home.social

#dependencies — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dependencies, aggregated by home.social.

fetched live
  1. Major Shai Hulud Campaign Strikes npm Again, Affecting keyv and 400 Packages, by (not on Mastodon or Bluesky):

    research.jfrog.com/post/shai-h

  2. AI coding agents can introduce risky dependencies faster than teams can vet them—“dependency cooldowns” might be the control we need. jpmellojr.blogspot.com/2026/07 #cooldowns #AI #AppSec #DevSecOps #dependencies

  3. AI coding agents can introduce risky dependencies faster than teams can vet them—“dependency cooldowns” might be the control we need. jpmellojr.blogspot.com/2026/07 #cooldowns #AI #AppSec #DevSecOps #dependencies

  4. AI coding agents can introduce risky dependencies faster than teams can vet them—“dependency cooldowns” might be the control we need. jpmellojr.blogspot.com/2026/07 #cooldowns #AI #AppSec #DevSecOps #dependencies

  5. AI coding agents can introduce risky dependencies faster than teams can vet them—“dependency cooldowns” might be the control we need. jpmellojr.blogspot.com/2026/07 #cooldowns #AI #AppSec #DevSecOps #dependencies

  6. AI coding agents can introduce risky dependencies faster than teams can vet them—“dependency cooldowns” might be the control we need. jpmellojr.blogspot.com/2026/07 #cooldowns #AI #AppSec #DevSecOps #dependencies

  7. [Перевод] Тестовые фикстуры: управление зависимостями в Gradle

    В многомодульных Gradle-проектах рано или поздно появляются вспомогательные классы для тестов: фабрики тестовых данных, билдеры, хелперы. Такие классы не относятся ни к продакшн-коду, ни к обычным тестам. Логично было бы переиспользовать их сразу в нескольких модулях, но классическая модель Gradle этого не позволяет: тестовые артефакты одного проекта нельзя просто так подключить как зависимость в другом. На самом деле Gradle умеет решать эту задачу из коробки без вспомогательных проектов и хитрых конфигураций. Начиная с версии 5.6, тестовые фикстуры стали в Gradle полноценной сущностью первого класса, и весь этот пласт боли можно убрать буквально несколькими строчками в build.gradle. Плагин java-test-fixtures заводит в модуле отдельный SourceSet, а другие модули подключают эти классы через лаконичный DSL. При публикации Gradle даже собирает отдельный *-test-fixtures.jar для независимых проектов. В статье на примерах показано, как расшарить тестовые хелперы между модулями, избавиться от дублирования и при этом сохранить чистые архитектурные границы. Если вы устали таскать тестовый код из модуля в модуль, то Вам точно пригодится.

    habr.com/ru/companies/spring_a

    #gradle #dependencies #java #kotlin

  8. [Перевод] Тестовые фикстуры: управление зависимостями в Gradle

    В многомодульных Gradle-проектах рано или поздно появляются вспомогательные классы для тестов: фабрики тестовых данных, билдеры, хелперы. Такие классы не относятся ни к продакшн-коду, ни к обычным тестам. Логично было бы переиспользовать их сразу в нескольких модулях, но классическая модель Gradle этого не позволяет: тестовые артефакты одного проекта нельзя просто так подключить как зависимость в другом. На самом деле Gradle умеет решать эту задачу из коробки без вспомогательных проектов и хитрых конфигураций. Начиная с версии 5.6, тестовые фикстуры стали в Gradle полноценной сущностью первого класса, и весь этот пласт боли можно убрать буквально несколькими строчками в build.gradle. Плагин java-test-fixtures заводит в модуле отдельный SourceSet, а другие модули подключают эти классы через лаконичный DSL. При публикации Gradle даже собирает отдельный *-test-fixtures.jar для независимых проектов. В статье на примерах показано, как расшарить тестовые хелперы между модулями, избавиться от дублирования и при этом сохранить чистые архитектурные границы. Если вы устали таскать тестовый код из модуля в модуль, то Вам точно пригодится.

    habr.com/ru/companies/spring_a

    #gradle #dependencies #java #kotlin

  9. [Перевод] Тестовые фикстуры: управление зависимостями в Gradle

    В многомодульных Gradle-проектах рано или поздно появляются вспомогательные классы для тестов: фабрики тестовых данных, билдеры, хелперы. Такие классы не относятся ни к продакшн-коду, ни к обычным тестам. Логично было бы переиспользовать их сразу в нескольких модулях, но классическая модель Gradle этого не позволяет: тестовые артефакты одного проекта нельзя просто так подключить как зависимость в другом. На самом деле Gradle умеет решать эту задачу из коробки без вспомогательных проектов и хитрых конфигураций. Начиная с версии 5.6, тестовые фикстуры стали в Gradle полноценной сущностью первого класса, и весь этот пласт боли можно убрать буквально несколькими строчками в build.gradle. Плагин java-test-fixtures заводит в модуле отдельный SourceSet, а другие модули подключают эти классы через лаконичный DSL. При публикации Gradle даже собирает отдельный *-test-fixtures.jar для независимых проектов. В статье на примерах показано, как расшарить тестовые хелперы между модулями, избавиться от дублирования и при этом сохранить чистые архитектурные границы. Если вы устали таскать тестовый код из модуля в модуль, то Вам точно пригодится.

    habr.com/ru/companies/spring_a

    #gradle #dependencies #java #kotlin

  10. 🖼️ Behold! A parade of #Ilograph #diagrams that promise to elevate your consciousness (or bore you to tears) with their gloriously mundane details about #serverless backends and #datacenter #networks. 🤔 Because who doesn’t dream of spending their free time swimming in an ocean of #request #dependencies and #DNS configurations? 💤
    app.ilograph.com/demo.ilograph #Tech #Configurations #HackerNews #ngated

  11. 🖼️ Behold! A parade of #Ilograph #diagrams that promise to elevate your consciousness (or bore you to tears) with their gloriously mundane details about #serverless backends and #datacenter #networks. 🤔 Because who doesn’t dream of spending their free time swimming in an ocean of #request #dependencies and #DNS configurations? 💤
    app.ilograph.com/demo.ilograph #Tech #Configurations #HackerNews #ngated

  12. 🖼️ Behold! A parade of #Ilograph #diagrams that promise to elevate your consciousness (or bore you to tears) with their gloriously mundane details about #serverless backends and #datacenter #networks. 🤔 Because who doesn’t dream of spending their free time swimming in an ocean of #request #dependencies and #DNS configurations? 💤
    app.ilograph.com/demo.ilograph #Tech #Configurations #HackerNews #ngated

  13. 🖼️ Behold! A parade of #Ilograph #diagrams that promise to elevate your consciousness (or bore you to tears) with their gloriously mundane details about #serverless backends and #datacenter #networks. 🤔 Because who doesn’t dream of spending their free time swimming in an ocean of #request #dependencies and #DNS configurations? 💤
    app.ilograph.com/demo.ilograph #Tech #Configurations #HackerNews #ngated

  14. 🖼️ Behold! A parade of #Ilograph #diagrams that promise to elevate your consciousness (or bore you to tears) with their gloriously mundane details about #serverless backends and #datacenter #networks. 🤔 Because who doesn’t dream of spending their free time swimming in an ocean of #request #dependencies and #DNS configurations? 💤
    app.ilograph.com/demo.ilograph #Tech #Configurations #HackerNews #ngated

  15. “For #Canada, our core #digital, #financial, #defence, and #infrastructure #dependencies already run through #U.S. systems. That #interdependence was mostly manageable when both countries operated under a shared assumption of mutual benefit. But that exposure is more of a vulnerability today.”

    RE: https://bsky.app/profile/did:plc:5zca2ola2zxpkw37w4f3wxtu/post/3mpqk6ytzvc2v

  16. “For #Canada, our core #digital, #financial, #defence, and #infrastructure #dependencies already run through #U.S. systems. That #interdependence was mostly manageable when both countries operated under a shared assumption of mutual benefit. But that exposure is more of a vulnerability today.”

    RE: https://bsky.app/profile/did:plc:5zca2ola2zxpkw37w4f3wxtu/post/3mpqk6ytzvc2v

  17. “For #Canada, our core #digital, #financial, #defence, and #infrastructure #dependencies already run through #U.S. systems. That #interdependence was mostly manageable when both countries operated under a shared assumption of mutual benefit. But that exposure is more of a vulnerability today.”

    RE: https://bsky.app/profile/did:plc:5zca2ola2zxpkw37w4f3wxtu/post/3mpqk6ytzvc2v

  18. “For #Canada, our core #digital, #financial, #defence, and #infrastructure #dependencies already run through #U.S. systems. That #interdependence was mostly manageable when both countries operated under a shared assumption of mutual benefit. But that exposure is more of a vulnerability today.”

    RE: https://bsky.app/profile/did:plc:5zca2ola2zxpkw37w4f3wxtu/post/3mpqk6ytzvc2v

  19. “For #Canada, our core #digital, #financial, #defence, and #infrastructure #dependencies already run through #U.S. systems. That #interdependence was mostly manageable when both countries operated under a shared assumption of mutual benefit. But that exposure is more of a vulnerability today.”

    RE: https://bsky.app/profile/did:plc:5zca2ola2zxpkw37w4f3wxtu/post/3mpqk6ytzvc2v

  20. Another view on #JabRef. Most probably the #Java #DesktopApplication with the most #dependencies.

    We are very happy for the strong community of maintainers.

    If you like our #OpenSource work, please give us a star ⭐ at github.com/jabref/jabref/.

    And surely a huge thank you to the whole community of Open Source maintainers driving the whole #Java and #JavaFX eco system.

  21. Another view on #JabRef. Most probably the #Java #DesktopApplication with the most #dependencies.

    We are very happy for the strong community of maintainers.

    If you like our #OpenSource work, please give us a star ⭐ at github.com/jabref/jabref/.

    And surely a huge thank you to the whole community of Open Source maintainers driving the whole #Java and #JavaFX eco system.

  22. Another view on #JabRef. Most probably the #Java #DesktopApplication with the most #dependencies.

    We are very happy for the strong community of maintainers.

    If you like our #OpenSource work, please give us a star ⭐ at github.com/jabref/jabref/.

    And surely a huge thank you to the whole community of Open Source maintainers driving the whole #Java and #JavaFX eco system.

  23. Another view on #JabRef. Most probably the #Java #DesktopApplication with the most #dependencies.

    We are very happy for the strong community of maintainers.

    If you like our #OpenSource work, please give us a star ⭐ at github.com/jabref/jabref/.

    And surely a huge thank you to the whole community of Open Source maintainers driving the whole #Java and #JavaFX eco system.

  24. Another view on #JabRef. Most probably the #Java #DesktopApplication with the most #dependencies.

    We are very happy for the strong community of maintainers.

    If you like our #OpenSource work, please give us a star ⭐ at github.com/jabref/jabref/.

    And surely a huge thank you to the whole community of Open Source maintainers driving the whole #Java and #JavaFX eco system.

  25. New release of CPAN::FindDependencies. This fixes a small infelicity where if you told it to use a directory for its cache and that directory doesn't exist, it just ignores what you said. It now tries to create the directory. If after that there's still no usable directory that is a fatal error.

    Thanks to Kurt Starsinic for the bug report.

    metacpan.org/release/DCANTRELL

    #CPAN #perl #dependencies #bugfix

  26. New release of CPAN::FindDependencies. This fixes a small infelicity where if you told it to use a directory for its cache and that directory doesn't exist, it just ignores what you said. It now tries to create the directory. If after that there's still no usable directory that is a fatal error.

    Thanks to Kurt Starsinic for the bug report.

    metacpan.org/release/DCANTRELL

  27. New release of CPAN::FindDependencies. This fixes a small infelicity where if you told it to use a directory for its cache and that directory doesn't exist, it just ignores what you said. It now tries to create the directory. If after that there's still no usable directory that is a fatal error.

    Thanks to Kurt Starsinic for the bug report.

    metacpan.org/release/DCANTRELL

    #CPAN #perl #dependencies #bugfix

  28. New release of CPAN::FindDependencies. This fixes a small infelicity where if you told it to use a directory for its cache and that directory doesn't exist, it just ignores what you said. It now tries to create the directory. If after that there's still no usable directory that is a fatal error.

    Thanks to Kurt Starsinic for the bug report.

    metacpan.org/release/DCANTRELL

    #CPAN #perl #dependencies #bugfix

  29. New release of CPAN::FindDependencies. This fixes a small infelicity where if you told it to use a directory for its cache and that directory doesn't exist, it just ignores what you said. It now tries to create the directory. If after that there's still no usable directory that is a fatal error.

    Thanks to Kurt Starsinic for the bug report.

    metacpan.org/release/DCANTRELL

    #CPAN #perl #dependencies #bugfix

  30. Как незаметная indirect-зависимость в Go дописала ручку в ваш HTTP-сервер

    Аккуратный Go-сервис на net/http с единственной ручкой /time. Обновляем одну библиотеку через go get, не трогая свой код. После рестарта в сервисе появляется ручка /__injected, которая отдаёт строки из памяти процесса. Мы её не регистрировали — а пакет, который это сделал, формально даже не используется. Разбираю шаг за шагом, как такое возможно: модель зависимостей Go и коварство //indirect, тихий вход через init(), сканирование кучи и unsafe. Pointer для поиска ServeMux в работающем сервере. И, конечно, как от этого защищаться — от аудита зависимостей до seccomp и read-only ФС. Весь код — в репозитории, «вредонос» написан в учебных целях. Запускать только в песочнице. Разобрать «вредоноса»

    habr.com/ru/articles/1048732/

    #init #gomod #dependencies

  31. Как незаметная indirect-зависимость в Go дописала ручку в ваш HTTP-сервер

    Аккуратный Go-сервис на net/http с единственной ручкой /time. Обновляем одну библиотеку через go get, не трогая свой код. После рестарта в сервисе появляется ручка /__injected, которая отдаёт строки из памяти процесса. Мы её не регистрировали — а пакет, который это сделал, формально даже не используется. Разбираю шаг за шагом, как такое возможно: модель зависимостей Go и коварство //indirect, тихий вход через init(), сканирование кучи и unsafe. Pointer для поиска ServeMux в работающем сервере. И, конечно, как от этого защищаться — от аудита зависимостей до seccomp и read-only ФС. Весь код — в репозитории, «вредонос» написан в учебных целях. Запускать только в песочнице. Разобрать «вредоноса»

    habr.com/ru/articles/1048732/

    #init #gomod #dependencies

  32. Как незаметная indirect-зависимость в Go дописала ручку в ваш HTTP-сервер

    Аккуратный Go-сервис на net/http с единственной ручкой /time. Обновляем одну библиотеку через go get, не трогая свой код. После рестарта в сервисе появляется ручка /__injected, которая отдаёт строки из памяти процесса. Мы её не регистрировали — а пакет, который это сделал, формально даже не используется. Разбираю шаг за шагом, как такое возможно: модель зависимостей Go и коварство //indirect, тихий вход через init(), сканирование кучи и unsafe. Pointer для поиска ServeMux в работающем сервере. И, конечно, как от этого защищаться — от аудита зависимостей до seccomp и read-only ФС. Весь код — в репозитории, «вредонос» написан в учебных целях. Запускать только в песочнице. Разобрать «вредоноса»

    habr.com/ru/articles/1048732/

    #init #gomod #dependencies