Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Andrew Nesbitt

@andrewnez@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

Package Management Nerd, working on mapping the world of open source software https://ecosyste.ms and blogging about package managers at https://nesbitt.io

0 Followers
0 Following
50 Posts
Joined April 01, 2017
GitHub:
https://github.com/andrew
Twitter:
https://twitter.com/teabass
Homepage:
https://nesbitt.io
bsky:
https://bsky.app/profile/andrewnez.bsky.social
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 1mo ago
Boosted by @trending@homestead.social
Now Hiring: Senior Open Source Maintainer https://nesbitt.io/2026/08/28/now-hiring-senior-open-source-maintainer.html
Now Hiring: Senior Open Source Maintainer
Andrew Nesbitt

Now Hiring: Senior Open Source Maintainer

A rare opportunity to make a real impact in a fast-paced, high-visibility role.

180
14
223
13
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
I’m now an official maintainer of homebrew🍻
287
8
36
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 1w ago
Was much easier to get git-pkgs modules running in the browser as wasm than expected!
5
2
3
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Interview with a Maintainer https://nesbitt.io/2026/07/24/interview-with-a-maintainer.html
Interview with a Maintainer
Andrew Nesbitt

Interview with a Maintainer

Episode 214 of Green Squares.

75
28
67
6
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
RE: https://mastodon.social/@andrewnez/116974498919761167 This one really touched a nerve, I’ve had a number of emails from real maintainers today sharing their stories that end up being way too similar 🥲
Open quoted post
Quoting
Andrew Nesbitt
@andrewnez@mastodon.social
Interview with a Maintainer https://nesbitt.io/2026/07/24/interview-with-a-maintainer.html
Open quoted post
mastodon.social

Andrew Nesbitt: "Interview with a Maintainer https://nesbitt.io/…" - Mastodon

53
6
39
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Paraphrasing an email from a security company : We copied one of your blog posts and turned into an advert for one of our products. Please add a link to our blog post to the end of yours. 🥉
33
4
4
1
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
The AI Phrasebook https://nesbitt.io/2026/07/31/the-ai-phrasebook.html
The AI Phrasebook
Andrew Nesbitt

The AI Phrasebook

We have autonomous agents at home.

28
9
22
2
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
--end-of-options https://nesbitt.io/2026/07/21/end-of-options.html
–end-of-options
Andrew Nesbitt

–end-of-options

The git flag I assumed was an LLM hallucination

27
10
16
2
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Taking Roads and Bridges literally - Reflections on UN Open Source Week 2026 https://nesbitt.io/2026/06/30/taking-roads-and-bridges-literally.html
nesbitt.io
36
0
29
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
The CRA is not about open source - https://nesbitt.io/2026/07/01/the-cra-is-not-about-open-source.html
The CRA is not about open source
Andrew Nesbitt

The CRA is not about open source

The CRA created an open-source steward role, then left maintenance unfunded.

32
7
30
3
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Replying to
Oh cool, an AI bot is now selling a t-shirt about my blog post about ai bots 🫠
32
7
8
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
I could not write this homebrew thread as a satire piece if i wanted to, real life is much more cursed: https://github.com/Homebrew/homebrew-core/issues/289444#issuecomment-5050717674
GitHub

Gemini-cli improperly deprecated · Issue #289444 · Homebrew/homebrew-core

brew config AND brew doctor output OR brew gist-logs <formula> link ○ → brew config bHOMEBREW_VERSION: 6.0.3 rORIGIN: https://github.com/Homebrew/brew HEAD: 5c38c6b3fc42281af432cda526dd0509172f681b...

15
4
5
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Why npm Dependency Trees Are So Big https://nesbitt.io/2026/07/28/why-npm-dependency-trees-are-so-big.html
Why npm Dependency Trees Are So Big
Andrew Nesbitt

Why npm Dependency Trees Are So Big

Two versions of lodash walk into a tree

12
0
14
1
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Seems that Google AI Overviews still doesn't quite understand satire.
13
1
3
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Anyone else get the fear when they get a dependabot update for anything called xz? https://github.com/git-pkgs/archives/pull/18
GitHub

Bump github.com/ulikunitz/xz from 0.5.15 to 0.5.16 by dependabot[bot] · Pull Request #18 · git-pkgs/archives

Bumps github.com/ulikunitz/xz from 0.5.15 to 0.5.16. Commits 024f909 isterminal_fallback.go: ensure +build and go:build lines are consistent ba40d80 Prepare release v0.5.16 82b346c internal/term:...

12
2
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Typical, I go out the house for half an hour and one of my databases falls over 🫠
12
4
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
For context: https://nesbitt.io/2026/02/03/incident-report-cve-2024-yikes.html
Incident Report: CVE-2024-YIKES
Andrew Nesbitt

Incident Report: CVE-2024-YIKES

A series of unfortunate events.

35
3
14
2
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Fun satire blog post coming tomorrow, and by fun I mean way to close to the bone that it could almost be true 😬
10
1
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago

Not a Security Issue: https://nesbitt.io/2026/05/12/not-a-security-issue.html

Not a Security Issue
Andrew Nesbitt

Not a Security Issue

How curl’s disclosure policy filtered an AI scanner’s findings at source

33
2
26
1
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
brew vulns has now been merged into homebrew and shipped in v6.0.11 https://github.com/Homebrew/brew/releases/tag/6.0.11
GitHub

Release 6.0.11 · Homebrew/brew

What's Changed Enable more cask metadata migration to JSON for all users by @MikeMcQuaid in #22958 Skip rewriting Mach-O binaries when delete_rpath changes nothing by @hyuraku in #23079 test_bot/f...

10
1
1
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Almost a million requests to the blog over the weekend, this post really did the rounds! https://nesbitt.io/2026/06/26/incident-report-cve-2026-lgtm.html Already got me thinking about the next instalment 🤔
Incident Report: CVE-2026-LGTM
Andrew Nesbitt

Incident Report: CVE-2026-LGTM

A series of unfortunate agents.

12
3
1
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Replying to
@Floppy@mastodon.me.uk @concretedog@mastodon.social notice they didn’t index any AGPL licensed projects 😉
4
3
2
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Replying to
@Di4na@hachyderm.io @Rairii@labyrinth.zone 🫠
3
1
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Replying to
Looking at both totals: GHS: $100M in 7 years (~$14M/yr). OSC: $42M in 9 years (~$4.7M/yr) ~$20M/yr combined = payroll of one mid-size software company, for the whole ecosystem $100M across 70k maintainers = ~$1,400 each, lifetime Corporate share: ~$5-6M/yr, from every company in the world combined
4
1
5
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago

Language Registries Are Unstable by Default: https://nesbitt.io/2026/05/15/language-registries-are-unstable-by-default.html

Language Registries Are Unstable by Default
Andrew Nesbitt

Language Registries Are Unstable by Default

apt install -t unstable, but make it your whole personality

11
8
16
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Replying to

Similar looking data for Open Source Collective:

  • $41.9M in total contributions to OSS collectives
  • 1.8% ($763k) flows collective-to-collective at all
  • 0.17% ($69,647) is in an actual loop
  • The loops are dependency funding: eslint/jest/vite/webdriverio/verdaccio/11ty, parcel/rspack/swc

So on both platforms, 98%+ of open source funding is net new money in, not recirculation

3
2
3
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago

I love how accidentally pressing the “request copilot review” button can now cost you a dollar (or more if it’s a big pr) 💸

8
1
1
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
A good first issue if you'd like to contribute to @ecosystems@mastodon.social to improve NuGet metadata: https://github.com/ecosyste-ms/packages/issues/1740
GitHub

Ingest NuGet verified (prefix reservation) flag into package metadata · Issue #1740 · ecosyste-ms/packages

NuGet's search API exposes a verified boolean per package indicating whether it's published under a reserved ID prefix: curl -s "https://azuresearch-usnc.nuget.org/query?q=packageid:Serilog&take=1"...

2
0
1
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago

So I had a productive flight to @pycon@fosstodon.org: https://alpha-omega-security.github.io/heatmap/

Note: this almost certainly does not work on small screens, sorry!

Note 2: only around 2k projects included atm mostly because downloading more data on plane wifi took too long.

alpha-omega-security.github.io
6
0
1
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Replying to
@aristot73@infosec.exchange @bagder@mastodon.social @icing@chaos.social would be good to document how each effort works with upstream (if at all)
3
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Replying to
@yossarian@infosec.exchange who needs cache poisoning across workflows when you can do it within just one
3
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago

Just landed in LA for @pycon@fosstodon.org, hopefully no more GitHub action related security incidents whilst I was traveling, there’s no space left to fit any more in!

5
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@sethmlarson@mastodon.social the less known googlesquat
4
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago

Starting the long trip to Long Beach for @pycon@fosstodon.org 🏖️

3
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@thomasfuchs@hachyderm.io “please try not to poison our training data”
3
2
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago

Centrality is not vitality, don't automatically reach for PageRank on dependency graphs: https://nesbitt.io/2026/05/14/centrality-is-not-vitality.html

Centrality is not vitality
Andrew Nesbitt

Centrality is not vitality

Don’t automatically reach for PageRank on dependency graphs

2
0
4
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Replying to
@Viss@mastodon.social hopefully it does not become more real over time!
1
1
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@mainec@fromm.social @thomasfuchs@hachyderm.io 🤦‍♂️
2
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@ct created 5 hours ago 🤔
2
0
1
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Replying to
@itgrrl@infosec.exchange 🤦‍♂️
1
1
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 3mo ago
Replying to
$42!?!? https://mercer.hyperagent.com/products/003-35-nobody-read-the-code-tee?variant=53154016002415
mercer.hyperagent.com
1
1
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@Di4na@hachyderm.io full refund available on request
1
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@sustainoss@hachyderm.io it says June 11th on the website?
0
2
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 2mo ago
Replying to
@gvwilson@mastodon.social I’m amazed they managed to find that many in the wild, no-one in oss uses them
0
2
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@alexandrageese@bonn.social is there a link?
0
0
0
0
Open post
Andrew Nesbitt @andrewnez@mastodon.social
· 4mo ago
Replying to
@Di4na@hachyderm.io kinda agree, but these past few months have been rough, and calling it what it is definitely makes the trade-off more clear
0
2
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:06:51 UTC