MikeTrendsTrends right now

search

open-source maintainers

Trends

  1. 1
    Greg Kroah-Hartman on Security in the LLM Age●Greg Kroah-Hartman – Security in the LLM Age [video]YhnTechnologyAI33824 min ago

    Kernel developer Greg Kroah-Hartman, maintainer of the Linux kernel's stable branch and a central figure in open-source security, has a talk examining software security in the age of large language models. The discussion covers how LLM-generated code and LLM-assisted workflows affect vulnerability handling, code review and trust in the open-source supply chain. It is drawing attention from developers weighing AI's risks and benefits for core infrastructure.

  2. 2
    Google freezes open-source bug bounty over AI slop reportsβ–ΌGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions β€” product flaw submissions halted until 2027 as maintainers drown in hallucinationsMmastodon1563 min ago

    Google has paused new submissions to its open-source bug bounty program until 2027, citing an overwhelming flood of low-quality, AI-generated vulnerability reports. Maintainers are reportedly drowning in thousands of invalid, hallucinated flaw claims, making it impossible to separate genuine security findings from automated noise.

  3. 3
    Rhun: open-source code editor written in assemblyβ–ΌShow HN: Rhun, an open-source code editor written in assemblyYhnCultureMusic6321 min ago

    A developer going by vladcodes has released Rhun, an open-source code editor written entirely in assembly language, sharing it with the Hacker News community. The project, available at rhun.app, is drawing attention for the unusual technical decision to build an editor at such a low level, a task most projects handle with higher-level languages. Commenters are likely debating the practicality, performance benefits, and maintainability of assembly-based tooling.

  4. 4
    WordPress.org's forced takeover of ACF plugin sparks debate●Analisis pengambilalihan paksa plugin ACF oleh WordPress.org menjadi Secure Custom Fields. Dampak etika open source danMmastodonTechnologySoftware523 h ago

    WordPress.org took over the popular Advanced Custom Fields plugin and renamed it Secure Custom Fields, prompting analysis of the ethics of the move. Commenters are weighing the impact on open-source principles, trust between maintainers and repositories, and software supply-chain security for developers who rely on plugins distributed through WordPress.org.

  5. 5

    Sentry, the open-source error tracking and performance monitoring platform maintained by Sentry, is seeing fresh attention among developers. The tool helps engineering teams catch, prioritise and fix crashes and performance problems in production software, and its Python-based repository remains a widely used reference project in the monitoring space.

  6. 6
    KDE's Kate wins over a Hugo site author as Markdown editor●I’ve written about how and why KDE’s Kate has become my Markdown editor of choice for my # homelab # Hugo website. SpellMmastodonTechnologySoftware61 d ago

    A Linux user has published a blog post explaining why KDE's Kate became their Markdown editor of choice for writing and maintaining a Hugo-based homelab website. They highlight Kate's spell checking, Markdown highlighting, live preview, and code snippets, saying the features let them work entirely within the KDE ecosystem without switching tools.

  7. 7
    Moderate vulnerability disclosed in Docling document parsing toolβ–ΌπŸš¨ EUVD-2026-92803 πŸ“Š Score: 4.0/10 (CVSS v3.1) πŸ“¦ Product: docling, docling-slim 🏒 Vendor: docling-project πŸ“… Updated: 2026MmastodonTechnologyCybersecurity04 h ago

    A new vulnerability, EUVD-2026-92803, has been catalogued affecting the docling and docling-slim packages maintained by the docling-project. The flaw carries a moderate severity score of 4.0 out of 10 under CVSS v3.1 and affects versions from 2.91.0 onward. Docling is widely used to parse document formats and connect them with generative AI tools, so affected users are advised to check versions and apply fixes.

  8. 8
    novelWriter maintainer weighs dropping Debian 12 packages●I'm still releasing novelWriter packages for Debian 12, and I just checked and noticed people are still downloading thosMmastodonTechnologySoftware111 d ago

    The maintainer of novelWriter says they are still building packages for Debian 12 and have noticed people keep downloading them, even though the Debian 12 release reached end-of-life a few months ago. They would like to drop support, which would let them move on from Python 3.11, but are weighing that against users who still rely on those builds.

  9. 9
    GitHub repositories gain a way to signal accessibility support●Open any repository on GitHub and you see the same tabs: README, Code of Conduct, Contributing,... # a11y # github # opeMmastodonTechnologySoftware315 h ago

    GitHub repositories can now declare their commitment to accessibility alongside the familiar README, Code of Conduct and Contributing tabs. The change gives open-source projects a standard place to show they care about inclusive design, letting maintainers communicate accessibility information to users and contributors directly within the repository interface. Developers are discussing how this could push accessibility into mainstream open-source workflows.

  10. 10
    OpenSSH Creator's Security Philosophy Draws Renewed Attention●OpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One https://zbruceli.org/blog/the-man-who-trMmastodonTechnologySoftware34 h ago

    A profile of the OpenSSH project and its creator is drawing attention across the tech community. OpenSSH underpins secure remote access on virtually every Mac, Linux server and Windows machine, yet is maintained with a deliberately paranoid approach: its code is written to trust no input, no system and no contributor. The piece highlights how this rigour has kept the critical open-source tool safe for decades, prompting discussion about whether other widely used software should adopt similar discipline.

  11. 11
    Kagi Ends Orion Browser Development for Linux, Will Open-Source It●Kagi Ends Orion Browser Development for Linux, Will Open-Source It https://linuxiac.com/kagi-ends-orion-browser-developmMmastodonTechnology322 h ago

    Search company Kagi has ended development of its Orion browser for Linux and will open-source the existing code. The move means Linux users will no longer receive official updates, but the community will be free to maintain and build on the browser themselves. The announcement is drawing attention among open-source and privacy-focused technology communities.

  12. 12
    Kernel developer defends maintaining Landstrip mail service●There's no risk to that I would not maintain Landstrip because there is nothing better available i.e., I use it myself tMmastodonTechnologyCybersecurity123 min ago

    Jarkko Sakkinen, a Linux kernel developer, says he sees no risk in continuing to maintain Landstrip, explaining that he uses the service himself and considers it the best available option. He also criticises GitHub contributors he describes as manager or architect types who arrive with open-ended suggestions such as conformance tests rather than practical contributions.

  13. 13

    Search company Kagi has confirmed it is stopping development of its Orion browser for Linux and will release the Linux version's code as open source. The decision means Linux users will not receive continued official updates, but the community will be free to maintain and build on the browser themselves. Reactions online focus on whether open-sourcing softens the blow of abandoning the platform.

  14. 14
    Kagi Ends Orion Browser Development for Linux, Will Open-Source It●Kagi Ends Orion Browser Development for Linux, Will Open-Source It Article URL: https:// linuxiac.com/kagi-ends-orion-bMmastodonTechnology220 h ago

    Search company Kagi has announced it is stopping development of its Orion browser for Linux and will release the Linux version's code as open source. The move means the Linux community will be able to maintain or fork the browser themselves, even as Kagi concentrates Orion's ongoing development on other platforms. Early reaction online is limited so far, with the announcement just beginning to circulate among developers and open-source enthusiasts.

  15. 15
    Google freezes bug bounty program amid flood of AI-generated junk reportsβ–ΌGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions β€” product flaw submissions halted until 2027 as maintainers drown in hallucinationsβœ‰newsTechnologySoftware1 d ago

    Google has paused submissions to its open-source bug bounty program until 2027, citing an overwhelming volume of invalid, AI-generated vulnerability reports. Maintainers are said to be drowning in hallucinated or low-quality flaw submissions that waste review time, prompting the freeze on product flaw reports. The move highlights a growing strain that generative AI tools are placing on security research programs.

  16. 16
    Kagi Ends Orion Browser Development for Linux and Windows, Plans Open-Source Handover●Kagi ends development of Orion Browser for Linux and Windows, with plans to open-source both versions and hand them overMmastodonTechnologySoftware81 d ago

    Search company Kagi has stopped developing its Orion browser for Linux and Windows. The company says it plans to release the code for both versions as open source and hand the projects over to the community rather than continue maintaining them in-house. The move affects users of the privacy-focused browser on those platforms, who will now depend on community stewardship if development continues at all.

  17. 17

    Kagi has announced it is stopping development of its Orion browser for Linux and will instead release the code as open source. The move means Linux users will no longer receive official updates, but the community will be able to maintain and build the browser themselves. Kagi positions the decision as a way to serve Linux users better without continuing costly in-house development.

  18. 18
    System76 bans AI-generated code in COSMIC contributions●The AI machine continues to cause problems for some developers - with System76 now banning LLM-generated content in codeMmastodonTechnologySoftware219 h ago

    System76, the Linux hardware and software company, will no longer accept LLM-generated content in pull requests for its COSMIC desktop environment project. The move means code submissions flagged as AI-generated will be rejected. The decision reflects a broader debate in open-source development, where maintainers are increasingly pushing back on low-quality or unreviewable AI-generated contributions flooding their queues.

  19. 19
    Updated fork of ncdu disk usage tool released●ncdu: NCurses Disk Usage (an updated fork) https://github.com/rcalixte/ncdu # Tech # OpenSource # CLIMmastodonTechnology31 d ago

    A maintained fork of ncdu, the NCurses-based disk usage analyser for the command line, is now available on GitHub under rcalixte's account. The project continues the popular terminal tool that lets users inspect and manage disk space interactively, drawing attention from developers interested in open-source command-line utilities.

  20. 20
    Developer adds CI workflow blocking AI-signed commits●I added a CI workflow to my project that blocks any PR that contains commits that are signed by AI agents or lists itselMmastodonTechnologySoftware21 d ago

    A software developer has added a continuous integration workflow to their open-source project that automatically rejects pull requests containing commits signed by major AI agents or marked as AI-assisted. The check is shared as a reusable workflow in a separate repository so the blocklists and regex patterns can be updated centrally across projects.

  21. 21
    Fasttracker II Clone reaches version 2.25●Fasttracker II Clone: tracker software released in version 2.25 https:// playingtux.com/en/articles/202 6/10/fasttrackerMmastodonTechnologySoftware31 d ago

    Fasttracker II Clone, the open-source recreation of the classic 1990s music tracker, has been released in version 2.25. The update is drawing attention among Linux users, retro gaming fans and chiptune musicians, who keep the tracker tradition alive on modern systems. The project continues to be maintained for Linux and other platforms as free software.

  22. 22
    Google suspends open-source bug bounty amid flood of AI-generated reports●Google suspends open-source bug bounty program as AI slop overwhelms maintainersβœ‰newsTechnologySoftware1 d ago

    Google has suspended its open-source bug bounty program, citing an overwhelming volume of low-quality, AI-generated vulnerability reports that burden maintainers. The decision highlights a growing problem across the security industry, as automated tools flood bug-tracking systems with junk submissions, making it harder for researchers to get legitimate findings reviewed and rewarded.

  23. 23
    pytest HTML report plugin passes three million downloads●Six years after its first release, the pytest plugin that turns a test run into one shareable HTML... # opensource # pytMmastodonTechnologySoftware22 d ago

    The open-source plugin pytest-html-reporter has surpassed 3.1 million downloads roughly six years after its first release. The tool converts a Python test run into a single shareable HTML report, making test results easier to distribute among developers. Developers in the Python and testing communities are celebrating the milestone and crediting the project's usefulness in automated testing workflows for its lasting popularity.

  24. 24
    LiteLLM supply-chain attack hits tech, banking and healthcare●LiteLLM Supply-Chain Attack β€” Technology, Banking and Healthcare the Most Affected 🚨 CRITICAL: TeamPCP's SANDCLOCK backdMmastodonTechnologyCybersecurity12 d ago

    Attackers used the SANDCLOCK backdoor, exploiting compromised LiteLLM maintainer credentials to push malicious PyPI packages, affecting more than 2,500 organisations across technology, finance and healthcare. The incident exposed cloud credentials and highlights the growing risk of open-source supply-chain compromises, with security researchers urging users to rotate secrets and update affected packages.

Repos