//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...
Working on mapping the world of open source software https://ecosyste.ms and empowering developers with https://octobox.io Mostly posting on https://mastodon.social/@andrewnez
Andrew Nesbitt









Loading...
Joint Guidance on Vulnerability Naming and Disclosure: nesbitt.io/2026/06/12/j...
What Happened to tea.xyz nesbitt.io/2026/06/11/w...
I had never really thought about it before, but it turns out that there are a number of package manager related patents: nesbitt.io/2026/06/08/p...
Forms of Open Source Government nesbitt.io/2026/06/09/f...
This Week in Package Management: 6 June 2026 nesbitt.io/2026/06/06/t...
This Week in Package Management: 6 June 2026 nesbitt.io/2026/06/06/t...
A survey of install-script allowlist mechanisms across package managers and language ecosystems: nesbitt.io/2026/06/05/i...
gittuf - a signed log for git refs nesbitt.io/2026/06/04/g...
Happy to see OSS maintainer burnout in the public discourse—good job Matthew! 'Heath believes governments should invest more in open source' - that she does 😘
I've been working on a jekyll plugin to make it easier to implement @standard.site: github.com/andrew/jekyl...
4h
1d
4d
3d
6d
6d
7d
8d
5d
7d
Releases, advisories, and articles from across the package management world
nesbitt.io
This Week in Package Management: 6 June 2026
Releases, advisories, and articles from across the package management world
nesbitt.io
This Week in Package Management: 6 June 2026
A survey of install-script allowlist mechanisms across package managers and language ecosystems.
nesbitt.io
Install-script allowlists
Branch protection is a row in someone else’s database
nesbitt.io
gittuf - a signed log for git refs
GitHub - andrew/jekyll-standard-site: Jekyll plugin that emits standard.site verification artifacts
Jekyll plugin that emits standard.site verification artifacts - andrew/jekyll-standard-site
github.com
Andrew Nesbitt
Andrew Nesbitt
Andrew Nesbitt
Andrew Nesbitt
Andrew Nesbitt
Andrew Nesbitt
Andrew Nesbitt