Andrew Nesbitt

@andrewnez@mastodon.social · Joined ⁨Apr⁩ ⁨2017⁩

Package Management Nerd, working on mapping the world of open source software ecosyste.ms and blogging about package managers at nesbitt.io

Homepage
nesbitt.io verified

Andrew Nesbitt boosted

zizmor 1.29.0 is released!

this release comes with a number of enhancements and bug fixes, but the big one is that we now support auditing pre-commit inputs! support is limited to just a single audit for now, but will expand over subsequent releases.

full notes: docs.zizmor.sh/release-notes/#

docs.zizmor.sh/release-notes/#1290
docs.zizmor.shRelease Notes - zizmorAbbreviated change notes about each zizmor release.

Andrew Nesbitt boosted

Let’s Play “htmx 4: the game” 🐴

#htmx 4 was published exclusively for the Game Boy and Game Boy Color platforms. I recorded my play-through including the source code. This game is tough!

sethmlarson.dev/htmx-4-the-game

#web #gameboy #gbdev #retrogaming

sethmlarson.dev/htmx-4-the-game
sethmlarson.devLet’s Play “htmx 4: the game”Moments ago I just finished playing “htmx 4: the game”, the first JavaScript library published exclusively for Game Boy and Game Boy Color. I've recorded my play session and published the video to ...by Seth Michael Larson

Andrew Nesbitt boosted

The GitHub BlogReference same-repository actions with self-repository syntax - GitHub ChangelogYou can now reference an action or reusable workflow that lives in the same repository using the new self-repository syntax. A uses: value that starts with $/ resolves to your…

Andrew Nesbitt boosted

I wrote a blog post

You don't have a supply chain, you have a supply soup

This is something I want to spend some time investigating in the future, it's all vastly more complicated and weird than we think it is

opensourcesecurity.io/2026/07-

opensourcesecurity.io/2026/07-supply-soup/
Open Source SecurityBlog - You don't have a supply chain, you have supply soup2026 has been a wild year. There are more vulnerabilities than anyone can count. We seem to keep talking about the number itself instead of things like how we got here or what we’re going to do about it, which is neat. The number of attacks against open source is basically an uncountable mess. Also very neat. And the cherry on top of this poop sundae is number of companies that have promised us they are going to “fix” open source, and when they use the word fix they really mean sell you a solution for a problem they mostly made up. Very cool, very cool.

Replying to @⁨bupd@mastodon.social⁩

@bupd related issue you might want to track: github.com/git-pkgs/git-pkgs/i

Use case We generate attribution artifacts for a few hundred internal repos (Go, Ruby, npm, Python). For every resolved dependency we need the SPDX identifier and the verbatim license text (plus NO...GitHublicenses: option to emit full license text per dependency (--license-text) · Issue #294 · git-pkgs/git-pkgsUse case We generate attribution artifacts for a few hundred internal repos (Go, Ruby, npm, Python). For every resolved dependency we need the SPDX identifier and the verbatim license text (plus NO...by taltcher

Working on a license scanner for git-pkgs, uses the scancode license rule corpus but much, much faster and less resource intensive: github.com/git-pkgs/licenses

My plan is to eventually use it to scan every version of every package with it soon.

Fast exact license matching against ScanCode's rule corpus in pure Go. - git-pkgs/licensesGitHubGitHub - git-pkgs/licenses: Fast exact license matching against ScanCode's rule corpus in pure Go.Fast exact license matching against ScanCode's rule corpus in pure Go. - git-pkgs/licenses

Andrew Nesbitt boosted

When people wonder why I wrote softwaremaxims.com/blog/open-s and why I am angry...

I just received the OpenSource Summit schedule from a LF newsletter.

And it is fascinating how much it can be all stuff from Alpha Centauri that have nothing to do with the realities of FOSS.

Like, I know for who it is. I get it. But also, why do you happily pay to be misinformed if you are in a decision making position?

I mean, I know why. I get it. But still, this is such a waste of money and time that is precious for everyone.

Musings about softwareYou Are All On The Hobbyists Maintainers’ Turf NowFor quite some time, I have felt some unease at the public discourse around OpenSource. In the past few years, we have seen a growing discourse around the sustainability and security of the large body of OpenSource software.