Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Package Manager CWEs

Patching and forking in package managers

Incident Report: CVE-2024-YIKES

A GitHub for maintainers

Revisiting the 2015 Open Source Census

GitHub Actions is the weakest link

Forge

Git’s Magic Files

Features everyone should steal from npmx

Package managers need to cool down

If It Quacks Like a Package Manager

How to attract AI bots to your open source project

Git's Magic Files

Package Management Namespaces

Whale Fall

Git in Postgres

The Many Flavors of Ignore Files

Crates.io’s Freaky Friday

Sandwich Bill of Materials

Where Do Specifications Fit in the Dependency Tree?

Zig and the M×N Supply Chain Problem

The C-Shaped Hole in Package Management

A Protocol for Package Management

Package management is a wicked problem

Reducing Dependabot Noise

Workspaces and Monorepos in Package Managers

git-pkgs: explore your dependency history

How dependabot works

Cursed Bundler: Using go get to install Ruby Gems

Package managers keep using Git as a database, it never works out

More →