Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories, by @dangoodin.bsky.social (@arstechnica@mastodon.social):
arstechnica.com/security/2026/03/supply-...
#security #github #dependencies
Latest posts tagged with #dependencies on Bluesky
Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories, by @dangoodin.bsky.social (@arstechnica@mastodon.social):
arstechnica.com/security/2026/03/supply-...
#security #github #dependencies
Tool: Dependencies Badge Generator, by (not on Mastodon or Bluesky):
https://depx.co/badge
#tools #exploration #images #dependencies #npm
#Development #Techniques
External import maps, today! · Using DOM methods to inject an import map ilo.im/16b2f1 by Lea Verou
_____
#Dependencies #JavaScript #NodeModules #ImportMaps #Browsers #WebPlatform #WebDev #Frontend #DOM #JavaScript
Guess what!
Yapping v1.1.0 is live!
pypi.org/project/yapp...
github.com/mrswats/yapp...
#Python #Dependencies
Wait a minute...🤔
If you don't have to download dependencies on CI all the time, then you can reduce setup wait times by 50% or more!
🐇 #Develocity Universal Cache is here 🐇
https://gradle.com/develocity/product/universal-cache/
#CI #Dependencies #Setup #Cache #ColdStart
Not seeing a lot of democracies benefitting from US malfeasance
Canada is doing well, ONLY because we are being forced into tightening #economic & #political #alliances -aka #dependencies- with #less-democratic nations
#Development #Pitfalls
Rely on AI and get left behind · Who will fix code no one understands anymore? ilo.im/16atf5 by Jason Gorman
_____
#Business #Engineering #Programming #Coding #AI #Dependencies #CognitiveDebt #WebDev #Frontend #Backend
Excited for #JCON EUROPE 2026? See Kevin Dubois at #JCON2026 in Cologne talking about 'Local #Development in the #AI Era'
Most of us like to do local #development. It means we’re in #control of any #dependencies, network issues/latency …
🎟️ 2026.europe.jcon.one/tickets
Free for #JUG members
Package managers are everywhere, with seemingly every language and operating system implementing their own solution. The lack of interoperability between these systems means that multi-lingual projects are unable to express precise dependencies across language ecosystems, and external system and hardware dependencies are typically implicit and unversioned. We define HyperRes, a formal system for describing versioned dependency resolution using a hypergraph that is expressive enough to model many ecosystems and solve dependency constraints across them. We define translations from dozens of existing package managers to HyperRes and comprehensively demonstrate that dependency resolution can work across ecosystems that are currently distinct. This does not require users to shift their choice of package managers; instead, HyperRes allows for the translation of packaging metadata between ecosystems, and for solving to be precisely specialised to a particular deployment environment.
This seems very interesting, and would make an interesting talk!
Solving Package Management via Hypergraph Dependency
Resolution - arxiv.org/pdf/2506.10803
#dependencies #packagemanagement #research
#Development #Guidelines
Dependency layers in design systems · “Be intentional about what you own.” ilo.im/16a01d by PJ Onori
_____
#Dependencies #Decisions #Community #Expertise #Codebase #Frameworks #DesignSystems #Development #WebDev #Frontend
Secure, Reliable Terraform At Scale With Sonatype Nexus Repository Terraform has become the de facto standard for infrastructure as code (IaC). From cloud-native startups to global enterprises, tea...
#Security #Bloggers #Network #dependencies […]
[Original post on securityboulevard.com]
Secure, Reliable Terraform At Scale With Sonatype Nexus Repository Terraform has become the de facto standard for infrastructure as code (IaC). From cloud-native startups to global enterprises, tea...
#repository #dependencies #Nexus #Repository #Terraform […]
[Original post on sonatype.com]
Node.js Package Configuration Guide, by @nodejs@social.lfx.dev:
https://nodejs.github.io/package-examples/
#guides #packages #dependencies #configuration #commonjs
#Development #Pitfalls
The 9 levels of JS dependency hell · Developers solved each problem, only to create the next ilo.im/169mic by Andrew Nesbitt
_____
#Programming #Coding #Dependencies #JavaScript #Packages #Attacks #AI #WebDev #Frontend #Backend
The Nine Levels of JavaScript Dependency Hell, by @andrewnez@mastodon.social:
nesbitt.io/2026/01/05/the-nine-leve...
#javascript #dependencies #maintainability
npm to Implement Staged Publishing After Turbulent Shift Off Classic Tokens, by @sarahgooding@fosstodon.org (@socketsecurity@fosstodon.org):
socket.dev/blog/npm-to-implement-st...
#npm #dependencies #security #github
Web Dependencies Are Broken—Can We Fix Them?, by @leaverou@front-end.social:
https://lea.verou.me/blog/2026/web-deps/
#dependencies #javascript #importmaps #webplatform
#Development #Proposals
Web dependencies are broken · “The time has come for an intervention.” ilo.im/169obu by Lea Verou
_____
#Dependencies #JavaScript #Bundlers #NodeModules #ImportMaps #CDNs #Browsers #WebPlatform #WebDev #Frontend
The Package Management Landscape, by @andrewnez@mastodon.social:
nesbitt.io/2026/01/03/the-package-m...
#dependencies #tooling #overviews #linklists
That's Some Other Dev's Problem
That's Some Other Dev's Problem
#Juniorvssenior #npm #dependencies #Technicaldebt #Developerexperience
programmerhumor.io/javascript-memes/thats-s...
How We’re Protecting Our Newsroom From npm Supply Chain Attacks, by @ryansobol.com (@pnpm@fosstodon.org):
pnpm.io/blog/2025/12/05/newsroom...
#npm #dependencies #security #casestudies
Gemnasium vs Snyk: Choosing the Right Dependency Scanner
A practical comparison of Gemnasium and Snyk for dependency security, workflow fit, and coverage.
https://whitespots.io/blog/gemnasium-vs-snyk
#dependencies #supplychain #DevSecOps
No More Tokens—Locking Down npm Publish Workflows, by @zachleat@zachleat.com:
https://www.zachleat.com/web/npm-security/
#npm #dependencies #security #github #processes
Camel Case Because I Have To
Camel Case Because I Have To
#javascript #npm #node_modules #dependencies #Package-hell
programmerhumor.io/javascript-memes/camel-c...
Include Math And Pray For Mercy
Include Math And Pray For Mercy
#Math #Libraries #dependencies #Cleancode #Softwareengineering
programmerhumor.io/math-memes/include-math-...