the tetris we need
27.02.2026 18:57 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 0@andrewnez.bsky.social
Working on mapping the world of open source software https://ecosyste.ms and empowering developers with https://octobox.io Mostly posting on https://mastodon.social/@andrewnez
the tetris we need
27.02.2026 18:57 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 0One of the motivations behind #OpenSource Wishlist was to promote the knowledge that we actually know exactly how to fix MOST sustainability issues, but you need to pay someone to do the work
sunnydeveloper.com/open-source-...
Instead of using git as a database, what if you used database as a git?
nesbitt.io/2026/02/26/g...
Two Kinds of Attestation: nesbitt.io/2026/02/25/t...
25.02.2026 10:33 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Respecting maintainer time should be in security policies. Even better: you don't even have to mention the elephant in the room!
sethmlarson.dev/respecting-m...
#opensource #oss #security
Reproducible Builds in Language Package Managers: nesbitt.io/2026/02/24/r...
24.02.2026 10:25 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0"Package Managers ร la Carte, A Formal Model of Dependency Resolution" preprint out today: a new package calculus to describe the cambrian explosion of systems that exist today arxiv.org/pdf/2602.18602 lead by @ryan.freumh.org
24.02.2026 09:29 โ ๐ 22 ๐ 9 ๐ฌ 2 ๐ 0Where Do Specifications Fit in the Dependency Tree? nesbitt.io/2026/02/23/w...
23.02.2026 11:38 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Forge-Specific Repository Folders: nesbitt.io/2026/02/22/f...
22.02.2026 13:21 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0What happens when a large open source project dies?
nesbitt.io/2026/02/21/w...
A Wikipedia article about the history of ActivityPub: nesbitt.io/2026/02/20/a...
20.02.2026 10:28 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0I've been rebuilding my Ruby supply chain libraries in Go for git-pkgs, 14 modules so far. Here's a tour: nesbitt.io/2026/02/19/g...
19.02.2026 12:35 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0What Package Registries Could Borrow from OCI: nesbitt.io/2026/02/18/w...
18.02.2026 13:00 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0It's time for a platform strings deep-dive.
An M1 Mac is aarch64-apple-darwin, arm64-darwin, darwin/arm64, or macosx_11_0_arm64 depending on which tool you ask.
nesbitt.io/2026/02/17/p...
What happens when you remove a 14MB dependency and vibe code a replacement: nesbitt.io/2026/02/16/c...
16.02.2026 10:40 โ ๐ 5 ๐ 0 ๐ฌ 1 ๐ 0โI donโt want AI slop in my codebase. Anyway, hereโs my 2,000-package JavaScript dependency tree.โ
15.02.2026 22:06 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0Most package managers were designed for laptops with warm caches, not ephemeral Docker builds that start clean every time: nesbitt.io/2026/02/15/s...
15.02.2026 11:50 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Took a stab at categorising different kinds of namespaces in package management: nesbitt.io/2026/02/14/p...
14.02.2026 11:00 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Andrew nails here many parts of what actually makes OSS maintaining hard work.
Empathy is needed more for OSS sustainability than money.
This post about "Respectful Open Source" by @andrewnez.bsky.social inspired me to have Claude build forkwatch, a tool that analyzes forks of any repo and highlights where multiple forks converge on the same fix.
nesbitt.io/2026/02/13/respectful-open-source.html
github.com/stympy/forkwatch
Wish I had a larger audience to share this with. A clear, measured take on a risk at the heart of the OSS experiment.
Takes me back to questions of moderation in open spaces. Once, just hurdling natural participation barriers was good-enough user verification. In a sea of AI bots, it isn't.
Treating Maintainer attention as a finite resource: nesbitt.io/2026/02/13/r...
13.02.2026 11:31 โ ๐ 20 ๐ 10 ๐ฌ 0 ๐ 1OSS Is Going Just Great: nesbitt.io/oss-is-going...
12.02.2026 18:18 โ ๐ 2 ๐ 2 ๐ฌ 0 ๐ 0Follow me down another rabbit hole and discover the many flavors of ignore files: nesbitt.io/2026/02/12/t...
12.02.2026 10:44 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0added, thanks!
11.02.2026 14:26 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Why almost nobody vendors their dependencies anymore: nesbitt.io/2026/02/10/l...
10.02.2026 11:15 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0Every package manager related podcast episode I could find: nesbitt.io/2026/02/09/p...
If you know of more please share or send a PR
SBOM 1.0: A specification for sandwich supply chain transparency.
nesbitt.io/2026/02/08/s...