Andrew Nesbitt has spent over a decade mapping open source infrastructure. His current project, ecosyste.ms, indexes 12 million packages, 287 million repositories, 24.5 billion dependencies, and 1.9 million maintainers. That is not a dashboard. That is a public dataset anyone can build on.

The interview covers what Nesbitt actually learned from running libraries.io first, who is consuming the ecosyste.ms data today, and how the dataset is structured for reuse. The dependency count alone raises hard questions about how well anyone understands the software supply chain they are already trusting.

The full conversation is worth your time for the specifics on methodology and the gaps Nesbitt is still trying to close. If you work in security, package management, or open source sustainability, this is primary source material.

[READ ORIGINAL →]