home.social

#packagevalidation — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #packagevalidation, aggregated by home.social.

fetched live
  1. How do you know whether the R packages your team relies on are safe to use?

    Litmus reviews each package across eight checks, combines the results into a risk score and flags packages that may need further review.

    From assessment to audit ready reporting, the Litmusverse helps teams manage R package risk more consistently.

    Learn more: jumpingrivers.com/litmus/

  2. Most teams are validating far more than they need to.

    Take an R package with 500 functions. The average team uses about 5.

    Most validation tools require you to check all 500. Every time.

    Litmus changes that. Validate only what you use.

    jumpingrivers.com/litmus/

  3. Open source R is powerful. Governing it at scale is hard.

    Most regulated teams have 500+ packages and no consistent way to answer the question auditors always ask: how do you know these are safe to use?

    Litmus automates that — assessing packages across code, docs, maintenance and vulnerability signals, then generating reports you can show.

    jumpingrivers.com/litmus

  4. New blog post: "Litmus: Maintainer Criteria"
    How often do bugs get fixed? Does the package use source control? Is it a solo or group effort? These critical questions help assess the long-term viability and risk profile of R packages in your workflow.

    Read more: jumpingrivers.com/blog/r-valid

    jumpingrivers.com/blog/r-valid

  5. Not all R packages are clearly “good” or “risky”, most fall somewhere in between. This post introduces our scoring framework around package documentation. We investigate the different measures, then look at a few well known packages.


    jumpingrivers.com/blog/r-valid