Post details
This post requires authentication to view.
This content type is full of IndieWeb post types, which are all content types which allow me to take greater ownership of my own data. These are likely unrelated to my blog posts. You can find a better breakdown by actual post kind below:
This post requires authentication to view.
Andrew Nesbitt builds tools and open datasets to support, sustain, and secure critical digital infrastructure. He's been exploring the world of open source metadata for over a decade. First with libraries.io and now with ecosyste.ms, which tracks over 12 million packages, 287 million repos, 24.5 billion dependencies, a...
My first blog post on the #Mend blog is naturally all about #Renovate: Building a more secure npm ecosystem with Mend Renovate
This has been something we've been building up to for ~2 months of hard work making it as predictable as possible, highly documented and builds on top of ~6 years of Renovate having this functionality
Thank you for being open and sharing 💜 ADHD can really suck, especially once we learn what it is and have to unpack how it's shaped us
It’s been quite a year of self-discovery.
Between and I took 6566 steps.
Supply chain attacks exploit fundamental trust assumptions in modern software development, from typosquatting to compromised build pipelines, while new defensive tools are emerging to make these trust relationships explicit and verifiable.

We are excited to announce the Call for Participation for the Package Managers devroom at @fosdem@fosstodon.org 2026, taking place on Saturday, 31st January 2026 at the Université libre de Bruxelles, Belgium. Submission deadline: 1st December 2025 https://blog.ecosyste.ms/2025/11/06/fosdem-2026-package-managers-devroom-cfp.html
Between and I took 6298 steps.
I will be attending
Events in the US right now are a mistake
By the way, a really fun thing about getting added to a years-old private channel is the backscroll. :)
What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source ...

We were very excited to see last week we hit 20,000(!) GitHub Stars on the #Renovate project 🚀 Thanks to our amazing community + users 🤗
The entire right-wing propaganda machine came after Zohran Mamdani. The president and his allies came after him. Democratic leaders, by and large, did not have his back until the last minute. He still won, turning out historic numbers and inspiring young voters. His politics can win anywhere.
Welcome back to Break, a Fallthrough aftershow! In this episode, Kris, Ian, and Matt extend their discussion from Fallthrough episode #44.Enjoying the aftershow? Let us know on social media! If you prefer to watch instead of just listen, head over to YouTube where you watch this episode of...

i hope this election cycle empowers everyone the next time a centrist liberal says to drop pro-trans and pro-immigrant rhetoric to enthusiastically tell them to shut the fuck up
Good things are possible and we don’t have to settle.
If you’re wondering what the future of the Democratic Party looks like, watch the young, brown democratic socialist on the TV right now.
This post requires authentication to view.
Between and I took 2659 steps.
Congrats! They're super lucky to have you and your expertise, looking forward to seeing what y'all do 🙌🏽
First it was GCP in June. Then it was AWS in October. Then it was Azure a week later. It seems that our cloud providers are having outages far more often, and for far longer, than any of us would like. In this episode, Kris, Ian, and Matthew discuss the two most recent outages along with some of...

Victor, VP of Marketing at Strapi, walks us through how AI can be used in content creation—what tools work, what to watch out for, and how you can try some of...

Between and I took 2354 steps.
My desire to run a sustainable software business started somewhere near 2003 in the Business of Software forum. I've built, sold, and acquired a dozen of products since that time, with I have to admit the majority of failures.I've seen three distincts era for software companies, we're definitably...

In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto's blog post about the XZ backdoor and how it's a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces. The show notes and blog post for this episode can be found at
Between and I took 7082 steps.
Guy Zerega led sales and marketing at Stack Overflow, where he once hired me.Now he leads sales at Cyborg - they offer end-to-end encrypted inference data. This...

In late 2021, the Log4Shell vulnerability sent shockwaves through the global tech community. For the first time, we're sharing the untold, inside story from ...

New proposal: go vet check for using %q with integer typesBlog: I'm Independently Verifying Go's Reproducible Builds by Andrew AyerJetBrains' language promise indexReddit: Why I built a ~39M op/s, zero-allocation ring buffer for file watchingBlog: A modern approach to preventing CSRF in Go


Adam Jacob joins us to discuss how agentic systems for building and managing infrastructure have fundamentally altered how he thinks about everything, including the last six years of his life. Along the way, he opines on the recent AWS outage, debates whether we're in an AI-induced bubble, quells any concerns of AGI an...
It's a FRIGHT...when your record a podcast with dead projects all around. Tech debt, poor choices, timing, market shift, and optimizing for the wrong things are all lurking around waiting to pop out at you! Just don't forget to push record.
Why, yes I am having to spend my Sunday morning looking into reducing the impact of bot scraping on my website after a significantly large AWS bill, why do you ask?

This post requires authentication to view.
It’s basically Deep Space Nine. [contains quote post or other embedded content]
Between and I took 4995 steps.
Some readers read every word, others skim. Some readers speak your language, others don't. Some readers read the original version, others a summary.
Between and I took 4167 steps.
Pretty sure I have the scariest engineering costume of the day.