<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Weekend at Bernie&#x27;s - Which of your dependencies are wearing sunglasses?]]></title><description><![CDATA[<p>Weekend at Bernie's - Which of your dependencies are wearing sunglasses?</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://nesbitt.io/2026/05/08/weekend-at-bernies.html" title="Weekend at Bernie’s">
<img src="https://nesbitt.io/images/boxes.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://nesbitt.io/2026/05/08/weekend-at-bernies.html">
Weekend at Bernie’s
</a>
</h5>
<p class="card-text line-clamp-3">Which of your dependencies are wearing sunglasses</p>
</div>
<a href="https://nesbitt.io/2026/05/08/weekend-at-bernies.html" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://nesbitt.io/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0">Andrew Nesbitt <span class="text-secondary">(nesbitt.io)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/c3d12578-f444-4cc0-80c2-7c5d39c00939/weekend-at-bernie-s-which-of-your-dependencies-are-wearing-sunglasses</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 08:47:31 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/c3d12578-f444-4cc0-80c2-7c5d39c00939.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 May 2026 11:02:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Weekend at Bernie&#x27;s - Which of your dependencies are wearing sunglasses? on Fri, 08 May 2026 16:23:29 GMT]]></title><description><![CDATA[<p>The code I used to collect and query this data from <span><a href="https://mastodon.social/@ecosystems">@<span>ecosystems</span></a></span> is here: <a href="https://github.com/andrew/weekend-at-bernies" rel="nofollow noopener"><span>https://</span><span>github.com/andrew/weekend-at-b</span><span>ernies</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116539877597732579</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116539877597732579</guid><dc:creator><![CDATA[andrewnez@mastodon.social]]></dc:creator><pubDate>Fri, 08 May 2026 16:23:29 GMT</pubDate></item><item><title><![CDATA[Reply to Weekend at Bernie&#x27;s - Which of your dependencies are wearing sunglasses? on Fri, 08 May 2026 16:02:28 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> That's a nice conundrum: </p><p>Declare a tight version range and get hit by vulnerabilities because new versions are not downloaded;</p><p>Or accept (patch) updates and get hit because a vulnerable update is downloaded (f.e. due to a supply chain attack).</p>]]></description><link>https://board.circlewithadot.net/post/https://genart.social/users/aerique/statuses/116539794915811584</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://genart.social/users/aerique/statuses/116539794915811584</guid><dc:creator><![CDATA[aerique@genart.social]]></dc:creator><pubDate>Fri, 08 May 2026 16:02:28 GMT</pubDate></item><item><title><![CDATA[Reply to Weekend at Bernie&#x27;s - Which of your dependencies are wearing sunglasses? on Fri, 08 May 2026 15:50:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/donaldball%40triangletoot.party">@<span>donaldball</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> if you read the post you’ll see that I definitely consider that, it’s about how responsive the maintainers are, not just how often they are committing/releasing</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116539747261685830</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116539747261685830</guid><dc:creator><![CDATA[andrewnez@mastodon.social]]></dc:creator><pubDate>Fri, 08 May 2026 15:50:20 GMT</pubDate></item><item><title><![CDATA[Reply to Weekend at Bernie&#x27;s - Which of your dependencies are wearing sunglasses? on Fri, 08 May 2026 15:48:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Maybe worth observing that there are mature language ecosystems (clojure, elixir) where folk are culturally quite careful about dependencies, and often times a package not being changed for years is a sign not of abandonment, but that the package is finished.</p>]]></description><link>https://board.circlewithadot.net/post/https://triangletoot.party/users/donaldball/statuses/116539738607840281</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://triangletoot.party/users/donaldball/statuses/116539738607840281</guid><dc:creator><![CDATA[donaldball@triangletoot.party]]></dc:creator><pubDate>Fri, 08 May 2026 15:48:08 GMT</pubDate></item><item><title><![CDATA[Reply to Weekend at Bernie&#x27;s - Which of your dependencies are wearing sunglasses? on Fri, 08 May 2026 14:30:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> could I get access to the list of dead critical repos in the Cargo ecosystem (ideally in order of criticality)? Seems very relevant to my RustSec work.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/djc/statuses/116539433872644447</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/djc/statuses/116539433872644447</guid><dc:creator><![CDATA[djc@hachyderm.io]]></dc:creator><pubDate>Fri, 08 May 2026 14:30:38 GMT</pubDate></item><item><title><![CDATA[Reply to Weekend at Bernie&#x27;s - Which of your dependencies are wearing sunglasses? on Fri, 08 May 2026 12:03:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> I had a bot write skip-trace to try to track down who in the real world owns a package. A lot of the package repos <br />- don't care who owns the package<br />- want to protect privacy</p><p>Is Mr Anonymous dead? How can you know anything about someone you know nothing about?</p><p><a href="https://mastodon.social/tags/Pypi" rel="tag">#<span>Pypi</span></a> provides no messaging system itself. But does have a package takeover process that depends on messaging!</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://pypi.org/project/skip-trace/">
Client Challenge
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://pypi.org/project/skip-trace/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://pypi.org/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(pypi.org)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/mistersql/statuses/116538855262370834</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/mistersql/statuses/116538855262370834</guid><dc:creator><![CDATA[mistersql@mastodon.social]]></dc:creator><pubDate>Fri, 08 May 2026 12:03:30 GMT</pubDate></item></channel></rss>