November 2025's Desert Island Discs (1 mins read).
Defining the 8 songs I'd take to a desert island (if I had the choice, of course).
Post details
Prolific software blogger, Sean Goedecke, joins us to discuss why he believes software engineers need to be involved in the politics of their organization, how to avoid worry driven development, what is "good taste" in software engineering, where agentic coding will take our industry, why getting the main thing right i...
Post details
Welcome back to Break, a Fallthrough aftershow! Sometimes we record an episode and don't ship it for a while. This is the case for this episode, which we recorded all the way back on July 30th! In it Kris and Matt discuss their, at the time, yet to be recorded episode with Mitchell Hashimoto,...

Post details
Software engineering has an identity problem. Some software engineers want to be craftspeople and artisans, while others want to be more like the traditional engineers, while others just want to write some code. In this episode, Kris and Matt talk about the state of software engineering today and...

Post details
Josh chats with Charlie Eriksen, a security researcher at Aikido Security. We discuss the recent NPM supply chain attacks that affect hundreds of packages. Charlie shares his experiences dealing with recent security breaches, the challenges of maintaining trust in open source software, and the importance of proactive measures to safeguard open source. The rapid pace of change is impacting our security practices and what steps can be taken to foster resilience in the face of evolving threats. The show notes and blog post for this episode can be found at
Post details
My first advice to junior contributors is to STOP using vibe coding for PRs. OSS is always about people more than about code. We don't need more code generated by LLM, we need more people who care.
Post details
(isbn:9781841499932)Post details
đ Go 1.25.4 and 1.24.10 are releasedThe Geomys Standard of CaređĄïž Claude Code Can Debug Low-level Cryptographyđ« go podcast() episode 64: Podman, the root-less alternative to Docker

Week Notes 25#45 (2 mins read).
What happened in the week of 2025-11-03?
Post details
Rita Kozlov is the VP of Developers and AI at Cloudflare. We talk about how Cloudflare focuses on building disruptive, efficient technologies like their Workers...

Post details
GitHub is updating how GitHub Actionsâ pull_request_target and environment branch protection rules are evaluated for pull-request-related events. These changes will take effect on 12/8/2025. They aim to reduce security criticalâŠ

Post details
In this episode of Engineering Enablement, host Laura Tacho talks with Fabien Deshayes, who leads multiple platform engineering teams at Monzo Bank. Fabien explains how Monzo is adopting AI responsibly within a highly regulated industry, balancing innovation with structure, control, and...

Post details
Tim Banks will optimize your modem baud rate and kick your assârespectfully. Then they'll teach you how to be a better person. Their career includes systems, sales, and many other facets of business, but who they are is not defined by what they do for money. Join us on this wonderful conversation...

Post details
When you become disabled thereâs a few things you notice right away: Ableism is everywhere. People will abandon you. Even those you were certain would stick by you. Just because something is illegal or against human rights code doesnât mean itâs not happening ALL the time Accessibility is not what it should be. People will blame you for your disabilities. It wonât matter what you do or how hard you try, you wonât be âgood enoughâ All the misconceptions you had about disabled people were wrong. Thatâs really the crux of it. Disability is a minority group you can join anytime. Most people will experience disability in their lifetime Yet discriminating against us is not only common itâs socially acceptable. Most people donât realize how misguided they are until it happens to them Many of us living with chronic illness had the same preconceived notions about disabled people until we became disabled ourselves We thought it wasnât âthat badâ. We believed we would be the exception Many of us became advocates because the realization that we were so horribly wrong shook us to our core. If we had that much ableism to work through, then so does everyone else. Thatâs why we need strong allies. We need people who will say disabled lives matter. We need to shift the public perception away from the idea that disability is a moral failing. We need to be visible, take up space and help people realize that all health is temporary and disability happens to almost everyone. Inclusion and accessibility matter! #disability #ableism #eugenics #chronicillness
Post details
Andrew Nesbitt builds tools and open datasets to support, sustain, and secure critical digital infrastructure. He's been exploring the world of open source metadata for over a decade. First with libraries.io and now with ecosyste.ms, which tracks over 12 million packages, 287 million repos, 24.5 billion dependencies, a...
My first blog post on the #Mend blog is naturally all about #Renovate: Building a more secure npm ecosystem with Mend Renovate
This has been something we've been building up to for ~2 months of hard work making it as predictable as possible, highly documented and builds on top of ~6 years of Renovate having this functionality
Post details
Supply chain attacks exploit fundamental trust assumptions in modern software development, from typosquatting to compromised build pipelines, while new defensive tools are emerging to make these trust relationships explicit and verifiable.

Building a more secure npm ecosystem with Mend Renovate (5 mins read).

Discover how Mend Renovate 42 is strengthening npm ecosystem security with "minimum release ageâ enforcement and best-practice defaults.
Post details
We are excited to announce the Call for Participation for the Package Managers devroom at @fosdem@fosstodon.org 2026, taking place on Saturday, 31st January 2026 at the Université libre de Bruxelles, Belgium. Submission deadline: 1st December 2025 https://blog.ecosyste.ms/2025/11/06/fosdem-2026-package-managers-devroom-cfp.html
I will be attending
Post details
What's in the SOSS? features the sharpest minds in security as they dig into the challenges and opportunities that create a recipe for success in making software more secure. Get a taste of all the ingredients that make up secure open source ...

Post details
We were very excited to see last week we hit 20,000(!) GitHub Stars on the #Renovate project đ Thanks to our amazing community + users đ€
Post details
Welcome back to Break, a Fallthrough aftershow! In this episode, Kris, Ian, and Matt extend their discussion from Fallthrough episode #44.Enjoying the aftershow? Let us know on social media! If you prefer to watch instead of just listen, head over to YouTube where you watch this episode of...

Post details
First it was GCP in June. Then it was AWS in October. Then it was Azure a week later. It seems that our cloud providers are having outages far more often, and for far longer, than any of us would like. In this episode, Kris, Ian, and Matthew discuss the two most recent outages along with some of...

Post details
Victor, VP of Marketing at Strapi, walks us through how AI can be used in content creationâwhat tools work, what to watch out for, and how you can try some of...

Post details
My desire to run a sustainable software business started somewhere near 2003 in the Business of Software forum. I've built, sold, and acquired a dozen of products since that time, with I have to admit the majority of failures.I've seen three distincts era for software companies, we're definitably...

Post details
In this episode, Josh and Otto dive into the world of Debian packaging, exploring the challenges of supply chain security and the importance of transparency in open source projects. They discuss Otto's blog post about the XZ backdoor and how it's a nearly impossible attack to detect. Otto does a great job breaking down an incredibly complex problem into understandable pieces. The show notes and blog post for this episode can be found at
Week Notes 25#44 (2 mins read).
What happened in the week of 2025-10-27?
Post details
Guy Zerega led sales and marketing at Stack Overflow, where he once hired me.Now he leads sales at Cyborg - they offer end-to-end encrypted inference data. This...

Post details
In late 2021, the Log4Shell vulnerability sent shockwaves through the global tech community. For the first time, we're sharing the untold, inside story from ...

Post details
New proposal: go vet check for using %q with integer typesBlog: I'm Independently Verifying Go's Reproducible Builds by Andrew AyerJetBrains' language promise indexReddit: Why I built a ~39M op/s, zero-allocation ring buffer for file watchingBlog: A modern approach to preventing CSRF in Go

Post details

Post details
Adam Jacob joins us to discuss how agentic systems for building and managing infrastructure have fundamentally altered how he thinks about everything, including the last six years of his life. Along the way, he opines on the recent AWS outage, debates whether we're in an AI-induced bubble, quells any concerns of AGI an...
Post details
It's a FRIGHT...when your record a podcast with dead projects all around. Tech debt, poor choices, timing, market shift, and optimizing for the wrong things are all lurking around waiting to pop out at you! Just don't forget to push record.
Why, yes I am having to spend my Sunday morning looking into reducing the impact of bot scraping on my website after a significantly large AWS bill, why do you ask?

Post details
Pretty sure I have the scariest engineering costume of the day.
Post details
Welcome back to Break, a Fallthrough aftershow! In this episode, Kris, Matt, and Steve talk extend their discussion from Fallthrough episode #43.Enjoying the aftershow? Let us know on social media! If you prefer to watch instead of just listen, head over to YouTube where you watch this episode of...

Post details
Jujutsu is a new version control system that's gaining in popularity. Its swappable backends allow users to continue using version control systems like Git without other users even noticing. Steve Klabnik aims to be a big part of it. Much like with Rust, he's getting involved early and making...
