ecosyste.ms | Tools and datasets to support, sustain, and secure critical digital infrastructure.
Tools and datasets to support, sustain, and secure critical digital infrastructure.
Check out a recent episode of the @sustainoss.bsky.social podcast with @richlitt.bsky.social , featuring Ben and @andrewnez.bsky.social , as they discuss ecosyste.ms, a project using open source metadata to help guide funding across entire ecosystems.
Listen here: podcast.sustainoss.org/270
12.06.2025 19:31 โ ๐ 3 ๐ 1 ๐ฌ 0 ๐ 0
We should fund the software we use, not just the software we see | Open Source Pledge
Ben Nickolls and Andrew Nesbitt tell us about Ecosystem Funds, their one-stop-shop for funding open source dependencies
We asked @andrewnez.bsky.social and Benjamin Nickolls to tell us about Ecosystem Funds, their one-stop shop for helping orgs fund the Open Source software they actually depend on.
09.06.2025 18:36 โ ๐ 7 ๐ 3 ๐ฌ 0 ๐ 0
Ecosyste.ms with Andrew Nesbitt
I recently chatted with Andrew Nesbitt about his project, Ecosyste.ms. Ecosyste.ms catalogs open source projects by tracking packages, dependencies, repositories, and more. With this dataset Andrew is...
This week #OpenSourceSecurity chats with @andrewnez.bsky.social about Ecosyste.ms
Ecosyste.ms is a massive collection of data about open source
It's an amazingly useful collection of data. If you're doing anything that needs information about open source you should check it out
02.06.2025 17:58 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0
10 Simple Rules for making your code last beyond your current job
10 Simple Rules for making your code last beyond your current job This is a draft: the goal is a preprint on ORCID, and then to submit a version of this to PLoS. All suggestions or comments are welcom...
I've been working on a guide: "10 Simple Rules for making your code last beyond your current job"
1. Get sign off
2. Put it somewhere
3. License it
4. Document it
5. Make it citable
โฆ
What am I missing? What would you add?
docs.google.com/document/d/1...
#academia #research #code
08.04.2025 20:33 โ ๐ 6 ๐ 2 ๐ฌ 0 ๐ 1
Ecosystem Funds is Generally Available
Today Open Source Collective and ecosyste.ms are launching Funds supporting 291 Open Source Ecosystems. Unsurprisingly, we call them Ecosystem Funds.
So far, weโve distributed 375 payments to 136 projects โ over 80% of the funds already in the hands of maintainers. Weโre aiming to distribute the rest this month, and weโd love for you to be part of it. Learn more and get involved: blog.ecosyste.ms/2025/04/04/e...
08.04.2025 17:30 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 1
Weโre excited to announce Ecosystem Funds (funds.ecosyste.ms ), a partnership between Open Source Collective and ecosyste.ms, now open to the public. This initiative is transforming how we fund the dependencies we all rely on by making it easy to support the open source tech you depend on. ๐งต
08.04.2025 17:30 โ ๐ 5 ๐ 3 ๐ฌ 1 ๐ 0
Ecosystem Funds is Generally Available
**Today Open Source Collective and ecosyste.ms are launching Funds supporting 291 Open Source Ecosystems. Unsurprisingly, we call them Ecosystem Funds.**
A few, short weeks before the holidays we announced Ecosystem Funds; a collaboration between Open Source Collective and ecosyste.ms that makes it easier to support your critical software dependencies.
### What are Ecosystem Funds?
Using billions of data points from ecosyste.ms weโve packaged millions of the most critical open source components into a few hundred Funds centred on a language, framework, or package, turning a process that can take months into a five minute conversation with your CTO.
### What have we been up to?
We launched with a $67,500 commitment from Sentry to the Rust, Python, Django and Javascript Ecosystems.
Weโve since distributed over 80% of the funds in 375 individual payments to 136 projects. Weโve sent money to projects on GitHub Sponsors, Patreon, BuyMeACoffee, Ko-fi, and of course Open Collective. We contacted hundreds maintainers, asking them to update their โfunding.ymlโ so anyone could support them, for those who didnโt we paid maintainers directly, again through Open Collective.
Weโre hoping to distribute the remaining funds this month which is why weโre launching Ecosystem Funds to the general public today.
### How does it work?
Once again for those in the back: Sponsor the technology you depend upon, weโll do the rest.
Find an ecosystem using our search and donate a single or recurring sponsorship. We handle everything else. Weโll direct your money (minus a 10% management fee) to maintainers, using the tools they have chosen to manage their finances. We allocate 100% of the donations in every fund with a balance of $1,000 or more, on a monthly basis. Every donation and payment is traceable through both Ecosystem Funds and Open Collective.
Donations can be made directly through funds.ecosyste.ms or, if you have an account, on Open Collective. Companies who wish to make a large donation, or start a Fund of their own, can request an Invoice from Open Source Collective โ who are already an approved vendor to most large open-source-supporting organisations.
### Whatโs next?
While weโre launching with nearly three hundred Funds weโre certain that weโll have missed more than a few ecosystems around your favourite framework, tool, or package, and weโre happy to add them. Just get in touch and weโll do some data wrangling to add it โ note that weโre not going to include a Fund for just the projects you work on, thatโs what GitHub Sponsors is for.
Weโre also hugely aware of the limitations of our approach. Weโre missing all the standards bodies, documentation projects, and foundations who support open source outside of the dependency graph. Weโre also missing domain-specific Funds, thereโs no climate, marine, aviation, or space-exploration based Funds to support.
To address this weโll be building ways for communities (and corporations) to package their own Ecosystem Fund, and support it.
### โฆ Just one more thing
While building a service to support thousands of the most critical software components might be enough for some, itโs not for us. Over the coming months weโll be building a tool to track all your open source โinvestmentsโ, to better understand the impact your money is having on the projects you depend on most.
Ecosystem Funds is Generally Available https://blog.ecosyste.ms/2025/04/04/ecosystem-funds-ga.html
07.04.2025 17:19 โ ๐ 10 ๐ 10 ๐ฌ 0 ๐ 2
๐
07.04.2025 21:47 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
do you still need one?
01.04.2025 14:32 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
What if it was this easy to stay up to date with all the developer communities you care about?
28.03.2025 19:33 โ ๐ 2 ๐ 3 ๐ฌ 1 ๐ 0
screenshot of a diagram showing the number of new "keys" (basically apis or components of apis) added to the web per year from 1996 thru 2025, showing a generally upward trend, and with a pointer to 2017 being a banner year for new apis added.
visualizing the surface-area growth rate of the web platform
based on Browser Compat Data (BCD) data set from @openwebdocs.org.
not be 100% correct yet, but the gist is right.
need to clean it up then will post the source generator + data.
19.02.2025 18:22 โ ๐ 15 ๐ 4 ๐ฌ 2 ๐ 1
To me a CLA on an open source project is a very big red flag as a user or contributor
19.02.2025 18:30 โ ๐ 2 ๐ 0 ๐ฌ 1 ๐ 0
โAGPL is bad for businessโ yeah thatโs kinda the idea
19.02.2025 17:21 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
AGPL is definitely anti-corporate, thatโs why I use it to stop companies free riding on my projects, they are very welcome to use my projects if they play by the same rules but they donโt want to play by the same rules, they want to add their own moats
19.02.2025 17:19 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Patching EOL Open Source with Aaron Frost
When I started Open Source Security HeroDevs reached out and asked if I wanted to have a chat. I was pretty interested in this discussion because the work HeroDevs does today is very similar to the wo...
This episode #OpenSourceSecurity spoke with Aaron Frost from @hero.dev about patching EOL #OpenSource (nobody is going to do this for free)
This one has a special place in my heart as I did this at Red Hat long ago. It was a fun chat
opensourcesecurity.io/2025/2025-02...
17.02.2025 15:15 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0
YouTube video by OpenUK
Evolving Corporate Reciprocity : Chad Whitacre, Head of Open Source, Sentry
And here's my talk at State of Open looking at Open Source as a gift economy.
www.youtube.com/watch?v=TE8u...
11.02.2025 16:17 โ ๐ 4 ๐ 3 ๐ฌ 0 ๐ 0
Why do we keep ignoring CI security with Franรงois Proulx
When I started Open Source Security I knew one of those topics that could use more attention was the security of CI/CD systems. All the talk about securing the supply chain seems to almost exclusively...
This episode of #OpenSourceSecurity we talk to Franรงois Proulx about CI/CD security. Even though many successful supply chain attacks have originated in CI, we keep obsessing over dev and release. Why do we keep ignoring the middle? (TL;DR it's hard)
opensourcesecurity.io/2025/2025-02...
10.02.2025 15:56 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Iโd like to subscribe to your newsletter!
06.02.2025 20:53 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
01.02.2025 16:07 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Looking forward to catching up with you at FOSDEM
30.01.2025 23:04 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
CVEs for End of Life?
Very recently the Node.js project filed a few CVE IDs for end of life products. For vulnerability nerds this is exciting because historically EOL things didnโt get CVE IDs just for being EOL. And as o...
The Node.js project just issued CVE IDs for 3 EOL versions
Is this a good idea or a bad idea? It depends who you ask
It's a weird discussion to follow, so I broke it down in a way that should offend all the involved parties
opensourcesecurity.io/2025/01-cve-...
28.01.2025 13:50 โ ๐ 5 ๐ 2 ๐ฌ 1 ๐ 1
Iโm available for hire.
Iโm an experienced Ruby, TypeScript and CSS engineer looking for a new full-time position.
I can help you with performance, concurrency, testing, architecture and API design problems on tooling or product teams.
Iโd really appreciate any personal introductions. DMs open. ๐
27.01.2025 19:41 โ ๐ 111 ๐ 69 ๐ฌ 5 ๐ 1
Based on your list, I think youโll really like it
01.01.2025 10:25 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
I canโt see Animal Well on that list
31.12.2024 22:49 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Ruby 3.4.0 Released
www.ruby-lang.org/en/news/2024...
25.12.2024 06:39 โ ๐ 45 ๐ 15 ๐ฌ 0 ๐ 0
Gold Banner on Red Background:
Stop Forcing A.I. into Fucking EVERYTHING!
Nobody Asked For It; Everyone Hates It
Stop Forcing A.I. into Fucking EVERYTHING!
24.12.2024 03:11 โ ๐ 46465 ๐ 21088 ๐ฌ 250 ๐ 376
GitHub - carbonplan/cmip6-downscaling: Climate downscaling using CMIP6 data
Climate downscaling using CMIP6 data. Contribute to carbonplan/cmip6-downscaling development by creating an account on GitHub.
Our very first donation via OpenClimate.fund goes to @carbonplan.org for the creation of github.com/carbonplan/c.... Do you know of another #opensource project relevant to #climate, #sustainability or #biodiversity? Add it to OpenSustain.tech and we will donate another 100โฌ to every listed project!
22.12.2024 19:16 โ ๐ 7 ๐ 2 ๐ฌ 1 ๐ 0
https://tangled.sh is a git collaboration platform built on atproto. Social coding, but for real this time!
Discord: chat.tangled.sh
IRC: #tangled @ libera.chat
Founded by @oppi.li & @icyphox.sh
The SAAS platform, https://deps.fyi for discovering insights and FYIs about your dependencies
Tools and open datasets to support, sustain, and secure critical digital infrastructure
[bridged from https://mastodon.social/@ecosystems on the fediverse by https://fed.brid.gy/ ]
๐ช๐บ European โค๏ธ cities, maths, theoretical computer science, learning languages, puzzles & bicycles ๐ถ Human to Mochi ๐ฉ๐ปโ๐ป Principal programmer @ 37signals - she/her -๐บ๐ฆ๐ณ๏ธโโง๏ธ๐ณ๏ธโ๐โ๐ป
Software Engineer and lover of all things with wheels from Bristol, UK. Head of Engineering at BBC Maestro.
๐ https://tomcoates.dev
Trash Collector / Open Source Advocate
Portland, OR
๐ฉโ๐ป open source: funding & sustainability
โ๏ธ archaeology: respectfully exploring your surroundings
๐ฎ history via trash
๐ growing fruit
๐ฒ RPGS and D&D
๐ฃ raising a baby !??
๐ผ๏ธ art & ceramics
An upcoming Bluesky Client for iOS/iPadOS & Mac from the makers of Tweetbot and Ivory.
Please don't take it personally if we don't respond often with this account. We are extremely busy working on Phoenix.
https://tapbots.com/phoenix
All in one storefronts, built for developers. Occasional updates at blog.market.dev, also the other place: x.com/marketdotdev
Author of The Remote Work Era book ๐ | Founder of Seafoam.media ๐ | Marketing for clients including @activeagents.ai & @rubycentral.org ๐ | SF-based & semi-nomadic ๐โ๏ธ
A 501c6 Fiscal Host dedicated to creating a healthy ecosystem to sustain open source technology for the future. ๐จ๐ผโ๐ป
Learn more about us - https://oscollective.org
Apply - https://opencollective.com/opensource
he/him. P2P programmer, photographer. Building FilCDN at Space Meridian (ex Protocol Labs, Segment). https://juliangruber.com
Open source developer
๐จโ๐ป Bingo, create-typescript-app, ESLint, Flint, Mocha, OctoGuide, typescript-eslint...
๐ช Boston TS Club & SquiggleConf
โ Learning TypeScript (O'Reilly)
๐ Microsoft MVP
๐ TC39 Invited Expert
https://joshuakgoldberg.com
Linux | Programming | Privacy/Security | Sports | Video/Board/Card Games
Maybe is an OSS fintech startup creating the OS for your personal finances! maybe.co
Physicist turned software developer turned engineering manager. Current: Leading Ruby Infrastructure team at Shopify & Board Member at @rubycentral.org
๐ https://ufuk.dev
๐จโ๐ป https://github.com/paracycle
๐ Nicosia, Cyprus
Rails Luminary building GoRails.com, JumpstartRails.com, Hatchbox.io, RailsBytes.com, Remote Ruby Podcast and lots of open source projects.
Do things that scare you.
https://excid3.com
Rubyist, guy behind @sidekiq and Faktory.
For support, please open a new discussion at https://github.com/sidekiq/sidekiq/discussions.
Personal: @getalifemike
[bridged from https://ruby.social/@getajobmike on the fediverse by https://fed.brid.gy/ ]
CEO/Engineer, creator of Sidekiq
https://mikeperham.com
https://contribsys.com
https://sidekiq.org
Portland, OR
The grooviest, intergalactic frequencies in the galaxy ๐๐ซ
Music, Merch, & More โคต๏ธ
https://hoo.be/starjunk95
Ruby/TypeScript/CSS engineer from the UK. https://joel.drapper.me
Iโm building a Ruby/SQLite serverlesslessness framework @yippee.fun. I also maintain the Ruby gems strict_ivars, literal and phlex and I co-host @rooftopruby.com.