Andrew Nesbitt (nesbitt.io)

title
Andrew Nesbitt (nesbitt.io)
type
entity
summary
Blog covering package registries, supply-chain observability, git internals, and open-source infrastructure
tags
blog, package-registry, open-source
author
Andrew Nesbitt
created
2026-04-22
updated
2026-09-13

Andrew Nesbitt's personal blog at nesbitt.io. Nesbitt maintains Libraries.io and the ecosyste.ms open-source observability toolset, and his writing reflects that β€” he's most interesting when he's looking at the structural layer of open-source: what git actually tracks, what a package registry exposes, what supply-chain data is legible from outside.

Style: short-to-medium posts, sourced and annotated, UK English. The technical level assumes familiarity with the topic but doesn't play insider; each post reads as a standalone piece of analysis rather than a running newsletter thread.

Ingested articles

  • git-magic-files (2026-02-05) β€” catalog of committed files that control git behavior (.gitignore, .gitattributes, .mailmap, .git-blame-ignore-revs, and more)
  • features-to-steal-from-npmx (2026-04-16) β€” feature catalog from npmx.dev as a registry-design spec, plus the competitive-pressure effect on npmjs.com
  • forge (2026-03-13) β€” one Go CLI and library over GitHub, GitLab, Gitea/Forgejo, and Bitbucket for humans and coding agents
  • cursed-bundler-go-get-ruby-gems (2025-12-25) β€” installing Ruby gems through go get, on the way to the argument that Golang's module proxy is an accidental general-purpose, content-addressed, transparency-logged package CDN
  • git-submodules-as-package-manager (2026-09-01) β€” submodules read as a package manager: resolution, storage, worktree collisions, CVEs
Sub-pages