
Sustain Episode 290: Andrew Nesbitt on AI, Transitive Dependencies, and the New Open Source Security Crunch
8 snips
Jul 20, 2026 Andrew Nesbitt, founder of Ecosyste.ms and builder of a registry-of-registries from dependency data, explains how AI scans millions of repos to spot risk. He highlights unseen transitive dependencies, the crisis of abandoned packages with critical bugs, and how LLMs speed both discovery and exploitation. Practical calls: prune and update dependencies and support maintainers responsibly.
AI Snips
Chapters
Transcript
Episode notes
Registry Of Registries Maps Critical Packages
- Ecosyste.ms maps dependency data across 300 million repositories to identify the most critical open source packages.
- Andrew Nesbitt uses that map to pick which 10,000 high-impact projects to prioritize for scanning with AI models.
Use AI To Triage High Impact Packages
- Use AI models to prioritize which packages to scan first because compute/token limits force selective triage.
- Andrew split 10,000 critical projects into actively maintained versus dormant to focus limited model time on high-risk targets.
Transitive Dependencies Are Largely Invisible Risk
- Many heavily used packages are invisible transitive dependencies that rarely get eyeballs or audits.
- These transitives are pulled indirectly by package managers, so maintainers and security teams often never review them.

