The Fragmented World of Dependency Policy: https://nesbitt.io/2026/03/19/the-fragmented-world-of-dependency-policy.html
@andrewnez This is a great observation, I've never really put this together before now
I have a feeling we won't see anything change anytime soon. The consumers that care about this data is a pretty low number (maybe the CRA will change that)
I also don't see any real cooperation or communication between any of the tools vendors. I will partially blame a lack of venues for this
All of the existing trade groups or foundations that would publish such standards are rather anemic in this space
