News

Recent funding, licensing, foundation, and monetization news from across open source.

All entries

Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens

Aikido Security reports that codexui-android, a remote web UI for OpenAI Codex with a real GitHub repo and tens of thousands of weekly npm downloads, quietly exfiltrated Codex, OpenAI, GitHub, SSH, and npm credentials from users' environments.

Added: ; Published: ; Source: Aikido

Restack: a new European consortium for a digital Europe

FSFE says it is part of Restack, a Horizon Europe consortium providing legal and licensing support for more than 200 Free Software projects while working to strengthen Europe's digital commons and reduce dependency on proprietary technology.

Added: ; Published: ; Source: Fsfe

ClickHouse triples annualized revenue to $250M, charting a path toward an IPO

TechCrunch reports that ClickHouse has reached a $250 million annualized revenue run rate after a $400 million Series D and $15 billion valuation, describing its open source database monetization through managed cloud services and continued acquisition of complementary open source startups.

Added: ; Published: ; Source: Techcrunch

The PHP Foundation Impact and Transparency Report 2025

The PHP Foundation reports that 536 sponsors and individual donors contributed $730,534 in 2025, funding 11 contracted developers and helping the foundation author roughly 42% of PHP core commits while supporting security, maintenance, and ecosystem work.

Added: ; Published: ; Source: Thephp

sqlite AGENTS.md

Simon Willison notes that SQLite added an AGENTS.md file telling AI coding agents and their users that SQLite requires public-domain contribution paperwork and does not accept agentic code, though maintainers may review concise human-authored proof-of-concept patches before reimplementing them.

Added: ; Published: ; Source: Simonwillison

Rust Will Save Linux From AI, Says Greg Kroah-Hartman

Slashdot covers Greg Kroah-Hartman's comments that Rust can help Linux handle a flood of AI-discovered security bugs by preventing common C memory, locking, error-handling, and untrusted-data mistakes before human review.

Added: ; Published: ; Source: Slashdot

AI Coding Agents Are Already Spreading Across GitHub, Study Finds

ADTmag reports on a study of 128,018 GitHub projects estimating coding-agent adoption at 22% to 29%, raising questions for open source teams about agent-generated pull requests, review requirements, labeling, auditing, and long-term maintenance costs.

Added: ; Published: ; Source: Adtmag

Introducing House Mates: the ClickHouse partner community and program

ClickHouse launched House Mates, a partner community and program with more than 60 integration, services, consulting, reseller, and ISV partners, formalizing a commercial ecosystem around the open source ClickHouse project and ClickHouse Cloud.

Added: ; Published: ; Source: Clickhouse

Why MotherDuck refuses to fork DuckDB

The New Stack reports on MotherDuck's relationship with DuckDB Labs and the DuckDB Foundation, saying the venture-backed company is commercializing open source DuckDB while choosing collaboration and extensibility over forking the core project.

Added: ; Published: ; Source: The New Stack

An Update on Composer and Packagist Supply Chain Security

Packagist details new Composer and Packagist.org supply chain defenses, credits Sovereign Tech Agency and Aikido funding for the work, and announces a sponsorship program starting at €2,500 per month to finance Packagist.org operations and security development.

Added: ; Published: ; Source: Packagist

Training our own AI models

PostHog says it plans to train its own AI models on customer data, with training enabled by default unless customers opt out, while promising anonymization, no third-party model providers, and no resale of models trained on the data.

Added: ; Published: ; Source: Posthog

Grow the ecosystem, not just yourself

Drupal founder Dries Buytaert argues that open source companies should compete through products while also sustaining the shared commons through code, security work, documentation, events, education, and sponsorships, criticizing Pantheon's attacks on Acquia as unhelpful Drupal ecosystem vendor conflict.

Added: ; Published: ; Source: Dri

ProxySQL joins MariaDB Foundation as Silver Sponsor

The MariaDB Foundation says ProxySQL has become a Silver Sponsor, with ProxySQL CEO René Cannaò framing the sponsorship as support for the open source database commons and a closer collaboration path between ProxySQL and MariaDB users, contributors, and maintainers.

Added: ; Published: ; Source: Mariadb

Alibaba Cloud Joins the PyTorch Foundation as a Platinum Member

The PyTorch Foundation says Alibaba Cloud has joined as a platinum member, adding financial and engineering support for the Linux Foundation-hosted open source AI framework and its global developer ecosystem.

Added: ; Published: ; Source: Pytorch

Open Source Maintainers Are Crashing Out

Boot.dev surveys recent open source maintainer conflicts and sustainability blowups, including npm funding ads and other monetization flashpoints, arguing that popular open source work remains financially fragile and difficult to sustain.

Added: ; Published: ; Source: Boot

AI Is Stressing Open Source Infrastructure

ECI Research reports from Open Source Summit 2026 that Valkey maintainers and Linux Foundation leaders described AI-assisted contributions and machine-scale package registry consumption as new pressure on open source governance, review capacity, and funding models.

Added: ; Published: ; Source: Efficientlyconnected

New financial support for F-Droid thanks to FLOSS/Fund

F-Droid says it received $50,000 from FLOSS/fund to support maintaining the free and open source Android app repository, noting that the no-strings funding program aims to donate up to $1 million annually to critical FLOSS projects.

Added: ; Published: ; Source: F Droid

Flexprice raises $1.5 Mn seed round led by Shastra VC

Entrackr reports that Flexprice raised a $1.5 million seed round led by Shastra VC to expand its open-source billing infrastructure for AI-native and API-first companies, including metering, revenue recognition, and usage-based pricing tools.

Added: ; Published: ; Source: Entrackr

Big Tech's Anti-Labor Playbook Has Come for Wikipedia

Jake Orlowitz writes that the Wikimedia Foundation fired longtime MediaWiki lead developer Brooke Vibber and disbanded the Community Tech team while holding large reserves and growing Wikimedia Enterprise revenue from AI-company API access, prompting Wikipedia editors to threaten solidarity action.

Added: ; Published: ; Source: Medium

Stop Advertising in Your Commits

Akseli Lahtinen argues that AI-tool attribution lines in commits for open source projects amount to free advertising for vendors, and says AI use should be disclosed in merge requests rather than embedded in commit metadata.

Added: ; Published: ; Source: Akselmo

Anthropic: Claude Mythos identified 10,000+ software flaws

Help Net Security reports that Anthropic's Project Glasswing update says Claude Mythos found more than 10,000 high- or critical-severity issues and disclosed 1,596 vulnerabilities across 281 open source projects, exposing a maintainer triage bottleneck.

Added: ; Published: ; Source: Helpnetsecurity

RFC: Artificial Contributors to Open Source

Andrew Nesbitt publishes a satirical Internet-Draft-style proposal for disclosure, quality, and behavior expectations around AI agents contributing to open source projects, reflecting pressure on maintainers to define norms for automated patches.

Added: ; Published: ; Source: Nesbitt

Human proof for FOSS contributions

Dillo maintainer Rodrigo Arias Mallo proposes asking new contributors to record programming sessions with asciinema as a way to distinguish human-written patches from LLM-generated contributions, highlighting AI-driven trust and review concerns in open source projects.

Added: ; Published: ; Source: Dillo Browser

The Open Source Silicon Business Model

Siliconimist interviews aesc silicon founder Daniel Schultz about building a semiconductor company around open source silicon, covering how services, expertise, and ecosystem adoption can support a business based on free designs.

Added: ; Published: ; Source: Siliconimist

The pressure

curl maintainer Daniel Stenberg describes the mental strain of handling a sustained flood of security reports after years of LLM and AI-slop submissions, saying the vulnerability triage workload is consuming nearly all of his work days.

Added: ; Published: ; Source: Haxx

Project Glasswing partners can now share Mythos findings beyond the programme

The Next Web reports that Anthropic loosened disclosure rules for Project Glasswing so partners using its Mythos cybersecurity model can share vulnerability findings with affected security teams, regulators, open source maintainers, the media, and the public under responsible-disclosure norms.

Added: ; Published: ; Source: Thenextweb

Bambu Lab Faces Open Source Licence Firestorm Over OrcaSlicer Fork

Open Source For You reports on Software Freedom Conservancy's AGPLv3 allegations against Bambu Lab, connecting the OrcaSlicer-bambulab cease-and-desist dispute to broader claims that Bambu's proprietary networking components impose extra restrictions on AGPL-licensed software.

Added: ; Published: ; Source: Opensourceforu

Open Source Makes Bugs Shallow, Linus Torvalds Says AI Makes Them Public

Techstrong.ai covers Linus Torvalds' Open Source Summit remarks about AI's effect on Linux kernel development, including increased patch volume, changes to security-disclosure guidance, and the maintainer process pressure created by AI-assisted reports and submissions.

Added: ; Published: ; Source: Techstrong

[$] Reviewing kernel patches with LLMs

LWN reports on Linux kernel community discussion at the 2026 LSF/MM+BPF Summit about using LLMs for patch review, including concerns about review quality, maintainer workload, and where AI assistance may or may not fit in kernel development.

Added: ; Published: ; Source: Lwn

AI-generated abandonware is hollowing out open source

LeadDev argues that generative AI is accelerating low-quality open source abandonware, reducing documentation traffic and revenue paths while adding to maintainers' burden from automated slop submissions.

Added: ; Published: ; Source: Leaddev

Anthropic to release Mythos-class models to the public

The Register reports that Anthropic wants to eventually release Mythos-class vulnerability-finding models while saying safeguards are not ready; Anthropic says Mythos has scanned more than 1,000 open source projects and found thousands of high- or critical-severity candidates, creating patch and disclosure pressure.

Added: ; Published: ; Source: The Register

DeepSeek funding round: AGI-first, open-source shift

The Cryptonomist reports that DeepSeek is pursuing its first external financing round while telling investors it plans to keep releasing open-source models and prioritize AGI research over near-term commercialization.

Added: ; Published: ; Source: Cryptonomist

AI might cut false positives, but it won’t stop the slop

CyberScoop reports that GitHub and bug bounty operators are tightening rules as AI tools sharply increase low-quality vulnerability submissions, including reports against open source projects and dependencies.

Added: ; Published: ; Source: Cyberscoop

Open Source First is right, but not enough.

Joost de Valk argues that Europe's Open Source First procurement push needs matching investment in the maintainers and public-interest infrastructure that digital sovereignty policies depend on.

Added: ; Published: ; Source: Joost

The Battle Over 3D Printer Software Licensing Matters For Everyone

Aftermath explains how Bambu Lab's action against an OrcaSlicer fork escalated into a broader AGPL dispute over Bambu Studio, arguing that 3D printing's open source software base makes the licensing fight important beyond one vendor.

Added: ; Published: ; Source: Aftermath

Yearslong fight over users' right to tweak smart TV software heads to trial

Ars Technica reports that Software Freedom Conservancy's GPL enforcement case against Vizio is headed to a California jury, with the nonprofit seeking complete source code for Vizio's Linux-based smart TV operating system so owners can modify the software running on their devices.

Added: ; Published: ; Source: Arstechnica

Building Pi with Pi

Armin Ronacher reflects on maintaining the open source Pi coding-agent project in a post-AI environment, describing how AI-generated issue reports and confident but wrong diagnoses create extra triage work for maintainers and agents alike.

Added: ; Published: ; Source: Pocoo

Code security startup Socket raises $60M in funding

SiliconANGLE reports that Socket raised a $60 million Series C at a $1 billion valuation to expand its developer-focused platform for blocking malicious open source packages, with the company tying demand to AI-assisted coding and growing dependency volume.

Added: ; Published: ; Source: Siliconangle

Comprehensive Response to Bambu's AGPLv3 Violations

Software Freedom Conservancy says Bambu Lab has violated AGPLv3 obligations around Bambu Studio and related 3D-printer software, and announced the baltobu reverse-engineering effort plus hosting for an Orca Slicer fork.

Added: ; Published: ; Source: Sfconservancy

pgBackRest Will Continue!

pgBackRest announced that a coalition of sponsors, including AWS, Supabase, pgEdge, Tiger Data, Percona, and Eon.io, will fund ongoing development so the open source PostgreSQL backup project is no longer dependent on a single sponsor.

Added: ; Published: ; Source: Pgbackrest

GoDaddy joins Agentic AI Foundation as Gold Member

A PRNewswire release carried by StockTitan says the Linux Foundation's Agentic AI Foundation added 43 new members, including GoDaddy as a Gold Member, to work on open standards for production-grade agentic AI.

Added: ; Published: ; Source: Stocktitan

OCX 2026: Open Source As Strategy

Forrester recapped Eclipse Foundation's OCX conference, highlighting discussions of open source funding models, vendor-neutral governance, regulation, AI, and license questions around AI-generated code.

Added: ; Published: ; Source: Forrester

The Quiet Renovation at Bitwarden

ByteHaven follows up on Bitwarden's Premium price increase, arguing that leadership changes and product direction point to a broader shift in how the open source password manager is being monetized.

Added: ; Published: ; Source: Ppb1701

18-year-old NGINX vulnerability allows DoS, potential RCE

BleepingComputer reports that an autonomous scanning system found an 18-year-old flaw in the open source NGINX web server, illustrating how AI-assisted or automated discovery can surface long-lived vulnerabilities in widely used infrastructure.

Added: ; Published: ; Source: Bleepingcomputer

GDS weighs in on the NHS's decision to retreat from Open Source

Simon Willison highlights the UK Government Digital Service's response to the NHS closing public repositories after vulnerability reports, with GDS recommending that public-sector code remain open by default despite AI-assisted vulnerability discovery concerns.

Added: ; Published: ; Source: Simonwillison

Kernel prepatch 7.1-rc4

LWN notes that Linux 7.1-rc4 documentation updates address the flood of AI-generated security reports that have made the kernel security list difficult to manage, with duplicated reports and guidance that AI-detected bugs are generally not secret vulnerabilities.

Added: ; Published: ; Source: Lwn

The Zulip Foundation

Zulip announced the Zulip Foundation, a new nonprofit home for the open source team chat project intended to support long-term governance, fundraising, and community stewardship.

Added: ; Published: ; Source: Zulip

Why Block handed Goose to the Linux Foundation

The New Stack reports on Block donating Goose, its open source AI coding agent, to the Linux Foundation and the OpenJS Foundation's Cross Project Council as a governance move for broader ecosystem adoption.

Added: ; Published: ; Source: The New Stack

OpenAI Hit by TanStack Supply Chain Attack

SecurityWeek reports that OpenAI rotated code-signing certificates after repositories containing them were compromised in a TanStack supply-chain attack, highlighting the exposure of AI vendors and developer tools to open source package ecosystem compromises.

Added: ; Published: ; Source: Securityweek

AI-Discovered Vulnerability Coordination Letter

A bipartisan group of U.S. lawmakers asked the Office of the National Cyber Director to coordinate federal and industry planning for high volumes of AI-discovered software vulnerability disclosures, including support for validating, triaging, and patching flaws in the software ecosystem.

Added: ; Published: ; Source: House