I'm a software engineer based in the UK and a maintainer of Homebrew. I've spent over a decade working in the world of package management and software dependencies, building tools to make open source more understandable, discoverable, and sustainable.
These days I'm focused on Ecosyste.ms, a project that maps dependency networks across open-source ecosystems to identify the projects that really matter. It builds on ideas from Libraries.io, which I started and later sold to Tidelift, and takes the concept further with broader data coverage and deeper analysis.
I'm also building git-pkgs, a family of tools and Go libraries for working with software dependencies. The core git pkgs command indexes lockfiles across your repository's history so you can see who added each dependency, when, and why, with vulnerability scanning and supply chain checks on top. Alongside it sit standalone tools like brief, forge, and proxy.
With Alpha-Omega I work on Scrutineer, a tool for scanning open source repositories for security vulnerabilities and managing the disclosure process end to end.
I created Octobox, which helps developers manage GitHub notifications, and 24 Pull Requests, an initiative to encourage open-source contributions during December.
I write about package managers, dependency resolution, and software supply chains at nesbitt.io/package-managers.
- This Week in Package Management: 5 September 2026
- How much should you trust your OSS data?
- Git Submodules as a Package Manager
- This Week in Package Management: 29 August 2026
- Now Hiring: Senior Open Source Maintainer
- Bazel Module Versions Aren’t SemVer
- Hardening the Override Flag
- This Week in Package Management: 22 August 2026
- Issues in the Repo
- Two-Factor Authentication Across Package Registries
- embedded-rust-packages - Find critical open-source packages that ship Rust code inside a non-Rust ecosystem
- package-manager-library-reuse - Survey of which libraries package managers themselves depend on, vendor, or link against
- homebrew-actions - Install GitHub Actions from a Homebrew tap
- critical-ai-scan - Survey of explicitly disclosed AI involvement in the git history of critical open source repositories, using the CHAOSS disclosure detectors
- package-name-prefixes - Prefix analysis of package names across PyPI, npm, crates.io, rubygems, hex, hackage and NuGet
- bundler-resolver-logger - Experimental structured tracing for Bundler's PubGrub resolver
- jekyll-standard-site - Jekyll plugin that emits standard.site verification artifacts
- pycon - Data collection and analysis for a PyCon talk on GitHub Actions security across Python packages.
- weekend-at-bernies - Data collection for Weekend at Bernie's blog post
- vid - Content-addressed vulnerability identifiers







