Tag
Package-managers
Every article tagged Package-managers across the Atmosphere.
112articles
Articles
Publications
What Happened to tea.xyz
Reading the tea leavespackage-managerssupply-chain
Package Manager Patents
A reference list of patents and applications relevant to package manager design, with notes on prior art.package-managershistory
This Week in Package Management: 6 June 2026
Releases, advisories, and articles from across the package management worldpackage-managersweekly
Install-script allowlists
A survey of install-script allowlist mechanisms across package managers and language ecosystems.package-managerssecurity
Skills Registry Threat Models
How long until we see a CVE filed against a markdown file?securitypackage-managers
This Week in Package Management: 30 May 2026
Releases, advisories, and articles from across the package management worldpackage-managersweekly
Composer's dependency policies
uBlock Origin for composer installpackage-managerssecurity
Package managers that package package managers
brew install spack install conda install cargo install uv tool install pip install poetry add pdm add conanpackage-managers
Signing is for the bad days
TUF, in-toto, and Sigstore only look pointless while nothing is on firesupply-chainsecurity
This Week in Package Management: 23 May 2026
Releases, advisories, and articles from across the package management worldpackage-managersweekly
Dependency Pruning
A survey of unused-dependency detectorssupply-chaindependencies
Language Registries Are Unstable by Default
apt install -t unstable, but make it your whole personalitypackage-managerssecurity
proxy
A lightweight multi-ecosystem caching package proxypackage-managerstools
Package Manager Threat Models
The non-CVE half of package manager securitypackage-managerssecurity
Package Manager CWEs
Recurring weakness classes in package managerspackage-managerssecurity
A GitHub for maintainers
Giving dependencies the same treatment the fork gotgithubpackage-managers
Patching and forking in package managers
What to do when upstream ghosts youpackage-managerssecurity
GitHub Actions is the weakest link
Anne Robinson would like a word with .github/workflowsgithubsecurity
The stages of package installation
Denial, anger, bargaining, depression, acceptance, postinstall.package-managerssecurity
Features everyone should steal from npmx
What happens when users design their own package registry frontendpackage-managersnpm
The Tuesday Test
Like the Turing test but with more tacos.package-managershomebrew