home.social

Search

464 results for “jvt”

  1. Dependency Management Data can now use sql-studio for database browsing

    Announcing the availability of the `sql-studio` database browser for dependency-management-data's web application.

    fed.brid.gy/r/https://www.jvt.

  2. Dependency Management Data's web application can now be deployed as a single static binary

    Announcing dependency-management-data's embedded SQL browser interface.

    fed.brid.gy/r/https://www.jvt.

  3. What can we learn about the backdooring of xz/liblzma, using OpenSSF Security Scorecards and dependency-management-data?

    Looking at how the recent CVE-2024-3094 vulnerability could provide insight into other cases of risk in dependencies and their lack of code review.

    fed.brid.gy/r/https://www.jvt.

  4. I'm on Changelog and Friends!

    Announcing my first podcast appearance on Changelog and Friends, talking about salary history, the IndieWeb, ADHD and dependency-management-data, among other things.

    fed.brid.gy/r/https://www.jvt.

  5. Quantifying your reliance on Open Source software (State of Open Con version)

    A writeup of my talk about the dependency-management-data project at the State of Open Con 2024 conference.

    fed.brid.gy/r/https://www.jvt.

  6. Celebrating dependency-management-data's first birthday

    Reflecting on the last year of the project.

    fed.brid.gy/r/https://www.jvt.

  7. Introducing insight into your dependencies' health in dependency-management-data

    How you can use the new dependency health functionality to better understand your dependencies.

    fed.brid.gy/r/https://www.jvt.

  8. dependency-management-data now has a logo!

    Very excited to note that the project now has a logo.

    fed.brid.gy/r/https://www.jvt.

  9. Manually triggering a Buildkite pipeline for a fork

    How to trigger a Buildkite pipeline to run on a fork, if you have access to trigger a build.

    fed.brid.gy/r/https://www.jvt.

  10. Listing environment variables used to trigger a Buildkite pipeline

    How to use Buildkite's GraphQL API to list the environment variables provided to trigger a pipeline.

    fed.brid.gy/r/https://www.jvt.

  11. Building dynamic jobs with BuildKite

    How to dynamically generate job configuration for BuildKite, while running inside a pipeline.

    fed.brid.gy/r/https://www.jvt.

  12. Importing a subdirectory from one repo into another

    How to import a subdirectory of a given Git repository into another one, using `git subtree`.

    fed.brid.gy/r/https://www.jvt.

  13. Importing a subdirectory from one repo into another

    How to import a subdirectory of a given Git repository into another one, using `git subtree`.

    fed.brid.gy/r/https://www.jvt.

  14. Merging multiple repositories into a monorepo, while preserving history, using git subtree

    How to merge multiple repositories, with their history, into a single repository, using the `git subtree add` command.

    fed.brid.gy/r/https://www.jvt.

  15. Merging multiple repositories into a monorepo, while preserving history, using git subtree

    How to merge multiple repositories, with their history, into a single repository, using the `git subtree add` command.

    fed.brid.gy/r/https://www.jvt.

  16. Merging multiple repositories into a monorepo, while preserving history, using git subtree

    How to merge multiple repositories, with their history, into a single repository, using the `git subtree add` command.

    fed.brid.gy/r/https://www.jvt.

  17. Merging multiple repositories into a monorepo, while preserving history, using git subtree

    How to merge multiple repositories, with their history, into a single repository, using the `git subtree add` command.

    fed.brid.gy/r/https://www.jvt.

  18. The first 100 days as a Renovate maintainer: the shocking inside view of a popular Open Source project

    Lessons learned from the first 100 days as my role as a Renovate maintainer, and a sneak peek into how the project works behind the scenes.

    fed.brid.gy/r/https://www.jvt.

  19. The first 100 days as a Renovate maintainer: the shocking inside view of a popular Open Source project

    Lessons learned from the first 100 days as my role as a Renovate maintainer, and a sneak peek into how the project works behind the scenes.

    fed.brid.gy/r/https://www.jvt.

  20. The first 100 days as a Renovate maintainer: the shocking inside view of a popular Open Source project

    Lessons learned from the first 100 days as my role as a Renovate maintainer, and a sneak peek into how the project works behind the scenes.

    fed.brid.gy/r/https://www.jvt.

  21. The first 100 days as a Renovate maintainer: the shocking inside view of a popular Open Source project

    Lessons learned from the first 100 days as my role as a Renovate maintainer, and a sneak peek into how the project works behind the scenes.

    fed.brid.gy/r/https://www.jvt.

  22. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  23. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  24. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  25. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github

  26. RE: mastodon.social/@hugovk/116399

    Starting with v8.0.0, Astral switched setup-uv to immutable releases with no floating v8 tags. This is good for security.

    But unfortunately #Dependabot and #Renovate couldn't upgrade from v7 to v8.0.0, and need a manual bump to get back on track. This is not so good for security.

    I posted about this on the three social networks, someone tagged @www.jvt.me and soon after Renovate now supports this! 🎉

    Here's his writeup into the world of #GitHubActions tags:
    jvt.me/posts/2026/04/24/github