search
open-source maintainers
Trends
- 1Greg Kroah-Hartman on Security in the LLM AgeβGreg Kroah-Hartman β Security in the LLM Age [video]
Kernel developer Greg Kroah-Hartman, maintainer of the Linux kernel's stable branch and a central figure in open-source security, has a talk examining software security in the age of large language models. The discussion covers how LLM-generated code and LLM-assisted workflows affect vulnerability handling, code review and trust in the open-source supply chain. It is drawing attention from developers weighing AI's risks and benefits for core infrastructure.
- 2Google freezes open-source bug bounty over AI slop reportsβΌGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions β product flaw submissions halted until 2027 as maintainers drown in hallucinations
Google has paused new submissions to its open-source bug bounty program until 2027, citing an overwhelming flood of low-quality, AI-generated vulnerability reports. Maintainers are reportedly drowning in thousands of invalid, hallucinated flaw claims, making it impossible to separate genuine security findings from automated noise.
- 3Rhun: open-source code editor written in assemblyβΌShow HN: Rhun, an open-source code editor written in assembly
A developer going by vladcodes has released Rhun, an open-source code editor written entirely in assembly language, sharing it with the Hacker News community. The project, available at rhun.app, is drawing attention for the unusual technical decision to build an editor at such a low level, a task most projects handle with higher-level languages. Commenters are likely debating the practicality, performance benefits, and maintainability of assembly-based tooling.
- 4WordPress.org's forced takeover of ACF plugin sparks debateβAnalisis pengambilalihan paksa plugin ACF oleh WordPress.org menjadi Secure Custom Fields. Dampak etika open source dan
WordPress.org took over the popular Advanced Custom Fields plugin and renamed it Secure Custom Fields, prompting analysis of the ethics of the move. Commenters are weighing the impact on open-source principles, trust between maintainers and repositories, and software supply-chain security for developers who rely on plugins distributed through WordPress.org.
- 5
Sentry, the open-source error tracking and performance monitoring platform maintained by Sentry, is seeing fresh attention among developers. The tool helps engineering teams catch, prioritise and fix crashes and performance problems in production software, and its Python-based repository remains a widely used reference project in the monitoring space.
- 6KDE's Kate wins over a Hugo site author as Markdown editorβIβve written about how and why KDEβs Kate has become my Markdown editor of choice for my # homelab # Hugo website. Spell
A Linux user has published a blog post explaining why KDE's Kate became their Markdown editor of choice for writing and maintaining a Hugo-based homelab website. They highlight Kate's spell checking, Markdown highlighting, live preview, and code snippets, saying the features let them work entirely within the KDE ecosystem without switching tools.
- 7Moderate vulnerability disclosed in Docling document parsing toolβΌπ¨ EUVD-2026-92803 π Score: 4.0/10 (CVSS v3.1) π¦ Product: docling, docling-slim π’ Vendor: docling-project π Updated: 2026
A new vulnerability, EUVD-2026-92803, has been catalogued affecting the docling and docling-slim packages maintained by the docling-project. The flaw carries a moderate severity score of 4.0 out of 10 under CVSS v3.1 and affects versions from 2.91.0 onward. Docling is widely used to parse document formats and connect them with generative AI tools, so affected users are advised to check versions and apply fixes.
- 8novelWriter maintainer weighs dropping Debian 12 packagesβI'm still releasing novelWriter packages for Debian 12, and I just checked and noticed people are still downloading thos
The maintainer of novelWriter says they are still building packages for Debian 12 and have noticed people keep downloading them, even though the Debian 12 release reached end-of-life a few months ago. They would like to drop support, which would let them move on from Python 3.11, but are weighing that against users who still rely on those builds.
- 9GitHub repositories gain a way to signal accessibility supportβOpen any repository on GitHub and you see the same tabs: README, Code of Conduct, Contributing,... # a11y # github # ope
GitHub repositories can now declare their commitment to accessibility alongside the familiar README, Code of Conduct and Contributing tabs. The change gives open-source projects a standard place to show they care about inclusive design, letting maintainers communicate accessibility information to users and contributors directly within the repository interface. Developers are discussing how this could push accessibility into mainstream open-source workflows.
- 10OpenSSH Creator's Security Philosophy Draws Renewed AttentionβOpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One https://zbruceli.org/blog/the-man-who-tr
A profile of the OpenSSH project and its creator is drawing attention across the tech community. OpenSSH underpins secure remote access on virtually every Mac, Linux server and Windows machine, yet is maintained with a deliberately paranoid approach: its code is written to trust no input, no system and no contributor. The piece highlights how this rigour has kept the critical open-source tool safe for decades, prompting discussion about whether other widely used software should adopt similar discipline.
- 11Kagi Ends Orion Browser Development for Linux, Will Open-Source ItβKagi Ends Orion Browser Development for Linux, Will Open-Source It https://linuxiac.com/kagi-ends-orion-browser-developm
Search company Kagi has ended development of its Orion browser for Linux and will open-source the existing code. The move means Linux users will no longer receive official updates, but the community will be free to maintain and build on the browser themselves. The announcement is drawing attention among open-source and privacy-focused technology communities.
- 12Kernel developer defends maintaining Landstrip mail serviceβThere's no risk to that I would not maintain Landstrip because there is nothing better available i.e., I use it myself t
Jarkko Sakkinen, a Linux kernel developer, says he sees no risk in continuing to maintain Landstrip, explaining that he uses the service himself and considers it the best available option. He also criticises GitHub contributors he describes as manager or architect types who arrive with open-ended suggestions such as conformance tests rather than practical contributions.
- 13
Search company Kagi has confirmed it is stopping development of its Orion browser for Linux and will release the Linux version's code as open source. The decision means Linux users will not receive continued official updates, but the community will be free to maintain and build on the browser themselves. Reactions online focus on whether open-sourcing softens the blow of abandoning the platform.
- 14Kagi Ends Orion Browser Development for Linux, Will Open-Source ItβKagi Ends Orion Browser Development for Linux, Will Open-Source It Article URL: https:// linuxiac.com/kagi-ends-orion-b
Search company Kagi has announced it is stopping development of its Orion browser for Linux and will release the Linux version's code as open source. The move means the Linux community will be able to maintain or fork the browser themselves, even as Kagi concentrates Orion's ongoing development on other platforms. Early reaction online is limited so far, with the announcement just beginning to circulate among developers and open-source enthusiasts.
- 15Google freezes bug bounty program amid flood of AI-generated junk reportsβΌGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions β product flaw submissions halted until 2027 as maintainers drown in hallucinations
Google has paused submissions to its open-source bug bounty program until 2027, citing an overwhelming volume of invalid, AI-generated vulnerability reports. Maintainers are said to be drowning in hallucinated or low-quality flaw submissions that waste review time, prompting the freeze on product flaw reports. The move highlights a growing strain that generative AI tools are placing on security research programs.
- 16Kagi Ends Orion Browser Development for Linux and Windows, Plans Open-Source HandoverβKagi ends development of Orion Browser for Linux and Windows, with plans to open-source both versions and hand them over
Search company Kagi has stopped developing its Orion browser for Linux and Windows. The company says it plans to release the code for both versions as open source and hand the projects over to the community rather than continue maintaining them in-house. The move affects users of the privacy-focused browser on those platforms, who will now depend on community stewardship if development continues at all.
- 17
Kagi has announced it is stopping development of its Orion browser for Linux and will instead release the code as open source. The move means Linux users will no longer receive official updates, but the community will be able to maintain and build the browser themselves. Kagi positions the decision as a way to serve Linux users better without continuing costly in-house development.
- 18System76 bans AI-generated code in COSMIC contributionsβThe AI machine continues to cause problems for some developers - with System76 now banning LLM-generated content in code
System76, the Linux hardware and software company, will no longer accept LLM-generated content in pull requests for its COSMIC desktop environment project. The move means code submissions flagged as AI-generated will be rejected. The decision reflects a broader debate in open-source development, where maintainers are increasingly pushing back on low-quality or unreviewable AI-generated contributions flooding their queues.
- 19Updated fork of ncdu disk usage tool releasedβncdu: NCurses Disk Usage (an updated fork) https://github.com/rcalixte/ncdu # Tech # OpenSource # CLI
A maintained fork of ncdu, the NCurses-based disk usage analyser for the command line, is now available on GitHub under rcalixte's account. The project continues the popular terminal tool that lets users inspect and manage disk space interactively, drawing attention from developers interested in open-source command-line utilities.
- 20Developer adds CI workflow blocking AI-signed commitsβI added a CI workflow to my project that blocks any PR that contains commits that are signed by AI agents or lists itsel
A software developer has added a continuous integration workflow to their open-source project that automatically rejects pull requests containing commits signed by major AI agents or marked as AI-assisted. The check is shared as a reusable workflow in a separate repository so the blocklists and regex patterns can be updated centrally across projects.
- 21Fasttracker II Clone reaches version 2.25βFasttracker II Clone: tracker software released in version 2.25 https:// playingtux.com/en/articles/202 6/10/fasttracker
Fasttracker II Clone, the open-source recreation of the classic 1990s music tracker, has been released in version 2.25. The update is drawing attention among Linux users, retro gaming fans and chiptune musicians, who keep the tracker tradition alive on modern systems. The project continues to be maintained for Linux and other platforms as free software.
- 22Google suspends open-source bug bounty amid flood of AI-generated reportsβGoogle suspends open-source bug bounty program as AI slop overwhelms maintainers
Google has suspended its open-source bug bounty program, citing an overwhelming volume of low-quality, AI-generated vulnerability reports that burden maintainers. The decision highlights a growing problem across the security industry, as automated tools flood bug-tracking systems with junk submissions, making it harder for researchers to get legitimate findings reviewed and rewarded.
- 23pytest HTML report plugin passes three million downloadsβSix years after its first release, the pytest plugin that turns a test run into one shareable HTML... # opensource # pyt
The open-source plugin pytest-html-reporter has surpassed 3.1 million downloads roughly six years after its first release. The tool converts a Python test run into a single shareable HTML report, making test results easier to distribute among developers. Developers in the Python and testing communities are celebrating the milestone and crediting the project's usefulness in automated testing workflows for its lasting popularity.
- 24LiteLLM supply-chain attack hits tech, banking and healthcareβLiteLLM Supply-Chain Attack β Technology, Banking and Healthcare the Most Affected π¨ CRITICAL: TeamPCP's SANDCLOCK backd
Attackers used the SANDCLOCK backdoor, exploiting compromised LiteLLM maintainer credentials to push malicious PyPI packages, affecting more than 2,500 organisations across technology, finance and healthcare. The incident exposed cloud credentials and highlights the growing risk of open-source supply-chain compromises, with security researchers urging users to rotate secrets and update affected packages.
Repos
- cs341-illinois/coursebook Open Source Introductory Systems Programming Textbook for the University of Illinois
- heyjunpenn/awesome-jev A verified, community-maintained catalog of 981 open-source projects built with Jev.