Replying to @wolf480pl@mstdn.io
@wolf480pl yep!
Package Management Nerd, working on mapping the world of open source software https://ecosyste.ms and blogging about package managers at https://nesbitt.io
Replying to @wolf480pl@mstdn.io
@wolf480pl yep!
Picked up a little project to keep me away from the computer this summer.
Replying to @sharlatan@mastodon.social
@sharlatan I’ve started looking but not got anything concrete yet, working on it though
The AI Phrasebook
https://nesbitt.io/2026/07/31/the-ai-phrasebook.html
nesbitt.io/2026/07/31/the-ai-phrasebook.html
Andrew NesbittThe AI PhrasebookWe have autonomous agents at home.Replying to @bupd@mastodon.social
@bupd related issue you might want to track: https://github.com/git-pkgs/git-pkgs/issues/294
GitHublicenses: option to emit full license text per dependency (--license-text) · Issue #294 · git-pkgs/git-pkgsUse case We generate attribution artifacts for a few hundred internal repos (Go, Ruby, npm, Python). For every resolved dependency we need the SPDX identifier and the verbatim license text (plus NO...Working on a license scanner for git-pkgs, uses the scancode license rule corpus but much, much faster and less resource intensive: https://github.com/git-pkgs/licenses
My plan is to eventually use it to scan every version of every package with it soon.
GitHubGitHub - git-pkgs/licenses: Fast exact license matching against ScanCode's rule corpus in pure Go.Fast exact license matching against ScanCode's rule corpus in pure Go. - git-pkgs/licensesReplying to @Di4na@hachyderm.io
@Di4na @Zimm_i48 @joshbressers I have some data on usage of FOSS libraries within private code bases if someone wants to do this research, also paging @vlad
Wheels, Bottles and Images
Andrew NesbittWheels, Bottles and ImagesAny sufficiently advanced package manager is indistinguishable from a container registry.Replying to @defuneste@fosstodon.org
@defuneste I’m still very dependent on https://octobox.io to stay on top of everything all these years later
OctoboxOctoboxUntangle your GitHub NotificationsReplying to @defuneste@fosstodon.org
@defuneste notifications is such a mess 🫠
Why npm Dependency Trees Are So Big
https://nesbitt.io/2026/07/28/why-npm-dependency-trees-are-so-big.html
Andrew NesbittWhy npm Dependency Trees Are So BigTwo versions of lodash walk into a treeReplying to @gvwilson@mastodon.social
@gvwilson I’m amazed they managed to find that many in the wild, no-one in oss uses them
Replying to @jacques@mastodon.chester.id.au
@jacques syncing details for all the packages, repos, registries etc
Replying to @veganstraightedge@ruby.social
@veganstraightedge fun research though, I’ve been meaning to do more classification of packages using https://github.com/ecosyste-ms/oss-taxonomy to aid discovery
GitHubGitHub - ecosyste-ms/oss-taxonomy: A structured, open-source taxonomy for classifying open source software projects.A structured, open-source taxonomy for classifying open source software projects. - ecosyste-ms/oss-taxonomyReplying to @veganstraightedge@ruby.social
@veganstraightedge I think there’s some legacy ones there, you can’t register new ones that clash with different cases, similar thing in the first 1k npm packages
Replying to @jezdez@publicidentity.net
@jezdez yep, will get it added for next weeks, also fascinating to read, shame I couldn’t be there
Anyone else get the fear when they get a dependabot update for anything called xz? https://github.com/git-pkgs/archives/pull/18
GitHubBump github.com/ulikunitz/xz from 0.5.15 to 0.5.16 by dependabot[bot] · Pull Request #18 · git-pkgs/archivesBumps github.com/ulikunitz/xz from 0.5.15 to 0.5.16.
Commits
024f909 isterminal_fallback.go: ensure +build and go:build lines are consistent
ba40d80 Prepare release v0.5.16
82b346c internal/term:...This Week in Package Management: 25 July 2026
https://nesbitt.io/2026/07/25/this-week-in-package-management.html
Andrew NesbittThis Week in Package Management: 25 July 2026Releases, advisories, and articles from across the package management world