heise online reports from Open Source Summit Europe in Prague that FINOS executive director Gabriele Columbro presented initial results from the OSERA Risk Navigator project, part of the Open-Source Enterprise Resiliency Alliance effort to help banks and other highly regulated organizations close security gaps in open source software. The article describes how a patch can take weeks, months or years to travel from a source repository into a bank's production environment, and how institutions often clone, patch and re-sync software themselves without telling upstream, leaving components in a publicly unknown state. It says AI tools such as Claude Mythos have put the patching backlog on bank executives' agendas by finding vulnerabilities in hours rather than months, and that Risk Navigator uses SBOMs to identify which files and libraries are vulnerable, prioritises remediation using CVSS, EPSS and CISA KEV data, and summarises the corrections so they can be planned operationally.
At the Linux Plumbers Conference in Prague, Qualcomm engineer Khem Raj questioned the relevance of Linux long-term-support distributions in the era of generative AI, pointing to the constant, heavy flow of patches and bug reports and arguing that rolling-release distributions are better suited to staying current with mainline work and easing the maintenance burden on developers.
Climate tech non-profit TransitionZero said its open source translator, which converts power system models between frameworks and commercial tools including PLEXOS, PyPSA, Sienna and OSeMOSYS, has become a core part of OpenGrid, the Linux Foundation and Breakthrough Energy initiative launched the same day to modernise electricity-grid planning. Built with Breakthrough Energy support, the translator is part of TransitionZero's open core of free tools for energy modelling, and the organisation plans to add it to its no-code Scenario Builder platform so users can import their existing model files directly, citing IEA figures that more than 2,500 gigawatts of renewable, storage and large-load projects are stalled in grid connection queues worldwide.
Solus published an update on its relicensing project, saying it has sent the first emails to contributors who have not yet consented to moving the getsolus/packages repository to the Mozilla Public License 2.0. The project says the package recipes currently lack clear licensing terms, which casts doubt on whether they are actually open source and blocks sharing recipes with aerynOS, so contributors are asked to reply to the email or comment on the GitHub issue agreeing to license all previous contributions under MPL-2.0, with the message to be re-sent in 30 days if unanswered. Solus chose MPL-2.0 because it combines file-level copyleft with permissiveness and because aerynOS already uses it, and it plans to convert its recipes to the aerynOS format so the two projects can share packaging work.
PartyKit announced it is closing its hosted platform, saying that since joining Cloudflare all its energy has gone into PartyServer, the open source successor that runs as a regular Worker with Durable Objects on a user's own Cloudflare account and underpins the Cloudflare Agents SDK. New projects stopped on October 9, projects inactive for three months are removed on October 12, deploys turn off on October 16 and the platform shuts down on October 23 with remaining projects and their room data deleted; users are told to migrate to PartyServer and deploy with wrangler, and to export data held in room storage, which PartyKit cannot move for them.
The ArchStrike team announced the project is shutting down, saying it had not been getting maintained for a while as the security tools it packaged increasingly gained official upstream packages, so the list of things it had to remove or rework grew while the payoff for its efforts dwindled. The team said its members each found themselves with less time to commit and took longer than they should have to agree to end the project, and it will leave the website up for a few weeks while the GitHub repositories remain archived.
Bitwarden told its community that the apps published to the various app stores will be the commercially licensed builds starting with the next release, while the GPLv3 open source version continues to be updated and published on GitHub and the download page will also link to the commercial build. The company said all current features remain in both versions, that forking, self-hosting and third-party community servers are unchanged, and that the change targets those who repackage and resell Bitwarden, but it acknowledged that some future components will be published only under the commercial license and that new features will be assigned a license case by case. Community members pressed for details on the feature split, self-hosted support and pricing tiers, with several describing the move as openwashing and a possible first step toward abandoning open source.
Linuxiac reports that Solus has begun contacting past contributors to secure approval for relicensing its package repository under MPL-2.0, a step it says is needed before it can share package recipes with aerynOS. Solus explained in May that its package.yml recipes were once kept in a single repository under GPL-2.0-or-later, but their license files were not carried over when development moved to a self-hosted Phabricator instance and the missing terms were never restored when the packages were consolidated into the current getsolus/packages repository on GitHub, leaving the licensing of the public recipes and of contributions made without an explicit license unclear. MPL-2.0 was chosen because it applies file-level copyleft while allowing covered files to be combined with differently licensed code, and because aerynOS already uses it. Solus has been adopting aerynOS packaging tools and intends to convert its recipes to the aerynOS format so the two projects can reuse packaging work instead of maintaining definitions for the same software separately, but says the licensing questions must be resolved first.
TechTarget reports from Open Source Summit Europe in Prague that a surge of AI-generated and AI-sourced code is adding unprecedented stress to software supply chains, just as the EU Cyber Resilience Act's vulnerability-reporting mandates took effect in September and place potentially costly liability on organizations that ship software in Europe. Under the CRA, open source dependencies that were previously treated separately from software products now fall within the liability of the commercial products that use them, and presenters described traditional software bills of materials as a band-aid for gushing wounds. The Open Source Security Foundation's Launchpad Special Interest Group, co-chaired by Microsoft, is working to create machine-readable CRA due-diligence baselines that span open source components.
Phoronix reports that Linux networking maintainer Jakub Kicinski diverted more than 50 fixes to net-next for Linux 7.4 and asked the subordinate subsystem trees to trim their submissions, yet the networking pull request for Linux 7.3-rc7 still carried 128 commits covering Ethernet driver regressions, MediaTek MT76 Wi-Fi, Bluetooth, CAN and WireGuard changes. The pull-request summary described some of the nxpwifi changes as 'LLM-ish fixes', and Kicinski concluded that the situation is what it is, with AI- and LLM-generated bug reports and patches continuing to overwhelm the networking subsystem and push less urgent work to the next merge window ahead of the 7.3-rc7 release expected on October 11.
The Wagtail content management system's core team said it will not take part in Google Summer of Code 2027, writing that it is seeing increasing volumes of low-quality contributions that waste everyone's time and that it would rather remove one incentive to contribute than close its feature requests and pull requests to everyone. The team stressed that this is not a code quality problem, since quality has always varied in a project of its size, but a problem with contribution motivation and behavior, and pointed to its GSoC AI policy and its earlier writing on open source maintenance, new contributors and AI agents. Applicants are told to register interest through a form rather than start contributing, because Wagtail cannot guarantee participation until March 2027, and it said other Wagtail-related projects may still take part.
Ars Technica reports on research using data from engineering-analytics vendor Jellyfish that found AI coding agents increase how much code is written without increasing the amount of finished software, because the average pull request review time balloons 49 percent after agents are introduced. The study found the share of pull requests with changes requested nearly doubled and comments per pull request rose 35 percent, while the share of workers doing code reviews grew 14 percent and the researchers said they could not attribute significant employment changes to AI. AI review tooling had only a marginal effect so far: 80 percent of measured firms used some form of AI code review by March 2026, but agents produced just 23.3 percent of review comments and 10.8 percent of pull requests, leaving the vast majority of review work to humans.
A bug report on the Strata repository documents that the project force-updated its main branch with a rewritten history that shares no common ancestor with the previous one: old commits and their replacements have identical file trees, author dates and subjects, but the new commits omit the earlier Claude-related commit trailers and have different parents. Because the bundled UPDATE.bat script runs git pull --ff-only and exits when that fails, existing checkouts can no longer update and the script's error message does not explain the rewrite or offer recovery steps, so users may mistake it for a local problem. The reporter, who preserved local changes on a new branch to work around it, asked the maintainer to announce the rewrite, document a safe recovery procedure that preserves local modifications and downloaded models, make the updater detect the situation, and avoid git reset --hard or git clean.
WordPress plugin developer Russell Aaron argues that the free-plus-Pro plugin pricing model is collapsing because buyers decide within about ten minutes of activation and increasingly paste a sales page into an AI chat to ask whether they can build the feature themselves, turning thin utility plugins into a theme snippet and shifting value to maintenance, integrations and support. He writes that Pro is now the free tier and Ultimate is what buyers expect, that trialware is barred from the WordPress.org directory so the free version has to stand on its own, and that inflated list prices followed by predictable discounts no longer work. The post was highlighted in the WP More newsletter on October 9 and follows earlier WordPress monetization debate about free plugins funded by payment fees and paid services.
Dirk Farin, the independent developer behind the libheif and libde265 HEIC and AVIF codec libraries, updated the project's status note to say the libraries are used by practically every open-source application and service that handles HEIC or AVIF files, but that the maintenance work is almost entirely unfunded. The note reports that 73 security advisories were published for libheif between January and October 2026, most of them found with automated tools by organizations that ship the library in their products, and that ten releases were made mainly to ship security fixes, with reproducing, fixing, testing, fuzzing and releasing still done in evenings and on weekends. Recurring sponsorship through GitHub Sponsors amounted to 1 per month as of September against a ,000 monthly goal that would fund about two days a week, and the project is offering paid commercial support that includes pre-release notice of embargoed advisories, a direct contact for security and integration questions, an agreed number of engineering hours per month, and scoped hardening or fuzzing projects.
VentureBeat reviewed Anthropic's vulnerability-disclosure dashboard and the Cyber Mission it announced on October 8, reporting that Anthropic models logged 29,439 findings between November 1, 2025 and October 2, 2026, of which 6,157 across 591 open-source projects were reported to maintainers and only 516 were patched upstream to Anthropic's knowledge, with no guarantee those patches were widely installed. Outside security firms reviewed 6,123 findings and confirmed 5,674 valid, while 4,824 of the reported findings went directly to maintainers and may include false positives; the Critical Infrastructure Defense Program's 11 partners include Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic did not say whether partners get free model access or who covers compute costs, and the piece notes fixes from its Glasswing work often take months and, in rare operational-technology cases, could take decades.
Wesley Moore announced that he is winding down Casuarina Linux, the glibc-based distribution he built as a derivative of Chimera Linux, after failing to attract co-maintainers. He writes that he assumed most of the hard work was done once the system bootstrapped and that maintenance would mostly mean updating packages, but that no one else stepped up to share the load, and that the project ran into problems such as C++ standard libraries not coexisting when everything was built against LLVM's libc++ while also providing GNU libstdc++. Package updates stop at the end of October 2026 depending on how his migration to another distribution goes, the infrastructure stays up until the end of 2026, and there are no plans yet to retire the package repository or website.
Webcomic author David Revoy, who publishes Pepper&Carrot under CC BY and MiniFantasyTheater under CC BY-SA and draws everything with free and open source software, added an AI-derivation prohibition on top of his Creative Commons licenses, writing that the licenses lack an option to bar AI-generated derivatives and that he now receives more than three permission requests a day from studios, publishers and game developers wanting to build AI works on his characters, lore and stories. His statement prohibits derivatives in which AI generates or substantially replaces the ideas, creative process or visual rendering, including AI-written fan fiction and scripts, AI-generated comics and renders, and AI-graphics games or interactive comics, and it extends a no-AI contribution policy already in place on the Pepper&Carrot repositories since March 2026. He says he will assert the moral rights European law gives him, publish an AI-derivation-prohibited notice alongside the Creative Commons terms and backport it to older works, while tolerating software that contains AI-assisted code, AI grammar and proofreading tools, and human-directed translation.
Speaking with Dirk Hohndel at Open Source Summit Europe, Linux creator Linus Torvalds said he really likes using AI, describing vibe coding as a wonderful way to find joy in programming and arguing that it can help newcomers get into development, but he drew a line at letting it run Linux kernel development, saying AI is fine for finding bugs. The interview covers how kernel development is changing as AI-assisted bug reports and tooling become part of the workflow, set against the growing pushback from projects such as System76's COSMIC desktop, which has barred LLM-generated contributions, and it lands as the kernel community weighs new AI agent resources and LLM contribution policies.
TechCrunch reports that Jeremy Klaperman left his role as Automattic's interim chief financial officer less than a month after he was elevated to the job following the governance crisis at the WordPress.com parent company, in which the entire board either quit or was fired after it voted to put CEO Matt Mullenweg on leave and he retook the role within 33 hours. Klaperman had been CFO of Automattic's VIP Enterprise unit and was meant to replace Mark Davies, who briefly held the CFO job before leaving along with chief legal officer Andy Missan; the new board announced in late September includes science-fiction author Hugh Howey, two co-founders of the defunct app IRL and author Amy Chan. A source told TechCrunch that Klaperman was upset the board was weighing external CFO candidates, that the board never legally approved his interim title, and that a disagreement with Mullenweg over a project tied to employee performance reviews led to his demotion back to VIP before he resigned, while the company said only that it is grateful for his leadership and is still searching for a permanent CFO.
Changelog interviews Gavriel Cohen, creator of NanoClaw and co-founder of NanoCo, about how a 40-hour weekend project became a viral open source hit and the foundation of an enterprise AI company. Cohen explains the security concerns that led him to build a small, container-isolated alternative to OpenClaw, why he released it under the MIT license, and why the project’s community and credibility are more valuable than keeping its code private, along with the approval and governance layers large companies require and NanoClaw’s containers, TypeScript, SQLite, and two-database design.
Linux Stans reports on a Reddit analysis that downloaded the full commit history of 23 projects phones, browsers and servers depend on and counted everyone making ten or more changes between October 2025 and October 2026, finding that 11 of the 23 have only one or two regular contributors. xz has a single regular contributor, Lasse Collin, who wrote 97 percent of its changes in 2025 and has received no new money since the 2024 backdoor, while sudo saw 5,408 of its 5,409 commits from 2008 to 2018 come from one person, Todd Miller, and eight projects including the time zone database, SQLite, zlib, xz and bash show no grant or sponsorship in the public funding sources checked. The piece contrasts that with OpenSSL, which lived on about $2,000 a year in donations until the Linux Foundation raised $5.4 million within two months of Heartbleed in 2014 and the project gained paid developers and an audit, and it also notes where r/linux readers disputed the contributor-counting method.
Modular announced the first projects supported through its Community Grant Program, backing six open source efforts in the Mojo and MAX ecosystem: the noeira reinforcement-learning framework written in Mojo, the bajo GPU physics simulator for parallel robotics and reinforcement-learning environments, a high-performance CPU and GPU Fast Fourier Transform implementation, the EmberJson parser, the floki HTTP client built on libcurl, and the Manim-inspired momanim animation framework. The program, launched in April 2026, pays grants starting at $500 over six months in three installments through GitHub Sponsors, prioritizes kernels, new model support and ecosystem gaps, and asks recipients to meet monthly with Modular and contribute an interview, blog post and community presentation.
The Eclipse Foundation's creation review for Eclipse Fastbelt concluded successfully on October 7, 2026, adding an MIT-licensed Go toolkit for building domain-specific languages to the foundation's Eclipse Cloud Development project area. Fastbelt generates language components from grammars and offers parallel processing and Language Server Protocol editor integration aimed at large workspaces and performance-sensitive language tooling. The proposal, published September 21 under project leads Mark Sujew and Miro Spönemann, calls for repository migration and intellectual-property review before the first release under Eclipse governance, and the project is listed as incubating.
AndBible lead developer Tuomas Airaksinen published the volunteer-run Bible study app's Q3 2026 financial report, logging 75.85 development hours of which 6.39 went unsponsored. Roughly two thirds of the quarter went into the first phase of a Compose and Kotlin Multiplatform port, and the project says it has no budget of its own: leftover hours from a completed reading-tracker commission ran out in July, after which all available hours in the generic sponsorship pool were redirected to the port, leaving that pool at zero with no buffer going into Q4. The report says overall funding is still below the target of about one full working day per week, around 90 hours a quarter, which would let the maintainer commit to a predictable pace, while the roadmap targets an Android release as AndBible 6.0 with a refreshed Material 3 interface and a unified iOS release in 2027.
Simon Willison notes that Cloudflare is acquiring Deno outright, roughly two months after the Deno team released celld, its open source implementation of Cloudflare's Durable Objects pattern, which Cloudflare wants to build on to make self-hosting workerd a first-class way to run apps using the Workers programming model. Deno itself will receive monthly bug-fix and security releases for one more year before Cloudflare ends runtime development, though it stays open source and the company welcomes others to continue it. Willison highlights Deno creator Ryan Dahl's explanation on Hacker News that he agreed to the decision because Deno was sucked into the gravity well of Node compatibility and no longer solves big problems, while Dahl says he is more interested in the new server-development model celld represents, and Willison calls Deno's permissions system his long-time favorite feature.
CNCF told OpenTelemetry .NET maintainer Martin Costello that its use of Verify.XunitV3's newer NuGet packages cannot be approved as a license exception because the Open Source Maintenance Fee is inconsistent with open source licensing, and recommended the project either build from the MIT-licensed source or keep using versions published before the fee took effect. Costello filed the request on October 1, noting the snapshot-testing dependency is not shipped in any user-facing code and that he understood OpenTelemetry to qualify for the OSMF's free open source exemption. OSMF creator Rob Mensching pushed back the same day, saying the fee is explicitly built to be compatible with F/OSS licenses and asking CNCF to explain its rationale. The exchange sets a foundation's third-party license policy directly against the paid-binaries maintenance model that has been spreading through the .NET ecosystem.
Automattic applied to ICANN to operate .wordpress as a top-level domain that only the company and its affiliates could register, filing through its Knock Knock WHOIS There registry subsidiary in ICANN's first round of new gTLD applications since 2012. The application, published alongside more than 1,600 others, describes .wordpress as a space Automattic will responsibly steward on behalf of the open-source project and the open web, but also as a closed, single-registrant namespace dedicated to WordPress-branded products and internal and external initiatives controlled by KKWT and its affiliates, and states that registrations will not be made available to unaffiliated third parties. The Repository notes the filing proposes no public-interest or registry voluntary commitments, reviving questions about how a for-profit company's commercial control of the WordPress name relates to the wider project and its foundation.
Organic Software's Matt marks the end of Deno after Cloudflare said it would acquire the company and shut the runtime down over the coming year, crediting the project's sandboxed security model, portability and zero-config developer experience while recalling how his team built products used by tens of thousands on Deno, Deno Deploy, Deno Sandboxes and Fresh. He blames the Deno company's tenuous venture-capital-backed business model for the outcome, calls the moment a mourning, and notes that escaping back to Node or Bun is straightforward because Deno never created strong lock-in.
David Heinemeier Hansson welcomed Namespace to the Omacom Foundation as a Distinguished Corporate Patron, contributing $100,000 a year in compute for three years that the foundation is putting directly into ARM builds and quality assurance for Omarchy. Hansson explains that Omarchy grew up on x86 and its testing was built around it, but ARM is arriving quickly through Omarchy M for Apple Silicon, Omarchy Dragon for Snapdragon laptops and Alibaba's Qwen Book, and that verifying an installer on cloud ARM machines usually requires running a virtual machine. Namespace runs Linux on Apple Silicon, where the same ARM image boots in about four seconds instead of the three-plus minutes needed when emulating the processor, and it already runs builds for Zed, DuckDB and mise, which the foundation also sponsors.
LLVM contributor Nikita Popov opened an RFC to extend the project's comparatively permissive AI tool policy by banning AI-generated or substantially AI-assisted textual communication, including pull request descriptions and RFC texts, while leaving the allowed uses of AI for code contributions unchanged. He argues the main cost is the volume of verbose, over-formatted pull request descriptions arriving from new contributors, which consume reviewer bandwidth twice over: once to read and again to rewrite into a mergeable form, and which erase the effort signal that used to help maintainers judge whether a stranger's contribution was made in good faith. The thread is the latest sign that large projects are separating AI-assisted code, which many still accept with human review, from AI-authored prose, which they increasingly reject.
elementary OS added a Generative AI Policy to its contributor guide that bars contributions generated by large language models and chatbots such as ChatGPT, Claude, Copilot, DeepSeek and Devin, covering code, documentation, issues and artwork, and explicitly forbidding the use of AI to write pull request descriptions. The project cites the negative effect of AI content on quality, legal complications including the inability to claim copyright and to ensure others' licensing and copyright were not violated, and ethical concerns over intellectual property theft, environmental impact and the devaluing of labor. A narrow exception permits dedicated machine translation tools for turning issues, discussions and comments into English, and the policy says the project cannot support anything that relies on AI output. The ban drew criticism from Basecamp creator David Heinemeier Hansson, who called the stance Luddism, and it joins a growing set of AI contribution rules from projects including COSMIC, LLVM and Flathub.
Deno creator Ryan Dahl announced that the entire Deno team is joining Cloudflare, where it will merge its runtime and hosting work with the Workers and Durable Objects teams and push that programming model as the default way to build servers. Deno will remain open source and receive monthly bug-fix and security releases for another year before the company ends runtime development, Deno Deploy will keep running for six months with migration support for paying customers moving to Cloudflare Workers, and the JSR registry will stay online with its infrastructure moved to Cloudflare.
The Social Web Foundation and its partner the Interledger Foundation opened the Fediverse Multimedia Grants program, offering grants of up to US$20,000 to developer and creator teams that pair ActivityPub software work with new audio, video and image publications on the fediverse. Applications opened on October 7, 2026 and close on November 4, with decisions announced November 18 and projects starting December 1. The foundation says multimedia is hard to develop, host and integrate across ActivityPub services and hard for creators to produce and build an audience around, so the program is meant to fund software better fitted to creators' authoring, editing, organizing and publishing needs while giving creators a permanent home on the fediverse.
Linux Magazine's third article in a five-part series on European-funded open source examines how NGI Zero and European Commission public funding supported more than 70 ActivityPub projects, letting communities assemble their own federated social spaces with tools such as Bonfire and researcher-governed scholarly publishing alternatives rather than depending on commercial platforms.
Meta's Pyrefly Python type checker published a new AI policy and expanded contributing guidelines after coding agents flooded the project with pull requests and issues that take longer to review than to generate. The policy's central tenet is "we want to interact with you, not your AI": it bans LLM-generated communication, autonomous-agent contributions and pull requests not thoroughly reviewed by their human author, and blocks AI from one-shotting issues labeled "good first issue", while still allowing AI for learning, investigation, coding and validation as long as contributors understand and own the result. The maintainers describe a growing backlog of untriaged issues, review-nudge traffic and burnout risk, and argue that issue and PR volume and throughput no longer signal a project's health.
Reuters reports that the Chinese developer behind ARTEX, an open-source autonomous AI penetration-testing agent, has converted the project to closed source and stopped public updates after CrowdStrike and South Korean investigators linked it to intrusions at South Korean banks. The developer, who uses the GitHub handle Autumn-27, wrote in a notice on the now-removed repository that "given the misuse of the tool, the ARTEX project will no longer be updated" and would receive no further public maintenance, while denying responsibility for any illegal use. CrowdStrike attributed the campaign to a China-based suspect who combined ARTEX with Anthropic's Claude Code to automate parts of the intrusion, and at least nine South Korean financial institutions have disclosed or been reported as targets since late September, prompting a police investigation.
The Repository reports that WordPress Executive Director Mary Hubbard emailed the CEOs of more than 30 hosting, plugin and security companies, including GoDaddy, Newfold Digital and Hostinger, asking them to help fund the project's security program, which Automattic has paid for since it launched in April 2017. Hubbard wrote that AI had "collapsed the cost of finding, reporting, and exploiting vulnerabilities" and that the program received nearly 2,000 reports in the past 90 days, more than at any point in its history; WordPress's HackerOne page shows 2,004 reports and more than $90,000 in bounties paid in that quarter out of just over $200,000 paid since 2017. She asked for contributions to a common bounty pool or sponsorship of triage and release work, warning that one company cannot carry the cost alone.
A new project, WhoFundsOSS, publishes a monthly public record of how much money companies have publicly pledged or donated to open source, counting only published figures and treating hidden amounts as zero rather than estimates. Its October 2026 snapshot ranks 200 companies out of 844 tracked, with Posit leading at $762,400, mostly its 2025 Open Source Pledge, Sentry second at $750,000 and CodeRabbit third at $602,600 across 105 named projects, drawing on sources including the Open Source Pledge, Open Collective, GitHub, and companies' own programs.
OpenGrants analyzes how the word "open" carries two different meanings in funding listings: a licensing condition applicants accept to receive money versus the open deliverable they are paid to produce, with the first costing rights and the second not. Using the UNICEF Venture Fund as an example of up to $100,000 in equity-free funding plus a year of mentoring for for-profit companies in programme countries with open source prototypes, it notes the record requires named licence families by output type, OSI-approved licences for software, CERN, MIT or TAPR for hardware, and CC-BY for design and content, making a plan built on proprietary code ineligible rather than merely weak regardless of mission fit.
TFiR interviews John Mertic, director of program management at the Linux Foundation and the Open Mainframe Project, about a new infrastructure program that gives qualifying open source projects access to real IBM Z, z/OS and cloud-native mainframe environments for development, testing and education. The program addresses a long-standing gap in which mainframe hardware was too expensive and often air-gapped for most contributors to reach, leaving only a handful of specialist companies able to do porting and testing work; Mertic says the project has fielded questions about hardware access since its founding event at LinuxCon Toronto in 2015.
The Repository reports that Magistrate Judge Ajay Krishnan said at a hearing on WP Engine's spoliation motion that he is inclined to deny its bid to sanction Automattic and Matt Mullenweg over messages it alleges were destroyed, calling Mullenweg's September 2024 post inviting contact via Signal with disappearing messages "admittedly problematic" while saying the rest of the record did not support a finding of spoliation. WP Engine alleges Mullenweg's WhatsApp and Signal messages were not captured until 20 months after Automattic's duty to preserve evidence began and wants the jury instructed to presume the lost messages supported its claims, while Automattic argues WP Engine cannot identify a single missing message. The remarks mark a shift in tone from April, when Krishnan ordered Mullenweg to explain the missing messages under oath.
Phoronix reports that Sasha Levin of NVIDIA proposed adding AI agent resources to the upstream Linux kernel, starting with a skill that lets LLM coding assistants automatically add a "Fixes: " tag identifying the first problematic commit a patch fixes. The resources would live in a new agents/ directory at the root of the kernel source tree, or possibly under the existing documentation directory, and would collect skills, prompts and other material for coding assistants, referenced by the kernel's existing AI and generated-content documentation. Levin has worked on other kernel AI initiatives including proposing AGENTS.md, AI-powered merge conflict resolution and AI-assisted selection of patches for backporting.
Forrester principal analyst Dario Maisto argues that the message of Open Source Summit Europe 2026 was that organisations and governments which merely consume open source remain dependent on others to shape their future, while those that govern, maintain, secure and sustain the ecosystems gain influence, resilience, sovereignty and strategic leverage. He writes that open source has become critical infrastructure underpinning cloud platforms, AI systems, cybersecurity tools and digital public services while many projects still depend on small groups of maintainers facing growing security, vulnerability-management, compliance and community pressure, and that maintainer sustainability and documentation emerged as recurring concerns. Maisto cites the summit's four-stage sovereignty framework of integrity, resilience, continuity and interdependency, and the statistic that Europe contributes roughly 40 percent of open source activity while remaining underrepresented in governance and leadership, arguing that contribution without governance creates a gap because governance determines project direction, funding priorities, security investment and long-term roadmaps.
The Stack reports from the Linux Foundation's Open Source Summit in Prague, where BBC senior principal software engineer Tom Sadler described the broadcaster's fork of dash.js, the JavaScript implementation for playing DASH (Dynamic Adaptive Streaming over HTTP) content in browser-based environments, used by the BBC for streaming on its websites and connected-TV apps. Sadler said the BBC has used open source since it went online and has opened at least 85 projects built by its tech team, but that its particular requirements make it harder to contribute back, and he described the fork as one that is meant to be kept up to date with mainline rather than a divergence or a competitive or hostile fork. The talk covered the organisation's approach to maintaining the fork and the legal challenges of upstreaming its code.
The EDGE AI Foundation announced three new working groups and a strategic partnership with LF Edge, the Linux Foundation's vendor-neutral umbrella for distributed edge computing. The Physical AI / Robotics Working Group, led by NXP Semiconductors with representatives from AWS, Arduino, Analog Devices, DeepX and Johns Hopkins University, will define frameworks for autonomous systems to operate safely and effectively in human environments; a Security Working Group led by Exein and Dell will define best practices and architectures for protecting edge AI models, data pipelines and end-user privacy at the point of action; and an Interoperability & Standards Working Group led by STMicroelectronics and NXP will work on common protocols, benchmarks and standards across edge hardware and software ecosystems. Under the LF Edge partnership the two organisations will align LF Edge's open-source reference projects with the Foundation's working groups to produce repeatable reference architectures, with foundation CEO Pete Bernard and Linux Foundation general manager Arpit Joshipura framing the work as accelerating secure, scalable and interoperable edge AI deployments.
FOSS Force's Christine Hall reports that the Rocky Enterprise Software Foundation forked the discontinued OpenRadioss finite element solver as OpenCourant after Siemens pulled the project's code from GitHub in an apparent attempt to make it hard to fork, keeping the fork under the GNU AGPL v3. Brian Clemens announced the fork the same day Phoronix reported the shutdown, and the project recovered a proprietary input-reader library that was never kept in git after a community member came forward with an archived package that was verified against an independently recovered binary, restoring builds for Linux x86-64, Linux arm64 and Windows x86-64, though one reader function remains missing on every platform and the team is asking anyone with an August or September 2026 OpenRadioss package to check.
The Verge reports that SpaceXAI is joining the Omacom Foundation, which oversees David Heinemeier Hansson's Arch-based Omarchy Linux distribution, as a Founding Corporate Patron and donating $1.5 million worth of Grok tokens to the project. According to Hansson's blog post announcing the partnership, the tokens will primarily be used to accelerate development, review code and patch bugs. The Verge frames the move as aligning two controversial tech leaders and notes that 1Password and Cloudflare previously drew criticism for contributing to Omarchy over Hansson's political writing.
FOSS Force reports that IBM and Red Hat's AI-driven Lightwell platform identified and remediated more than 400 previously unknown vulnerabilities in popular Java libraries, a figure that rose from 300 in the embargoed draft to 400 by the final release. The announcement accompanied general availability of Clearinghouse, the part of the platform that lets users submit open source dependencies for review and remediation, previously restricted to financial services, while the other half, Network, offers Red Hat-rebuilt and signed secure package repositories. Lightwell VP and GM Gunnar Hellekson said AI agents shifted the threat landscape overnight and exploit old dependencies at machine speed, and Red Hat said applicable fixes are contributed back upstream under responsible disclosure protocols.
Anthropic launched the Anthropic Cyber Mission, a long-term commitment to help defenders secure software and systems, through which it says it will deploy engineering talent and provide tools and funding for those securing critical infrastructure and open-source software. It introduced the Critical Infrastructure Defense Program with founding partners including Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation, and for open source it launched OSS Scanner, an opt-in service inspired by Google's OSS-Fuzz that sends enrolled projects periodic free scans from Anthropic's most capable models with proof-of-concept exploits, explanations and suggested fixes, though the reports are model-generated without human review and expected to exceed 90 percent true positives. Anthropic said it funded the organizations behind widely used open-source code, including the Python Software Foundation, Alpha-Omega and OpenSSF through the Linux Foundation, and the Apache Software Foundation, plus Akrites and Gold Eagle, and launched the Defender Advantage Fund (0xDAF) in August to keep OSS Scanner free. Maintainers can also apply for free Claude Max subscriptions through Claude for Open Source and for expanded access via the Cyber Verification Program.
The OCUDU Ecosystem Foundation, hosted by the Linux Foundation, announced the OCUDU 26.10 release of its open source RAN CU/DU platform, adding 3GPP Release 17 non-terrestrial network support for 5G satellite connectivity, O-RAN Split 7.2b, 8T8R MIMO with enhanced beamforming and multi-beam operation, native 5G positioning, and security and latency improvements such as continuous fuzz testing, OSS-Fuzz participation and DTLS signaling encryption. The Linux Foundation says the foundation has welcomed 95 new members and doubled the technical project's active contributor count since launching, with participating organizations expanding tenfold, and it will co-host the OCUDU Ecosystem Developer Summit with Virginia Tech and the Commonwealth Cyber Initiative on October 20-22 in Alexandria, Virginia.
LWN reports on a Kangrejos 2026 talk by Tomáš Šedovič, a program manager at the Rust Foundation who co-leads the project's goals team, describing how the Rust project organizes, tracks, and amends its goals. The overview was aimed at helping Rust for Linux developers understand how goals are set and maintained and how contributors who take one on get the support they need, and notes that Rust for Linux has inspired several current project goals.
heise online reports on an opinion piece by Eric S. Raymond, co-founder of the Open Source Initiative, arguing that large language models spell the end of closed-source software. Raymond contends that AI-assisted decompilation and reimplementation remove the protection secrecy once provided, leaving only patents and software-as-a-service as viable moats, and predicts a hard collapse rather than gradual erosion, with at most niche survivors such as tax software whose value lies in continuously updated rules rather than code. He bases the claim on a personal experiment in which an AI assistant decompiled the DOS shareware game Firefighter and translated it into Rust for his Heritage Games Collection, saying the model inferred Borland Pascal from the data layout and produced readable code. On legality, he points to a US path modelled on Phoenix Technologies' clean-room IBM PC BIOS work, where someone converts a binary into a specification and generates new code without looking at the decompiled output, now achievable in about a day. The article notes that security researchers take a more nuanced view, that obfuscation is cheaper to defeat but not worthless and that code signing and secure boot prevent modified code from running but not from being read, and that Raymond expects reverse engineering to expose long-hidden intellectual-property disputes.
How-To Geek surveys the intensifying dispute inside KDE over what role, if any, AI should play, as a flood of generated contributions consumes maintainer time. It recounts KWin developer Vlad Zahorodnii's mailing-list post 'How to deal with fully LLM-generated merge requests', which complains about verbose replies that arrive impossibly quickly, compares the influx to a DDoS attack and suggests simply closing obviously LLM-generated requests. It details contributor Nate Graham's proposed policy, built on a human-in-the-loop principle that requires a person to make the decisions and the result to be functionally indistinguishable from unaided work, permitting LLMs for drafting and bug-finding so long as a human verifies and tests the output and allowing machine translation of one's own words, while prohibiting copy-pasted output the submitter does not understand. The article notes the practical difficulty of detecting LLM use, community objections that generated code may be plagiarised and incompatible with KDE's licences, KDE Eco's concerns about AI energy and water use, the strict no-AI 'KDE for the People' campaign, and an Akademy proposal for an AI-native KDE with a Kadai integration offering local AI, other models or none, concluding that the fight may split the project into pro- and anti-AI factions.
GamingOnLinux reports that Flathub has largely walked back the near-total ban on generative AI it introduced in May 2026, replacing it with a disclosure regime first amended on September 4. Submitters must disclose any AI-generated code, documentation, packaging or other material they know or reasonably believe is included in an application or its Flathub packaging, identifying the affected parts and approximate extent, while Flathub manifests must not contain AI-generated or AI-assisted content and disclosure does not exempt a submission from that rule. AI used only for research, discussion or debugging need not be disclosed when no generated material ships, other disclosed material is evaluated at reviewer discretion, and reviewers may reject a submission without further review over concerns about its review, quality or maintainability. AI tools or agents are barred from opening or automating Flathub submission pull requests or generating their commit messages, descriptions, review comments or replies, and submitters may not request AI-agent reviews; undisclosed or misrepresented material may be rejected. The article notes that leaving decisions to reviewers could produce inconsistent outcomes, with one app approved and another rejected.
The Register reports that ArtCraft has added WordCraft, plus Excel and PowerPoint counterparts, to its growing collection of Rust applications it describes as 'clean-room reimplementations' of proprietary software, built heavily with Claude and dual-licensed under MIT or Apache 2.0. WordCraft is at a pre-alpha stage the company estimates at 62 percent feature parity, with DOCX compatibility testing not yet begun and charts, SmartArt and embedded OLE objects dropped, and ArtCraft's repositories also model Photoshop, Illustrator and Premiere Pro. ArtCraft says the apps were built from public specifications and observation using original or openly licensed assets; the Document Foundation behind LibreOffice declined to comment and Microsoft and Adobe gave no substantive response, while lawyer Neil Brown told the paper the legal position would depend on jurisdiction and that an independent reimplementation may be non-infringing, though a deep-pocketed aggrieved party with a lot to lose could make litigation likely.
Dan Cohen marks the twentieth anniversary of Zotero's launch with an account of how the open source research tool took five years of collaboration among historians at George Mason University's Center for History and New Media before its first beta appeared, arguing that the slow, communal way it was conceived produced durable software rather than the ephemeral output AI can now generate instantly. He traces the project's origins in earlier tools like Scribe and Web Scrapbook and a naming process that ended with an Albanian dictionary and a lawyer's warning against 'Firefox Scholar', and notes the launch drew 60,000 users within a month, with additional funding from the Mellon and Alfred P. Sloan foundations later paying for syncing and for independence from the Firefox browser. Zotero is now maintained by the non-profit Corporation for Digital Scholarship.
Open Source Initiative executive director Duane O'Brien represented the OSI at the 81st UN General Assembly, speaking on a UN Digital Cooperation Day panel about defining Open Source AI and joining a Creative Commons symposium on openness and digital sovereignty, where he summed up the organization's position as 'Open by itself does very little but enables a lot'. He described the Open Source AI Definition as the product of two years of workshops in 18 countries and said the OSI will soon reopen conversations about it, and noted that the G7's Vision on AI Openness, which the OSI helped draft, now calls for releasing the training data developers can share and accurately describing what they cannot. The OSI also attended the inaugural 50-in-5 Awards for digital public infrastructure, stressing that software qualifies as a digital public good only if it carries an OSI-approved license, and O'Brien argued that open alternatives need decades of sustained investment to flourish.
Phoronix reports on Google engineer Roman Gushchin's status update at the Linux Plumbers Conference on Sashiko, the Google-built agentic code review system for the Linux kernel. In less than a year the open source tool, which works with Google's Gemini and other LLMs, has completed more than 191,000 patch reviews across 99 mailing lists, performed over 19 million autonomous git lookups, and drawn more than 7,600 replies from over 1,100 kernel developers. More than 1,277 upstream kernel commits this year cite Sashiko, along with 1,567 in linux-next, and 463 CVEs so far this year reference it. Google engineers are now working on a local terminal review mode, a persistent bug database, and self-review for Sashiko.
Its FOSS reports that several long-standing sponsors of Gentoo's infrastructure have stopped contributing, leaving the source-based Linux distribution asking for replacements because it runs largely on donated hardware and hosting and keeps only a few machines of its own. Gentoo's wiki lists five ways to help: donated machines for its US hosting sites, colocation with rack space, power and connectivity, virtual machines with at least 2 vCPUs, 4GB of RAM and 25GB of storage, fully hosted physical servers, or money to cover colocation and hosting; capacity outside the US is described as the most urgent need. The article notes the sponsors page still lists Oregon State University's Open Source Lab, CDN77, HP and Hetzner, and contrasts Gentoo's shortfall with LVFS, whose firmware update service now draws Premier-tier support of $100,000 a year each from Lenovo and Dell alongside backing from Framework, the Open Source Firmware Foundation, the Linux Foundation, Red Hat, HP and NVIDIA.
Diginomica reports from the opening day of Open Source Summit Europe in Prague, where Linux Foundation Europe GM Thierry Carrez noted that European contributors account for 38% of the code across the Linux Foundation's 620 projects (44% of the Linux kernel, 35% of Kubernetes, over 50% of Zephyr) but supply only 15% of foundation funding and take part in governance at just 37% of the rate they contribute code. Carrez drew a line between "public source", where code is merely visible, and genuine open source control that requires the familiarity to understand, operate and if necessary fork a project, warning that US and Asian firms already treat openly governed open source as a strategic investment. CNCF executive director Jonathan Bryce added that who operates the code matters as much as who writes it, citing OVH's push for "open operations" alongside open source.
EdTech Innovation Hub reports that Renaissance Philanthropy and XTX Markets have added $17.1 million to the AI for Math Fund, taking total commitments to $35.1 million. The 2026 Core Grants round was expected to hand out $10.5 million but was expanded after more than 470 applications, and will fund 22 proposals across 30 organizations with grants of $100,000 to $1 million over 12 to 24 months. Funded work includes AI-assisted theorem proving, research infrastructure and datasets, and open-source tooling such as TorchLean, which connects machine learning to the Lean proof checker, plus a browser-based visual proof environment for inspecting and editing long formal proofs.
Data Drop at sheets.works visualises who actually maintains 23 pieces of software that phones, browsers and servers depend on, counting everyone who made ten or more changes to each project between October 2025 and October 2026 and then checking which of those libraries ship on an Android phone, an iPhone and a Windows PC. It finds that 11 of the 23 projects had only one or two people doing the regular work, and sets that against what they are paid: Lasse Collin wrote 97 percent of xz changes in 2025 after years of unpaid hobby work that preceded the Jia Tan backdoor, core-js author Denis Pushkarev raised $57 a month and has two GitHub sponsors, Todd Miller has maintained sudo since the early 1990s and reached about $61,700 a year on Open Collective only after asking for a sponsor in February 2026, Daniel Stenberg's curl takes in about $89,700 a year plus 195,000 euros from Germany's Sovereign Tech Agency, and zlib's Mark Adler and libxml2 have no public funding at all. The piece also contrasts OpenSSL's $5.4 million from the Linux Foundation after Heartbleed with the absence of new money after the xz backdoor, and notes that Germany's Sovereign Tech Agency has funded about 90 open source projects since 2022 while Alpha-Omega gave out nearly $6 million last year.
FOSS United published the results of its 2026 Governing Board elections, held alongside IndiaFOSS 2026, after three members of the inaugural board stepped down and ten candidates stood for the three open seats. About 1,131 people took part out of roughly 25,000 eligible voters, with 985 casting votes and about 146 abstaining; the foundation used the STAR voting method and the Better Voting platform. The new members are Dr. Mohit P. Tahiliani, an associate professor at NIT Karnataka and member of the ns-3 steering council who says he wants to help students become long-term contributors and unlock funding for FOSS projects, Ashutosh Pandey, a compiler engineer and longtime community organiser, and Ramya Ragupathy, who works on humanitarian tech and with non-profits in the FOSS4G space. They join sitting board members Bodhish Thomas and Bowarna.
The Hindu reports that Telangana's MeeSeva citizen-services platform moved its backend from Oracle to open-source PostgreSQL in April 2026, cutting a large share of licensing costs for a system that handles millions of government transactions. The article details the technical and administrative hurdles of shifting a mission-critical public service off proprietary software, and argues the case could push other governments to reconsider how much they spend on closed-source database and application licences.
Phoronix reports that Claude Code and AI agents have produced "open-source, clean-room reimplementation" versions of Adobe Photoshop, Premiere and Lightroom under the ArtCraft project, written in Rust. Photocraft reimplements Photoshop, Filmcraft reimplements Premiere for video editing and Lightcraft reimplements Lightroom, and readers pointed Phoronix to the releases, which debuted the week before with several rapid updates attributed to AI-assisted iteration. The apps ship as native binaries for Linux, FreeBSD, macOS and Windows, with code on GitHub and more at getartcraft.com, and Phoronix framed them as a demonstrator of AI's power and as potentially pressing legal challenges.
Time Extension interviews Synamax, a game historian and developer who has worked since February on a decompilation and recompilation of the 1999 N64 racer Beetle Adventure Racing with a group of volunteers, after a 'low-quality vibe-coded' recomp was produced from their work without consent. Synamax argues an ethical reverse-engineering community would recognise another person's project rather than take and 'finish' it with generative AI, saying the episode is insulting and hurtful after years of unpaid preservation work. The piece also covers Banjo Kazooie Recompiled developer Dariosamo criticising a YouTuber for promoting a Banjo Tooie AI recomp without disclosing that it was unrelated to the human-made tooling behind the original port.
TechSpot reports that Dario, a lead contributor to a Banjo-Kazooie PC port, published a lengthy critique of the growing use of LLMs to decompile, recompile and port retro games, arguing the practice produces verbose, hard-to-audit code from developers with little knowledge of the games and is displacing the human reverse-engineering work that makes the ports possible. He also disputes that AI saves time. TechSpot notes that the HarbourMasters team behind well-known ports of Super Mario 64, Mario Kart 64, Star Fox 64 and the Zelda games was revealed to have used LLMs for years, and that AI-assisted recompilations of titles such as Banjo Tooie and Beetle Adventure Racing have angered developers whose work was reused without their knowledge.
Kotaku reports that a PlayStation homebrew developer using the handle Zer0Day published an AI-generated reverse-engineered copy of GoldHEN, the closed-source PS4 homebrew enabler maintained by Sistro and a small team over about five years, and defended it in a GitHub README and on X by arguing that 'code should not be a cage' and that 'creativity should never have to ask for permission'. Sistro has said the GoldHEN source stays private because it has been abused before, and contributor Pharaoh2k said the rip-off copies years of unpaid work on a fully copyrighted, actively maintained project. Kotaku ties the dispute to wider turmoil in the PlayStation scene, citing roughly 1,840 GitHub forks of the young PS5 emulators KytyPS5, SharpEmu and AnyPS5, up from about 1,300 three days earlier, as evidence of a wave of vibe-coded projects.
Ars Technica reports that software developer Brandon Thomas, whose Artcraft brand began as a controllable AI image editor, has pivoted to a suite of seven open source apps recreating the interfaces and tools of Adobe Photoshop, Illustrator, Premiere, Lightroom, After Effects, InDesign and Acrobat Pro. Thomas said he used Anthropic's Claude Opus 5.5 to build the clean-room replacements in Rust, with WebAssembly builds for the browser, and released the apps under MIT and Apache licenses. He told Reddit and Hacker News that development of the free apps would be funded by selling token-based access to the underlying Artcraft visual AI model and IDE, which appears inside the apps alongside third-party models, arguing that revenue stream keeps the project from becoming 'some orphaned small-team project'. Commenters on Hacker News highlighted the early alpha's shortcomings, and Thomas walked back an initial claim of reaching 100 percent feature parity within a month to say 99 percent parity would take months rather than years. Ars noted that while reverse engineering functionality without copying code has generally been found legally acceptable, the clones could face legal trouble if their trade dress too closely mimics Adobe's interfaces, and that Thomas has since February coded exclusively with AI tools and predicts a near future of open source 1:1 equivalents of popular paid software.
Percona announced Valkey-proxy, a new open source project now accepted as an official Valkey project, aimed at making it easier for enterprises to move from Redis to the Linux Foundation-backed fork. The code is due to be released later in October and the project is targeting general availability in 2027 under the BSD-3-Clause licence, sitting between an application and a Valkey deployment so software written for a single standalone instance keeps working while gaining the scalability of cluster mode, and pooling backend connections so connection counts stay bounded. Percona's Redis/Valkey general manager Kyle Davis told The Stack at Open Source Summit Europe in Prague that without a standard open source proxy many enterprises cannot migrate, leaving them on commercial Redis, which is expensive to license and run, or on a cloud provider's proprietary, platform-tied proxy, and described the work as addressing an 'original sin' inherited from Redis that made it hard to scale on top of the data store.
The Register reports on a survey of 269 executives, managers and professionals at VMware customer organisations, conducted by Unisphere Research between December 2025 and February 2026 and commissioned by third-party support provider Rimini Street, in which nine in 10 respondents said higher licensing costs were prompting them to consider alternatives and 54 percent cited the end of perpetual-license support as a reason to evaluate other options. The survey also found that 48 percent had no plans to move workloads to Broadcom's preferred VMware Cloud Foundation subscription platform, adding to the pressure Broadcom faces as customers weigh lower-cost alternatives and open source virtualisation and cloud stacks.
TIER IV won a grant from Japan's Ministry of Economy, Trade and Industry to run autonomous bus trials in Saudi Arabia and adapt its open source autonomous-driving software, Autoware, to desert conditions and right-hand traffic. The award comes under a METI programme for joint technology projects in the Global South and will also fund local talent schemes, as Saudi Arabia aims for 15 percent of its public transport to be autonomous by 2030. Automotive World said that target gives TIER IV a market large enough to justify retraining its system for local roads.
Thierry Carrez, general manager of Linux Foundation Europe, told The Stack at Open Source Summit Europe in Prague that European companies need to contribute more resources to the open source projects they depend on, arguing the continent is not strategically investing in the governance of the ecosystems it relies on and risks leaving them dominated by US and Chinese companies. He pointed to the foundation's 2026 State of Open Source in Europe report, which found that 59 percent of European organisations surveyed contributed code upstream but only 37 percent took part in project governance, and said around 38 percent of contributions to Linux Foundation projects came from Europe while only 15 percent of governance activity did. Carrez framed the gap as a digital-sovereignty problem: contributing code without sharing responsibility for maintenance, security and direction does not give European organisations real control over the technology, even as governments adopt open source alternatives to products such as Microsoft Office.
OpenSSH 10.6 was released, and FOSS Force highlights the note that longtime maintainer Damien Miller attached to the announcement on the openssh-unix-announce mailing list: the project has received a large number of security bug reports that are AI findings or were made with AI assistance, and while many have no security impact under a realistic threat model, the team very much welcomes them, especially when combined with human triage, analysis, test cases and proposed fixes. The stance contrasts with other projects that have complained about floods of AI-generated vulnerability reports. FOSS Force counts 11 security fixes in the release alongside many bugfixes and about a dozen new features, including extending the WarnWeakCrypto option from the client to both sides so it is on by default and logs whenever a key agreement scheme is not post-quantum safe, and a new restriction that disallows the dollar sign and backslash in usernames entered on the command line to avoid mischief from untrusted sources, which does not affect usernames set in configuration files.
The Register reports on the backlash to Ruby on Rails creator David Heinemeier Hansson's benchmark comparing agent-written rewrites of his company's Campfire chat app in Elixir, Go and Rust against the original Rails version. His chart showed Rust well ahead across five tasks, but critics argued the Rust port received far more post-generation tuning than the one-shot Go and Elixir implementations, and some rewrote the Elixir code to match or beat Rust, leading Google engineer Jaana Dogan and others to call the measurement flawed. DHH, who told Rails World 2026 that AI has all but eliminated the need to hand-write code, responded that agents can only use the go-fast switches they find and that language choice involves more than raw speed. The episode underlined that AI-generated work still needs review rather than trust.
The Cloud Native Computing Foundation announced at Open Source Summit Europe that OVHcloud has upgraded to a Platinum Member, extending a decade-plus record of open infrastructure work as cloud native and AI infrastructure converge on vendor-neutral standards. CNCF noted that OVHcloud has built on OpenStack since 2012 and joined the OpenStack Foundation in 2014, contributed an independently developed Kubernetes Operator to the graduated Harbor registry project in 2020 and joined as a maintainer, and in March 2026 had its AI Deploy and Managed Kubernetes Service approved through the CNCF Kubernetes AI Conformance Program. Executive director Jonathan Bryce credited that upstream engineering, while founder and CEO Octave Klaba said independence means the freedom to build on open standards and contribute to the technologies a company relies on rather than being locked into one ecosystem. CNCF cited a Gartner forecast that European sovereign cloud spending will reach 12.6 billion dollars in 2026.
The CNCF Technical Oversight Committee voted to accept Meshery as a CNCF incubating project. Meshery is an open source, cloud native management plane for designing, visualizing and operating Kubernetes-based infrastructure across clouds, created by Lee Calcote and the team at Layer5 in 2019 and accepted as a sandbox project on June 22, 2021. CNCF says Meshery has become the fifth highest-velocity project in the foundation, with a 350 percent increase in code commits over the year from July 1, 2025 to July 1, 2026 and the general availability of Meshery v1.0, and it now reports more than 7,000 contributors and 1,000 contributing organizations, a 36.6 percent year-over-year rise in active contributors, almost 15,000 GitHub stars and an LFX Insights software value of 393 million dollars. TOC sponsor Karena Angell credited the project's extensible model-based architecture, and the roadmap covers multi-cluster and fleet management with Kubernetes RBAC integration, a Meshery MCP Server for AI-assisted read-only access to registry and cluster state, distributed performance testing, and a more governed registry and workflow engine.
Docsy, an open source theme for the Hugo static site generator used to build technical documentation sites, is joining the Linux Foundation. Erin McKean, a senior developer relations engineer at Google and a member of the Docsy steering committee, announced the move in a keynote at the Linux Foundation's Open Source Summit Europe in Prague. Google first announced Docsy in 2019, and by the end of 2024 about 2,200 projects were using it, including Kubernetes, OpenTelemetry, gRPC and Jaeger under the Cloud Native Computing Foundation. McKean said the move brings the project closer to the communities already using it, and focused on AI agents as a new consumer of technical documentation. Docsy has added opt-in, experimental features to serve them, including a Markdown copy of each page and an llms.txt index introduced in version 0.15.0 in May, an upgrade guide written so it could also be followed by an AI assistant in version 0.16.0 in July, and a hidden directive pointing visiting agents to a site's llms.txt index in version 0.17.0 in August. The roadmap includes agent-friendly documentation scores so maintainers can measure how easily AI tools find, navigate and consume their docs, which McKean said should also reduce the routine questions that land on maintainers.
Beelzebub, the company behind the GPLv3-licensed open source deception and honeypot framework of the same name, raised a EUR 3 million seed round led exclusively by Italian deep tech investor United Ventures, bringing total funding to about EUR 3.3 million after an earlier EUR 300,000 pre-seed. The Milan-based company said the capital will fund research hiring and international sales expansion, including offices in Rome and San Francisco by the end of the year, targeting essential-infrastructure operators regulated under the EU's NIS2 directive. The platform follows an assumed-breach approach, pairing an Arcangelo red-team layer that simulates AI-driven attacks with LLM-based decoys that imitate servers, databases, APIs, cloud infrastructure and operational technology devices so attackers already inside a network are drawn into an isolated environment and analyzed. Beelzebub began in 2021 as an open source research project by security researcher Mario Candela, with more than 60 independent researchers feeding live threat intelligence, and was incorporated as a company in July 2025.
Google announced on 1 October 2026 that it is temporarily closing the product vulnerability side of its Open Source Software Vulnerability Reward Program, which since 2022 had paid outside researchers for security flaws in the company's open source code including Flutter, Angular, Go and Fuchsia. It's FOSS reports that supply chain reports, which cover how software is built and shipped, remain open, submissions made before 1 October are unaffected, and some Google Cloud repositories may still be reported through the Cloud VRP. Google engineers wrote in March that AI-generated reports were flooding the program with hallucinated findings and legitimate but low-impact coding errors, and the company first tightened memory corruption requirements and then stopped offering rewards or credit for product vulnerabilities in its OT2 and OT3 tiers, while cutting the top supply chain reward for OT2 projects to 3,133.70 dollars. Supply chain reports still pay from 500 dollars on OT2 projects up to 31,337 dollars on flagship ones, and Google pointed researchers to its Patch Rewards Program, which pays 100 to 15,000 dollars for patches that survive a month without being reverted. The company said it would update on the program in the first quarter of 2027.
The Register reports that System76 has added an explicit no-AI rule to the COSMIC desktop contributor guidelines, requiring contributors to declare that a pull request contains no LLM-generated code, comments or descriptions, and notes that GNOME Calendar and GNOME Extensions already restrict AI-generated submissions while still permitting AI learning aids and code completion. The article contrasts that position with GNOME developer Michael Catanzaro's call for the project to accept AI-generated bug reports, arguing that developers will keep failing to write secure code in memory-unsafe languages such as C, C++ and Vala, and points to his earlier posts urging against a ban on AI-assisted issue reports and to his reduction of GNOME Security's disclosure deadline from 90 days to 30. It frames the debate as a question of where projects draw the line as AI-assisted reports, triage and fixes spread, noting similar controversies in KDE and decisions to allow AI contributions in Debian and the Linux kernel.
Computing infrastructure provider xFusion joined the Linux Foundation, saying it will contribute open benchmarks, reference architectures and operational practices for enterprise AI infrastructure. The company anchors the work in its Singapore Open Lab, a neutral hub for evaluating AI hardware, foundation models and platforms, and says it is developing an open framework for AI Infrastructure Efficiency and Intelligence covering observability, benchmarking and efficiency measurement across heterogeneous AI environments. Aitra, an open reference platform incubating under the SODA Foundation, is described as one of the first implementations. xFusion said it will contribute code and expertise to Linux Foundation projects and working groups and continue developing Aitra under SODA Foundation governance, building on earlier collaboration with the foundation.
At Open Source Summit Europe, the Fintech Open Source Foundation announced that the Open Source Enterprise Resiliency Alliance is operational with initial funding from six Premier members, including Deutsche Bank, Goldman Sachs, Morgan Stanley, NatWest and RBC. The Linux Foundation vertical said OSERA, announced as an intent to form in June, has published a first version of a patching and attestation standard and delivered attested secure package updates across more than 50 widely used Java and Spring ecosystem projects. The alliance argues that banks running similar open source stacks duplicate work when they each fix the same vulnerabilities, citing research that one in five financial institutions maintain private versions of the same projects, a fork tax that raises cost and risk. Its source code is public, governance is member-led under the Linux Foundation and its standards are open, and it frames the work as complementary to commercial and community support models as regulations such as DORA, NIS2 and the EU Cyber Resilience Act raise expectations for vulnerability management.
The Linux Foundation published version 1.0 of the OpenChain Automotive Software Bill of Materials Framework, a standard approach for describing and exchanging software component data across the automotive supply chain. The framework sets out a structure for automotive SBOMs, guidance on required and recommended fields with completeness and quality criteria, alignment with SPDX (ISO/IEC 5962) and usage scenarios for suppliers and OEMs, without replacing existing standards. OpenChain general manager Mary Meixia Wang said software-defined vehicles make transparency and traceability across components essential, and the effort grew out of early work by contributors from Toyota, Hitachi Solutions and the OpenChain Automotive Working Group. The project is open to participation and will evolve based on industry feedback and adoption.
The Linux Foundation announced OpenGrid, a new initiative hosted by the foundation that aims to build open data and interoperability infrastructure for power grid planning. Rather than replacing existing planning software, OpenGrid provides a shared layer of open standards and schemas, programmatic APIs and a Data Hub of validated, model-ready datasets so commercial and open source tools can work together, with a first lighthouse application called the OpenGrid Translator planned for release in 2027. The foundation cited more than 2,500 gigawatts of generation and storage projects stuck in grid connection queues and the need to more than double annual grid investment past 600 billion dollars by 2030, arguing that fragmented data and incompatible, costly modeling tools shut many institutions out of planning. Chair Alice Yake of Breakthrough Energy GRIDS said too many plans currently rely on data others cannot verify and tools much of the world cannot afford, and the foundation says it will expand the ecosystem over time to include open solvers, no-code interfaces and AI-assisted data preparation.
The Linux Foundation, LF Europe, LF Research and NeoNephos released the fifth annual 2026 State of Open Source in Europe report at Open Source Summit Europe, finding that 94 percent of European organizations consider digital sovereignty important, including 61 percent who call it very important, with security and privacy the leading drivers. Organizations with advanced open source governance reported an average return of more than four times their investment, against 3.6 times for those without formal governance, and European developers account for nearly 40 percent of contributions to foundational projects such as Kubernetes and OpenStack. The report also documents strain: 94 percent use or pilot generative AI coding tools, 48 percent maintain private forks, and those maintaining forks report spending an average of 311 hours per release cycle patching 9.5 forks while 28 percent cannot track that cost at all. It says 31 percent of European organizations still lack a formal open source governance framework, and LF Europe general manager Thierry Carrez argued that consuming open source without contributing upstream does not give organizations effective control over the technology.
The Linux Foundation announced at Open Source Summit Europe in Prague that Amazon Web Services has become a Platinum Member, its highest level of membership, giving AWS representation on the foundation's board of directors. The release frames the step as an expansion of more than a decade of AWS participation, noting that AWS transferred OpenSearch into the OpenSearch Software Foundation in 2024 and is a founding member of the Akrites initiative and the Agentic AI Foundation. AWS now holds active memberships in 25 Linux Foundation projects and foundations, is a Platinum Member of the Agentic AI Foundation, CNCF, the PyTorch Foundation and the Yocto Project, and is a premier member of groups including the Academy Software Foundation, Alpha-Omega, the FinOps Foundation, the Jupyter Foundation, OpenSSF, the Post-Quantum Cryptography Alliance, Valkey and the x402 Foundation. CEO Jim Zemlin said sustaining open source requires long-term investment from the companies that build on it, and AWS head of open source Stormy Peters said AWS looks for a neutral home when it builds infrastructure that solves a problem beyond AWS.
Akka published an account of using a spec-driven AI delivery harness to rebuild 65 popular open source projects, including Uptime Kuma, Changedetection.io, Redash, Glance and ActivityWatch, on its own platform in a reported 99.3 hours across an initial tranche at a cost of about 9.41 billion tokens. The company said it selected projects across popular AI frameworks, Go and TypeScript networking libraries and complex software-as-a-service applications, then ran a loop of setup, discovery, porting, benchmarking and improvement in which Claude with Akka Specify handled implementation, testing and review while a common benchmark runner compared behavior, code size and latency. Akka said it licensed the ports under Apache licensing except where GUI interfaces were copied verbatim and kept under the original terms with attribution, and it reported mixed results, with some rebuilds much smaller and faster and others, such as Netflix Metaflow, roughly 100 times slower, while its own harness notes that the workloads compared for the largest claimed speedup differed.
The NetBSD Foundation publishes a Google Summer of Code 2026 report on funded work to modernize racoon2, the project's IKEv1/IKEv2 key-exchange and IPsec policy daemon, as it is prepared to serve as an L2TP/IPsec or IKEv2 VPN server for built-in Windows, iOS and Android VPN clients. Student Artem Belan implemented RFC 7383 IKE fragmentation and RFC 3947 NAT original address handling, added RFC 7296 NAT-T traffic-selector substitution so configurations no longer need workaround selectors, unified the wildcard address macros, fixed IPv6 handling and enabled it by default, corrected policy and proposal negotiation to follow the peer's proposal, and built a dependency-free unit-test framework that runs under sanitizers. All changes were merged upstream through pull requests #13-#39 between June and September 2026, with documentation, samples and a NEWS entry updated to match.
Business Wire reports that Temporal, the open-source durable execution platform that powers agents for OpenAI and Cursor, has brought on the team behind the authorization company Oso to accelerate its work on AI agent security. The goal is to make fine-grained authorization a native part of execution so that identity, access and policy enforcement follow agents as they call tools, act on business-critical data and coordinate work across systems. Temporal co-founder and CEO Samar Abbas said control over an agent's actions and authority must be as fundamental as the reliability and visibility already built into the execution architecture, and the announcement cites research that 96 percent of permissions go unused, arguing that unlike people, agents will not limit themselves and cannot be allowed to set or expand their own authority.
GamesRadar reports that agg23, the developer who ported the SNES FPGA core to the Analogue Pocket, publicly rejected an unrequested contributor patch that added an experimental MSU-1 streaming feature, saying it was a roughly 50,000-line diff that was completely built by an LLM and contained large amounts of unrelated code he would have had to review by hand. The core is one of the open-source openFPGA emulators the handheld supports, and the maintainer said the behavior was not acceptable, that pushing machine-generated work nobody asked for infringes on other people's time and brainpower, and that AI-generated code has no place in his project. The article ties the incident to a broader fight across retro-emulation and open-source projects over low-effort, vibe-coded contributions, noting that the RPCS3 team made a similar plea to stop submitting AI slop code earlier in the year.
Phoronix reports that TrendAI's Zero Day Initiative disclosed twelve more security vulnerabilities in the X.Org Server codebase and XWayland, found with the assistance of AI, extending a long run of disclosures against the display server that a researcher described more than a decade ago as being in even worse shape than it looks. The flaws, present in versions before xorg-server-21.1.25 and xwayland-24.1.14, are mostly use-after-free, heap buffer overflow, out-of-bounds read and write, double free and numeric truncation bugs, spanning XKB, Present, XInput, GLX, XFixes, RandR, Glamor and gesture code.
Neowin reports that the Dutch tax authority, the Belastingdienst, is halting its move to Microsoft 365 and will instead run Microsoft email and calendar services on its own servers next year while it looks for European options for storage and collaboration. The agency is trying to reduce its reliance on Microsoft without cutting the company off entirely, and will keep using tools such as Outlook, after earlier Dutch reporting said the rollout had been paused over a critical report and a EUR 14.4 million bill for the original migration.
ZDNet's Jack Wallen argues that the world depends on open-source software and that more of it deserves to be paid for, revisiting an earlier list of open-source apps he would happily buy and noting how much it has changed over the past year. He picks seven apps he believes justify a price, from Firefox to other desktop and productivity tools, and asks developers who add a fee to make it a one-time purchase rather than a subscription.
The New Stack speaks with Cloud Native Computing Foundation executive director Jonathan Bryce about the feedback loop between AI and open source, noting that OpenAI leaned on Kubernetes and other open source tooling in 2018 because nothing off the shelf could handle its training runs at that scale, and that AI labs have since contributed back so banks, manufacturers and others can build their own AI infrastructure. Bryce says the CNCF has accepted and moved products through its graduation process faster than ever over the past 18 months, in part because it has built agents to help with due diligence at the different stages, and argues that software now has to answer AI queries at agent speed rather than human pace while non-deterministic agents need guardrails. He frames the foundation's KubeCon event in Salt Lake City in November as more important than ever for the community to determine the future of open source amid that acceleration.
The Apache Software Foundation published a progress report on its Responsible AI Initiative, launched in April 2026, whose charter vice president Jeff Genender presented in the August board report and which is framed around human oversight, licensing integrity, security and documentation. The initiative groups its work into access to AI models and tooling, project-level ecosystem support, and community engagement, and it has relied on in-kind donations of frontier model access, including through Anthropic's Project Glasswing program, that let ASF Tooling, Security and Infrastructure teams run full security scans across 75 project management committees and 230 repositories in three days. It is also producing recommendations and guidelines for projects that develop software with AI assistance and for the governance and use of donated funds, compute time and inference tokens. Supporting efforts include LLMAO, metered LLM access for ASF projects and committers without per-project provider keys, the Gofannon agent workbench, agent memory work, Apache Magpie for agent-assisted repository maintainership, and Apache Sourcelume for AI training-data provenance. RAI will present a hackathon and a roundtable at Community Over Code Glasgow on October 12, where participants will discuss AI-driven maintainer challenges such as attracting new committers, preserving meritocracy under The Apache Way, coping with automated vulnerability report floods, and whether AI strengthens or erodes the commons.
Linux Foundation Research and the TODO Group released The 2026 State of OSPOs and Open Source Management, sponsored by CNCF and the FinOps Foundation, alongside Open Source Summit Europe. The report finds open source program offices becoming permanent corporate functions, with 57% staying in the same organizational home for the past two to three years and 53% of large enterprises running a formally structured OSPO, while Asia-Pacific is set to lead the next wave as 20% of organizations there plan an OSPO, double the rate in the Americas and Europe. On AI, 79% of OSPOs involved in AI governance contribute to policy, evaluation of open models and datasets, risk management and legal review, 85% of those in AI decision-making are engaged at or before technology selection, and the top AI risks OSPOs manage are licensing and intellectual property and security vulnerabilities at 65% each, ahead of data privacy at 59%. Agentic AI is already entering operations, with 69% of organizations prototyping or running agentic tools for OSPO workflows and 18% using them in production. Respondents ranked software quality, security and compliance as the most impactful OSPO outcome at 58%, and among organizations planning an OSPO, 79% expect to launch within two years and 66% intend to fund dedicated full-time staff.
Telecompaper reports that digital infrastructure provider Hayo has joined the Linux Foundation and become a member of the CAMARA Project, the Linux Foundation open source effort that defines, develops and tests standardized northbound telco network APIs in collaboration with the GSMA Operator Platform Group. Hayo, which operates CAMARA-aligned APIs for number verification, SIM-swap detection, device location and status, KYC match and quality on demand, said the membership reflects a commitment to open standards and interoperability and that it will work with operators, hyperscalers, CPaaS providers and aggregators to bring standardized network APIs to market across Africa and the Middle East. CEO Feraz Ahmed framed network APIs as a foundation for digital identity, fraud prevention and new operator revenue, and the piece cites IDC's forecast that the worldwide network API market will grow from $1.5 billion in 2025 to $6.9 billion by 2029.
The Eclipse Foundation's Open VSX extension registry added Trusted Publishing so publishers using GitHub Actions can replace a stored personal access token with short-lived credentials: a CI workflow presents a signed identity token, the registry checks it against a registration naming the owner, repository and workflow file, and returns a publishing token that lasts about five minutes and works for one extension only. The model follows OpenSSF's "Trusted Publishers for All Package Repositories" guidance already used by PyPI, npm, RubyGems, NuGet, crates.io and pub.dev, and requires a signed Publisher Agreement, a verified namespace owned by the registrant and an extension with an existing active version, since the first publication still needs a PAT. Registrations match immutable numeric repository and owner IDs while the workflow filename is matched by name, are not tied to a branch or tag so pinning a deployment environment and reviewers is advised, allow only one trusted publisher per extension, and are deleted if their creator stops being a namespace owner. GitLab and self-hosted providers are planned, and the post stresses that whoever can change or run the workflow can still publish, moving the security burden to branch protection, workflow review and environment approvals.