The Manifest

The Manifest

By Andrew Nesbitt and Alex PoundsNewsTechnologyEducationHow ToTech News
Download on the App Store

The Manifest episodes

  • Episode 16: Conda Forge, Mamba, and Packaging Con with Wolf Vollprecht

    Wherein we talk with Wolf Vollprecht about his work on Conda Forge and Mamba and the upcoming Packaging-Con event that he's organizing.

    The Packaging Con 2021: Call for Presentations is open until 1st September 2021,14:00 (UTC) if you'd like to speak: https://pretalx.com/packagingcon-2021/cfp

    Special Guest: Wolf Vollprecht.

    Links:

    • conda-forge
  • conda-forge on GitHub
  • Anaconda.org
  • PackagingCon 2021
  • PackagingCon 2021: Call for Presentations
  • Package Management devroom FOSDEM 2018
  • Wolf Vollprecht on GitHub
  • Wolf Vollprecht
  • Wolf Vollprecht on Twitter
  • QuantStack
  • QuantStack on GitHub
  • 36 min
  • Episode 14: Debian and Reproducible Builds with Chris Lamb

    Wherein we discuss how package management works in Debian and the Reproducible Builds project with Chris Lamb, a director of both the Open Source Initiative and of Software in the Public Interest, previously the Debian Project Leader and a core developer on the Reproducible Builds project.

    Special Guest: Chris Lamb.

    57 min
  • Episode 13: Conan with Diego Rodriguez-Losada

    Wherein we discuss Conan, the C and C++ package manager with Diego Rodriguez-Losada as it reaches 1.0. We talk about what inspired the development of Conan, package management problems specific to C/C++ package management and the plans for the future.

    Note: This episode was recorded 9 months before it was published, so some details may be out of date.

    Special Guest: Diego Rodriguez-Losada.

    Links:

    • Conan
  • Conan on GitHub
  • Bintray
  • Bincrafters
  • biicode
  • JFrog Xray
  • Conan hits 1.0
  • Cpplang Slack
  • Diego's website
  • Diego on Twitter
  • Diego on GitHub
  • SwampUP
  • 1 hr 10 min
  • Episode 12: Clojars with Daniel Compton

    Wherein we discuss Clojars, the clojure package manager registry and it's relationship to Maven with Daniel Compton.

    Special Guest: Daniel Compton.

    Links:

    • Clojars
  • Datomic
  • Clojure
  • Microsoft Dynamics NAV
  • C/AL programming language
  • Maven
  • The Manifest Episode 6: Maven with Brian Fox
  • Leiningen
  • Boot: build tooling for Clojure
  • cljdoc
  • Maven Artifact Resolver
  • OpenJDK
  • Graal
  • ClojureScript
  • Google Closure Compiler
  • vgo
  • Git Deps for Clojure
  • Deps - Private Maven Repository Hosting
  • Daniel Compton's website
  • Daniel Compton on GitHub
  • Daniel Compton on Twitter
  • Clojars on GitHub
  • 1 hr 5 min
  • Episode 11: Spack with Todd Gamblin

    Wherein we chat with Todd Gamblin about Spack, the package manager for supercomputers. We talk the unique challenges that packaging for High-performance computing platforms bring to package management, whether you should mine bitcoins on super computers and what's planned for the future of spack.

    Special Guest: Todd Gamblin.

    Links:

    • Spack
  • Spack on GitHub
  • Spack documentation
  • Lawrence Livermore National Laboratory
  • High-performance computering on Wikipedia
  • EasyBuild
  • Spack white paper
  • How To Make Package Managers Cry
  • PubGrub: Next-Generation Version Solving – Natalie Weizenbaum
  • Todd Gamblin on GitHub
  • Todd Gamblin on Twitter
  • Todd Gamblin on The Changelog
  • 57 min
  • Episode 10: Licensing with Kate Stewart

    Wherein we discuss open source licensing and how that relates to software packaging with Kate Stewart, of Linux Foundation and SPDX.

    Special Guest: Kate Stewart.

    Links:

    • Board support package
  • LTIB
  • Software Package Data Exchange (SPDX)
  • DEP5
  • Freshmeat
  • FOSSology
  • Black Duck
  • Compliance Basics for Developers
  • Choose a License
  • FreeRTOS
  • The `React Patent License’ Controversy
  • SPDX on GitHub
  • librariesio/spdx: A SPDX license normalizer
  • librariesio/license-compatibility: Check compatibility between different SPDX licenses
  • Free Software Foundation
  • FOSDEM 2018 - Legal and Policy Issues devroom
  • Heather Meeker
  • Kyle Mitchell
  • Luis Villa
  • Oracle America, Inc. v. Google, Inc.
  • Spdx-tech mailing list
  • Spdx-legal mailing list
  • Kate Stewart on Twitter
  • 57 min
  • Episode 9: Typosquatting with Adam Baldwin

    Wherein we discuss typosquatting and other security matters with Adam Baldwin, of Lift security and the Node Security Platform. We cover what kind of exploits people are trying, speculate about how blockchains may well be the answer, and unsuccessfully attempt to start a turf war between various package managers.

    Special Guest: Adam Baldwin.

    Links:

    • Lift Security
  • npm registry
  • Typo.js on GitHub
  • 52% of All JavaScript npm Packages Could Have Been Hacked via Weak Credentials
  • Have I been pwned?
  • Protect your npm account with two-factor authentication
  • Typosquatting programming language package managers
  • Shellshock
  • Dependency CI
  • The Update Framework
  • package.community
  • crossenv malware on the npm registry
  • Node Security Platform
  • Yarn
  • Adam Baldwin on Twitter
  • Adam Baldwin on GitHub
  • 51 min
  • Episode 8: Cargo and Crates.io with Carol (Nichols || Goulding)

    Wherein we discuss Cargo (the Rust package manager) and Crates.io (the Rust package registry) with Carol (Nichols || Goulding). We talk about the Rust language, the history of the project, the features that make Cargo the envy of all the other package managers, and the sustainability of the project.

    Special Guest: Carol (Nichols || Goulding).

    Links:

    • FOSDEM Package Management Devroom CFP
  • Crates.io
  • Cargo on GitHub
  • 59 min
  • Episode 7: The Update Framework with Trishank Karthik Kuppusamy

    Wherein we chat with Trishank Karthik Kuppusamy about The Update Framework, a security layer that lets package managers assure the veracity and integrity of their packages. We talk about how it grew out of the TOR Project, how it works, how Uptane is used for package management in cars (!), and what package maintainers can do to help their own security.

    Special Guest: Trishank Karthik Kuppusamy.

    Links:

    • FOSDEM Package Management Devroom CFP
  • The Update Framework
  • The Update Framework on GitHub
  • 58 min

About The Manifest

From the publisher's feed

Welcome to The Manifest, a podcast all about package management. Your hosts are Alex Pounds and Andrew Nesbitt. Together they explore the technical details of package management, the stories and the…