Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 4 weeks ago

I didn’t realise just how US centric all of package management was until I made these tables 😅

The Dependency Layer in Digital Sovereignty: https://nesbitt.io/2026/01/28/the-dependency-layer-in-digital-sovereignty.html

Andrew Nesbitt

The Dependency Layer in Digital Sovereignty

Where package management fits in the digital sovereignty discussion.
  • Copy link
  • Flag this post
  • Block
Jeroen Baten
Jeroen Baten
@JeroenBaten@mastodon.nl  ·  activity timestamp 3 weeks ago

@andrewnez why does this excellent blog post not mention codeberg?

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 3 weeks ago

@JeroenBaten I'll update the post to mention that near the top

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 3 weeks ago

@JeroenBaten codeberg/forgejo currently doesn’t have any dependency graph or insights functionality

  • Copy link
  • Flag this comment
  • Block
Stephen Paulger
Stephen Paulger
@aimaz@mstdn.social  ·  activity timestamp 4 weeks ago

@andrewnez the frequency of your insightful blogs on package management is impressive.

Super minor nitpick. Blackduck was dropped by Synopsys. It's now an independent company, still US-based though.

  • Copy link
  • Flag this comment
  • Block
Siegfried.
Siegfried.
@realSiegfried@troet.cafe  ·  activity timestamp 4 weeks ago

@andrewnez We were running Gitlab servers on our local machines in Germany for many years. I see no dependency to the US, except the early setup.

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 4 weeks ago

@realSiegfried do you pay for the dependency insights feature?

  • Copy link
  • Flag this comment
  • Block
Siegfried.
Siegfried.
@realSiegfried@troet.cafe  ·  activity timestamp 4 weeks ago

@andrewnez No.

  • Copy link
  • Flag this comment
  • Block
Pradyun Gedam
Pradyun Gedam
@pradyunsg@mastodon.social  ·  activity timestamp 4 weeks ago

@andrewnez I'm also surprised how few are non-profits or B corps in that listing.

(dunno if you wanna add a column for that?)

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 4 weeks ago

@pradyunsg yeah I think that would be worth adding a column

  • Copy link
  • Flag this comment
  • Block
slampoud
slampoud
@slampoud@mastodon.cloud  ·  activity timestamp 4 weeks ago

@andrewnez I was having a conversation with a friend in security the other day who was recalling how, when the CVE fiasco happened recently, everyone noticed EU had what seemed like an alternative they could maybe turn to, but upon closer inspection it was essentially a mirror. we need to do decentralization better, alongside sovereignty, for humanity’s sake

  • Copy link
  • Flag this comment
  • Block
mossman
mossman
@mossman@social.vivaldi.net  ·  activity timestamp 4 weeks ago

@andrewnez listened to an interesting point on a podcast by Everything Electric this morning. To paraphrase: "96% of the world is *NOT* living in the USA, so can we all please just stop talking about their news and get on with our own lives again?"

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 4 weeks ago

@mossman my post is mostly about needing more standards in package management, the US acting crazy is just a useful way to get more people asking for those standards to be developed

  • Copy link
  • Flag this comment
  • Block
mossman
mossman
@mossman@social.vivaldi.net  ·  activity timestamp 4 weeks ago

@andrewnez I was kind of making the same point. We need to stop allowing all our lives be dominated by systems and corporations centred on a monoculture which doesn't actually reflect the global diversity

  • Copy link
  • Flag this comment
  • Block
IzzyOnDroid ✅
IzzyOnDroid ✅
@IzzyOnDroid@floss.social  ·  activity timestamp 4 weeks ago

@andrewnez for forges, you might wish to add @Codeberg (Germany, EU). Not sure where Sourcehut sits (is it NL, @sir ?)

So there ARE alternatives. And as already pointed out in another comment by @jens , Forgejo/Gitea can be self-hosted as well. And at least for Forgejo, Federation is upcoming IIRC, to take another hurdle (separate registrations) from self-hosted installs.

But yeah, that list reads horrible, re "sovereignty" 😢

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 4 weeks ago

@IzzyOnDroid codeberg/forgejo/srht don’t have the dependency graph security features that the others have that I was talking about

  • Copy link
  • Flag this comment
  • Block
Jens Finkhäuser
Jens Finkhäuser
@jens@social.finkhaeuser.de  ·  activity timestamp 4 weeks ago

@andrewnez Consider that gitea contains package registries, and forgejo is the FLOSS fork. It's perfectly possible to build a bunch of these things with a self-hosted forgejo instance.

Which really means that a bunch of things forgejo does should become de facto standards.

There are also things that can be standardized that help here. For example, there are a few competing solutions for platform/language independent package meta information, including dependencies.

Could focus on that, too.

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 4 weeks ago

@jens I’ve been working on that

2 media
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this comment
  • Block
Benjamin Geer
Benjamin Geer
@benjamingeer@piaille.fr  ·  activity timestamp 4 weeks ago

@andrewnez @gvwilson What about the Linux package repositories? Canonical, at least, is UK-based if I’m not mistaken, with subsidiaries in several countries.

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social  ·  activity timestamp 4 weeks ago

@benjamingeer the Linux distros are much more friendly to being mirrored and standing your own up than many of the language package managers

  • Copy link
  • Flag this comment
  • Block
Marcus Rohrmoser 🌻
Marcus Rohrmoser 🌻
@mro@digitalcourage.social  ·  activity timestamp 4 weeks ago

@andrewnez @benjamingeer
I am bit bugged as there seem to be no mirrors for e.g. security.ubuntu.com

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.29 no JS en
Federation disabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct