Andrew NesbittHow This Blog Is BuiltA full walkthrough of the custom static site generator, content pipeline, and edge deployment behind nesbitt.io.Andrew Nesbitt
Package Management Nerd, working on mapping the world of open source software https://ecosyste.ms and blogging about package managers at https://nesbitt.io
- GitHub
- https://github.com/andrew verified
- https://twitter.com/teabass
- Homepage
- https://nesbitt.io verified
Andrew NesbittHow This Blog Is BuiltA full walkthrough of the custom static site generator, content pipeline, and edge deployment behind nesbitt.io.Tripped over this cursed bit of software today, look at that massive readme diagram: https://github.com/raydac/mvn-golang
GitHubGitHub - raydac/mvn-golang: maven plugin to automate GoSDK load and build of projectsmaven plugin to automate GoSDK load and build of projects - raydac/mvn-golangSomething I've been working on recently to improve testing around dependencies: https://github.com/alpha-omega-security/hyrum
Reuses a lot of pieces of git-pkgs and scrutineer
GitHubGitHub - alpha-omega-security/hyrum: Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness.Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness. - alpha-omega-security/hyrumShared Code Between Package Managers
https://nesbitt.io/2026/08/11/package-manager-library-reuse.html
Andrew NesbittShared Code Between Package ManagersWhich package-management libraries twenty package managers reuse from each other.Thinking of adding support for vendored dependencies to git-pkgs: https://github.com/git-pkgs/git-pkgs/issues/317
I had enough of getting daily security warnings on the hundreds of npm dependencies of Docusaurus so I'm switching https://docs.ecosyste.ms to use hugo: https://github.com/ecosyste-ms/docs/pull/115
This Week in Package Management: 8 August 2026
https://nesbitt.io/2026/08/08/this-week-in-package-management.html
Andrew NesbittThis Week in Package Management: 8 August 2026Releases, advisories, and articles from across the package management worldThe Software Stewardship Lab
https://nesbitt.io/2026/08/07/the-software-stewardship-lab.html
Andrew NesbittThe Software Stewardship LabA new applied research lab for open source sustainability, launching todayA year of AI disclosure in critical packages: https://nesbitt.io/2026/08/06/a-year-of-ai-disclosure-in-critical-packages.html
Andrew NesbittA year of AI disclosure in critical packagesAssisted-By: Daniel StenbergRE: https://mastodon.social/@andrewnez/117031823385268173
I’m now getting daily reminder emails that I have not responded to this request yet. 😬
Paraphrasing an email from a security company : We copied one of your blog posts and turned into an advert for one of our products. Please add a link to our blog post to the end of yours. 🥉
Unexpected use case for https://github.com/git-pkgs/proxy - putting it in front of their Artifactory.
I suspect people are using it for edge fan-out without actually paying for Artifactory Edge nodes.
github.com/git-pkgs/proxy
GitHubGitHub - git-pkgs/proxy: A lightweight caching proxy for package registries.A lightweight caching proxy for package registries. - git-pkgs/proxyhttps://github.com/chaoss/disclosure is proving to be a very useful tool in analysing disclosure of ai contributions to oss projects.
GitHubGitHub - chaoss/disclosure: Github Action to gather signals of disclosed AI contribution to aid community health monitoring tools and open source maintainersGithub Action to gather signals of disclosed AI contribution to aid community health monitoring tools and open source maintainers - chaoss/disclosurebrew install actions/checkout - Using Homebrew's tap machinery as a curated distribution layer for GitHub Actions.
https://nesbitt.io/2026/08/04/brew-install-actions-checkout.html
Andrew Nesbittbrew install actions/checkoutUsing Homebrew’s tap machinery as a curated distribution layer for GitHub Actions.Replying to @andrewnez@mastodon.social
Also if you're adding cache busting url parameters to api requests to try and get fresher results, I'm just going to block you, don't do that.
Curl had it's summer of bliss, @ecosystems is having it's Summer of Piss (taking) by security companies hammering the public api and ignoring the data license.
Replying to @andrewnez@mastodon.social
Anubis upgraded to 1.26.2 and difficulty level increased.
Also found some new security companies heavily scraping, I look forward to seeing whatever they produce with this CC-BY-SA data that I'm sure they will follow the license of and republish their findings under the same license.
RE: https://mastodon.social/@andrewnez/117032582823441702
Investigating this today, looks like there's a new residential proxy scraping the html of the various ecosyste.ms services, not the json api.
Useragent is all last years chrome on desktop mac, all executing js and passing anubis, see if I can make some tweaks to that config to shut it down.
92m requests to @ecosystems so far today, the biggest single day I've ever seen 🫠
Replying to @andrewnez@mastodon.social
It’s now up to 101m 🫣
92m requests to @ecosystems so far today, the biggest single day I've ever seen 🫠
