May 2026
Language Registries Are Unstable by Default
apt install -t unstable, but make it your whole personality
Centrality is not vitality
Don't automatically reach for PageRank on dependency graphs
Showing Our Work
An independent benchmark of the ecosyste.ms Python fund
Not a Security Issue
How curl's disclosure policy filtered an AI scanner's findings at source
proxy
A lightweight multi-ecosystem caching package proxy
Madame Semver Will See You Now
The cards do not lie.
The Mismeasure of Open Source
The streetlight effect in project-health scoring
Weekend at Bernie's
Which of your dependencies are wearing sunglasses
Free as in Tribbles
The next metaphor after free-as-in-puppy
Revisiting the 2015 Open Source Census
The riskiest projects in open source, scored a decade early
Package Manager Threat Models
The non-CVE half of package manager security
Package Manager CWEs
Recurring weakness classes in package managers
A GitHub for maintainers
Giving dependencies the same treatment the fork got
Patching and forking in package managers
What to do when upstream ghosts you