Andrew Nesbitt boosted
Andrew NesbittHow This Blog Is BuiltA full walkthrough of the custom static site generator, content pipeline, and edge deployment behind nesbitt.io.Package Management Nerd, working on mapping the world of open source software https://ecosyste.ms and blogging about package managers at https://nesbitt.io
Andrew Nesbitt boosted
Andrew NesbittHow This Blog Is BuiltA full walkthrough of the custom static site generator, content pipeline, and edge deployment behind nesbitt.io.Andrew Nesbitt boosted
If you want to be involved in the Python Packaging Council elections, register to vote before August 25! I'm there, along with 16 other fantastic choices. https://blog.python.org/2026/08/2026-packaging-council-nominees/ and ask me questions at https://discuss.python.org/t/ppc-nomination-ama-for-henry-schreiner !
Andrew Nesbitt boosted
What's the difference between a package index and a package registry? One helps you discover packages, the other hosts and serves them. 📦 A new post explains how they fit together. Read more: https://swiftpackageindex.com/blog/what-is-a-package-registry
swiftpackageindex.com/blog/what-is-a-package-registryAndrew Nesbitt boosted
Richard Scarry already summarized everything there is to know about cyber security, about 50 years ago.
Andrew Nesbitt boosted
Ethics aside, we can clearly no longer deny the utility of necromancy. Perhaps a year ago, when the pathetic shambling of the animated dead so often made a hollow mockery of our arts. But now! Incantations that once took weeks of toil can be wrested from their tormented souls in mere minutes!
Without the awesome power of the newly dead coursing through our veins, how are we to solve the great problems of our age, like the mysterious disappearance of so many of our elderly and sick friends, or the festering piles of rotten flesh that now clog our streets and homes?
If you still have qualms about using the large soul providers, you can always obtain your own local, free range specimens, although of course they won’t obey quite as faithfully as ones from the leading charnel houses.
Honestly, do you want to be left behind?
Andrew Nesbitt boosted
Replying to @andrewnez@mastodon.social
@andrewnez You’ve missed out on a perfectly good opportunity to overengineer something simple.
Andrew NesbittHow This Blog Is BuiltA full walkthrough of the custom static site generator, content pipeline, and edge deployment behind nesbitt.io.Andrew Nesbitt boosted
Replying to @edorian@phpc.social
@edorian where do you think I get my inspiration from?
Andrew Nesbitt boosted
@andrewnez MY EYES
Tripped over this cursed bit of software today, look at that massive readme diagram: https://github.com/raydac/mvn-golang
GitHubGitHub - raydac/mvn-golang: maven plugin to automate GoSDK load and build of projectsmaven plugin to automate GoSDK load and build of projects - raydac/mvn-golangAndrew Nesbitt boosted
So much of the critical infrastructure that we all rely on contains open source projects that are under-resourced and struggling. One way to help these projects is by funding development and maintenance so that contributors can focus on this work, but it can be hard to justify continuing to fund open source projects. Measuring the impact of open source funding is the best way to continue to fund open source because it allows you to show leadership and other stakeholders the impact of that funding. Here's a blog post to get you started, and I'm available for consulting engagements on this topic.
https://fastwonderblog.com/2026/06/02/how-ospos-can-measure-the-impact-of-oss-funding/
Replying to @Floppy@mastodon.me.uk
@Floppy the notification APIs across gitlab and forgejo are pretty terrible, so would be hard to get something close to octobox, if it was easier I would have already done it as I have the same problem
Andrew Nesbitt boosted
A line I'm going to 100% steal from the meeting I'm in right now: "our circle is now a pretzel".
Replying to @sundaram123krishnan@mastodon.social
@sundaram123krishnan this is awesome!
Andrew Nesbitt boosted
@sundaram123krishnan wrote "PyPI dependencies, resolved and built for you" about the new tool 'coprtree' that utilizes data from ecosyste.ms.
https://fedora-copr.github.io//posts/pypi-dependencies-resolved-and-built-for-you
Andrew Nesbitt boosted
⋆。 ̊ ☁︎ ̊。⋆。 ̊☽ ̊。⋆
Something I've been working on recently to improve testing around dependencies: https://github.com/alpha-omega-security/hyrum
Reuses a lot of pieces of git-pkgs and scrutineer
GitHubGitHub - alpha-omega-security/hyrum: Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness.Generate hermetic tests that capture how a repository uses each of its dependencies. Built on git-pkgs and alpha-omega-security/harness. - alpha-omega-security/hyrumReplying to @rachel@tech.lgbt
@rachel it’s also already installed in all Linux and Mac OS GitHub action runners