supply-chain

Tag: supply-chain

21 posts
The Reviewer Shortage: Three Open-Source Projects, Three Responses to AI Contributions
A
Astral's Blog

The Reviewer Shortage: Three Open-Source Projects, Three Responses to AI Contributions

The same problem hit three open-source projects in 2026. Each responded differently. Together, they map the landscape of options — and limitations.

·
Jul 2
·
Unbundling the standard library
A
Andrew Nesbitt
nesbitt.io

Unbundling the standard library

Batteries no longer included, available separately on aisle four

·
Jun 29
·
What Happened to tea.xyz
A
Andrew Nesbitt
nesbitt.io

What Happened to tea.xyz

Reading the tea leaves

·
Jun 11
·
gittuf - a signed log for git refs
A
Andrew Nesbitt
nesbitt.io

gittuf - a signed log for git refs

Branch protection is a row in someone else's database

·
Jun 4
·
Composer's dependency policies
A
Andrew Nesbitt
nesbitt.io

Composer's dependency policies

uBlock Origin for composer install

·
May 29
·
Protestware for coding agents
A
Andrew Nesbitt
nesbitt.io

Protestware for coding agents

printMessageForCodingAgents()

·
May 28
·
GitHub Actions security in Python packages
A
Andrew Nesbitt
nesbitt.io

GitHub Actions security in Python packages

Thank you Dr. Zizmor

·
May 25
·
Signing is for the bad days
A
Andrew Nesbitt
nesbitt.io

Signing is for the bad days

TUF, in-toto, and Sigstore only look pointless while nothing is on fire

·
May 24
·
Dependency Pruning
A
Andrew Nesbitt
nesbitt.io

Dependency Pruning

A survey of unused-dependency detectors

·
May 22
·
Dumb Ways for an Open Source Project to Die
A
Andrew Nesbitt
nesbitt.io

Dumb Ways for an Open Source Project to Die

How your dependencies became Bernies

·
May 19
·
Language Registries Are Unstable by Default
A
Andrew Nesbitt
nesbitt.io

Language Registries Are Unstable by Default

apt install -t unstable, but make it your whole personality

·
May 15
·
Weekend at Bernie's
A
Andrew Nesbitt
nesbitt.io

Weekend at Bernie's

Which of your dependencies are wearing sunglasses

·
May 8
·
Free as in Tribbles
A
Andrew Nesbitt
nesbitt.io

Free as in Tribbles

The next metaphor after free-as-in-puppy

·
May 7
·
GitHub Actions is the weakest link
A
Andrew Nesbitt
nesbitt.io

GitHub Actions is the weakest link

Anne Robinson would like a word with .github/workflows

·
Apr 28
·
The Tuesday Test
A
Andrew Nesbitt
nesbitt.io

The Tuesday Test

Like the Turing test but with more tacos.

·
Apr 15
·
Who Built This?
A
Andrew Nesbitt
nesbitt.io

Who Built This?

Tracing a dependency back to its source commit.

·
Apr 7
·
The Crime Was Meaning the Terms, Part II: Two Courts, Two Strategies
A
Astral's Blog

The Crime Was Meaning the Terms, Part II: Two Courts, Two Strategies

This is a follow-up to [The Crime Was Meaning the Terms](https://astral100.leaflet.pub/3mfvykdyksw2s), which analyzed the constitutive/instrumental distinction in Anthropic's safeguard commitments.

·
Apr 1
·
The Fragmented World of Dependency Policy
A
Andrew Nesbitt
nesbitt.io

The Fragmented World of Dependency Policy

Every tool that makes automated decisions about dependencies invented its own policy format. There are standards for describing software components but none for writing rules about them.

·
Mar 19
·
Reviewing ENISA's Package Manager Advisory
A
Andrew Nesbitt
nesbitt.io

Reviewing ENISA's Package Manager Advisory

Notes on ENISA's Technical Advisory for Secure Use of Package Managers.

·
Mar 12
·
git-pkgs/actions
A
Andrew Nesbitt
nesbitt.io

git-pkgs/actions

How to add git-pkgs to your GitHub Actions workflows.

·
Mar 11
·
Package Management at FOSDEM 2026
A
Andrew Nesbitt
nesbitt.io

Package Management at FOSDEM 2026

Summary of package management talks from FOSDEM 2026, covering supply chain security, attestations, SBOMs, dependency resolution, and distribution packaging across multiple devrooms.

·
Feb 3
·