The Three Pillars of JavaScript Bloat

A brief look at the three main causes of bloat in our JavaScript dependency trees, and how we can start to address them.

GNOME 50 removes Google Drive integration after libgdata lost maintenance and was archived, leaving unresolved security issues and outdated dependencies. The change reflects risks of unmaintained code in open ecosystems, prioritizing security and transparency over fragile proprietary integrations ⚙️

🔗 https://itsfoss.com/news/gnome-drops-google-drive-support/

#TechNews #GNOME #GNOME50 #Google #Drive #GoogleDrive #Linux #OpenSource #FOSS #Security #Dependencies #Maintenance #Privacy #Transparency #Software #Desktop #IT

GNOME 50 Drops Google Drive Integration (For a Valid Reason)

Nobody stepped up to maintain a key package, and its security baggage eventually led to this.

It's FOSS

#Development #Overviews
Package managers need to cool down · The state of dependency update delay mechanisms https://ilo.im/16bnm5

_____
#Attacks #SupplyChain #PackageManagers #Dependencies #Npm #Vulnerability #Security #WebDev #Frontend #Backend

Package Managers Need to Cool Down

A survey of dependency cooldown support across package managers and update tools.

Andrew Nesbitt

#Development #Pitfalls
Lessons learned after breaking production · What software engineers never want to experience again https://ilo.im/16bkbg

_____
#Engineering #Troubleshooting #Debugging #Rollbacks #Backups #Dependencies #QuickFixes #WebDev #Frontend #Backend

7 lessons engineers learn only after breaking production

Last April, I wrote a well-received article about the 13 software engineering laws - Hyrum’s, Conway’s, Zawinski’s, and 10 famous others.

Manager.dev

Should someone be interested, there is a #rc for the new #imagepipe version.

https://kaffeemitkoffein.de/nextcloud/index.php/s/Dees7SB22sXtoJa

A short story:
I am building the #android #sdk on my own and use my own #sdk build to develop #imagepipe .

See here:
https://codeberg.org/Starfish/SDK-Rebuilds

Doing it that way, I learned a lot.

#imagepipe also has zero #dependencies, so that the resulting #apk is only 643 KiB in size. It fits on a 3.5" #floppy #disk, should you remember them.

#imagepipe is also downward compatible to support devices running #android 4.0.1, whilst targeting #android 16, so you can use #imagepipe even on very old, outdated devices.

Unfortunately, my #samsung Galaxy young broke, so that I cannot test #imagepipe on a native device with a display as small as 320x240 pixels anymore. The last versions worked well on it.

apks_testing

MyCloud - This is a private cloud server.

MyCloud

#AskFedi, #Fediverse, a topic just came up: many in the #EU are looking to #renewables to strengthen their #sovereignty by reducing #dependencies - e.g. #methane for #electricity generation.

The challenge to balance is just as sharp when it comes to #food #SupplyChain s. How can densely populated regions produce bread grains, rice, or for that matter mustard and lentils?

#VerticalFarming #VF and #UrbanAgriculture #UA can improve availability of leafy produce, fruits; but seed crops?

"Lock the Ghost: In the software world, “remove” is not equal to "gone.""

https://www.cert.at/en/blog/2026/3/lock-the-ghost

#pypi #dependencies #supplychain #lockfiles #python

CERT.at - Lock the Ghost

In the software world, “remove” is not equal to "gone." This is crystal clear. There is always a good reason for that. Let’s take a short trip through how Python Package Index handles removals and how we can lock the ghost in an uv.lock file – forever!

@knowprose
Wow! What a read - dependencies everywhere, who would have thought it. That’s probably what happens when you (we) have a world (theoretically) governed by international rules of law. And who doesn’t get “crankier with sand in their shorts”?

#dependencies #internationalRulesOfLaw

Supply-Chain Attack Using Invisible Code Hits GitHub and Other Repositories, by @dangoodin.bsky.social (@arstechnica):

https://arstechnica.com/security/2026/03/supply-chain-attack-using-invisible-code-hits-github-and-other-repositories/

#security #github #dependencies

Supply-chain attack using invisible code hits GitHub and other repositories

Unicode that's invisible to the human eye was largely abandoned—until attackers took notice.

Ars Technica
Can't upgrade to 26.04 due to unmet dependencies

I've been trying to upgrade from 25.10 to 26.04 but keep getting the following dependency errors when trying to fully upgrade: root@elara:~# apt install linux-modules-nvidia-580-generic-hwe-24...

Ask Ubuntu