Andrew Nesbitt

@andrewnez@mastodon.social · Joined ⁨Apr⁩ ⁨2017⁩

Package Management Nerd, working on mapping the world of open source software ecosyste.ms and blogging about package managers at nesbitt.io

Homepage
nesbitt.io verified

Something I've been working on recently to improve testing around dependencies: github.com/alpha-omega-securit

Reuses a lot of pieces of git-pkgs and scrutineer

Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness. - alpha-omega-security/hyrumGitHubGitHub - alpha-omega-security/hyrum: Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness.Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness. - alpha-omega-security/hyrum

Thinking of adding support for vendored dependencies to git-pkgs: github.com/git-pkgs/git-pkgs/i

I would like git-pkgs to report dependencies whose package contents or cached artifacts are committed to a repository. Working-directory scans honor .gitignore, but historical scans inspect every t...GitHubDetect and report vendored dependencies · Issue #317 · git-pkgs/git-pkgsI would like git-pkgs to report dependencies whose package contents or cached artifacts are committed to a repository. Working-directory scans honor .gitignore, but historical scans inspect every t...by andrew

github.com/chaoss/disclosure is proving to be a very useful tool in analysing disclosure of ai contributions to oss projects.

Github Action to gather signals of disclosed AI contribution to aid community health monitoring tools and open source maintainers - chaoss/disclosureGitHubGitHub - chaoss/disclosure: Github Action to gather signals of disclosed AI contribution to aid community health monitoring tools and open source maintainersGithub Action to gather signals of disclosed AI contribution to aid community health monitoring tools and open source maintainers - chaoss/disclosure

RE: mastodon.social/@andrewnez/117

Investigating this today, looks like there's a new residential proxy scraping the html of the various ecosyste.ms services, not the json api.

Useragent is all last years chrome on desktop mac, all executing js and passing anubis, see if I can make some tweaks to that config to shut it down.

Andrew Nesbitt@andrewnez@mastodon.social

92m requests to @ecosystems so far today, the biggest single day I've ever seen 🫠