Sign in

Jamie Tanna

@www.jvt.me.web.brid.gy
355 followers 1 following 1.6K posts
PostsRepliesMedia
Jamie Tanna @www.jvt.me.web.brid.gy · 4h
Anyone at #OSSEU know where - ideally near the venue - to get a UK-to-EU travel adapter? I dun goofed and only brought my USB-C adapter and forgot my laptop needs to charge 😅
000
Jamie Tanna @www.jvt.me.web.brid.gy · 6h
Listened to Expend4bles LIVE! w/ Jessica St. Clair Post details > How Did This Get Made? · Episode
000
Jamie Tanna @www.jvt.me.web.brid.gy · 7h
Listened to Double Dragon LIVE! (Classic) Post details > How Did This Get Made? · Episode
000
Jamie Tanna @www.jvt.me.web.brid.gy · 9h
Listened to goodpods.com/podcasts/how-did-this-… .
000
Jamie Tanna @www.jvt.me.web.brid.gy · 10h
Listened to Battlefield Earth w/ Rob Huebel (Classic) Post details > How Did This Get Made? · Episode
000
Jamie Tanna @www.jvt.me.web.brid.gy · 13h
Listened to Disclosure w/ Nick Kroll & Emily Altman (Classic) Post details > How Did This Get Made? · Episode
000
Jamie Tanna @www.jvt.me.web.brid.gy · 14h
Listened to Jonathan Livingston Seagull LIVE! - Earwolf Post details > The HDTGM crew are LIVE from the Beacon Theatre in New York to break down the 1973 tale of a rebellious young seagull who just wants to fly fast and ends up... in outer space?!
000
Jamie Tanna @www.jvt.me.web.brid.gy · 15h
Listened to Open Source Security: Dependency attacks in 2026 with James Matchett Post details > Josh chats with Jeff Matchett from Cloudsmith about a new report they put out. It has some scary looking statistics in it about how organizations are using dependencies. There are some surprising […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 15h
Listened to Time Cop LIVE! W/ Nick Kroll (HDTGM Matinee) - Earwolf Post details > Nick Kroll (Oh, Hello on Broadway, The House) returns to join Paul, June, and Jason to discuss the 1994 Jean-Claude Van Damme movie Timecop.
010
Jamie Tanna @www.jvt.me.web.brid.gy · 18h
Listened to Superman IV: The Quest For Peace LIVE! w/ Natasha Lyonne & Jessica St. Clair (Classic) Post details > How Did This Get Made? · Episode
000
Jamie Tanna @www.jvt.me.web.brid.gy · 04/10/2026
Listened to Serenity: LIVE! (w/ Nick Kroll) - Earwolf Post details > HDTGM All-star Nick Kroll (Big Mouth) joins Paul, June, and Jason to discuss the 2019 neo-noir thriller Serenity. Recorded live from Austin City Limits at the Moody Theater, they talk about the big twist that comes way too […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 04/10/2026
What happened in the week of 2026-09-28?
jvt.me
Week Notes 26#40
* A chilled journey back home, with a stop-off at Blakeney for a walk with the dogs * We bumped into Dougie on the road home which was a nice surprise! * Finally looked into a massive papercut I have with my Neovim + Vale setup, where I need to stop Vale and then clear LSP diagnostics, which Claude Sonnet 5 found as an upstream issue in Vale's LSP, which was fixed by the maintainers * Was cool to see my post about why I - still - think Renovate is the best tool for the job appear on Lobsters * This week I celebrated my blog's 10th anniversary - I could've spent a lot of more time reflecting but also maybe want a bit more time to think about what to say - maybe it'll even be a private post just for me * Started on the TfL jigsaw, which is going well * A busy week at work, announcing some big security advisories and prepping for Open Source Summit * Did a bit of life admin, like finally sorting out my phone contract, upgrading to Monzo Max and getting Discord Nitro * Had a good time at Phil Wang on Saturday - a few bits that were the same as his bit in last year's Christmas gig, but still good! * James Trickey was a good warmup * A nice time at pizza Thursday, but felt like I didn't really get a chance to talk to anyone! * A busy weekend, as on Friday evening, we noticed that one of our radiators had been leaking (enough so that we found out by water dripping through the floorboards into the hallway) - I've managed to change the lockshield valve, but there's a lot of water we're drying out up there * (Most likely) Morph brought in a very dead mouse one day 😅 Playing: * (No _Blue Prince_) * _Kingshot_ (per usual) * Looking forward to KvK! * _Apex Legends_ * The Street Fighter mode being its own queue meant _such long_ wait times that I ended up playing regular Wildcard Reading: * _The Sins of Our Fathers_ Watched: * _Neagley (Series 1)_ * _The Expanse (Season 5)_ * _Taskmaster (Series 22)_ * (No _Furiosa: A Mad Max Saga (2024)_) * _The Celebrity Traitors (Series 2)_ * _Ted Lasso (Season 1)_ * _Between Two Ferns (on YouTube)_
000
Jamie Tanna @www.jvt.me.web.brid.gy · 04/10/2026
Listened to www.google.com/goto?url=CAEScgHrOzA… .
000
Jamie Tanna @www.jvt.me.web.brid.gy · 04/10/2026
Listened to Shoot 'Em Up Post details > How Did This Get Made? · Episode
000
Jamie Tanna @www.jvt.me.web.brid.gy · 03/10/2026
Listened to Closed That Tab: What "How Complex Systems Fail" Teaches Software Engineers by Overcommitted | Software Engineering and Programming Insights Post details > Closed That Tab is back. Erika finally read Richard Cook's How Complex Systems Fail, an 18 point paper Cook wrote with patient […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 03/10/2026
Listened to The Quick and the Invalid - Continue Post details > Welcome to Continue: Go Proposals edition! Each edition of this show will handle a specific topic that can be covered continuously. This edition is for Go Proposals. Each week Kris and Matt will…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 03/10/2026
Listened to Keep Your Enemies Closer - Fallthrough Post details > Steve is back! He joins Kris and Matt to discuss the drama around DHH's latest keynote at Rails World and Steve's latest views on AI. Interestingly, Steve believes that he'll sit in opposition to…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 03/10/2026
Listened to Megalopolis LIVE! - Earwolf Post details > STOP TIME! This week Paul, June and Jason are breaking down the 2024 Francis Ford Coppola film, Megalopolis, LIVE from the New York Comedy Festival at Town Hall.
000
Jamie Tanna @www.jvt.me.web.brid.gy · 03/10/2026
Listened to Matinee Monday: Con Air LIVE! - Earwolf Post details > Recorded LIVE from Largo in Los Angeles, filmmaker and author Seth Grahame-Smith joins Paul, Jason, and June to discuss the 1997 Nick Cage classic, Con Air. They cover everything from Nic Cage’s southern accent, John Cusack's […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 03/10/2026
Listened to Little Italy - Earwolf Post details > Paul, June, and Jason are in-studio to discuss the 2018 romantic comedy Little Italy starring Emma Roberts and Hayden Christensen. They talk about the stereotypical Italian accents, the hair dye, the rain soccer game, the Luigi character, and […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 03/10/2026
Listened to Test-Driven Development with Claude Code, featuring Paul Hammond | Better Than Vibes Post details > Paul Hammond on LinkedIn: www.linkedin.com/in/paul-hammond-bb…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 02/10/2026
Listened to Thinking, Fast and Cheap - Fallthrough Post details > Another week, another duo episode, but this time around it's Dylan who's joining Kris! He brings a fresh perspective to the AI conversation that Kris and Matt have been engaging in. The big…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 02/10/2026
Listened to Kristin Isaac: The Customer Doesn’t Care About Your Technical Debt Post details > Customers don’t ask you to pay down technical debt. They notice when the product is slow, unreliable, or keeps breaking in the same damn way. Kristin Isaac joins Robby to explore how engineers can […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 01/10/2026
Listened to The Map with No Name - Continue Post details > Welcome to Continue: Go Proposals edition! Each edition of this show will handle a specific topic that can be covered continuously. This edition is for Go Proposals. Each week Kris and Matt will…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 01/10/2026
Listened to Open Source Security: CRA vulnerability reporting with Daniel Thompson Post details > Josh welcomes back Daniel Thompson to explain what just happened regarding vulnerability reporting and the CRA on September 11. The very first CRA requirements kicked in, but what does it really […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 01/10/2026
Celebrating another massive milestone in my blog, and a short reflection.
jvt.me
A DECADE of writing on this blog
This year I'm fortunate to be celebrating a few 10th anniversaries. One of the big ones is that this blog is officially 10 years old! This post is the _1285th post_ I've written on here, and I still love this part of myself. I've written about how it's helped me as someone neurodiverse, some reasons about why I think you should blog and reflecting on hitting 1000 posts (which is _even more_ wild that was 2 years ago!! I swore it was more recent than that), and I've definitely got a number of other posts in there about the benefits. It all started 10 years ago, where I remember sitting downstairs in "the Software Studio" at Capital One, trying to desperately finish off what would be the first of many blog posts. In my memory, I felt like I was slightly taking the piss, because my lunch break was a lot longer than it should have been, which considering I was just over one month into my first job, wasn't the best look, but "I needed to get it finished". But looking back at the history, I posted it at 1050, which means I hadn't even _had_ my lunch break and I was already trying to finish the post, which is an even worse look in retrospect 🫠 That post was celebrating the start of Hacktoberfest, which I wanted to land on the first day of Hacktoberfest, so I could share it around Hacksoc Nottingham, as I would be doing a workshop about Git + Open Source later that week. In 2016, I had basically nothing on my site - it was more of a portfolio site with some of the projects I've worked on, and this one blog post - so the traffic to my site was understandably pretty low. It wasn't until early 2017 that I started getting some real traffic, with my blog post about why you should use GitLab.com, as a big fan of the platform, which alongside using GitLab CI and Capistrano, I ended up seeing a lot more traffic. Later that year, I put some words to Blogumentation - Writing Blog Posts as a Method of Documentation, which would become a staple of my website, accounting for 557 posts (~43%) on my site. Looking back, I had no idea what the next 10 years would have in store for me. It's been a whirlwind, it's been glacial, and it's been much more public than maybe I would've thought this decade of my life would have been - but I don't think I'd change anything. This blog has had untold benefit to me as a person and to my career, and having the platform to do things like sharing my salary publicly has been such a positive in of itself. I've had my website since as early as 2011-06-22, where I used `jamietanna.co.uk` as my main URL, and used it to do web design as a side gig. As I think I've said before, I moved onto `jvt.me` at some point later - maybe 2016, according to the Internet Archive - primarily so I could provide a short URL to folks, but then ended up liking it enough to stick with it, and it's been a documented part of my identity for some time, to the point of ridicule. This is a little bit more stream-of-consciousness than some of my other posts, and I don't know how much more I want to pour out in the world about this - maybe it's best to keep this one a bit shorter? Considering this anniversary, I'll try and give my old posts a re-read. I do find it a little bit jarring reading how I used to write, what used to be important to me (especially if you look back at the start of my Week Notes, which started just as COVID19 starts to loom across the world), and how devoid of context some of my posts were (due to requirements of $job). You're recommended to hit some of the greatest hits, too, or peruse the very long list on /archives - or not at all. It's a free Internet. Here's to another decade 🥂
000
Jamie Tanna @www.jvt.me.web.brid.gy · 30/09/2026
Listened to A Fistful of Deques - Continue Post details > Welcome to Continue: Go Proposals edition! Each edition of this show will handle a specific topic that can be covered continuously. This edition is for Go Proposals. Each week Kris and Matt will…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 30/09/2026
Writing a tool, using Slack Block Kit, to write really pretty Slack messages, with syntax highlighting, tables and more.
jvt.me
Authoring Markdown externally and getting even 'prettier' output in Slack with md2slack
You know what's a little bit sad to think to yourself? > Wow, I'm a little bit jealous of how nice that person's Slack message looks And yet, that something I thought to myself last week 😅 I was looking at a colleague's message - which was posted to Slack via Claude - and it had the regular sort of rendered-Markdown that you'd expect from Slack, but inline in the message it had a pretty-rendered table, and a syntax-highlighted code snippet, followed by other bits of text. (Aside: I'm not really a fan of people using AI to post to Slack, because it infers that a) the human may not be involved in the loop and b) does that mean all our private conversations are now being ingested by the AI provider?) This wasn't a "normal" message that could be posted normally, especially as it included multiple types of content all rendered nicely. After doing some digging, it looks like it was created using the Slack Block Kit, which is much more powerful than the interface you get through Slack's clients. With a bit of help from Claude Sonnet 5 I managed to get it to reproduce the message via Block Kit and some API calls, which then led me to what I really wanted - to be able to post these sorts of rich messages myself. This is a step further on my journey of writing Markdown externally and then getting it into Slack, which I've talked about before on Linux or on Mac. I set Claude Sonnet 5 on creating a command-line tool that would allow posting a richer Markdown body into Slack, which I've published as md2slack. For example, let's take the following Markdown <!-- Co-authored-by: Claude Sonnet 5 --> # Deploy Failure: `payments-api` **Status:** investigating — pods crash-looping since ~14:02 UTC. We think this is caused by a bad config value pushed in the last release. See the [rollout history](https://example.com/rollouts) for context. ## What we know - Error only appears on the `us-east` cluster - Started right after `v2.4.1` rolled out - ~~Not~~ related to the database migration — ruled that out at 14:15 ## Timeline 1. `14:02` — first crash loop alerts fire 2. `14:09` — on-call acknowledges 3. `14:15` — database migration ruled out ## Recent error counts ```sql select pod_name, COUNT(*) as errors from app_logs where service = 'payments-api' and level = 'ERROR' and ts > now() - interval '30 minutes' group by pod_name order by errors desc; ``` | Pod | Restarts | Status | | --- | ---: | --- | | payments-api-7d9 | 14 | `CrashLoopBackOff` | | payments-api-a21 | 11 | `CrashLoopBackOff` | | payments-api-f03 | 0 | `Running` | ## Rollback ```sh kubectl rollout undo deployment/payments-api -n us-east ``` > Once rolled back, we'll confirm error rates return to baseline before > closing this out. This then renders as: This is a much nicer view, and I'm looking forward to using it where I'm trying to share more in-depth examples that I've previously been using a snippet for (or dealing with Slack's not-that-good interface for). Note that this does require you are able to create and install an App into your Slack Workspace, which isn't always as straightforward at a company.
000
Jamie Tanna @www.jvt.me.web.brid.gy · 30/09/2026
How to take a newline-delimited (`.ndjson`/`.jsonl`) file with OpenTelemetry traces inside of it, and ingest it into a local OTLP/HTTP traces receiver.
jvt.me
Uploading a large OpenTelemetry trace to a local OTLP/HTTP traces receiver
I've recently been doing some work with improving the performance of Renovate on larger repositories. To guide this investigation, I'm leveraging our OpenTelemetry support to more meaningfully understand how Renovate operates in parts of the codebase, and hone in on areas of improvement. One of the repositories I'm running these tests is particularly large, and leads to traces of roughly ~30MB in size. When trying to ingest them into my local Jaeger instance, I hit HTTP size limits, and the documentation I'd written in the past (with help from Claude Sonnet 5) for ingesting these doesn't seem to handle the size limits. With a bit of tweaking with Claude Sonnet 5, this is now better handled with: while IFS= read -r line || [ -n "$line" ]; do curl -s -X POST http://localhost:4318/v1/traces \ -H 'Content-Type: application/json' \ --data-binary @- <<< "$line" done < /tmp/traces.jsonl Notice that we redirect (via a herestring) the line's contents in via `stdin`, instead of passing it as an argument, which is what led to the shell crashing. With this few-liner this leads to us being able to ingest very large traces!
000
Jamie Tanna @www.jvt.me.web.brid.gy · 30/09/2026
Listened to September 28th, 2026 — Infrastructure Frontiers Post details > Episode 9 of Infrastructure Frontiers with Nell Shamrell-Harrington. Industry Experts run down all the AI news for Infrastructure Engineers. Adam Jacob,…
swamp-club.com
September 28th, 2026 — Infrastructure Frontiers
Episode 9 of Infrastructure Frontiers with Nell Shamrell-Harrington. Industry Experts run down all the AI news for Infrastructure Engineers. Adam Jacob,…
000
Reposted by Jamie Tanna
Renovate @renovatebot.com · 25/09/2026
We're excited to announce that Renovate maintainers Sebastian Poxhofer and Jamie Tanna will be at @linuxfoundation.org's Open Source Summit Europe in Prague in a couple of weeks, and look forward to meeting folks who are there We'll also be at the @openssf.org's Community Day, too
111
Reposted by Jamie Tanna
Renovate @renovatebot.com · 29/09/2026
We've announced 1 Critical, 2 High and 1 Moderate security advisories - we recommend you upgrade to a minimum of 44.79.0 (2026-09-10) More info: github.com/renovatebot/...
github.com
[SECURITY]: Announcing 1 Critical, 2 High and 1 Moderate advisories · renovatebot renovate · Discussion #46549
We're announcing 4 GitHub Security Advisories (GHSAs) that affect the Renovate CLI. There are 1 Critical, 2 High and 1 Moderate advisories. It is recommended that you upgrade to a minimum of Renova...
002
Jamie Tanna @www.jvt.me.web.brid.gy · 29/09/2026
Listened to Open Source Security: Sovereignty, policy, and OpenUK with Amanda Brock Post details > Josh welcomes Amanda Brock from OpenUK to chat about sovereignty, policy, open source, and a whole host of other topics. Amanda has front row seat into how sovereignty decisions can affect a […]
jvt.me
Original post on jvt.me
001
Jamie Tanna @www.jvt.me.web.brid.gy · 29/09/2026
Listened to We're taking a fall break | Cup o' Go Post details
000
Jamie Tanna @www.jvt.me.web.brid.gy · 29/09/2026
Listened to www.youtube.com/watch?v=frjMq57m_1c .
000
Jamie Tanna @www.jvt.me.web.brid.gy · 27/09/2026
What happened in the week of 2026-09-21?
jvt.me
Week Notes 26#39
* A busy week at work: * My anniversary, so I took some time to look back at this last year * It was too busy to even get a draft together for This Week in Package Management * I've been actioning my plan to proactively give away our Community (OSS) plan and so it's been a nice week digging into who'd get some good benefits from it, and doing some outreach * A lovely long weekend in Blakeney with Anna's family * We drove across Thursday afternoon (I took a half day), and then I was working from the house on Friday which was nice to do a bit of admin on things + send out some emails, while also being able to go to the beach ☀️ * We've had a really nice time, and the weather has been so very nice! Considering we were here two years ago to the week with a cold, but not rainy, week, it was a shock to be wearing shorts and getting a bit of a tan * Cookie's loved the beach, but each day we've been, we've still not managed to get to the _actual_ sea - it's always been quite far out, and as much as we tried yesterday, after at least half an hour of walking towards it, there was still a good chunk of the way to walk to the actual waves * Had some good food across Wells Deli, The Three Horseshoes (unfortunately after it's changed hands), The Golden Fleece and Wells Gelato, although speed of service hasn't been great * Cookie's been good for the most part, including when we joined the niblings for crabbing yesterday * Had some fun playing "lava monsters" with the nibblings this afternoon * Played a bit of table tennis which was nice * We managed to complete the pizza jigsaw just before dinner this evening, albeit there's definitely a piece we've lost * While letting Cookie out for a wee just before bed, she noticed that there are quite a few frogs outside 👀 Playing: * (No _Blue Prince_) * _Kingshot_ (per usual) * _Apex Legends_ Reading: * _The Sins of Our Fathers_ Watched: * (No _Veep_ (Season 7)) * We've officially given up on the last few episodes * _Reacher (Season 4)_ * (No _The Expanse (Season 5)_) * _Saturday Night Live_ * _Saturday Night Live UK_ * I tried again, but _really_ can't get into "our" version of SNL * _Taskmaster (Series 22)_ * (No _Furiosa: A Mad Max Saga (2024)_) * _Neagley (Series 1)_ * Much better than this last season of _Reacher_
000
Jamie Tanna @www.jvt.me.web.brid.gy · 24/09/2026
Listened to www.podchaser.com/podcasts/how-did-… .
000
Jamie Tanna @www.jvt.me.web.brid.gy · 24/09/2026
Listened to Sanjeev Bhaskar | Off Menu with Ed Gamble and James Acaster Post details > Listen to Sanjeev Bhaskar from Off Menu with Ed Gamble and James Acaster. We’re in National Treasure territory again as we welcome British comedy royalty Sanjeev Bhaskar to the Dream Restaurant. The ‘Goodness […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 23/09/2026
How to improve your code review experience on a temporary private forks on GitHub, by making sure that the code is showed at the maximum page width.
jvt.me
Getting a full-width PR review pane on GitHub temporary private forks
This is the sort of post that will have more preamble than the resulting code, but bear with me. If you're working on security fixes to a project on GitHub, you'll likely be using a temporary private fork to collaborate on. If you do so, as well as things like CI and other GitHub Apps not being enabled on the repo, you'll also find that the PR page doesn't seem to be as responsive as it suggests it will be. For instance: We can see that there's a lot of blank space either side of the PR, which wouldn't be the case on a regular PR: If we use the following client-side Javascript: document.querySelector('.container-xl.p-responsive').style = 'max-width: 3000px' We then get the private PR rendering more like we'd expect on a non-temporary repo:
000
Jamie Tanna @www.jvt.me.web.brid.gy · 23/09/2026
Listened to September 21st, 2026 — Infrastructure Frontiers Post details > Episode 8 of Infrastructure Frontiers with Zach Hamm. Industry Experts run down all the AI news for Infrastructure Engineers. Adam Jacob, Paul Stack, and…
swamp-club.com
September 21st, 2026 — Infrastructure Frontiers
Episode 8 of Infrastructure Frontiers with Zach Hamm. Industry Experts run down all the AI news for Infrastructure Engineers. Adam Jacob, Paul Stack, and…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 22/09/2026
Listened to Open Source Security: The curl summer of Bliss with Daniel and Stefan Post details > Josh chats with Daniel and Stefan from curl about their summer of bliss. Curl stopped taking vulnerability reports for a month and nothing much happened really. Daniel and Stefan have a really […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 22/09/2026
Listened to Apocalypse Not Now - Fallthrough Post details > Kris and Matthew have some more spicy and it's about the latest AI news cycle: a greater than ten percent chance that AI wipes out humanity inside a decade. Neither of them are worried about it…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 21/09/2026
Reviewing some of the key highlights of my last year working as the Renovate Project Lead, and showing some stats about the project, its community and myself.
jvt.me
Looking back at my first year as the Renovate Project Lead
A year ago on Thursday, I logged on for my first day joining Mend to work on Renovate full-time. Similar to what I did after my first 100 days, I thought now would be a good time to recap how this last year has gone. This is also a fun way of doing a public mini performance review! I'd planned to try and land this on my actual anniversary, but I know this is going to be a busy week - as they all seem to be, nowadays - so thought I'd pre-publish it (and because I don't like waiting to hit publish). Plus, publishing this now means that I don't have to keep re-writing this as the stats change! Note that below includes analysis from Claude Opus 5, based on data from our "maintainer dashboard" and commits on `main` over the last year. I've done some double-checking of some of these stats. Claude Opus 5 has created each of the charts on this page. ## Changes in the industry Before I get into how things have gone with the Renovate project, I wanted to look at the wider industry's context. In the last year, we've seen: * a significant rise in supply chain attacks, where malicious package releases are being used to compromise others and continue propagation as a worm (such as the "Shai Hulud"/"Sha1 Hulud"), or purely used to target specific users and organisations * an overwhelming increase of contributions across the Open Source ecosystem using AI, swamping and burning out maintainers faster than ever * a similar increase in reports of privately reported security vulnerabilities in code, with a high percentage of these being bogus * (as far as I can tell) higher adoption in dependency update tools, while also seeing calls to disable (your dependency update tools) or to prune the dependencies you own * I have a lot of thoughts on this, and had hoped to do a conference talk about this, but the talk proposal wasn't compelling enough to get past a couple of CFPs - I'm still planning on writing it up as a form of blog post! * increased AI usage has also led to service providers, like GitHub, seeing increased instability, outages, as well as the general feeling that products themselves are feeling a little bit lower in quality ## Changes in the project Over the last year, we've also seen some changes in how folks interact with Renovate. Firstly, it appears that there is an increase in adoption of Renovate, which is great! I'm especially biased right now, but I still think that Renovate is the best tool for dependency updates out there. ### Reduction in "I need help" Secondly, we've seen an interesting trend in how folks interact with the project. In prior years, we would have a fair few "Request Help" discussions - often "how do I get Renovate to do ..." or "I've configured ..., but it's not working how I expect it to" - which are down 43% this last year: A breakdown of how the trend of Discussions being created against the project has changed since September 2024. In 2024, we saw ~180/month "Request Help"s and ~50/month "Suggest an Idea"s being raised. By September 2025, "Request Help"s were down to ~140/month and "Suggest an Idea"s down to ~25/month. Through to the end of August 2026, the "Request Help"s are down to ~80/month and "Suggest an Idea"s up to ~30/month. My instinct is that with the rise of LLM usage, more folks are asking their LLMs to answer questions like this, instead of coming to us. I can't fault folks for using a tool with immediate responses - even if it's likely got outdated knowledge, or the chance of suggesting solutions we wouldn't recommend any more - as it gives them that faster feedback so they can get unblocked. I do think this is a shame, however, because previously we could use the contents of "Request Help"s as a feedback loop for what issues folks are seeing most commonly, and what areas we may need to improve, but now it's hidden inside a user's chat windows. We've been quite fortunate to have this as a signal in the past, and now we're going to need to work a bit harder to see how we can improve this going forwards. I don't have any numbers to hand on this, but when we do receive "Request Help"s, a lot of the time, they include a "I got an agent to trace through the code and it looks like this line needs a fix", rather than a real case of "I honestly don't know how to do this, please help". ### Improving life for agents (and humans) Speaking of AI agents, we've also made several improvements over the last year to try and make it easier for agents to contribute: * introducing an `AGENTS.md` * introducing a `pnpm check` command that runs all CI-like checks, locally * making sure that agents use `pnpm check` as a stop hook (and a few other options to tune tool usage) * nudging agents to fill in the PR template better * nudging agents to not raise Issues, because we use GitHub Discussions * adding linting rules that avoid the same comments coming up in code review Sergei and Sebastian have been doing some really great work on this - as well as a few other folks - and it's made a massive difference for my own usage of LLMs with the codebase, and getting even better code out the other end. That being said, prior to these changes were we seeing - for the most part - fairly technically correct code, but it wouldn't necessarily fit in the areas that it was added for, or wouldn't completely fit our code style, but would handle a lot of file-directory architecture choices. ### An increase in contribution It's pretty great that work we've done for years to keep the codebase well-defined has made it easier for humans and LLMs both to contribute, and we can see this in the data of contributions. Prior to September last year, every 6-month block of the year for the last 18 months, we saw ~700 commits every 6 months. In the first half of 2026, we saw that number increase to 1035 (48% increase), which is a whopping increase for a 0% increase in maintainers on the project 🤓 We can see this in how the external contributions have increased over the months: A breakdown of how the trend of PRs being created against the project has changed since September 2024. Between September 2024 and March 2026, we saw fairly consistent number of external PRs between 47 and 79 PRs/month, from 35-58 distinct authors. In March 2025, we see this increase to 96 PRs from 677 distinct authors, up to a peak of 124 PRs from 86 distinct authors. Similarly, we're receiving increased numbers of PRs, but are still continuing to merge them, albeit it's taking a bit longer: The breakdown of how many PRs are merged/closed without merge/not-yet-merged-or-closed, looking at 6 month periods (as a "cohort"). We see a fairly stable percentage of PRs closed without merge (17% to 23%) over the cohorts. In 2024-H1, we see 83% of the 336 PRs are merged. In 2024-H2, we see 79% of the 390 PRs are merged. In 2025-H1, we see 76% of the 393 PRs are merged, and 1.3% still needing a decision. In 2025-H2, we see 69% of the 375 PRs are merged, and 8% still needing a decision. In 2026-H1, we see 61% of the 494 PRs are merged, and 20% still needing a decision. Considering we're seeing an increase in new contributors, these are folks who aren't necessarily going to know the practices of the project, so it may take more time to iterate through changes: The breakdown of the number of new contributors to the project, looking at 6 month periods, and based off merged contributions. In 2024-H1, there were 183 new contributors. In 2024-H2, there were 193 new contributors. In 2025-H1, there were 179 new contributors. In 2025-H2, there were 171 new contributors. In 2026-H1, there were 205 new contributors. ### _Please_ stop raising Issues As noted above, because we use GitHub Discussions for triage, there shouldn't be any Issues being created by folks outside of the project, but that doesn't stop them right? Although we've done a few things to try and stop users doing this - like a big glaring warning, and auto-closing them if they're not raised by a collaborator on the project - there were still some cases we'd get repeat offenders, especially as GitHub still didn't block it via the API or in specific UI widgets. I'd often give a temporary block to "nudge" the user that their behaviour wasn't correct, but a lot of the times, these were created by an AI Agent, not even a human who was being a bit of a dick. Thankfully by August (after a needed follow-up fix to the original release in June), it was possible to completely close out Issue creation from non-collaborators, which also means there's one fewer place I need to keep on top of. ### `E_TOO_MANY_RELEASES` Another big issue we've hit this year is that when publishing new npm packages, we hit: npm error code E406 npm error 406 Not Acceptable - PUT https://registry.npmjs.org/renovate - Package publish failed. npm error Your package metadata is too large (100.01 MB > 100 MB). This is quite a novel error in the npm ecosystem, as there aren't that many projects that release quite so much that they hit hard limits on the registry size 😅 This happened twice this year: * In my first full week but was resolved within ~2 days of downtime * In April, resolved after a month of no new npm releases During this window, we were still able to publish Docker images, but not having the npm package led to a lot of knock-on effects that weren't ideal. We've performed some significant cleanup at this point, and aren't yet planning on reducing our release cadence, due to the utility it provides to us as a project. ### Continuing to ship 🚀 Speaking of our frequent release cadence, over this year, we shipped: A count of the releases that Renovate shipped over the last year, showing (at time of data collection) 1813 releases, of which 1276 are patch releases, 533 are minor releases and 3 major releases. (Of which one major version wasn't intentional) These changes also led to a number of changes across Renovate's excellent support of things it can update: A timeline of changes to the modules that Renovate supports, showing that in the last year: * Managers grew from 110 to 118 * Datasources grew from 76 to 82 * Versioning schemes grew from 46 to 54 * We added 1 new Platform It's been great to see how much stuff we've got done considering the small team, and I'm always incredibly appreciative of maintainers Sebastian and Michael, who also do a tonne to keep this project going! ## My key achievements I'm very happy with some of the key things I've led on: * Doubling down on `minimumReleaseAge`, before the rest of the ecosystem * Renovate's had the ability to set `minimumReleaseAge` (also referred to as a "cooldown") since _2019_ - we've seen a good adoption of the feature over the years, but an noteworthy increase in the last couple of years * Foreseeing this as something we needed to be more opinionated about, I decided to set things in motion before I'd even joined officially to provide better defaults to protect our users * As I'd written on the Mend blog, this was an important change we made to secure more folks where possible, and would be the start of further work to improve `minimumReleaseAge`, and generally widening our support for this, as well as where we would set it "on-by-default" * This also involved a _tonne_ of work from me and Rahul, where we worked towards my vision of what would be a good point for this to be on-by-default, and writing a little more in-depth documentation for a key feature than we may have in the past * It was nice to see our friends at Dependabot introduce cooldown functionality last July, and then, based on some feedback I'd shared with the folks at GitHub earlier this year, they enabled cooldowns by default this July, as well as many of the package managers now adopting it, led by `pnpm` * The wider ecosystem agreed with my thinking, because not long after we'd enabled it for `config:best-practices` users, we saw more posts from folks like William Woodruff about why cooldowns are important, and prompted by `pnpm` adding `minimumReleaseAge` functionality in early September * Malicious package prevention * we're still working through making it available for users who aren't using `vulnerabilityAlerts` through Open Source Vulnerabilities (OSV), but being able to block dependency updates to a known malicious version is really important * Security hardening * As an ongoing effort, helped and accelerated by AI tools, we're doing a lot of work to close out potential gaps in things that have been around for a bit * constraintsFiltering=strict for Go * Something that's bugged me for a while as an author of Go libraries/tools that doesn't want to update the `go` directive unnecessarily, you can now use `constraintsFiltering=strict` to only receive PRs for updates that don't bump your `go` directive * Increased OpenTelemetry instrumentation * The telemetry that Sebastian had originally added into the project was a great start, but I had a bit more time to spend on improving how our instrumentation works * We've now got strong coverage of some of the key operations in Renovate so far, and it's currently being used to help improve the performance of Renovate when it runs against monorepos, which wouldn't be possible purely from our logs themselves * apk add extraction in Dockerfiles * Visualising some - in my opinion - interesting stats about how a given release train ran * For instance, for Renovate 42 and for Renovate 43 * Being competitive with our features * For instance, within hours of being made aware of an issue with how both Renovate and Dependabot handled GitHub Actions' tagging formats, I'd started working on fixing this - as it would block users from migrating from a mutable/"floating" tag to immutable tags, which are more secure, while Dependabot are still yet to implement this * Albeit it was a little more difficult than I'd originally thought - having slightly broken things a couple of times while I iterated on it 🫣 * Or supporting the GitHub Actions' lockfile format, before Dependabot did * Providing a bit more insight into the project, from the outside * This blog post, and after my first 100 days * Writing a bit more in-depth about things like why we use Discussions and how we're using the "maintainer dashboard" to do better things * Adding some different means to provide more focussed feedback to us * Doing some more project management-y things (which were being done at some level before) like adding an epic tracking all potential deprecations we're going to remove in a future version, and pre-announcing new releases, with a new "Maintainer announcements" Discussion category, so folks can follow via RSS * Changes we're making to Mend-hosted infrastructure, such as when I decided we would enable "vigilant mode" on the @renovate-bot user on GitHub.com * Being a bit more clear that i.e. we're a small team, or that we're taking things a bit easier with summer holidays or at the end of the calendar year * Documenting areas that customers are interested in being merged/fixed or explicit requests they have, to help improve visibility + priority calls * Some key improvements to our documentation * I've worked to make sure our documentation is more complete, for instance autogenerating key pieces of information, such as "what are the given `depTypes` this manager supports", or "what `tool`s can I tell Renovate to install i.e. with `constraints`?", as well as working to make our JSON Schema as representative as possible * Adding more in-depth documentation like minimumReleaseAge or how environment variables are handled There's actually a load of other things that I'm happy we've got done over this year, but this section is getting very long 😹 ## Title change When I officially joined Mend, I had a bit of a mouthful of a job title, which also didn't really reflect the work and impact I was having when folks inside and outside of Mend read it. In May, we changed my title to make the scope of the work and impact I was having official: -Senior Developer and Open Source project maintainer +Renovate Project Lead This is probably a little bit of a vanity thing, but it made sure that it was clear that my role is leading the Renovate project, shaping direction of where both the Open Source project and our product offerings go. ## Some personal stats Let's look at some of how I spent my year. I've intentionally not included code review, which has been a chunk of my time, but not as significantly as it has been for Michael. For instance, let's refresh ourselves on how many external PRs we've been seeing recently: The breakdown of how many PRs are merged/closed without merge/not-yet-merged-or-closed, looking at 6 month periods (as a "cohort"). We see a fairly stable percentage of PRs closed without merge (17% to 23%) over the cohorts. In 2024-H1, we see 83% of the 336 PRs are merged. In 2024-H2, we see 79% of the 390 PRs are merged. In 2025-H1, we see 76% of the 393 PRs are merged, and 1.3% still needing a decision. In 2025-H2, we see 69% of the 376 PRs are merged, and 8% still needing a decision. In 2026-H1, we see 61% of the 500 PRs are merged, and 20% still needing a decision. If we look at human (or agent) commits, we can see that I've started taking up more time in the overall percentage of project's commits. The breakdown of how many human commits there are in the last year, looking at 6 month periods, between "everyone else" and me. In 2024-H1 through 2025-H1 I have 0 commits, so "everyone else" is doing very well. In 2025-H2, I have ~180 commits compared to ~510 from "everyone else". In 2026-H1 I have ~410 commits compared to ~620 from "everyone else". In 2026-H2 (so far) I have ~270 commits compared to ~370 from "everyone else". However, this is then much more drastic if you look at it based on number of commits per person: The breakdown of how many human commits there are in the last year, broken down by GitHub username, showing the top 10 usernames. At the top, `@jamietanna` (the author of this post) has 875 commits. The next best, in order, are the other two Renovate maintainers with `@viceice` at 186 and `@secustor` with 137 commits. 7 of the top 10 contributors are collaborators on the project, and 2 of them are for the same human, under two different usernames. The 10th place has 12 commits in the last year. These commits are a mix of things: Based on my commit messages, there were: * 221 `fix` * 155 `docs` * 146 `chore` * 129 `feat` * 78 `test` * 75 `ci` * 65 `refactor` * 7 others Across a mix of files and parts of the project: Over the year, including i.e. linting fixes, I've touched: * 11/11 of the Platforms * 73/118 of the Managers * 26/82 of the Datasources * 10/54 of the Versioning schemes Note that this isn't the entirety of Renovate, and I've purposefully omitted the other areas for brevity. These changes have been across Mend customers' requests, reports of bugs from the community, features I want to deliver as well as a mix of other backlogs that we have, and I'm working to make more explicit. With the small team we have, we're trying to review as best as we can while this number keeps on growing. And it's clear to see that the more changes I'm authoring, there is a smaller percentage of community PRs that get in, because we have limited review time - something we're hoping to try and improve where we can. We can see that as well as committing a lot of things, I also am largely present in the GitHub Discussions: Before I joined the project, I naturally didn't spend much of my time regularly interacting with the the GitHub Discussions, unless I had an issue or feature request, so up until September 2025, I effectively had 0 engagement. However, from September 2025, the amount of discussion comments from others decreased as I did more, as well as the general decline of folks using GitHub Discussions to ask questions. An interesting view that Claude Opus 5 noted was that - since I've joined - I've done a bad job with keeping on top of labelling our Issues appropriately 😅 Before I joined, our labelling of Issues on the repo was at ~95%-98% over time. Since I've joined, we're down to ~45% of newly created Issues with any `priority` label, and ~75% with any labels at all. This isn't ideal, and is hopefully something we can fix! This is largely because the intake form for Issues would guide you towards creating the Issue with the right fields, but as GitHub (maybe late last year?) allowed maintainers to use free-form inputs, I lazily started using that. I'd hoped that with the new structured Issue metadata, we'd be able to migrate to them for a number of the "mandatory" labels we used, but unfortunately due to platform limitations of 100 items per field, we unfortunately can't take advantage of it for some of our fields. ## My own AI increase As much as I continue to say I'm an AI skeptic, you may not believe me when you look at how many of my commits are now including AI-generate content in them: A stacked bar chart showing my commits (on `main`) per month from October 2025 to September 2026. From October 2025 to January 2026, the AI usage was between 2% and 7%. In February this increases to ~29%, and in August and September 2025 (so far), we're seeing roughly 88% AI usage. I've definitely been using AI a whole lot more this last year. Some of it is absolutely to "keep up" - with the increased load on maintainers, if there are metrics needing to be hit or even for fear of "being left behind". But it's also disingenuous to not also say that I _am_ enjoying having AI agents available to me, that I can use to parallelise tasks while working on other things (for instance, writing this blog post 😉), while also lamenting whether "craft" can exist and the worries about how Open Source survives. As I noted in How much AI can a maintainer get away with using without losing their humanity?, I'm not at the point - and I don't think I really want to be - of replying to other human people with AI. I'm still thinking fairly critically, doing my own writing of my blog - also as Bryan Cantril recommends - and my replies to humans, but worrying that the increase in workload will lead to compromises needing to be made. ## Mend products I won't go into this in the same level of detail here, but there are a number of key changes that I've done/helped shape this year that I'm very happy about, and I know a number of our customers have been very appreciative of! I'll also note that I've ended up shipping ~102 Renovate upgrades to Mend-hosted apps, roughly up ~50% compared to the previous year. ## Performance review: happy? I'm pretty happy with how the last year has gone. There are of course some situations and conversations we could've handled better, there are areas that I wish we'd tested a little better before they got merged, but given the tiny core team we have we've done very well generally with the increase in workload. But I'm also big-headed enough to say that I think I'm absolutely the right person to have picked up the mantle with Rhys leaving, and I'm very happy I did. It would have been interesting to see how someone else would've responded to a number of the changes over this last year, but I guess we don't get to see that. Looking forward to seeing how things go this coming year!
000
Jamie Tanna @www.jvt.me.web.brid.gy · 21/09/2026
Listened to The Elements of Slop - Fallthrough Post details > Kris and Matthew have some feelings about AI they want to discuss. No, not about benchmarks or agents, but about the people using it to write things they should be plenty capable of writing…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 20/09/2026
What happened in the week of 2026-09-14?
jvt.me
Week Notes 26#38
* A busy week at work: * Most importantly, apk add/apt installs are now extracted in Dockerfiles, which is a much-wanted feature! * Got some **??** to my 1 year anniversary post * Anna's been in London this week, so **??** the fur babies **??** * Had an alright massage - a bit disappointing but still much needed * Had a nice breakfast at Speciality yesterday with Carol and Alan, and a nice lunch today at The Garage in Chilwell - the Lebanese (Karke) was very good 😋 * Doing a clear out of my emails - as Zoho emailed me to let me know I'm nearing my storage limit - and reading through some of the old emails I've got is a bit of a time warp * A nice pizza night, and the Curriza - chicken tikka, mango chutney, onion bhaji on a pizza, with chesse - was quite good! * Was cool to hear that Jerod's joined Socket! Playing: * (No _Blue Prince_) * _Kingshot_ (per usual) * _Apex Legends_ Reading: * _The Sins of Our Fathers_ Watched: * (No _Veep_ (Season 7)) * _Reacher (Season 4)_ * _Margo's Got Money Troubles (Season 1)_ * _Unacceptable (Season 1)_ * (No _The Expanse (Season 5)_) * _Saturday Night Live_ * _Taskmaster (Series 22)_ * _Furiosa: A Mad Max Saga (2024)_ * _Neagley (Series 1)_
000
Jamie Tanna @www.jvt.me.web.brid.gy · 20/09/2026
Listened to Cgo Unchained - Continue Post details > Welcome to Continue: Go Proposals edition! Each edition of this show will handle a specific topic that can be covered continuously. This edition is for Go Proposals. Each week Kris and Matt will…
000
Jamie Tanna @www.jvt.me.web.brid.gy · 20/09/2026
Listened to A totally racist episode so cache(sh) me outside how bout dah?! | Cup o' Go Post details > Thanks for listening! Find all the things at cupogo.dev. Meetups roundup:🇮🇹 GoLab 🇺🇸🌁 GoSF 🇯🇵 TinyGo 2026 🇮🇱 Gophercon Israel Cancelled :( Blogoverse deep divesData races and the limits of […]
jvt.me
Original post on jvt.me
001
Jamie Tanna @www.jvt.me.web.brid.gy · 18/09/2026
Listened to podtail.com/podcast/how-did-this-ge… .
001
Jamie Tanna @www.jvt.me.web.brid.gy · 18/09/2026
Listened to A big episode about tiny things | Cup o' Go Post details > golang.org/x/tools v0.50.0 releasedBlog: Finding unreachable functions with deadcode by Alan Donovan Russ Cox leaves google, and opines on LLMs for debugging Coding agent guidelines for modern Go Jonathan's new podcast […]
jvt.me
Original post on jvt.me
000
Jamie Tanna @www.jvt.me.web.brid.gy · 18/09/2026
Sharing that Renovate 44.103.0 automagically parses `apk add` and `apt install` commands inside a `Dockerfile`.
jvt.me
Updating apk add and apt install definitions in Dockerfiles with Renovate
If you're writing `Dockerfile`s that install packages using system package managers, such as `apk` or `apt`, you might be pinning your versions of packages, to make sure that you have more reproducible builds, or if you're on a rolling release distribution like Wolfi and Chainguard Images, you want to make sure you only get package versions you want. When these system package manager versions are pinned, it can then be a little cumbersome to keep them updated in an automated fashion, as most tools don't have a way to automagically parse your files and propose updates. So you're probably one one of two camps - "I'll get my AI agent to go and update it for me" or "we'll not update anything until things break". I've previously had this managed - at least for `apk add` updates - by using a Custom Regex Manager with Renovate to keep them updated, which required you break the install command over multiple lines: # ... RUN apk upgrade --no-cache && \ apk add --no-cache \ bash=5.2.37-r2 \ py3-pip \ python3 \ rsyslog=8.2412.0-r1 \ runit=2.2.0 ENV APP_HOST=0.0.0.0 ENV app_port=5000 ENV SNAPP_PORT 5000 This isn't _that much_ of a problem - as it also improves readability - but you generally want the tools to work around you, not vice versa. As of earlier this morning, we've shipped inbuilt support in Renovate, so if you have a `Dockerfile` with `apk add`, or an `apt install` (or `apt-get install`) like below, you'll be able to receive package updates for them 🎉 For instance, with the following `Dockerfile`: # SPDX-License-Identifier: AGPL-3.0-only # Via https://docs.renovatebot.com/modules/manager/dockerfile/#run-apt-install-support FROM debian:trixie RUN apt-get update \ && apt-get install -y --no-install-recommends \ # newlines for readability only curl=8.14.1-2 \ git=1:2.47.3-0+deb13u1 \ && rm -rf /var/lib/apt/lists/* Renovate will detect that you have a package pin for `curl` and `git`, and if there are updates available, will propose them. Right now, we don't currently auto-detect the distribution you're using and auto-wire the registry URL to look up packages with, so in the meantime you'll need to explicitly tell Renovate how to do that, for instance : { "packageRules": [ { "matchFileNames": ["Dockerfile.wolfi"], "matchDatasources": ["apk"], "registryUrls": ["https://packages.wolfi.dev/os?arch=x86_64"] }, { "matchFileNames": ["Dockerfile.local"], "matchDatasources": ["deb"], "registryUrls": [ "https://deb.debian.org/debian?suite=trixie&components=main,contrib,non-free&binaryArch=amd64" ] } ] } My hope is that early next week, my PR to derive this information will land, so you won't even need to configure anything - it'll ✨ just work ✨ This is something I've wanted for at least over a year, and we've had user requests for this for - at a quick check - over 5 years! So I'm really glad we've got this over the line, and I'm looking forward to hearing feedback about this. We're also very open to other system package managers - feel free to raise a "Suggest an Idea" Discussion if there are others you'd like added. You can see more details in the docs: * RUN apk add support * RUN apt install support, * Wolfi and Chainguard Images example (If this post looks familiar, it might be because this blog post replaces [a post I wrote last year], because renovate now supports this functionality natively, as of Renovate 44.100.0 🎉) (There are some subsequent fixes, so I'd recommend using 44.103.0 as the earliest version to test with)
000