Skip to content
Standard
Reader
Log in
Tag
Supply-chain
Articles and publications tagged Supply-chain across the Atmosphere.
22
articles
1
publication
Articles
Publications
Recent
Recent
Trending
Most popular
Andrew Nesbitt
·
Sep 22, 2026
Unfinished Work in Package Security
Some assembly required.
package-managers
·
security
Andrew Nesbitt
·
Sep 15, 2026
Shadowing the Standard Library
export PYTHONSAFEPATH=1
security
·
supply-chain
Andrew Nesbitt
·
Sep 10, 2026
Package Manager Trends
min-release-age, minimum-release-age, -Zmin-publish-age, cooldown.
package-managers
·
supply-chain
Andrew Nesbitt
·
Jun 29, 2026
Unbundling the standard library
Batteries no longer included, available separately on aisle four
package-managers
·
security
Andrew Nesbitt
·
Jun 11, 2026
What Happened to tea.xyz
Reading the tea leaves
package-managers
·
supply-chain
Andrew Nesbitt
·
Jun 4, 2026
gittuf - a signed log for git refs
Branch protection is a row in someone else's database
git
·
security
Andrew Nesbitt
·
May 29, 2026
Composer's dependency policies
uBlock Origin for composer install
package-managers
·
security
Andrew Nesbitt
·
May 28, 2026
Protestware for coding agents
printMessageForCodingAgents()
supply-chain
·
security
Andrew Nesbitt
·
May 25, 2026
GitHub Actions security in Python packages
Thank you Dr. Zizmor
security
·
supply-chain
Andrew Nesbitt
·
May 24, 2026
Signing is for the bad days
TUF, in-toto, and Sigstore only look pointless while nothing is on fire
supply-chain
·
security
Andrew Nesbitt
·
May 22, 2026
Dependency Pruning
A survey of unused-dependency detectors
supply-chain
·
dependencies
Andrew Nesbitt
·
May 19, 2026
Dumb Ways for an Open Source Project to Die
How your dependencies became Bernies
open-source
·
maintainers
Andrew Nesbitt
·
May 15, 2026
Language Registries Are Unstable by Default
apt install -t unstable, but make it your whole personality
package-managers
·
security
Andrew Nesbitt
·
May 8, 2026
Weekend at Bernie's
Which of your dependencies are wearing sunglasses
open-source
·
security
Andrew Nesbitt
·
May 7, 2026
Free as in Tribbles
The next metaphor after free-as-in-puppy
open-source
·
dependencies
Andrew Nesbitt
·
Apr 28, 2026
GitHub Actions is the weakest link
Anne Robinson would like a word with .github/workflows
github
·
security
Andrew Nesbitt
·
Apr 15, 2026
The Tuesday Test
Like the Turing test but with more tacos.
package-managers
·
homebrew
Andrew Nesbitt
·
Apr 7, 2026
Who Built This?
Tracing a dependency back to its source commit.
package-managers
·
security
Andrew Nesbitt
·
Mar 19, 2026
The Fragmented World of Dependency Policy
Every tool that makes automated decisions about dependencies invented its own policy format. There are standards for describing software components but none for writing rules about them.
package-managers
·
supply-chain
Andrew Nesbitt
·
Mar 12, 2026
Reviewing ENISA's Package Manager Advisory
Notes on ENISA's Technical Advisory for Secure Use of Package Managers.
package-managers
·
security
Andrew Nesbitt
·
Mar 11, 2026
git-pkgs/actions
How to add git-pkgs to your GitHub Actions workflows.
git-pkgs
·
github-actions
Andrew Nesbitt
·
Feb 4, 2026
Package Management at FOSDEM 2026
Summary of package management talks from FOSDEM 2026, covering supply chain security, attestations, SBOMs, dependency resolution, and distribution packaging across multiple devrooms.
package-managers
·
conferences
You've reached the end.
Home
Latest
Discover
Search