Most package managers could separate download from install for better Docker layer caching.
Maintainer attention as a finite resource.
Zig's long road to supply chain security.
Where package management fits in the digital sovereignty discussion.
Follow serde@crates.io from your Mastodon account
Why fixing package managers is harder than it looks.
A shared vocabulary for resolution, publishing, and governance across ecosystems.
Extending import maps with package metadata to improve dependency management and security for browser-native JavaScript.
Applying Jepsen-style adversarial testing to package managers.
Go's module system accidentally created a universal, content-addressed, transparency-logged package CDN. You could abuse this for any language.
Lockfiles and SBOMs record the same information in different formats. What if package managers used SBOMs directly, instead of converting later?