home.social

#dependency-management-data — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dependency-management-data, aggregated by home.social.

fetched live
  1. A couple of weeks ago I was at the Manchester Gophers, giving them a sneak peek of my tutorial I'm doing on Friday at #GopherConUK, and I had a blast - was a great time with some great people, and always a fan of sharing more about #DependencyManagementData

    Their post has some other great photos, but I think if you really want a convince to go and speak - if the great people isn't enough - you also get an amazing speaker gift - a custom made Gopher!

  2. A couple of weeks ago I was at the Manchester Gophers, giving them a sneak peek of my tutorial I'm doing on Friday at #GopherConUK, and I had a blast - was a great time with some great people, and always a fan of sharing more about #DependencyManagementData

    Their post has some other great photos, but I think if you really want a convince to go and speak - if the great people isn't enough - you also get an amazing speaker gift - a custom made Gopher!

  3. COVID test negative ✅

    Next stop: London for #GopherConUK

    Looking forward to seeing folks, learning from some awesome people, and sharing some cool insights you can learn from your organisation with #DependencyManagementData 🔥

  4. COVID test negative ✅

    Next stop: London for #GopherConUK

    Looking forward to seeing folks, learning from some awesome people, and sharing some cool insights you can learn from your organisation with #DependencyManagementData 🔥

  5. Creating beautiful visualisations of dependency data with Evidence

    How to use Dependency Management Data and Evidence to create beautiful visualisations for insights about your dependency data.

    fed.brid.gy/r/https://www.jvt.

  6. Creating beautiful visualisations of dependency data with Evidence

    How to use Dependency Management Data and Evidence to create beautiful visualisations for insights about your dependency data.

    fed.brid.gy/r/https://www.jvt.

  7. Properly patching packages: persistently producing patches for published projects, particularly practically prevented by patch-package policy

    How to use `patch-package` to modify NPM dependencies, for instance when you're distributing an executable and you want to patch something you rely upon, without relying upon `postinstall` scripts.

    fed.brid.gy/r/https://www.jvt.

  8. Properly patching packages: persistently producing patches for published projects, particularly practically prevented by patch-package policy

    How to use `patch-package` to modify NPM dependencies, for instance when you're distributing an executable and you want to patch something you rely upon, without relying upon `postinstall` scripts.

    fed.brid.gy/r/https://www.jvt.

  9. Off the back of the tj-actions/changed-files #SupplyChainSecurity attack, I've written up how you can use #DependencyManagementData to determine the impact across your org - already found it's been very useful 👀

  10. Off the back of the tj-actions/changed-files #SupplyChainSecurity attack, I've written up how you can use #DependencyManagementData to determine the impact across your org - already found it's been very useful 👀

  11. Celebrating dependency-management-data's second birthday

    Reflecting on the last year of the project.

    fed.brid.gy/r/https://www.jvt.

  12. Celebrating dependency-management-data's second birthday

    Reflecting on the last year of the project.

    fed.brid.gy/r/https://www.jvt.

  13. FYI that #DependencyManagementData v0.114.0 is out with an important refactor, but is one to watch out for!

    If you're using the Renovate datasource, the package_names may be different to what they were previously. This now makes them actual package names, rather than the "pretty" depName but it's likely to catch folks out 👀

  14. FYI that #DependencyManagementData v0.114.0 is out with an important refactor, but is one to watch out for!

    If you're using the Renovate datasource, the package_names may be different to what they were previously. This now makes them actual package names, rather than the "pretty" depName but it's likely to catch folks out 👀

  15. You can now resolve remote presets when using Renovate's local platform in renovate-graph

    Announcing a new release of `renovate-graph`, which can now follow `github>` and `local>` presets.

    fed.brid.gy/r/https://www.jvt.

  16. You can now resolve remote presets when using Renovate's local platform in renovate-graph

    Announcing a new release of `renovate-graph`, which can now follow `github>` and `local>` presets.

    fed.brid.gy/r/https://www.jvt.

  17. Creating renovate-packagedata-diff to diff Renovate package data dumps

    Announcing the release of `renovate-packagedata-diff` which makes it possible to provide a semantic diff between different Renovate package data dumps.

    fed.brid.gy/r/https://www.jvt.

  18. Creating renovate-packagedata-diff to diff Renovate package data dumps

    Announcing the release of `renovate-packagedata-diff` which makes it possible to provide a semantic diff between different Renovate package data dumps.

    fed.brid.gy/r/https://www.jvt.

  19. Lessons learned adding OpenTelemetry to a (Cobra) command-line Go tool

    Some reflections on what I've found good and not so good about instrumenting a command-line tool with OpenTelemetry.

    fed.brid.gy/r/https://www.jvt.

  20. Lessons learned adding OpenTelemetry to a (Cobra) command-line Go tool

    Some reflections on what I've found good and not so good about instrumenting a command-line tool with OpenTelemetry.

    fed.brid.gy/r/https://www.jvt.

  21. Summarising the skipReasons for Renovate data exports

    How to work out what `skipReason`s you have for your Renovate package data.

    fed.brid.gy/r/https://www.jvt.

  22. Summarising the skipReasons for Renovate data exports

    How to work out what `skipReason`s you have for your Renovate package data.

    fed.brid.gy/r/https://www.jvt.

  23. How to use Dependency Management Data to discover which dependencies are participating in Hacktoberfest

    Detailing how you could use dependency-management-data to gain insight into which dependencies you use are participating in Hacktoberfest.

    fed.brid.gy/r/https://www.jvt.

  24. How to use Dependency Management Data to discover which dependencies are participating in Hacktoberfest

    Detailing how you could use dependency-management-data to gain insight into which dependencies you use are participating in Hacktoberfest.

    fed.brid.gy/r/https://www.jvt.

  25. You can now parse repo-level Renovate configuration with renovate-graph

    Announcing a new release of `renovate-graph` which now parses repo-level Renovate configuration.

    fed.brid.gy/r/https://www.jvt.

  26. You can now parse repo-level Renovate configuration with renovate-graph

    Announcing a new release of `renovate-graph` which now parses repo-level Renovate configuration.

    fed.brid.gy/r/https://www.jvt.

  27. Dependency Management Data's Open Policy Agent support is now a whole lot more efficient

    Talking about the latest release of Dependency Management Data and some refactoring that's led to better performance.

    fed.brid.gy/r/https://www.jvt.

  28. Dependency Management Data's Open Policy Agent support is now a whole lot more efficient

    Talking about the latest release of Dependency Management Data and some refactoring that's led to better performance.

    fed.brid.gy/r/https://www.jvt.

  29. Dependency Management Data's now on Mastodon!

    Announcing the dependency-management-data Mastodon account for automated release announcements (and more?).

    fed.brid.gy/r/https://www.jvt.

  30. Dependency Management Data's now on Mastodon!

    Announcing the dependency-management-data Mastodon account for automated release announcements (and more?).

    fed.brid.gy/r/https://www.jvt.

  31. Dynamically querying EndOfLife.date data for internal packages with Open Policy Agent and Dependency Management Data

    How you can retrieve End-of-Life data via EndOfLife.date using Dependency Management Data's Policies functionality.

    fed.brid.gy/r/https://www.jvt.

  32. Dynamically querying EndOfLife.date data for internal packages with Open Policy Agent and Dependency Management Data

    How you can retrieve End-of-Life data via EndOfLife.date using Dependency Management Data's Policies functionality.

    fed.brid.gy/r/https://www.jvt.

  33. Dependency Management Data is now a lot easier to work with when using Software Bill of Materials

    Announcing an improved model for interacting with SBOMs, removing the need to understand the Repo Key up-front.

    fed.brid.gy/r/https://www.jvt.

  34. Dependency Management Data is now a lot easier to work with when using Software Bill of Materials

    Announcing an improved model for interacting with SBOMs, removing the need to understand the Repo Key up-front.

    fed.brid.gy/r/https://www.jvt.

  35. Dependency Management Data can now use sql-studio for database browsing

    Announcing the availability of the `sql-studio` database browser for dependency-management-data's web application.

    fed.brid.gy/r/https://www.jvt.

  36. Dependency Management Data can now use sql-studio for database browsing

    Announcing the availability of the `sql-studio` database browser for dependency-management-data's web application.

    fed.brid.gy/r/https://www.jvt.

  37. Dependency Management Data's web application can now be deployed as a single static binary

    Announcing dependency-management-data's embedded SQL browser interface.

    fed.brid.gy/r/https://www.jvt.

  38. Dependency Management Data's web application can now be deployed as a single static binary

    Announcing dependency-management-data's embedded SQL browser interface.

    fed.brid.gy/r/https://www.jvt.

  39. What can we learn about the backdooring of xz/liblzma, using OpenSSF Security Scorecards and dependency-management-data?

    Looking at how the recent CVE-2024-3094 vulnerability could provide insight into other cases of risk in dependencies and their lack of code review.

    fed.brid.gy/r/https://www.jvt.

  40. What can we learn about the backdooring of xz/liblzma, using OpenSSF Security Scorecards and dependency-management-data?

    Looking at how the recent CVE-2024-3094 vulnerability could provide insight into other cases of risk in dependencies and their lack of code review.

    fed.brid.gy/r/https://www.jvt.

  41. I'm on Changelog and Friends!

    Announcing my first podcast appearance on Changelog and Friends, talking about salary history, the IndieWeb, ADHD and dependency-management-data, among other things.

    fed.brid.gy/r/https://www.jvt.

  42. I'm on Changelog and Friends!

    Announcing my first podcast appearance on Changelog and Friends, talking about salary history, the IndieWeb, ADHD and dependency-management-data, among other things.

    fed.brid.gy/r/https://www.jvt.

  43. Very excited to see that the videos from #StateOfOpenCon #SOOCon24 are up - so if you missed my talk Quantifying Your Reliance on Open Source Software with #DependencyManagementData, you can find the recording on YouTube.

    If you're interested, also check out the slides and the full talk writeup.

  44. Very excited to see that the videos from #StateOfOpenCon #SOOCon24 are up - so if you missed my talk Quantifying Your Reliance on Open Source Software with #DependencyManagementData, you can find the recording on YouTube.

    If you're interested, also check out the slides and the full talk writeup.

  45. Quantifying your reliance on Open Source software (State of Open Con version)

    A writeup of my talk about the dependency-management-data project at the State of Open Con 2024 conference.

    fed.brid.gy/r/https://www.jvt.

  46. Quantifying your reliance on Open Source software (State of Open Con version)

    A writeup of my talk about the dependency-management-data project at the State of Open Con 2024 conference.

    fed.brid.gy/r/https://www.jvt.

  47. Celebrating dependency-management-data's first birthday

    Reflecting on the last year of the project.

    fed.brid.gy/r/https://www.jvt.

  48. Celebrating dependency-management-data's first birthday

    Reflecting on the last year of the project.

    fed.brid.gy/r/https://www.jvt.

  49. Introducing insight into your dependencies' health in dependency-management-data

    How you can use the new dependency health functionality to better understand your dependencies.

    fed.brid.gy/r/https://www.jvt.

  50. Introducing insight into your dependencies' health in dependency-management-data

    How you can use the new dependency health functionality to better understand your dependencies.

    fed.brid.gy/r/https://www.jvt.

  51. dependency-management-data now has a logo!

    Very excited to note that the project now has a logo.

    fed.brid.gy/r/https://www.jvt.

  52. dependency-management-data now has a logo!

    Very excited to note that the project now has a logo.

    fed.brid.gy/r/https://www.jvt.

  53. I was pretty chuffed with adding these Slack notifications (via Goreleaser and go-semantic-release) for releases to #DependencyManagementData which flag when there are breaking changes in the release! Makes it much easier to see at a glance, especially as there's a lot of changes going into it 🤓

  54. I was pretty chuffed with adding these Slack notifications (via Goreleaser and go-semantic-release) for releases to #DependencyManagementData which flag when there are breaking changes in the release! Makes it much easier to see at a glance, especially as there's a lot of changes going into it 🤓