<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[A GitHub for maintainers - Giving dependencies the same treatment the fork got]]></title><description><![CDATA[<p>A GitHub for maintainers - Giving dependencies the same treatment the fork got</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://nesbitt.io/2026/05/02/a-github-for-maintainers.html" title="A GitHub for maintainers">
<img src="https://nesbitt.io/images/boxes.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://nesbitt.io/2026/05/02/a-github-for-maintainers.html">
A GitHub for maintainers
</a>
</h5>
<p class="card-text line-clamp-3">Giving dependencies the same treatment the fork got</p>
</div>
<a href="https://nesbitt.io/2026/05/02/a-github-for-maintainers.html" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://nesbitt.io/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />



<p class="d-inline-block text-truncate mb-0">Andrew Nesbitt <span class="text-secondary">(nesbitt.io)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/f0049380-c584-4f0f-bff3-47a36859ac47/a-github-for-maintainers-giving-dependencies-the-same-treatment-the-fork-got</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:38:08 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/f0049380-c584-4f0f-bff3-47a36859ac47.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 02 May 2026 17:22:37 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sun, 03 May 2026 11:46:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> back in 2015 we experimented with 'reverse PRs' for docker/go: so every time i pushed to the lib i maintain i'd get a report back of all the downstream users i'd broken. I still really want that</p>]]></description><link>https://board.circlewithadot.net/post/https://amok.recoil.org/users/avsm/statuses/116510478721178294</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://amok.recoil.org/users/avsm/statuses/116510478721178294</guid><dc:creator><![CDATA[avsm@amok.recoil.org]]></dc:creator><pubDate>Sun, 03 May 2026 11:46:58 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sun, 03 May 2026 07:03:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/csepp%40merveilles.town">@<span>csepp</span></a></span><br /><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span><br />while at it, why not add a, separate "known defect database" where things don't get closed by a stalebot / as "we don't have time for that"?</p>]]></description><link>https://board.circlewithadot.net/post/https://mstdn.io/users/wolf480pl/statuses/116509363927182700</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mstdn.io/users/wolf480pl/statuses/116509363927182700</guid><dc:creator><![CDATA[wolf480pl@mstdn.io]]></dc:creator><pubDate>Sun, 03 May 2026 07:03:27 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sat, 02 May 2026 22:10:00 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> &gt; Rename “issues”<br />Oh my glowcloud, yes, please!  I would also add that users need a place to report incidents as a thing separate from a known defect.  An incident could have multiple causes, or even an unknown cause.</p>]]></description><link>https://board.circlewithadot.net/post/https://merveilles.town/users/csepp/statuses/116507266290914352</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://merveilles.town/users/csepp/statuses/116507266290914352</guid><dc:creator><![CDATA[csepp@merveilles.town]]></dc:creator><pubDate>Sat, 02 May 2026 22:10:00 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sat, 02 May 2026 20:31:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span><br />I'm obliged to do some advertising for tools that were developed in a research context for just this use case: <a href="https://github.com/alien-tools/breakbot" rel="nofollow noopener"><span>https://</span><span>github.com/alien-tools/breakbot</span><span></span></a> for Java, with static analysis (by Ochoa, Degueule and <span><a href="https://social.sciences.re/@jrfaller">@<span>jrfaller</span></a></span>) and <a href="https://github.com/rocq-community/coq-nix-toolbox" rel="nofollow noopener"><span>https://</span><span>github.com/rocq-community/coq-</span><span>nix-toolbox</span></a> for Coq/Rocq project but which would be feasible to generalize to other ecosystems (by Cohen and me).<br /><span><a href="/user/djc%40hachyderm.io">@<span>djc</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://fediscience.org/users/Zimm_i48/statuses/116506877049821041</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fediscience.org/users/Zimm_i48/statuses/116506877049821041</guid><dc:creator><![CDATA[zimm_i48@fediscience.org]]></dc:creator><pubDate>Sat, 02 May 2026 20:31:01 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sat, 02 May 2026 18:16:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/djc%40hachyderm.io">@<span>djc</span></a></span> also only needs a subset of dependents, not every single one</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116506349678996490</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116506349678996490</guid><dc:creator><![CDATA[andrewnez@mastodon.social]]></dc:creator><pubDate>Sat, 02 May 2026 18:16:54 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sat, 02 May 2026 18:15:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/djc%40hachyderm.io">@<span>djc</span></a></span> could probably do the same for go and java too</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116506342652637853</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116506342652637853</guid><dc:creator><![CDATA[andrewnez@mastodon.social]]></dc:creator><pubDate>Sat, 02 May 2026 18:15:06 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sat, 02 May 2026 18:14:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> maybe. And arguably it’s not all that different from triggering every downstream’s CI via Dependabot/Renovate after the release.</p><p>Though now I’m wondering for Rust if it would be feasible to do like a static analysis version of this, plowing through the rustwide corpus looking for specific code paths.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/djc/statuses/116506340368918410</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/djc/statuses/116506340368918410</guid><dc:creator><![CDATA[djc@hachyderm.io]]></dc:creator><pubDate>Sat, 02 May 2026 18:14:32 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sat, 02 May 2026 18:11:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/djc%40hachyderm.io">@<span>djc</span></a></span> I think it could be ran cheap enough, especially if it’s not ran on every commit</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116506327794821164</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/andrewnez/statuses/116506327794821164</guid><dc:creator><![CDATA[andrewnez@mastodon.social]]></dc:creator><pubDate>Sat, 02 May 2026 18:11:20 GMT</pubDate></item><item><title><![CDATA[Reply to A GitHub for maintainers - Giving dependencies the same treatment the fork got on Sat, 02 May 2026 18:01:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/andrewnez%40mastodon.social">@<span>andrewnez</span></a></span> having something crater-like would be amazing, but it also seems very expensive, potentially prohibitively so? I do wonder if we could do the static analysis version of that at least for languages like Rust.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/djc/statuses/116506289456565629</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/djc/statuses/116506289456565629</guid><dc:creator><![CDATA[djc@hachyderm.io]]></dc:creator><pubDate>Sat, 02 May 2026 18:01:35 GMT</pubDate></item></channel></rss>