HTTP adapters) are plugins that implement a swappable backend interface. Shared tool configuration (`eslint-config-airbnb`, Prettier configs) is data that a dev tool reads. In each case, the relationship to the rest of the system didn’t differ enough from an existing role to justify its own entry. Policy (OPA policies, Gatekeeper constraints, Sigstore bundles) and facade (simplified glue interfaces) were also considered, but policy feels like a specialization of data or infrastructure depending on context, and facade overlaps too much with wrapper. Rails is both a framework and a meta-package. ESLint is an application with a plugin architecture and an ecosystem of shared config data packages. ActiveRecord’s PostgreSQL adapter is both a plugin (it conforms to ActiveRecord’s backend interface) and depends on `pg`, a wrapper (it provides an idiomatic Ruby interface to libpq). The taxonomy gets more useful when you can describe a package as the intersection of two roles rather than forcing it into one, because the combination tells you something neither role says alone. You wouldn’t pin a data package tightly, because it needs to update when the world changes, not when the code changes. Upgrading a framework carries more risk than upgrading a library, because your code is shaped around the framework’s conventions and a breaking change ripples through everything, while a swappable backend plugin is designed so you can replace one implementation without touching the rest of your application. Types, CLI tools, compilers, and generators almost never belong in production dependencies, though they routinely end up there because nobody set the dependency scope correctly. Wrappers with native extensions carry a larger attack surface than pure-code libraries, a distinction that matters more as supply chain security tooling matures and starts treating different kinds of dependencies differently. Experienced developers already make these judgments instinctively. 1. There’s an emerging grey area between compiler and library: packages like `styled-components` and `tRPC` provide a runtime API that gets partially or fully erased at build time by a compiler plugin. They behave as libraries in your source code but as compiler inputs in your build pipeline, straddling two roles at once. ↩
005
Reposted by Thomas Sandmann
Eric Book @erc-bk.fosstodon.org.ap.brid.gy · 20/03/2026
RE: mas.to/@CRANberriesFeed/11625644503… starburst: Seamless AWS Cloud Bursting for Parallel R Workloads A 'future' backend that enables seamless execution of parallel R workloads on AWS, including 'EC2' and 'Fargate'. 'staRburst' handles environment synchronization, data […]
fosstodon.org
Original post on fosstodon.org
001