home.social

#dependencymanagement — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dependencymanagement, aggregated by home.social.

  1. 🚀 "In a revolutionary finding, Olivier Gambier advocates for the groundbreaking strategy of *not* updating your dependencies in 2026. Because nothing screams 'innovation' like turning your server into a digital Jurassic Park 🦖, where ancient vulnerabilities roam free and happy!" 🧑‍💻🔗
    mendral.com/blog/you-should-no #HackerNews #DependencyManagement #DigitalJurassicPark #TechInnovation #SoftwareDevelopment #HackerNews #ngated

  2. 🚀 "In a revolutionary finding, Olivier Gambier advocates for the groundbreaking strategy of *not* updating your dependencies in 2026. Because nothing screams 'innovation' like turning your server into a digital Jurassic Park 🦖, where ancient vulnerabilities roam free and happy!" 🧑‍💻🔗
    mendral.com/blog/you-should-no #HackerNews #DependencyManagement #DigitalJurassicPark #TechInnovation #SoftwareDevelopment #HackerNews #ngated

  3. 🚀 "In a revolutionary finding, Olivier Gambier advocates for the groundbreaking strategy of *not* updating your dependencies in 2026. Because nothing screams 'innovation' like turning your server into a digital Jurassic Park 🦖, where ancient vulnerabilities roam free and happy!" 🧑‍💻🔗
    mendral.com/blog/you-should-no #HackerNews #DependencyManagement #DigitalJurassicPark #TechInnovation #SoftwareDevelopment #HackerNews #ngated

  4. 🚀 "In a revolutionary finding, Olivier Gambier advocates for the groundbreaking strategy of *not* updating your dependencies in 2026. Because nothing screams 'innovation' like turning your server into a digital Jurassic Park 🦖, where ancient vulnerabilities roam free and happy!" 🧑‍💻🔗
    mendral.com/blog/you-should-no #HackerNews #DependencyManagement #DigitalJurassicPark #TechInnovation #SoftwareDevelopment #HackerNews #ngated

  5. 🚀 "In a revolutionary finding, Olivier Gambier advocates for the groundbreaking strategy of *not* updating your dependencies in 2026. Because nothing screams 'innovation' like turning your server into a digital Jurassic Park 🦖, where ancient vulnerabilities roam free and happy!" 🧑‍💻🔗
    mendral.com/blog/you-should-no #HackerNews #DependencyManagement #DigitalJurassicPark #TechInnovation #SoftwareDevelopment #HackerNews #ngated

  6. Сможете ли вы спроектировать Maven‑монорепозиторий для 5 микросервисов?

    В этой статье мы разберём реальную задачу на проектирование Maven Multi‑Module: от циклических зависимостей и неправильного использования spring‑boot‑maven‑plugin до смешения ролей агрегатора и родителя. Затем соберём эталонную структуру по лучшим практикам Spring Cloud и Netflix, добавим CI/CD‑диаграмму и научимся запускать сервис локально без Eureka и RabbitMQ. Найти ошибки

    habr.com/ru/companies/otus/art

    #Maven #монорепозиторий #микросервисы #Spring_Boot #multimodule #dependencyManagement #Maven_Wrapper #архитектура_сборки #Java

  7. Сможете ли вы спроектировать Maven‑монорепозиторий для 5 микросервисов?

    В этой статье мы разберём реальную задачу на проектирование Maven Multi‑Module: от циклических зависимостей и неправильного использования spring‑boot‑maven‑plugin до смешения ролей агрегатора и родителя. Затем соберём эталонную структуру по лучшим практикам Spring Cloud и Netflix, добавим CI/CD‑диаграмму и научимся запускать сервис локально без Eureka и RabbitMQ. Найти ошибки

    habr.com/ru/companies/otus/art

    #Maven #монорепозиторий #микросервисы #Spring_Boot #multimodule #dependencyManagement #Maven_Wrapper #архитектура_сборки #Java

  8. Сможете ли вы спроектировать Maven‑монорепозиторий для 5 микросервисов?

    В этой статье мы разберём реальную задачу на проектирование Maven Multi‑Module: от циклических зависимостей и неправильного использования spring‑boot‑maven‑plugin до смешения ролей агрегатора и родителя. Затем соберём эталонную структуру по лучшим практикам Spring Cloud и Netflix, добавим CI/CD‑диаграмму и научимся запускать сервис локально без Eureka и RabbitMQ. Найти ошибки

    habr.com/ru/companies/otus/art

    #Maven #монорепозиторий #микросервисы #Spring_Boot #multimodule #dependencyManagement #Maven_Wrapper #архитектура_сборки #Java

  9. Сможете ли вы спроектировать Maven‑монорепозиторий для 5 микросервисов?

    В этой статье мы разберём реальную задачу на проектирование Maven Multi‑Module: от циклических зависимостей и неправильного использования spring‑boot‑maven‑plugin до смешения ролей агрегатора и родителя. Затем соберём эталонную структуру по лучшим практикам Spring Cloud и Netflix, добавим CI/CD‑диаграмму и научимся запускать сервис локально без Eureka и RabbitMQ. Найти ошибки

    habr.com/ru/companies/otus/art

    #Maven #монорепозиторий #микросервисы #Spring_Boot #multimodule #dependencyManagement #Maven_Wrapper #архитектура_сборки #Java

  10. Are you working with software dependencies in constrained environments? Then this might interest you:

    I’ll give a lightning talk on how we approach practical license and vulnerability management when resources are limited. As Technical Solution Lead at Alliander I deal daily issues regarding licensing and security. I’ll talk about tooling, share key findings and insights.

    Where & when to go?
    Monday, March 23
    13:15 CET
    Amsterdam

    #Ospology #DevOps #Security #OpenSource #DependencyManagement

  11. Are you working with software dependencies in constrained environments? Then this might interest you:

    I’ll give a lightning talk on how we approach practical license and vulnerability management when resources are limited. As Technical Solution Lead at Alliander I deal daily issues regarding licensing and security. I’ll talk about tooling, share key findings and insights.

    Where & when to go?
    Monday, March 23
    13:15 CET
    Amsterdam

    #Ospology #DevOps #Security #OpenSource #DependencyManagement

  12. Are you working with software dependencies in constrained environments? Then this might interest you:

    I’ll give a lightning talk on how we approach practical license and vulnerability management when resources are limited. As Technical Solution Lead at Alliander I deal daily issues regarding licensing and security. I’ll talk about tooling, share key findings and insights.

    Where & when to go?
    Monday, March 23
    13:15 CET
    Amsterdam

    #Ospology #DevOps #Security #OpenSource #DependencyManagement

  13. Are you working with software dependencies in constrained environments? Then this might interest you:

    I’ll give a lightning talk on how we approach practical license and vulnerability management when resources are limited. As Technical Solution Lead at Alliander I deal daily issues regarding licensing and security. I’ll talk about tooling, share key findings and insights.

    Where & when to go?
    Monday, March 23
    13:15 CET
    Amsterdam

    #Ospology #DevOps #Security #OpenSource #DependencyManagement

  14. Are you working with software dependencies in constrained environments? Then this might interest you:

    I’ll give a lightning talk on how we approach practical license and vulnerability management when resources are limited. As Technical Solution Lead at Alliander I deal daily issues regarding licensing and security. I’ll talk about tooling, share key findings and insights.

    Where & when to go?
    Monday, March 23
    13:15 CET
    Amsterdam

    #Ospology #DevOps #Security #OpenSource #DependencyManagement

  15. Hey devs! 👋

    I build mobile apps and got tired of manually fixing broken builds and dependencies after package updates. So I decided to build an AI agent that automatically fixes update-related errors and updates dependencies — even library upgrades.

    Quick facts about the agent:
    - Runs on deepseek in deepseek-chst (v3.2) mode with temperature 0.0.
    - Can revive the project after errors and run automated tests.
    - Won’t require confirmations for common commands (build, run, flutter pub get, etc.) to save time.
    - While the agent fixes things automatically, you can do something useful or grab a coffee ☕.

    Why this matters:
    - I tried dozens of solutions — many crash frequently or demand confirmations even for simple commands (cd, cat, etc.). Endless "Y + Enter" kills productivity.

    Want to help?
    - If you want to join improving this tool — follow me and leave feedback. I’ll share the open Git repo and welcome your suggestions and criticism.

    Thanks — have a great day/evening (time zones may vary)!

    #devtools #aiagent #automation #mobiledev #flutter #dependencymanagement #ci #devops #softwareengineering #productivity

  16. Hey devs! 👋

    I build mobile apps and got tired of manually fixing broken builds and dependencies after package updates. So I decided to build an AI agent that automatically fixes update-related errors and updates dependencies — even library upgrades.

    Quick facts about the agent:
    - Runs on deepseek in deepseek-chst (v3.2) mode with temperature 0.0.
    - Can revive the project after errors and run automated tests.
    - Won’t require confirmations for common commands (build, run, flutter pub get, etc.) to save time.
    - While the agent fixes things automatically, you can do something useful or grab a coffee ☕.

    Why this matters:
    - I tried dozens of solutions — many crash frequently or demand confirmations even for simple commands (cd, cat, etc.). Endless "Y + Enter" kills productivity.

    Want to help?
    - If you want to join improving this tool — follow me and leave feedback. I’ll share the open Git repo and welcome your suggestions and criticism.

    Thanks — have a great day/evening (time zones may vary)!

    #devtools #aiagent #automation #mobiledev #flutter #dependencymanagement #ci #devops #softwareengineering #productivity

  17. Hey devs! 👋

    I build mobile apps and got tired of manually fixing broken builds and dependencies after package updates. So I decided to build an AI agent that automatically fixes update-related errors and updates dependencies — even library upgrades.

    Quick facts about the agent:
    - Runs on deepseek in deepseek-chst (v3.2) mode with temperature 0.0.
    - Can revive the project after errors and run automated tests.
    - Won’t require confirmations for common commands (build, run, flutter pub get, etc.) to save time.
    - While the agent fixes things automatically, you can do something useful or grab a coffee ☕.

    Why this matters:
    - I tried dozens of solutions — many crash frequently or demand confirmations even for simple commands (cd, cat, etc.). Endless "Y + Enter" kills productivity.

    Want to help?
    - If you want to join improving this tool — follow me and leave feedback. I’ll share the open Git repo and welcome your suggestions and criticism.

    Thanks — have a great day/evening (time zones may vary)!

    #devtools #aiagent #automation #mobiledev #flutter #dependencymanagement #ci #devops #softwareengineering #productivity

  18. Oh boy, another tool to generate and verify #lockfiles for GitHub Actions, because we all know life's too short to trust those pesky mutable tags. 🔒✨ Let's spend our precious time pinning every single action to exact commit SHAs, because who doesn't love a good game of dependency whack-a-mole? 🎯🛠️
    gh-actions-lockfile.net #GitHubActions #dependencyManagement #automation #tools #HackerNews #ngated

  19. Oh boy, another tool to generate and verify #lockfiles for GitHub Actions, because we all know life's too short to trust those pesky mutable tags. 🔒✨ Let's spend our precious time pinning every single action to exact commit SHAs, because who doesn't love a good game of dependency whack-a-mole? 🎯🛠️
    gh-actions-lockfile.net #GitHubActions #dependencyManagement #automation #tools #HackerNews #ngated

  20. Oh boy, another tool to generate and verify #lockfiles for GitHub Actions, because we all know life's too short to trust those pesky mutable tags. 🔒✨ Let's spend our precious time pinning every single action to exact commit SHAs, because who doesn't love a good game of dependency whack-a-mole? 🎯🛠️
    gh-actions-lockfile.net #GitHubActions #dependencyManagement #automation #tools #HackerNews #ngated

  21. Oh boy, another tool to generate and verify #lockfiles for GitHub Actions, because we all know life's too short to trust those pesky mutable tags. 🔒✨ Let's spend our precious time pinning every single action to exact commit SHAs, because who doesn't love a good game of dependency whack-a-mole? 🎯🛠️
    gh-actions-lockfile.net #GitHubActions #dependencyManagement #automation #tools #HackerNews #ngated

  22. I am really enjoying the Pixi package manager, pixi.sh , made by @prefix. We have been using conda at my work for managing the dependencies of our python application. It involves scientific data analysis so there are lots of dependencies, and it has been a challenge to keep things up to date. Pixi has nice support for cleanly defining the direct dependencies in the pixi.toml file, and then it automatically generates a lock file. There is a command to upgrade all the dependencies too. It's amazing! I'm just starting to use it, but it is helpful so far.

    #conda
    #packageManagement
    #pixi
    #dependencyManagement

  23. I am really enjoying the Pixi package manager, pixi.sh , made by @prefix. We have been using conda at my work for managing the dependencies of our python application. It involves scientific data analysis so there are lots of dependencies, and it has been a challenge to keep things up to date. Pixi has nice support for cleanly defining the direct dependencies in the pixi.toml file, and then it automatically generates a lock file. There is a command to upgrade all the dependencies too. It's amazing! I'm just starting to use it, but it is helpful so far.

    #conda
    #packageManagement
    #pixi
    #dependencyManagement

  24. I am really enjoying the Pixi package manager, pixi.sh , made by @prefix. We have been using conda at my work for managing the dependencies of our python application. It involves scientific data analysis so there are lots of dependencies, and it has been a challenge to keep things up to date. Pixi has nice support for cleanly defining the direct dependencies in the pixi.toml file, and then it automatically generates a lock file. There is a command to upgrade all the dependencies too. It's amazing! I'm just starting to use it, but it is helpful so far.

    #conda
    #packageManagement
    #pixi
    #dependencyManagement

  25. I am really enjoying the Pixi package manager, pixi.sh , made by @prefix. We have been using conda at my work for managing the dependencies of our python application. It involves scientific data analysis so there are lots of dependencies, and it has been a challenge to keep things up to date. Pixi has nice support for cleanly defining the direct dependencies in the pixi.toml file, and then it automatically generates a lock file. There is a command to upgrade all the dependencies too. It's amazing! I'm just starting to use it, but it is helpful so far.

    #conda
    #packageManagement
    #pixi
    #dependencyManagement

  26. I am really enjoying the Pixi package manager, pixi.sh , made by @prefix. We have been using conda at my work for managing the dependencies of our python application. It involves scientific data analysis so there are lots of dependencies, and it has been a challenge to keep things up to date. Pixi has nice support for cleanly defining the direct dependencies in the pixi.toml file, and then it automatically generates a lock file. There is a command to upgrade all the dependencies too. It's amazing! I'm just starting to use it, but it is helpful so far.

    #conda
    #packageManagement
    #pixi
    #dependencyManagement

  27. "Cooldowns enforce positive behavior from supply chain security vendors: vendors are still incentivized to discover and report attacks quickly, but are not as incentivized to emit volumes of blogspam about 'critical' attacks on largely underfunded open source ecosystems."

    #npm #supplychainattack #dependencymanagement

    blog.yossarian.net/2025/11/21/

  28. "Cooldowns enforce positive behavior from supply chain security vendors: vendors are still incentivized to discover and report attacks quickly, but are not as incentivized to emit volumes of blogspam about 'critical' attacks on largely underfunded open source ecosystems."

    #npm #supplychainattack #dependencymanagement

    blog.yossarian.net/2025/11/21/

  29. "Cooldowns enforce positive behavior from supply chain security vendors: vendors are still incentivized to discover and report attacks quickly, but are not as incentivized to emit volumes of blogspam about 'critical' attacks on largely underfunded open source ecosystems."

    blog.yossarian.net/2025/11/21/

  30. "Cooldowns enforce positive behavior from supply chain security vendors: vendors are still incentivized to discover and report attacks quickly, but are not as incentivized to emit volumes of blogspam about 'critical' attacks on largely underfunded open source ecosystems."

    #npm #supplychainattack #dependencymanagement

    blog.yossarian.net/2025/11/21/

  31. "Cooldowns enforce positive behavior from supply chain security vendors: vendors are still incentivized to discover and report attacks quickly, but are not as incentivized to emit volumes of blogspam about 'critical' attacks on largely underfunded open source ecosystems."

    #npm #supplychainattack #dependencymanagement

    blog.yossarian.net/2025/11/21/