search
open-source maintainers
Trends
- 1WordPress.org's forced takeover of ACF plugin sparks debateβAnalisis pengambilalihan paksa plugin ACF oleh WordPress.org menjadi Secure Custom Fields. Dampak etika open source dan
WordPress.org took over the popular Advanced Custom Fields plugin and renamed it Secure Custom Fields, prompting analysis of the ethics of the move. Commenters are weighing the impact on open-source principles, trust between maintainers and repositories, and software supply-chain security for developers who rely on plugins distributed through WordPress.org.
- 2Greg Kroah-Hartman on security in the LLM ageβGreg Kroah-Hartman β Security in the LLM Age [video]
Greg Kroah-Hartman, the longtime Linux kernel maintainer who oversees stable kernel releases, has a talk on software security in the era of large language models. The discussion covers what LLM-generated code means for the kernel's security processes and for maintainers reviewing an influx of machine-written patches.
- 3KDE's Kate wins over a Hugo site author as Markdown editorβIβve written about how and why KDEβs Kate has become my Markdown editor of choice for my # homelab # Hugo website. Spell
A Linux user has published a blog post explaining why KDE's Kate became their Markdown editor of choice for writing and maintaining a Hugo-based homelab website. They highlight Kate's spell checking, Markdown highlighting, live preview, and code snippets, saying the features let them work entirely within the KDE ecosystem without switching tools.
- 4Google pauses open-source bug bounty until 2027 amid AI slop reportsβΌGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions β product flaw submissions halted until 2027 as maintainers drown in hallucinations
Google has suspended submissions to its open-source bug bounty program, halting product flaw reports until 2027. The pause follows a flood of invalid, AI-generated reports that has overwhelmed engineers and open-source maintainers with thousands of sloppy, hallucinated submissions. The move has drawn attention to how automated low-quality output is choking security research pipelines that rely on human triage.
- 5
Sentry, the open-source error tracking and performance monitoring platform maintained by Sentry, is seeing fresh attention among developers. The tool helps engineering teams catch, prioritise and fix crashes and performance problems in production software, and its Python-based repository remains a widely used reference project in the monitoring space.
- 6
Google has suspended part of its Open Source Vulnerability Reward Program as of October 1, halting payouts for product vulnerability submissions after a flood of low-quality, AI-generated invalid reports overwhelmed the program. The move covers Google-maintained open-source projects, with the company citing the burden of triaging junk submissions. The change has drawn discussion among developers concerned about security reporting quality.
- 7novelWriter maintainer weighs dropping Debian 12 packagesβI'm still releasing novelWriter packages for Debian 12, and I just checked and noticed people are still downloading thos
The maintainer of novelWriter says they are still building packages for Debian 12 and have noticed people keep downloading them, even though the Debian 12 release reached end-of-life a few months ago. They would like to drop support, which would let them move on from Python 3.11, but are weighing that against users who still rely on those builds.
- 8GitHub repositories gain a way to signal accessibility supportβOpen any repository on GitHub and you see the same tabs: README, Code of Conduct, Contributing,... # a11y # github # ope
GitHub repositories can now declare their commitment to accessibility alongside the familiar README, Code of Conduct and Contributing tabs. The change gives open-source projects a standard place to show they care about inclusive design, letting maintainers communicate accessibility information to users and contributors directly within the repository interface. Developers are discussing how this could push accessibility into mainstream open-source workflows.
- 9Google freezes bug bounty program amid flood of AI-generated junk reportsβΌGoogle freezes open-source bug bounty program amid flood of invalid AI slop submissions β product flaw submissions halted until 2027 as maintainers drown in hallucinations
Google has paused submissions to its open-source bug bounty program until 2027, citing an overwhelming volume of invalid, AI-generated vulnerability reports. Maintainers are said to be drowning in hallucinated or low-quality flaw submissions that waste review time, prompting the freeze on product flaw reports. The move highlights a growing strain that generative AI tools are placing on security research programs.
- 10StreetComplete iOS port via Kotlin Multiplatform reaches halfway pointβEl mantenedor de StreetComplete, westnordost, reporta que la migraciΓ³n a iOS con Kotlin Multiplatform y Compose Multipla
StreetComplete maintainer westnordost reports that the effort to bring the OpenStreetMap surveying app to iOS using Kotlin Multiplatform and Compose Multiplatform has reached roughly 50 percent completion after several months of work. The update gives the open-source mapping community a concrete progress marker on bringing the popular Android app to Apple devices.
- 11Kagi Ends Orion Browser Development for Linux and Windows, Plans Open-Source HandoverβKagi ends development of Orion Browser for Linux and Windows, with plans to open-source both versions and hand them over
Search company Kagi has stopped developing its Orion browser for Linux and Windows. The company says it plans to release the code for both versions as open source and hand the projects over to the community rather than continue maintaining them in-house. The move affects users of the privacy-focused browser on those platforms, who will now depend on community stewardship if development continues at all.
- 12Kagi Ends Orion Browser Development for Linux, Will Open-Source ItβKagi Ends Orion Browser Development for Linux, Will Open-Source It https://linuxiac.com/kagi-ends-orion-browser-developm
Search company Kagi has ended development of its Orion browser for Linux and will open-source the existing code. The move means Linux users will no longer receive official updates, but the community will be free to maintain and build on the browser themselves. The announcement is drawing attention among open-source and privacy-focused technology communities.
- 13
Search company Kagi has confirmed it is stopping development of its Orion browser for Linux and will release the Linux version's code as open source. The decision means Linux users will not receive continued official updates, but the community will be free to maintain and build on the browser themselves. Reactions online focus on whether open-sourcing softens the blow of abandoning the platform.
- 14Kagi Ends Orion Browser Development for Linux, Will Open-Source ItβKagi Ends Orion Browser Development for Linux, Will Open-Source It Article URL: https:// linuxiac.com/kagi-ends-orion-b
Search company Kagi has announced it is stopping development of its Orion browser for Linux and will release the Linux version's code as open source. The move means the Linux community will be able to maintain or fork the browser themselves, even as Kagi concentrates Orion's ongoing development on other platforms. Early reaction online is limited so far, with the announcement just beginning to circulate among developers and open-source enthusiasts.
- 15Dutch animal rights party criticised for omitting Mastodon from job adβΌRE: https:// mastodon.social/@PartijvoordeD ieren/117360440016649804 Waarom wordt # Mastodon niet genoemd in de vacature
The Dutch Party for the Animals posted a vacancy for a full-time social media and content specialist for its parliamentary faction, listing Instagram, TikTok, Bluesky and Facebook among the platforms. Mastodon users are questioning why the decentralised network Mastodon is not mentioned, noting the party itself maintains an active account there. The discussion highlights debate over whether organisations should include smaller, open-source platforms in their communications work.
- 16
Kagi has announced it is stopping development of its Orion browser for Linux and will instead release the code as open source. The move means Linux users will no longer receive official updates, but the community will be able to maintain and build the browser themselves. Kagi positions the decision as a way to serve Linux users better without continuing costly in-house development.
- 17Updated fork of ncdu disk usage tool releasedβncdu: NCurses Disk Usage (an updated fork) https://github.com/rcalixte/ncdu # Tech # OpenSource # CLI
A maintained fork of ncdu, the NCurses-based disk usage analyser for the command line, is now available on GitHub under rcalixte's account. The project continues the popular terminal tool that lets users inspect and manage disk space interactively, drawing attention from developers interested in open-source command-line utilities.
- 18System76 bans AI-generated code in COSMIC contributionsβThe AI machine continues to cause problems for some developers - with System76 now banning LLM-generated content in code
System76, the Linux hardware and software company, will no longer accept LLM-generated content in pull requests for its COSMIC desktop environment project. The move means code submissions flagged as AI-generated will be rejected. The decision reflects a broader debate in open-source development, where maintainers are increasingly pushing back on low-quality or unreviewable AI-generated contributions flooding their queues.
- 19Pidgin developers begin work toward 3.0 Alpha 4βGreetings Programs!! We're back tonight starting our work towards @ pidgin 3.0 Alpha 4!! Come on by!! https:// twitch.tv
Work is underway on Pidgin 3.0 Alpha 4, the next testing release of the long-running open-source instant messaging client. Developer rw_grim announced a live coding session kicking off the push toward the new alpha, inviting the open-source community to watch and follow along as development resumes.
- 20
Version 18.1 of GDB, the GNU Debugger widely used for debugging C, C++ and other compiled programs, has been released. The announcement was made on the GDB mailing list maintained by Sourceware, pointing users to the new stable point release. Developers are sharing the news in programming communities, where the debugger remains a core tool in open-source toolchains alongside GCC.
- 21Fasttracker II Clone reaches version 2.25βFasttracker II Clone: tracker software released in version 2.25 https:// playingtux.com/en/articles/202 6/10/fasttracker
Fasttracker II Clone, the open-source recreation of the classic 1990s music tracker, has been released in version 2.25. The update is drawing attention among Linux users, retro gaming fans and chiptune musicians, who keep the tracker tradition alive on modern systems. The project continues to be maintained for Linux and other platforms as free software.
- 22Developer adds CI workflow blocking AI-signed commitsβI added a CI workflow to my project that blocks any PR that contains commits that are signed by AI agents or lists itsel
A software developer has added a continuous integration workflow to their open-source project that automatically rejects pull requests containing commits signed by major AI agents or marked as AI-assisted. The check is shared as a reusable workflow in a separate repository so the blocklists and regex patterns can be updated centrally across projects.
- 23pytest HTML report plugin passes three million downloadsβSix years after its first release, the pytest plugin that turns a test run into one shareable HTML... # opensource # pyt
The open-source plugin pytest-html-reporter has surpassed 3.1 million downloads roughly six years after its first release. The tool converts a Python test run into a single shareable HTML report, making test results easier to distribute among developers. Developers in the Python and testing communities are celebrating the milestone and crediting the project's usefulness in automated testing workflows for its lasting popularity.
- 24PHP Depend 3.0.0 released after years of developmentβAfter years of development PHP Depend 3.0.0 has finally been released! π https:// github.com/pdepend/pdepend/rel eases/t
PHP Depend, an open-source static code analysis tool for PHP, has released version 3.0.0 following years of development. The release was announced by the project's maintainers and shared with the PHP developer community. It matters to developers who use the tool to measure code quality and complexity in PHP projects.
- 25Google suspends open-source bug bounty amid flood of AI-generated reportsβGoogle suspends open-source bug bounty program as AI slop overwhelms maintainers
Google has suspended its open-source bug bounty program, citing an overwhelming volume of low-quality, AI-generated vulnerability reports that burden maintainers. The decision highlights a growing problem across the security industry, as automated tools flood bug-tracking systems with junk submissions, making it harder for researchers to get legitimate findings reviewed and rewarded.
- 26Cloudflare launches managed OS for AI agent workspacesβCloudflare OS: your company's agent workspace, managed for you https://blog.cloudflare.com/managed-cloudflare-os/ # Clou
Cloudflare has announced a managed Cloudflare OS, pitched as a company workspace for AI agents that is maintained for customers rather than self-hosted. The announcement, shared on Cloudflare's blog with open-source and AI tags, positions the product as infrastructure for organisations running agentic software without managing the underlying environment themselves. Early response online has been modest so far, circulating mainly among developer and open-source communities.
- 27
The Chompi, a compact lo-fi sampler and synthesizer popular with experimental musicians, is being discontinued, and its creators are releasing it as open-source hardware and software. That means the design files and code will be publicly available, allowing the community to build, modify, and maintain their own units after official production ends.
- 28LiteLLM supply-chain attack hits tech, banking and healthcareβLiteLLM Supply-Chain Attack β Technology, Banking and Healthcare the Most Affected π¨ CRITICAL: TeamPCP's SANDCLOCK backd
Attackers used the SANDCLOCK backdoor, exploiting compromised LiteLLM maintainer credentials to push malicious PyPI packages, affecting more than 2,500 organisations across technology, finance and healthcare. The incident exposed cloud credentials and highlights the growing risk of open-source supply-chain compromises, with security researchers urging users to rotate secrets and update affected packages.
- 29Backtalk offers community fork of Android's TalkBack screen readerβBy @ TheQuinbox Backtalk is a fork of Google's TalkBack, the screen reader for blind and visually-impaired users of Andr
A modified version of Google's TalkBack screen reader, called Backtalk, is drawing attention in accessibility circles. Built by developer TheQuinbox, the fork takes Google's open-source releases and adds fixes and extra features for blind and visually impaired Android users. The project is hosted on GitHub and is explicitly not affiliated with Google.
- 30BigBlueButton connector for Nextcloud now supports version 35βπ Le connecteur # BigBlueButton pour # Nextcloud dont nous assurons le dΓ©veloppement et la maintenance est dΓ©sormais com
Arawa, the firm maintaining the BigBlueButton connector for Nextcloud, has released version 2.9.4, making the app compatible with Nextcloud 35 (Hub 26 Summer). The update also remains compatible with Nextcloud 33 and 34, allowing users on older installations to integrate BigBlueButton video conferencing into their Nextcloud instances. The announcement was shared with the open-source community.
- 31IFPI accused of pushing to label yt-dlp a piracy toolβApparently, the IFPI is pushing to label # ytdlp as a # piracy tool. Even as a paying # YouTube Premium subscriber, this
The International Federation of the Phonographic Industry is reportedly pressing to classify yt-dlp, the widely used open-source media downloader, as a piracy tool. Critics, including paying YouTube Premium subscribers, call the move harassment of open-source maintainers and warn that treating general-purpose tools as piracy services could set a precedent for banning technologies like torrent clients.
- 32Hackergarten Luzern developers find and fix bug during meetupβAnother @ hackergarten Luzern evening, this time with no shortage of ideas on the flipchart. I missed the opening pitche
At another Hackergarten meetup in Lucerne, Switzerland, an attendee who arrived after the opening pitches joined the FitPub project as usual and discovered a bug while exploring its public timeline. The bug was reported to a maintainer and quickly fixed. The event again produced a flipchart full of project ideas, and attendees shared their progress openly with the local developer community.
- 33Longtime Collabora engineer leaves to launch AI-focused businessβAfter sixteen years at @ collabora , I'm moving on to start my own business, focused on software engineering in the age
An engineer who spent sixteen years at Collabora has announced he is leaving to start his own business focused on software engineering in the age of AI. He is also stepping down as maintainer of WirePlumber, the PipeWire session manager, with Julian Bouzas, who has worked alongside him since 2019, taking over the project.
- 34High-severity vulnerability disclosed in Apache Thrift Lua libraryβπ¨ EUVD-2026-91330 π Score: 8.7/10 (CVSS v3.1) π¦ Product: Apache Thrift π’ Vendor: Apache Software Foundation π Updated: 2
A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.
- 35Open-source AI assistant Ankita seeks Hacktoberfest contributorsβAnkita, the open-source desktop AI assistant, is looking for Hacktoberfest contributors. Real issues, fast reviews, ever
Ankita, an open-source desktop AI assistant built with Node and Electron, is inviting developers to contribute during Hacktoberfest. The project's maintainers are offering real, meaningful issues, fast code reviews, and credit for every contributor as part of the annual open-source event. The appeal highlights Ankita's inclusive community approach and its aim to grow through collaborative development during October.
- 36Old Python projects rot quietly as docstrings lag behindβOld Python projects rot in a quiet way. Functions get new parameters and the docstring above them... # python # document
A developer scanned four popular Python libraries and found documentation quietly drifting out of date: functions gain new parameters over time while the docstrings above them still describe older versions. The observation is resonating with programmers who recognise the pattern, sparking discussion about how open-source projects maintain documentation as code evolves and what tools could catch these silent inconsistencies.
- 37Open-source pay-gap cost calculator promises zero network callsβI maintain a small open-source calculator that prices what it costs to close an unexplained gender... # opensource # jav
A developer maintains a small open-source calculator that estimates the cost of closing an unexplained gender pay gap. The tool is built in JavaScript and is designed to make zero network calls, so salary data entered by employers or analysts never leaves the user's browser. The privacy-first approach is drawing attention in open-source and HR communities.
- 38Apache APISIX vulnerability logs unmasked sensitive header valuesβπ¨ EUVD-2026-90763 π Score: 5.7/10 (CVSS v3.1) π¦ Product: Apache APISIX π’ Vendor: Apache Software Foundation π Updated: 2
A medium-severity vulnerability, EUVD-2026-90763, has been catalogued in Apache APISIX, the open-source API gateway maintained by the Apache Software Foundation. Rated 5.7 out of 10 under CVSS v3.1, the flaw involves the insertion of sensitive information into log files, with unmasked header values potentially being written in cleartext.
- 39D7VK 2.3 marks turning point with maintenance mode moveβD7VK 2.3 segna un punto di svolta con lβingresso in modalitΓ manutenzione. Una notizia positiva per i giocatori Linux ch
D7VK 2.3 has been released, marking a turning point as the open-source translation layer enters maintenance mode. The update is described as good news for Linux gamers who play classic titles and older Windows games, since a stable, maintained codebase means continued compatibility for legacy gaming on Linux without requiring major new development.
- 40High-severity command injection flaw fixed in RenovateβΌπ¨ EUVD-2024-55728 π Score: 8.4/10 (CVSS v3.1) π¦ Product: renovate π’ Vendor: renovatebot π Published: 2026-08-19 | Update
A high-severity vulnerability, EUVD-2024-55728, was published for Renovate, the popular open-source dependency update tool maintained by renovatebot. Versions 37.158.0 before 37.199.0 contain a command injection flaw in the helmv3 manager's registryAliases handling, rated 8.4 out of 10 on the CVSS v3.1 scale. Users are being urged to update to a patched release, as the bug could allow attackers to execute arbitrary commands through manipulated registry alias values.
Repos
- cs341-illinois/coursebook Open Source Introductory Systems Programming Textbook for the University of Illinois
- heyjunpenn/awesome-jev A verified, community-maintained catalog of 981 open-source projects built with Jev.