package-manager

Tag

Cards List
#package-manager

Uv 0.12.0

Hacker News Top · 1h ago Cached

uv 0.12.0 is a major release of the extremely fast Python package and project manager written in Rust, offering a replacement for pip, pip-tools, pipx, poetry, pyenv, twine, virtualenv, and more.

0 favorites 0 likes
#package-manager

Show HN: Sx 2.0 – Share AI skills with your team through a Dropbox folder

Hacker News Top · 2026-07-13 Cached

Sx 2.0 is a desktop app that enables teams to share AI skills via a shared folder (Dropbox, Google Drive, etc.), without requiring git or terminal. It translates skills into formats compatible with various AI clients.

0 favorites 0 likes
#package-manager

Show HN: Ant – A JavaScript runtime and ecosystem

Hacker News Top · 2026-07-11

Ant is a JavaScript runtime and ecosystem including an engine, package manager, registry (ants.land), deployment platform, and desktop app framework (Ant Desktop) designed as a coherent alternative to existing JavaScript stacks.

0 favorites 0 likes
#package-manager

@evanyou: One of the reasons we don’t provide a built-in package manager in Vite+ is because I’m not sure about the idea of vendo…

X AI KOLs Following · 2026-07-11 Cached

Evan You explains that Vite+ does not include a built-in package manager because he is uncomfortable with vendoring someone else's package manager and claiming its features as their own.

0 favorites 0 likes
#package-manager

@charliermarsh: In preview, `uv tool install` will now write a `uv.lock` lockfile for every tool, alongside the installation itself

X AI KOLs Following · 2026-07-07 Cached

In preview, uv tool install now writes a uv.lock lockfile for every tool during installation.

0 favorites 0 likes
#package-manager

skillhub - compose package manager for AI agent skills (Claude Code, Cursor, Codex)

Reddit r/openclaw · 2026-07-02

skillhub is a package manager for AI agent skills, compatible with Claude Code, Cursor, and Codex.

0 favorites 0 likes
#package-manager

A hash proves the bytes, not the source

Lobsters Hottest · 2026-06-28 Cached

Collider 1.3.0 adds path traversal protection for repository indices and strips bearer tokens on cross-origin redirects to prevent security vulnerabilities.

0 favorites 0 likes
#package-manager

@charliermarsh: This talk that I gave at Jane Street a year ago is by far the one that is referenced to me most in-person. People seem …

X AI KOLs Following · 2026-06-25 Cached

Charlie Marsh's talk explains how uv, a Rust-based Python package manager developed by Astral, solves dependency resolution with a CDCL SAT solver and a unified lockfile, achieving extreme speed by rethinking the toolchain from scratch.

0 favorites 0 likes
#package-manager

Nix needs relocatable binaries

Lobsters Hottest · 2026-06-22 Cached

The article identifies the problem that Nix binaries are not relocatable, causing hash changes and recompilation when the store prefix changes, and proposes using relative paths with $ORIGIN in RUNPATH to achieve relocatability without invalidating caches.

0 favorites 0 likes
#package-manager

Practical software freedom with GNU Guix

Lobsters Hottest · 2026-06-18 Cached

A talk introducing the four software freedoms, their importance and limitations, and how GNU Guix enables verification, modification, and sharing of software to ensure user freedom.

0 favorites 0 likes
#package-manager

@charliermarsh: Announcing uv audit: native support for vulnerability scanning across your project's dependencies

X AI KOLs Following · 2026-06-16 Cached

Charlie Marsh announces uv audit, a native vulnerability scanning feature for project dependencies in the uv package manager.

0 favorites 0 likes
#package-manager

Malicious Packages Spreading in AUR

Lobsters Hottest · 2026-06-11 Cached

Security alert: malicious packages are being spread in the Arch User Repository (AUR), posing a risk to Arch Linux users.

0 favorites 0 likes
#package-manager

Show HN: Homebrew 6.0.0

Hacker News Top · 2026-06-11 Cached

Homebrew 6.0.0 introduces tap trust security, a new default internal JSON API for faster updates, Linux sandboxing via Bubblewrap, and various improvements based on user survey feedback.

0 favorites 0 likes
#package-manager

Vulnerability and malware checks in uv

Lobsters Hottest · 2026-06-08 Cached

uv announces new security features: a fast dependency auditing command (uv audit) and optional malware scanning on sync operations, both currently in preview.

0 favorites 0 likes
#package-manager

The Guix Nix Abomination: Leveraging Guix derivations in Nix

Lobsters Hottest · 2026-06-07 Cached

A technical exploration showing how Nix can build a Guix derivation, highlighting the shared underlying 'Input Output Machine' architecture and the possibility of cross-ecosystem interoperability.

0 favorites 0 likes
#package-manager

NixOS 26.05 released

Lobsters Hottest · 2026-05-30 Cached

NixOS 26.05 'Yarara' is released, featuring systemd in initrd, GNOME 50, deprecation of x86_64-darwin, and thousands of package updates.

0 favorites 0 likes
#package-manager

Nix on Sailfish X (Sailfish OS for Sony Xperia)

Lobsters Hottest · 2026-05-30 Cached

A technical guide on installing the Nix package manager on Sailfish OS for Sony Xperia devices, covering filesystem layout, LVM partitioning, and F2FS considerations.

0 favorites 0 likes
#package-manager

Staged publishing and new install-time controls for npm

Hacker News Top · 2026-05-22 Cached

npm introduces staged publishing, requiring human approval via 2FA for package releases, and new `--allow-*` flags (file, remote, directory) to control install sources, improving supply-chain security in npm CLI 11.15.0.

0 favorites 0 likes
#package-manager

'No way to prevent this,' says only package manager where this regularly happens

Hacker News Top · 2026-05-16 Cached

Satirical article highlighting the recurring supply chain attacks in the npm registry, contrasting with more secure ecosystems like Go and Rust, and mocking the JavaScript community's acceptance of such vulnerabilities.

0 favorites 0 likes
#package-manager

Show HN: Sx – an open-source package manager for AI skills, MCPs, and commands

Hacker News Top · 2026-05-15 Cached

sx is an open-source package manager for sharing AI skills, MCP configs, and commands across teams. It helps capture individual AI expertise and distribute it automatically to team members.

0 favorites 0 likes
Next →
← Back to home

Submit Feedback