EPISODE · Jun 5, 2026 · 7 MIN
How Open Source Projects Manage Dependency Churn
from Open Source with Fexingo: Linux, GitHub, and Community-Driven Software Conversations · host Fexingo
In episode 32 of Open Source with Fexingo, Lucas and Luna explore the growing challenge of dependency churn in open source projects. With over 2.5 million packages on npm alone, maintainers face constant updates, security patches, and breaking changes. The hosts dive into the story of a single Node.js utility library that depended on 1,200 packages — and how its creator trimmed it down to just 12. They discuss tools like Dependabot, the concept of 'dependency hygiene,' and why the left-pad incident of 2016 still haunts the ecosystem. Lucas explains why the average JavaScript project now has 1,500 vulnerable dependencies, and Luna questions whether the free-rider problem is getting worse. The episode offers practical takeaways for developers and project leads, including how to audit your own dependency tree without losing your mind. #DependencyChurn #OpenSource #NodeJs #JavaScript #npm #Dependabot #LeftPad #SupplyChainSecurity #MaintainerBurnout #SemVer #LockFiles #TechDebt #FexingoBusiness #BusinessPodcast #Tech #SoftwareMaintenance #DeveloperTools #CommunityDriven Keep every episode free: buymeacoffee.com/fexingo
What this episode covers
In episode 32 of Open Source with Fexingo, Lucas and Luna explore the growing challenge of dependency churn in open source projects. With over 2.5 million packages on npm alone, maintainers face constant updates, security patches, and breaking changes. The hosts dive into the story of a single Node.js utility library that depended on 1,200 packages — and how its creator trimmed it down to just 12. They discuss tools like Dependabot, the concept of 'dependency hygiene,' and why the left-pad incident of 2016 still haunts the ecosystem. Lucas explains why the average JavaScript project now has 1,500 vulnerable dependencies, and Luna questions whether the free-rider problem is getting worse. The episode offers practical takeaways for developers and project leads, including how to audit your own dependency tree without losing your mind. #DependencyChurn #OpenSource #NodeJs #JavaScript #npm #Dependabot #LeftPad #SupplyChainSecurity #MaintainerBurnout #SemVer #LockFiles #TechDebt #FexingoBusiness #BusinessPodcast #Tech #SoftwareMaintenance #DeveloperTools #CommunityDriven Keep every episode free: buymeacoffee.com/fexingo
NOW PLAYING
How Open Source Projects Manage Dependency Churn
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Mar 19, 2026 ·34m
Feb 18, 2026 ·11m
Feb 11, 2026 ·45m