Package managers need to cool down

If It Quacks Like a Package Manager

Git's Magic Files

Package Management Namespaces

Whale Fall

Git in Postgres

The Many Flavors of Ignore Files

Crates.io’s Freaky Friday

Sandwich Bill of Materials

Where Do Specifications Fit in the Dependency Tree?

Zig and the M×N Supply Chain Problem

The C-Shaped Hole in Package Management

A Protocol for Package Management

Package management is a wicked problem

Reducing Dependabot Noise

Workspaces and Monorepos in Package Managers

git-pkgs: explore your dependency history

How dependabot works

Cursed Bundler: Using go get to install Ruby Gems

Package managers keep using Git as a database, it never works out

How uv got so fast

How to Ruin All of Package Management

GitHub Actions has a package manager, and it might be the worst

Could lockfiles just be SBOMs?

Package Manager Design Tradeoffs

What is a Package Manager?

From ZeroVer to SemVer: A Comprehensive List of Versioning Schemes in Open Source