Andrew NesbittHow This Blog Is BuiltA full walkthrough of the custom static site generator, content pipeline, and edge deployment behind nesbitt.io.Andrew Nesbitt
Package Management Nerd, working on mapping the world of open source software https://ecosyste.ms and blogging about package managers at https://nesbitt.io
- GitHub
- https://github.com/andrew verified
- https://twitter.com/teabass
- Homepage
- https://nesbitt.io verified
Andrew NesbittHow This Blog Is BuiltA full walkthrough of the custom static site generator, content pipeline, and edge deployment behind nesbitt.io.Replying to @edorian@phpc.social
@edorian where do you think I get my inspiration from?
Tripped over this cursed bit of software today, look at that massive readme diagram: https://github.com/raydac/mvn-golang
GitHubGitHub - raydac/mvn-golang: maven plugin to automate GoSDK load and build of projectsmaven plugin to automate GoSDK load and build of projects - raydac/mvn-golangReplying to @Floppy@mastodon.me.uk
@Floppy the notification APIs across gitlab and forgejo are pretty terrible, so would be hard to get something close to octobox, if it was easier I would have already done it as I have the same problem
Replying to @sundaram123krishnan@mastodon.social
@sundaram123krishnan this is awesome!
Something I've been working on recently to improve testing around dependencies: https://github.com/alpha-omega-security/hyrum
Reuses a lot of pieces of git-pkgs and scrutineer
GitHubGitHub - alpha-omega-security/hyrum: Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness.Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness. - alpha-omega-security/hyrumReplying to @rachel@tech.lgbt
@rachel it’s also already installed in all Linux and Mac OS GitHub action runners
Shared Code Between Package Managers
https://nesbitt.io/2026/08/11/package-manager-library-reuse.html
Andrew NesbittShared Code Between Package ManagersWhich package-management libraries twenty package managers reuse from each other.Replying to @jnunemaker@ruby.social
@jnunemaker libcurl backend
Replying to @voxpelli.com@bsky.brid.gy
@voxpelli.com one small part: https://github.com/git-pkgs/downstream another I'm hoping to publish tomorrow
the index will be the most challenging as it could end up huge, will likely focus on the top 1% of packages to begin with.
Replying to @voxpelli.com@bsky.brid.gy
@voxpelli.com funny you should mention that, I’m working on some parts of that at the moment, although actually deploying it at scale would be a way off atm
Replying to @jacques@mastodon.chester.id.au
@jacques yep, it’s not nice, it was Hugo or Jekyll for me
Replying to @ripienaar@devco.social
@ripienaar I’ve been using it for git-pkgs.dev for the past 6 months without issue
Thinking of adding support for vendored dependencies to git-pkgs: https://github.com/git-pkgs/git-pkgs/issues/317
I had enough of getting daily security warnings on the hundreds of npm dependencies of Docusaurus so I'm switching https://docs.ecosyste.ms to use hugo: https://github.com/ecosyste-ms/docs/pull/115
This Week in Package Management: 8 August 2026
https://nesbitt.io/2026/08/08/this-week-in-package-management.html
Andrew NesbittThis Week in Package Management: 8 August 2026Releases, advisories, and articles from across the package management worldThe Software Stewardship Lab
https://nesbitt.io/2026/08/07/the-software-stewardship-lab.html
Andrew NesbittThe Software Stewardship LabA new applied research lab for open source sustainability, launching todayA year of AI disclosure in critical packages: https://nesbitt.io/2026/08/06/a-year-of-ai-disclosure-in-critical-packages.html
Andrew NesbittA year of AI disclosure in critical packagesAssisted-By: Daniel StenbergRE: https://mastodon.social/@andrewnez/117031823385268173
I’m now getting daily reminder emails that I have not responded to this request yet. 😬
Paraphrasing an email from a security company : We copied one of your blog posts and turned into an advert for one of our products. Please add a link to our blog post to the end of yours. 🥉