| GitHub | https://github.com/andrew |
| https://twitter.com/teabass | |
| Homepage | https://nesbitt.io |
| bsky | https://bsky.app/profile/andrewnez.bsky.social |
| GitHub | https://github.com/andrew |
| https://twitter.com/teabass | |
| Homepage | https://nesbitt.io |
| bsky | https://bsky.app/profile/andrewnez.bsky.social |
Conventional commit format sucks. What you really want is to use git trailers. The subject line of a commit message is PRIME real estate, and shouldn't be wasted on tools
đ˘ Announcing the Open Social Awardsđ
Alongside @publicspaces and @waag, we aim to honor the work of independent builders around the world, creating innovative products for the open web!
More details belowâŚ
RE: https://fosstodon.org/@jni/116287554201659198
I said digital attestations and `pylock.toml` would have helped with the litellm attack. People asked for more details, so I wrote a blog post explaining why. It also hopefully acts at motivation for people to use:
- Trusted publishing
- Digital attestations
- Lock files, and `pylock.toml` specifically
https://snarky.ca/why-pylock-toml-includes-digital-attestations/
So yes, @jni , I have a "human-readable intro" because I wrote one for you (and the other folks asking me questions on the subject). đ
I wrote this up in a bit more detail in a clickbait titled article

Thank you for clicking on the clickbait! What a year itâs been. It seems like open source is under constant attack. The security people donât know whatâs going on anymore. What day is it? It doesnât matter. The latest open source mess is the popular open source scanner Trivy being compromised, for a month, then other open source projects downstream in the âchainâ getting compromised, which will probably lead to more things getting compromised until we get back to Trivy someday. Then I think we have to call it a supply wheel. Iâm not sure how these rules work.