Dependency Management Data's now on Mastodon! (1 mins read).

Announcing the dependency-management-data Mastodon account for automated release announcements (and more?).
Dependency Management Data's now on Mastodon! (1 mins read).
Announcing the dependency-management-data Mastodon account for automated release announcements (and more?).
Dynamically querying EndOfLife.date data for internal packages with Open Policy Agent and Dependency Management Data (3 mins read).
How you can retrieve End-of-Life data via EndOfLife.date using Dependency Management Data's Policies functionality.
Attached: 1 image #AaronSwartz killed himself because he scraped research data and they aggressively prosecuted him. Now #AI companies say they should scrape our data for free.
Attached: 1 image
If you have a personal website, which I assume you do if you're following me here, you should add yourself to the Internet Phonebook while the call for websites is still open! They even have an "indie …
Attached: 1 image Wake up everyone, a new response header just dropped
Literally last night I was reading [this post on r/Rick and Morty] (https://www.reddit.com/r/rickandmorty/comments/1dvcja9/comment/lbmkw2k/) (some spoilers) and:
Political candidates that survive assassination almost always win
Is 😬😬 re US Politics
Git was designed to be distributed but there is a lot of gravity around GitHub. What does the model look like for a business that encourages you to run your own git server and what does the backend for gitea.com look like?
Conferences & CFPs🇮🇱 GopherCon Israel, Sept 9 @ Tel AvivCFP open until Jul 15🇦🇺 GopherCon AU, NoCFP open until Sept 15🇮🇳 GopherCon India, Dec 1 @ Jaipur🇩🇪 Fyne Conf, Sept 20 @ BerlinCFP open until Aug 16🇸🇬 GopherCon Singapore, October TBDCFP open until Aug 19Go 1.23 draft release notes⏲️ Blog:...
Welcome to Kaizen 15! We go deep on the big Changelog News redesign, give shout outs to folks who’ve helped us along the way & Gerhard takes us on his journey to turn Jerod’s pipe dream into a reality!
Content warning: transphobia, cis people who vote Labour read this, ukpol
89 things I know about Git commits (7 mins read).
Some of the things I've learned over a decade of Git usage, and working on writing good commit messages.
Paul Copplestone, CEO of Supabase (the meme-lord himself), joins the show to take us on the journey of Supabase leading Postgres for life, and how it all starts with Postgres as the base-layer substrate for the entire Supabase platform. They’re laser focused on the drive ahead, not the rear-view mirror. Disclosure: Ada...
This week on The Business of Open Source, I spoke with Joe Duffy, co-founder and CEO of Pulumi.We kicked off the conversation by talking about why Pulumi is open source in the first place — a mix of Joe’s long-standing interest in open source and a feeling like a developer tool like Pulumi just...
Join us for an insightful discussion on the intricacies of Developer Relations in the open source world. Our panel of experts will delve into key differences between open and closed source platforms, the unique challenges and opportunities in open source DevRel, and the impact of AI tools on the community. Gain practical insights and hear success stories from industry leaders.
Anyone know if there's a way of tweaking the new #FirefoxNightly Android layout?
Not a fan of the two row format they've now got
Really hate that the address bar only shows the domain, not the full URL, until you tap into it 😕
This week on The Business of Open Source, I spoke with Tyler Jewell — for the second time, now. Last time I spoke with Tyler, he was an investor at Dell Technologies Capital, he’s since taken over as CEO of Lightbend. We talked about a lot, but there was a definite theme to our conversation:...
Carol Lee (Clinical Scientist) shares her research on code review anxiety. We dive deep into her recent research paper “Understanding and Effectively Mitigating Code Review Anxiety”. We get into all the nooks and crannies of this topic — common code review myths, strategies for coping, the need for awareness and self-r...
Gareth Greenaway from the Salt project joins us for a trip down memory lane with configuration management and why open source projects have changed over the past decade.
Dependency Management Data is now a lot easier to work with when using Software Bill of Materials (3 mins read).
Announcing an improved model for interacting with SBOMs, removing the need to understand the Repo Key up-front.
Visit our homepage - cupogo.dev - for links to our Patreon, Store, past episodes, and more.🚢 Releases1.23 RC1 released1.22.5 & 1.21.12 pre-release announcementProposals1️⃣ Accepted: cmd/gofmt: change -d to exit 1 if diffs exist🆕 Accepted: list deprecations and newer available dep versions 🪢...
Attached: 1 image 10 July - Second OpenUK Digital Meet-up! Join Dr Dawn Foster, James Humphries and host Jamie Tanna, in their talks on high-profile forks, their impacts and the challenges of launching a fork. Register https://www.meetup.com/openuk/events/301139203/?utm_medium=referral&utm_campaign=share-btn_savedevents_share_modal&utm_source=link #openuk #digitalmeetup #opensourcelondon
and talk about the latest polyfill.io mess. Apparently someone took over a very popular project and started to serve malware. First XZ, now this. What does it mean for open source? We don't have any answers, and it's hard to even talk about this problem because it's so big. The thing is though, even if we can't fix open source, it's here to stay. Show Notes
Week Notes 24#27 (5 mins read).
What happened in the week of 2024-07-01?
Adam & Jerod discuss the news! But first, we discuss how you can keep up with the software world (good question, Tyler Boyd!) On the docket: Developer job postings trend, the Ladybird Browser Initiative, the Polyfill.js supply chain attack & is the future self-hosted?
Go 1.22.5 & 1.21.12 releasedConferences🇮🇱 GopherCon Israel, Sept 9 @ Tel AvivCFP open until Jul 15🇦🇺 GopherCon AU, NoCFP open until Sept 15🇮🇳 GopherCon India, Dec 1 @ JaipurNew proposal: include abandoned packages in list of deprecationsBlog post: gRPC: The Good Parts by Kevin McDonald🍪 New...
Dependencies! We need them, but how do we use them effectively and safely? In this week’s episode Kris is joined by Ian and Johnny to discuss the polyfill.io supply chain attack, the history of dependency management and usage in Go, and the Go Proverb that “a little copying is better than a little dependency”. Of cours...
Attached: 1 image Can not stop laughing at this
If there's one thing I've learned as a browser-engine dev: Everything is political! The most mundane things (e.g. how we answer "what time is it?") has the weight of historical politics behind it. Software freedom is a political project, you can't "leave politics out of it"! It makes a lot more sense to ask "how is this political?" than "is this political?". Because it is!
Technology is political. If your project or organisation has a “no politics” clause, you’re saying you’re happy to exclude people whose very existence is political in our societies. It’s only defensible if you’re coming from a place of privilege where the dominant politics are to your advantage so you can take them as given. There is no such thing as “no politics”; there is only “no politics other than the politics of the status quo that I benefit from, which I’ve internalised as normal.”
The “innovation token” model for selecting technologies is bad, and here’s why.
🗳️✅ Get the fuckers out of power
If you view changing documentation to use generic “they” instead of “he” text as too political to be acceptable, then I’m sorry but your project is deeply unserious. “The generic user is a man” is a deeply political statement, and hiding behind “we’re apolitical” is bullshit. https://hachyderm.io/@Mara/112718515777208791
Predrag Gruevski and Chris Krycho joined the show to talk about SemVer. We explore the challenges and the advantages of semantic versioning (aka SemVer), the need for improving the tooling around SemVer, where semantic versioning really shines and where it’s needed, Types and SemVer, whether or not there’s a better way...
ICYMI: Burnout can happen at any point in everyone's career. But, what happens when burnout is taking place amongst other things? Burnout++ https://chrisshort.net/video/cloud-native-rejeckts-eu-2024-burnout-plus-plus/ #mentalhealth #burnout
Maintainer Week is finally here and we’re excited to make this an annual thing! If Maintainer Week is new to you, check out episode #442 with Josh Simmons and Kara Sowles. Today we’re talking Brett Cannon. Brett is Dev Manager of the Python Extension for VS Code, Python Steering Council Member, and core team member for...
This week is all about Maintainer Week — it’s a week long event starting June 7th for open source maintainers to gather, share, and be celebrated. We’re joined by Josh Simmons (Ecosystem Strategy Lead at Tidelift & President of Open Source Initiative) and Kara Sowles (Senior Open Source Program Manager at GitHub). ...
Daniel Stenberg shares his guiding principles for BDFL’ing curl, gives us his perspective on the state of the internet, talks financial independence, ensuring curl won’t be the next XZ & more!
One THOUSAND blog posts (3 mins read).
Celebrating a massive milestone in my blog, and a short reflection.
Reader survey: Who reads my blog? (2 mins read).
Wondering how my readers read my blog, and why.
Week Notes 24#26 (4 mins read).
What happened in the week of 2024-06-24?
Attached: 1 image
Dependency Management Data can now use sql-studio for database browsing (1 mins read).
Announcing the availability of the sql-studio
database browser for dependency-management-data's web application.
Creating a test harness for validating Renovate regex manager rules (4 mins read).
How to set up a test harness to make it eaiser to modify scary looking regexes in your Renovate configuration.
Our award winning worthy survey game show is back, this time Mat Ryer hosts it live on stage at GopherCon EU Berlin 2024! Join in & play along as we see which team can better guess what these GopherCon gophers had to say!
I will be attending
Anyone going to #GopherConUK? 👀