The Maintainer of Last Resort

Chainguard proposes a neutral maintainer-of-last-resort model for abandoned open-source projects, including patching, trusted builds, advisory coordination, and commercial support when upstream disclosure or maintenance fails.

Added: ; Published: ; Source: Chainguard

Alpha-Omega funds Rust security triage operations

Developer Tech reports that Alpha-Omega funding is supporting dedicated Rust security triage work to help the open-source ecosystem handle AI-assisted vulnerability reports, patch review, supply-chain monitoring, and maintainer load.

Added: ; Published: ; Source: Developer Tech

Introducing Patch the Planet

Trail of Bits introduced Patch the Planet, an OpenAI Daybreak-backed initiative that pairs security engineers and AI tools with open-source maintainers to triage findings and submit fixes, reporting 64 pull requests and 51 issues across 19 projects in its first week.

Added: ; Published: ; Source: Trailofbits

Godot tolerates 'some AI assistance' but will reject 'slop'

Game Developer reports that Godot maintainers are clarifying the open-source engine's generative-AI contribution policy, allowing limited assistance but rejecting fully AI-generated or low-quality pull requests after community concern.

Added: ; Published: ; Source: Gamedeveloper

Why Drawing Tablet Brands Won't Collaborate on Linux Floss Drivers

David Revoy explains why drawing tablet vendors have not been collaborating on Linux FLOSS driver work, citing vendor reluctance around competitor-branded repositories and calling for companies to fund full-time developers for the shared driver infrastructure.

Added: ; Published: ; Source: Davidrevoy

Pledging Another $400k to the Zig Software Foundation

Mitchell Hashimoto pledged another $400,000 to the Zig Software Foundation, bringing his family's total pledged support to $700,000, and tied the donation to Zig's maintainership and community philosophy amid renewed discussion of its no-LLM contribution policy.

Added: ; Published: ; Source: Mitchellh

Devs know AI code is riddled with holes, but ship it anyway

DevClass reports on a Checkmarx survey finding that most developers believe AI-generated code is more vulnerable while many still ship known-vulnerable code, with production applications relying heavily on open-source dependencies and maintainers facing AI-discovered vulnerability pressure.

Added: ; Published: ; Source: Devclass

Why open infrastructure will define the AI era

InfoWorld argues that AI coding tools and cloud APIs are creating a new vendor-lock-in risk for software development, while open infrastructure, standards, and foundations can keep teams from depending on proprietary usage-billed platforms.

Added: ; Published: ; Source: Infoworld

CAS Vulnerability Disclosure

The Apereo CAS project disclosed and patched a security issue, then warned that AI-assisted vulnerability reports are increasing across open source and that maintainer capacity and automated deployment will shape how projects and adopters handle faster patch cycles.

Added: ; Published: ; Source: Apereo

OpenBao strides forward in the enterprise

Computer Weekly's Open Source Insider says OpenBao is seeing broader enterprise adoption after HashiCorp's move to the Business Source License, with Nvidia, Broadcom, GitLab, support vendors, and hired core maintainers backing the OpenSSF-hosted Vault fork.

Added: ; Published: ; Source: Computerweekly

CleverCrow: Community-funded coding agents for maintainers

CleverCrow launched a service for open source maintainers where community backers pool small pledges on issues to pay coding-agent compute, while maintainers approve plans, review draft PRs, and unused funds are refunded.

Added: ; Published: ; Source: Clevercrow

uriparser pauses vulnerability reports until August

The uriparser project joined curl's vulnerability-report break, asking AI, fuzzing, and security researchers to pause new reports until August 1 while inviting funders to support maintainer work.

Added: ; Published: ; Source: Github

The Vulnerability Report Is Dead. Long Live the Prompt!

Eclipse Foundation security lead Mikaël Barbero argues that AI-assisted vulnerability reports can help open source maintainers only when they provide concrete reproduction steps, proposed fixes, and validation instead of adding speculative report volume.

Added: ; Published: ; Source: Eclipse

Open source won. That is why LGTM stopped being enough

Home Assistant maintainer Franck Nijhof argues that open-source review now has higher stakes because projects have become critical infrastructure, with AI-generated pull requests amplifying older problems around context, trust, supply-chain risk, and maintainer workload.

Added: ; Published: ; Source: Frenck

Anthropic Mythos Finds 23,019 Vulnerability Candidates as Patching Lags

eWeek reports that Anthropic's gated Claude Mythos Preview produced 23,019 candidate vulnerabilities across more than 1,000 open-source projects, while only 97 upstream patches had landed, highlighting how AI-assisted discovery can outrun maintainer coordination and patch pipelines.

Added: ; Published: ; Source: Eweek

Beyond All Reason and Hooded Horse: a new chapter

The open-source RTS game Beyond All Reason signed a publishing partnership with Hooded Horse to fund its Steam release and long-term development, while saying the code stays open source, the BAR team keeps the IP, and the free multiplayer version remains available.

Added: ; Published: ; Source: Beyondallreason

The European Social Stack

The European Social Stack declaration calls on governments, municipalities, public-service media, and civic institutions to publish on open European social platforms and fund resilient decentralized technologies such as the Fediverse, Atmosphere, Matrix, and XMPP.

Added: ; Published: ; Source: European

Why African agri-tech keeps failing, and what open-source changes

Disrupt Africa says AgriOS, an open-source ERP for African agri-SMEs, has moved governance to the Linux Foundation as part of a distributed model meant to preserve shared infrastructure, let local service providers customize deployments, and sustain the project through downstream commercial users.

Added: ; Published: ; Source: Disruptafrica

ownCloud web-extensions Repo Is Now Apache 2.0. We're Going All In.

ownCloud said its web-extensions repository has been relicensed from AGPL-3.0 to Apache-2.0, the first result of a 108-repository OSPO-led relicensing program intended to make ownCloud more procurement-friendly and compatible with Apache Software Foundation policy.

Added: ; Published: ; Source: Owncloud

Minimus for Open Source

Minimus is offering qualified open source maintainers free access to thousands of hardened container images, including FedRAMP- and FIPS-ready images, custom image creation, supply-chain protection, compliance reporting, and signed SBOMs.

Added: ; Published: ; Source: Minimus

Open Source vs the Invisible Hand

Andrew Nesbitt argues that open source libraries behave like public goods with few exclusion mechanisms, leaving maintainers, governments, companies, package managers, and marketplaces still searching for sustainable funding and governance models.

Added: ; Published: ; Source: Nesbitt

AI policy and v1.1 CLA

OpenSSL told contributors that non-trivial AI-generated submissions must be declared with an Assisted-by trailer and require the updated v1.1 contributor license agreement with AI clauses, giving reviewers new labels for AI-related CLA handling.

Added: ; Published: ; Source: Github

The Raku Foundation is born

The Raku community launched an independent Raku Foundation to coordinate the language specification, support Rakudo, steward the ecosystem, and create dedicated representation and fundraising outside The Perl and Raku Foundation.

Added: ; Published: ; Source: Raku

Linux Foundation launches DocLang group for AI documents

IT Brief reports that the LF AI & Data Foundation launched the DocLang Specification Working Group, bringing IBM, NVIDIA, Red Hat, ABBYY, and HumanSignal together under Joint Development Foundation governance to develop an open AI-native document format.

Added: ; Published: ; Source: Com

Contargo makes logistics code available to everyone

Contargo released its internally developed containerLib Java library as open source in the Open Logistics Foundation repository, framing container-number and truck-plate validation as shared logistics infrastructure rather than a competitive advantage.

Added: ; Published: ; Source: Ajot

Flarum Audit joins the Open Source core

Flarum said it purchased the formerly premium Audit extension code and is releasing it as a first-party open source audit-log feature, removing the previous free/pro split and bundling it with new Flarum 2.0 installs.

Added: ; Published: ; Source: Flarum

OkHttp, Okio, Retrofit, and SQLDelight join Commonhaus!

The Commonhaus Foundation announced that OkHttp, Okio, Retrofit, and SQLDelight have joined under the lysine.dev banner, bringing widely used Java and Kotlin networking and database libraries into the foundation as member projects.

Added: ; Published: ; Source: Commonhaus

How pull request limits are cutting down the noise

GitHub introduced configurable pull request limits to help open source maintainers manage surging contribution volume, including AI-agent pull requests and low-quality PR spam, with issue limits and cross-repository controls planned.

Added: ; Published: ; Source: GitHub Blog

Maintain-a-thon 2.0 at UN Open Source Week 2026

The Sovereign Tech Agency and the UN Office for Digital and Emerging Technologies are convening open source maintainers at UN Open Source Week 2026 for a second maintain-a-thon focused on sustaining critical digital infrastructure.

Added: ; Published: ; Source: Sovereign

The Future of Session

The Session Technology Foundation said community donations kept the open-source private messaging project from winding down after financial constraints forced layoffs, and outlined a leaner development plan focused on libsession, Session Pro Beta, and future grants or public funding.

Added: ; Published: ; Source: Getsession

The OSI 2025 Annual Report Is Now Available

The Open Source Initiative published its 2025 annual report, covering licensing stewardship, policy work on cybersecurity and procurement, sustainability, financial performance, and calls for sponsor and member support.

Added: ; Published: ; Source: Opensource

Prismatic Open-Sources Its Entire Connector Library Under Apache-2.0

Prismatic open-sourced its pre-built application connector and data platform component library under Apache-2.0, saying AI has made connector creation less differentiating while its commercial value remains in operating customer integrations at scale.

Added: ; Published: ; Source: Globenewswire

eBPF Foundation opens 2026 Academic Research Grant Program

The eBPF Foundation opened applications for its 2026 Academic Research Grant Program, offering unrestricted grants of up to $50,000 for faculty pursuing original eBPF research in areas such as verification, security, and networking optimization.

Added: ; Published: ; Source: Ebpf

Why is wolfSSL reporting so many CVEs?

wolfSSL explains that AI-driven vulnerability discovery has sharply increased the volume and severity of CVEs it reports per release, while AI slop reports have strained open source maintainers and the CVE system.

Added: ; Published: ; Source: Wolfssl

Element recognised as a Digital Public Good

Element said the Digital Public Goods Alliance recognized Element as a Digital Public Good, and used the announcement to urge governments relying on Matrix-based open source communications to fund upstream vendors and the Matrix.org Foundation.

Added: ; Published: ; Source: Element

Announcing the Search for a DSF Executive Director

The Django Software Foundation said six Django agencies pledged $47,500 to fund the foundation's first Executive Director, a paid role intended to expand operations, fundraising, grants, and long-term framework sustainability.

Added: ; Published: ; Source: Djangoproject

FreeBSD AI-assisted Vulnerability Discovery Project launch

The FreeBSD Foundation launched a six-month AI-assisted vulnerability discovery project funded by an Alpha-Omega grant, paying FreeBSD Security Team members under fixed-term contracts to find and manually patch exploitable vulnerabilities.

Added: ; Published: ; Source: Freebsdfoundation

An Interview with the Executive Director of The PHP Foundation

Vonage interviewed PHP Foundation executive director Elizabeth Barron about the foundation's work, PHP community sustainability, conference support, and the burden AI-assisted security and coding tools are putting on open source maintainers.

Added: ; Published: ; Source: Vonage

Did AI Just Break Software Security For Ever?

Foojay argues that AI-assisted vulnerability discovery is upsetting the security equilibrium for widely used software, citing curl's AI-generated bug-report burden, Jazzband's burnout, and the need for commercial support or migration plans for end-of-life dependencies.

Added: ; Published: ; Source: Foojay

Linux Finally Ends AppleTalk Protocol Support

Phoronix reports that the Linux kernel is dropping AppleTalk protocol support after maintainers received a surge of AI-generated patches for obsolete networking code that Apple itself stopped supporting years ago.

Added: ; Published: ; Source: Phoronix

Chainguard Launches Athena, the Industry Coalition to Fix Open Source Vulnerabilities Before Attackers Can Find Them

Chainguard and founding members including BNY, Cisco, Cloudflare, Docker, JPMorganChase, Kyndryl, LTIMindtree, and PwC launched Athena, an industry coalition to coordinate AI-era open-source vulnerability findings and fixes, saying it has already processed more than 20,000 findings and generated over 2,000 patches across 500 projects.

Added: ; Published: ; Source: Prnewswire

Why AI-Generated Code Is a Security Risk in Open Source Projects

TFiR interviews Linux Foundation research lead Hilary Carter about AI-generated code reintroducing insecure or deprecated code into open-source pull requests, Zephyr's security posture, and upcoming research on generative AI's impact on open-source software security.

Added: ; Published: ; Source: Tfir

Making Sure Open Science Stays Open

Issues in Science and Technology discusses the funding and governance needed to keep open research data infrastructure running, including Dryad and Invest in Open Infrastructure's work on open-source systems for research communities.

Added: ; Published: ; Source: Issues

We changed how Synergy licensing works

Symless said it revised a May EULA change that required business licenses for any work use, limiting the requirement to licenses bought, reimbursed, deployed, or managed by organizations while emphasizing Synergy's open source core and one-time personal licenses.

Added: ; Published: ; Source: Symless

Open Publishing, Commercial Scale

Sonatype's Brian Fox argues that public open-source package registries are becoming commercial-scale infrastructure, pointing to Maven Central publishing notifications, OpenSSF sustainability discussions, and paid managed registry models such as Eclipse Open VSX.

Added: ; Published: ; Source: Sonatype

FOSSUnited Grants

Scrite says it received a ₹3 lakh FOSSUnited grant to support the open-source screenwriting project's operations through 2027, including hosting, software licensing, code-signing certificates, and legal-document review.

Added: ; Published: ; Source: Scrite

An AI Security Engineer in Residence for the Rust Ecosystem

The Rust Foundation says Alpha-Omega funding will support a full-time AI Security Engineer in Residence to help Rust maintainers review critical crates, validate AI-assisted vulnerability reports, and reduce security triage noise.

Added: ; Published: ; Source: Rust Foundation

67 Open Technology Projects Awarded NGI Zero Grants

NLnet announced 67 grants across the NGI Zero Commons Fund, NGI Taler, and NGI Fediversity programs, supporting open technology projects spanning privacy-preserving payments, hosting, developer tools, and user autonomy.

Added: ; Published: ; Source: Nlnet

Our maintainer delegation for UN Open Source Week

The Sovereign Tech Agency said it is bringing nine open source maintainers to UN Open Source Week 2026 to represent practitioner perspectives in discussions about sustaining and securing critical digital infrastructure.

Added: ; Published: ; Source: Sovereign

Dronecode Welcomes Agam Robotics as a Silver Member

The Dronecode Foundation said Agam Robotics joined as a Silver Member, bringing an India-based maker of open-source-aligned UAV hardware and Pixhawk-standard autopilots into the foundation ecosystem.

Added: ; Published: ; Source: Dronecode

Modrinth joins Spark Universe

The open-source Minecraft mod platform Modrinth says it has joined Spark Universe, while promising to keep the project open source, independent from Essential, and focused on creator monetization.

Added: ; Published: ; Source: Modrinth

Craig McLuckie on Culture as a Team's Operating System in the AI Era

InfoQ interviews Kubernetes co-creator Craig McLuckie about AI coding tools' impact on open-source communities, including maintainer fatigue from AI-generated slop pull requests, the need for stronger review culture, and how engineering teams should treat culture as an operating system.

Added: ; Published: ; Source: Infoq

AI vulnerability discovery is pushing 2026 CVEs toward 66,000

Help Net Security reports that AI-assisted bug hunting is pushing 2026 CVE forecasts toward 66,000 disclosures, while urgent-patch ratios remain flat and maintainers face a race between faster AI-built exploits, patches, detection signatures, and validation work.

Added: ; Published: ; Source: Helpnetsecurity

Chainguard Launches Athena, the Industry Coalition to Fix Open Source Vulnerabilities Before Attackers Can Find Them

Chainguard announced Athena, an industry coalition with BNY, Cisco, Cloudflare, Docker, JPMorganChase, PwC, and others to coordinate discovery, pre-embargo remediation, and patch publication for open-source vulnerabilities found by AI and security researchers, saying it has processed more than 20,000 findings and generated over 2,000 patches.

Added: ; Published: ; Source: Yahoo

A human in control

Daniel Stenberg says curl will remain human-led despite AI coding tools, requiring human review and ownership for every merge and arguing that long-term maintainability, project knowledge, and human communication matter more than faster code generation.

Added: ; Published: ; Source: Haxx

FreeBSD Receives Funding To Launch AI-Assisted Vulnerability Discovery

Phoronix reports that the FreeBSD Project launched an AI-Assisted Vulnerability Discovery Project with grant funding from the Linux Foundation-backed Alpha-Omega project to find and report vulnerabilities in FreeBSD and open-source components.

Added: ; Published: ; Source: Phoronix

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

The Hacker News reports on Tenet Security's Agentjacking attack, where malicious Sentry error reports in the open-source monitoring platform can steer AI coding agents into running attacker-controlled commands on developer machines, exposing another workflow risk for agent-assisted software maintenance.

Added: ; Published: ; Source: Thehackernews

Improving Arm64 support in CNCF projects with OCI credits

CNCF says the Oracle Cloud Infrastructure credits pool is funding Arm64 CI and build work across cloud-native projects, including maintainers receiving compute support to improve multi-architecture testing and reduce infrastructure costs.

Added: ; Published: ; Source: CNCF

When code costs nothing to produce, how do you review it all?

Laurie Voss argues that AI coding agents have collapsed the cost of producing plausible code while leaving human review as the bottleneck, citing research on GitHub developers and METR tests where open-source maintainers said they would reject about half of agent-generated pull requests that passed automated benchmark checks.

Added: ; Published: ; Source: Linkedin

Curl will not accept vulnerability reports during July 2026

Daniel Stenberg says the curl project will pause HackerOne and security-email vulnerability intake for July 2026 so maintainers can recover from months of unusually heavy report pressure, while paid support customers will still receive service and the next curl release is pushed back two weeks.

Added: ; Published: ; Source: Haxx

Snowplow Limited Use License FAQ

Snowplow says it is moving new versions of core pipeline components and dbt models from Apache 2.0 to a source-available Limited Use License that permits source access, modification, and non-production or non-commercial use, but bars production deployment and competing SaaS or on-prem offerings unless users pay.

Added: ; Published: ; Source: Snowplow

NanoClaw now armed with JFrog for safer packages

The Register reports that the open-source NanoClaw AI-agent framework integrated with JFrog's vetted registries so agents can fetch packages from reviewed sources, while NanoCo also built a human-approved PR Factory to triage the surge of AI-generated contributions to the project.

Added: ; Published: ; Source: The Register

AI is code – and can't be prompted into being smarter

The Register argues that AI coding agents behave like software that will ingest untrusted instructions, connecting the jqwik maintainer's anti-AI output warnings with Shai-Hulud-style supply-chain attacks and the broader risk that bots can be manipulated through open-source project text and build artifacts.

Added: ; Published: ; Source: The Register

Announcement: Unleash open source moves to AGPLv3

Unleash's June 9 release notes say Unleash v8 moves the primary GitHub repository and unleash-server npm package from Apache 2.0 to AGPLv3, while official Docker images and SDKs remain under permissive terms and commercial SaaS modifiers are directed to a commercial license.

Added: ; Published: ; Source: Getunleash