-
@ecosyste-ms and @octobox
- Bristol, UK
-
01:23
(UTC +01:00) - https://nesbitt.io
- https://orcid.org/0009-0007-2710-1118
- @teabass
- @andrewnez@mastodon.social
- @andrewnez.bsky.social
- wj68rzx
Sponsoring
Highlights
-
sbom Public
Parse, generate, and validate Software Bill of Materials (SBOM)
-
gitballs Public
Storing multiple tarballs in git to save space
-
nesbitt.io Public
Personal blog built with Jekyll and hosted on GitHub Pages. I write about package management, software supply chain security, and open source infrastructure.
-
-
ultimate-awesome Public
Every awesome list on every topic, including awesome lists of awesome lists, updated daily.
-
-
joss Public
Forked from openjournals/jossThe Journal of Open Source Software
Ruby MIT License UpdatedApr 28, 2026 -
osv.dev Public
Forked from google/osv.devOpen source vulnerability DB and triage service.
Python Apache License 2.0 UpdatedApr 28, 2026 -
-
vers Public
A Ruby gem for parsing, comparing and sorting versions according to the VERS spec.
-
grass-ruby Public
A fast Sass compiler for Ruby, powered by grass (Rust)
-
purl Public
A Ruby library for parsing, validating, and generating Package URLs (PURLs) as defined by the PURL specification
-
dirhash Public
Generate Go module zip digests compatible with sum.golang.org
-
swhid Public
Generate and parse SoftWare Hash IDentifiers (SWHIDs)
-
sarif Public
A Ruby SDK for SARIF (Static Analysis Results Interchange Format) 2.1.0.
-
diffoscope Public
Ruby bindings for diffoscope - Compare packages, tarballs, files, URLs, or package URLs
-
-
changelog-parser Public
Parse changelog files into structured data
-
typosquatting Public
Detect potential typosquatting packages across package ecosystems
-
sidekiq-mcp Public
A Sidekiq plugin that provides an MCP (Model Context Protocol) server for LLMs to interact with Sidekiq queues, stats, and failed jobs
-
json-schema-diff Public
Semantic diff for JSON files using JSON Schema metadata
-
ruby-upgrade-action Public
GitHub action to upgrade version of Ruby in various places to the latest
-
jekyll-stats Public
Jekyll plugin that generates site statistics
-
swhid-go Public
A Go library and CLI for computing Software Heritage Identifiers (SWHIDs).
-
-
oss-rebuild Public
Forked from google/oss-rebuildSecuring open-source package ecosystems by originating, validating, and augmenting build attestations.
Go Apache License 2.0 UpdatedApr 15, 2026 -
foss-backstage Public
Is InnerSource Commons good for open source?
-
hanami-sprockets Public
An alternative to hanami-assets that doesn't rely on npm
-
gitlab-faraday Public
Ruby wrapper for the GitLab REST API, a fork of github.com/NARKOZ/gitlab updated to use Faraday
-
PBOM Public
Paper Bill of Materials (PBOM) - Generate a paper bill of materials from the software of a paper







