search
open-source maintainers
Trends
- 1Greg Kroah-Hartman on security in the age of LLMs●Greg Kroah-Hartman – Security in the LLM Age [video]
Linux kernel maintainer Greg Kroah-Hartman is featured in a talk about security in the LLM age, examining how large language models affect the security of the software supply chain and open-source development. The discussion touches on risks that AI-generated code poses to kernel-quality standards and how maintainers can respond to an influx of machine-produced patches.
- 2Massive open-source pull request sparks AI slop debate●Ok, this got to be a repo diff record. +238,856 -260 https:// github.com/saga-soft/novelWrit er/pull/3067 # AI # Slop #
A pull request on the open-source project novelWriter by saga-soft is drawing attention for its sheer scale: roughly 238,856 lines added against just 260 removed, a size developers are calling a possible repo diff record. Commenters suspect bulk AI-generated code, tagging it as "AI slop", and are debating whether maintainers can meaningfully review changes of this magnitude.
- 3Rhun: an open-source code editor written in assembly●Show HN: Rhun, an open-source code editor written in assembly
A developer has released Rhun, an open-source code editor written entirely in assembly language, and shared it with the Hacker News community. The project is drawing attention for its unusual technical approach, as most modern editors are built with higher-level languages. Commenters are likely debating the practicality, performance and maintainability of writing developer tooling at such a low level.
- 4Two ARM64 compiler bugs hit curl in GCC and Rust toolchains▼Two ARM64-specific compiler optimization bugs, in GCC 15/16 and Rust, hit curl
curl maintainer Daniel Stenberg reports that two ARM64-specific compiler optimization bugs, one in GCC 15/16 and one in the Rust compiler, have affected curl. The bugs, triggered by aggressive optimization on 64-bit ARM platforms, caused miscompiled code in the widely used data transfer library. The report has drawn attention from developers discussing the risks compiler bugs pose to critical open-source infrastructure.
- 5Gentoo puts its Chromium package on notice●Last rites for Gentoo's Chromium package https://lwn.net/SubscriberLink/1097760/2be4d9e3eeb59039/ # Linux # OpenSource #
Gentoo Linux has declared 'last rites' for its Chromium package, a step in Gentoo's process that marks software for removal from the distribution's repositories. The move signals that the package is no longer being properly maintained. Linux and open-source communities are discussing what the loss of packaged Chromium means for Gentoo users who rely on it.
- 6Google pauses open-source bug bounty program after flood of invalid AI-generated reports▼Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations
Google has suspended submissions to its open-source bug bounty program until 2027, according to Tom's Hardware, after a surge of low-quality, AI-generated bug reports overwhelmed engineers and maintainers. The reports, often plausible-sounding but fabricated or hallucinated flaws, have made it impractical to separate genuine vulnerabilities from noise, prompting the freeze on new product flaw submissions.
- 7Moderate security flaw disclosed in Backstage Cloudflare Access plugin●🚨 EUVD-2026-93990 📊 Score: 6.8/10 (CVSS v3.1) 📦 Product: backstage, plugin-auth-backend-module-cloudflare-access-provide
A new vulnerability, EUVD-2026-93990, has been catalogued affecting the Cloudflare Access authentication provider plugin for Backstage, the open-source framework for building developer portals maintained under the Backstage project. Versions 0.1.0 through 0.5.0 are affected. The flaw carries a CVSS v3.1 score of 6.8, marking it as a moderate-severity issue. The advisory was updated on 6 October 2026, and administrators running the plugin are advised to check for patched releases.
- 8Israel estimated to hold 90 nuclear warheads▼◽ Nuclear Arsenal of Israel! 🇮🇱 👀 📈 ☢️ ◽ https://www. globalmilitary.net/nuclear/isr/ In 2026, Israel has a total of 90
Israel is estimated to possess around 90 nuclear warheads, making it the Middle East's only nuclear-armed state. The country maintains a policy of official silence, neither confirming nor denying its arsenal, but open-source research points to a small, mature and steadily maintained stockpile. Renewed attention to the figures comes amid ongoing regional tensions and debate over nuclear proliferation.
- 9Forensic Guide Explains How to Investigate Compromised GitHub Repositories●(opensourcemalware.com) Reconstructing the Real History of a Compromised GitHub Repository: A Forensic Guide to Detectin
A new guide published on opensourcemalware.com walks readers through reconstructing the real history of a compromised GitHub repository. It covers forensic techniques for detecting tampering and malicious activity in open-source projects, helping maintainers and security teams identify when an attacker has altered commit history or injected harmful code into a package.
- 10Linaro engineer weighs rising tide of AI-generated bug reports●What happens when LLMs start filing bug reports? 🤔 In his latest blog post, Alex Bennée (Tech Lead at Linaro) addresses
Alex Bennée, Tech Lead at Linaro, has published a blog post examining what he calls the "Bugpocalypse" — a sudden influx of AI-generated bug reports in the QEMU issue tracker. He argues that while large language models are getting better at spotting potential issues, the volume and quality of machine-filed reports pose new challenges for open-source maintainers who must triage them.
- 11MiSTer FPGA recreates Konami's Thrill Drive 2 arcade game▼MiSTer FPGA Arcade Konami Viper - Thrill Drive 2 https://www. youtube.com/watch?v=JyDbLj2A1gw # rgamingmoments # gaming
The MiSTer FPGA project, which recreates classic arcade hardware on open-source field-programmable gate arrays, is now running Konami's Viper-based racing game Thrill Drive 2. The news is being shared among retro gaming fans, who follow each new arcade core release as a milestone in preserving hardware that is increasingly hard to maintain.
- 12Underpeaks Core offers free self-hosted headless CMS for Flutter●If you've ever built the same app for web and mobile, you know the tax: two codebases, two... # webdev # flutter # nextj
Developers are highlighting the cost of maintaining separate web and mobile codebases, pointing to Underpeaks Core, a free, self-hosted, open-source headless CMS built for Flutter apps. The tool is pitched as a way to share one backend across web and mobile, easing the so-called dual-codebase tax that teams pay when building the same product twice.
Repos
- cs341-illinois/coursebook Open Source Introductory Systems Programming Textbook for the University of Illinois
- heyjunpenn/awesome-jev A verified, community-maintained catalog of 981 open-source projects built with Jev.