A look at MinIO alternatives: Ceph and Garage

LWN reviews Ceph and Garage as open-source object-storage alternatives after MinIO's company put the project into maintenance mode and then archived it, leaving users to evaluate community-governed replacements.

Added: ; Published: ; Source: Lwn

Nominet DNS Fund - What we've learned and what's new for 2026?

Nominet opened a second application window for its DNS Fund, increasing available support to £650,000, adding multi-year awards and grants of up to £15,000 for individual open-source DNS maintainers, and focusing on sustainability for essential DNS infrastructure.

Added: ; Published: ; Source: Nominet

How the Django Software Foundation Became a CNA

The Django Software Foundation explained how it became a CVE Numbering Authority, giving the foundation the ability to assign CVEs for Django and selected community projects while aligning security advisories with its existing release workflow.

Added: ; Published: ; Source: Djangoproject

The AI code paradox: Moving fast without breaking security

Red Hat outlines a policy, skills, and automation framework for safer AI-assisted coding, tying enterprise security risk to the same maintainer burden open-source projects face when AI-generated pull requests arrive faster than humans can review them.

Added: ; Published: ; Source: Redhat

Should frontier AI firms fund OSS ecosystem security?

ReversingLabs reports on calls for frontier AI companies to fund open-source security remediation as AI vulnerability discovery outpaces maintainer capacity, including proposals for a Great Refactor Fund and direct support for maintainers, reviewers, and security engineers.

Added: ; Published: ; Source: Reversinglabs

I wrote a 70x faster SQL parser while barely looking at the code

PostHog describes using parallel Claude Code sessions, property-based testing, and production shadow mode to replace its ANTLR-based SQL parser with a hand-rolled parser, illustrating a controlled AI-assisted workflow for a large open-source analytics codebase.

Added: ; Published: ; Source: Posthog

AMPEL Accepted as New OpenSSF Sandbox Project

OpenSSF accepted AMPEL as a new sandbox project, moving the supply-chain policy engine toward Linux Foundation control so developers and downstream consumers can verify signed metadata about source, builds, dependencies, and releases.

Added: ; Published: ; Source: Github

[$] Fedora: 2FA, or not 2FA, that is the question

LWN reports on Fedora's discussion of new two-factor authentication requirements for packagers after an alleged account compromise led to an AI agent causing problems for the project, highlighting open-source supply-chain and maintainer workflow pressures.

Added: ; Published: ; Source: Lwn

Old rivals unite to create shared automotive operating system

New Atlas reports that BMW, Mercedes-Benz, Volkswagen, Stellantis, and other automakers are pooling software through Eclipse S-Core to build an open-source software foundation for future vehicle operating systems.

Added: ; Published: ; Source: Newatlas

PR spam today looks like email spam in the early 2000s

Greptile describes a surge of low-quality AI-generated pull requests around the OpenClaw project and argues that open-source maintainers need new trust and moderation systems as AI agents make PR spam cheap.

Added: ; Published: ; Source: Greptile

Software Freedom Conservancy Sets Rules for AI-Assisted Code

Linuxiac reports on Software Freedom Conservancy guidance for LLM-assisted FOSS contributions, emphasizing human review and understanding, disclosure of AI use, avoidance of unattended generated patches, and maintainers' right to reject AI-assisted submissions.

Added: ; Published: ; Source: Linuxiac

Open-source security is posing challenges governments can't easily solve

CyberScoop reports that governments and industry are struggling to close open-source software security gaps, with experts pointing to chronic underinvestment, volunteer maintainer limits, and AI-driven vulnerability discovery that can outpace disclosure and patching.

Added: ; Published: ; Source: Cyberscoop

Open source grapples with agentic coding

InfoWorld argues that open-source maintainers should judge AI-assisted submissions by quality and license compliance rather than banning them outright, while acknowledging review overload, copyright questions, and GPL-compliance risks from agentic coding tools.

Added: ; Published: ; Source: Infoworld

Freedom is Not Free: A Model for Open Source Sustainability

Tiffany Farriss argues that projects such as Drupal have become shared digital infrastructure without operational funding for supply-chain security, product management, and CI, and proposes procurement and foundation cost models that move support from donations into operating budgets.

Added: ; Published: ; Source: Palantir

Vulnerability Reports Are Not Special Anymore

Filippo Valsorda argues that LLM-assisted vulnerability discovery has made bug reports less scarce and less confidential, changing how open-source maintainers should triage, prioritize, and disclose security findings.

Added: ; Published: ; Source: Filippo

Swift Package Index Joins Apple

Swift Package Index announced that it has joined Apple, moving the Swift package discovery service into Apple after operating as an independent community project.

Added: ; Published: ; Source: Swiftpackageindex

Open Source AI Fellowship Announced at UN Open Source Week

OSI launched a two-year Open Source AI Fellowship with Duke University and launch sponsorship from Red Hat, AWS, Google, Automattic, and Mozilla to support research, policy work, and community consensus around open-source AI governance and standards.

Added: ; Published: ; Source: Opensource

UNDP announces initiative to drive sovereign, open-source DPI efforts in Africa

Biometric Update reports that UNDP's Africa Accelerator for Digital Public Infrastructure will provide technical expertise, policy support, institutional strengthening, and investment facilitation for African governments adopting open-source digital public infrastructure instead of proprietary platforms.

Added: ; Published: ; Source: Biometricupdate

The Maintainer of Last Resort

Chainguard proposes a neutral maintainer-of-last-resort model for abandoned open-source projects, including patching, trusted builds, advisory coordination, and commercial support when upstream disclosure or maintenance fails.

Added: ; Published: ; Source: Chainguard

Alpha-Omega funds Rust security triage operations

Developer Tech reports that Alpha-Omega funding is supporting dedicated Rust security triage work to help the open-source ecosystem handle AI-assisted vulnerability reports, patch review, supply-chain monitoring, and maintainer load.

Added: ; Published: ; Source: Developer Tech

Introducing Patch the Planet

Trail of Bits introduced Patch the Planet, an OpenAI Daybreak-backed initiative that pairs security engineers and AI tools with open-source maintainers to triage findings and submit fixes, reporting 64 pull requests and 51 issues across 19 projects in its first week.

Added: ; Published: ; Source: Trailofbits

Godot tolerates 'some AI assistance' but will reject 'slop'

Game Developer reports that Godot maintainers are clarifying the open-source engine's generative-AI contribution policy, allowing limited assistance but rejecting fully AI-generated or low-quality pull requests after community concern.

Added: ; Published: ; Source: Gamedeveloper

Why Drawing Tablet Brands Won't Collaborate on Linux Floss Drivers

David Revoy explains why drawing tablet vendors have not been collaborating on Linux FLOSS driver work, citing vendor reluctance around competitor-branded repositories and calling for companies to fund full-time developers for the shared driver infrastructure.

Added: ; Published: ; Source: Davidrevoy

Pledging Another $400k to the Zig Software Foundation

Mitchell Hashimoto pledged another $400,000 to the Zig Software Foundation, bringing his family's total pledged support to $700,000, and tied the donation to Zig's maintainership and community philosophy amid renewed discussion of its no-LLM contribution policy.

Added: ; Published: ; Source: Mitchellh

Devs know AI code is riddled with holes, but ship it anyway

DevClass reports on a Checkmarx survey finding that most developers believe AI-generated code is more vulnerable while many still ship known-vulnerable code, with production applications relying heavily on open-source dependencies and maintainers facing AI-discovered vulnerability pressure.

Added: ; Published: ; Source: Devclass

Why open infrastructure will define the AI era

InfoWorld argues that AI coding tools and cloud APIs are creating a new vendor-lock-in risk for software development, while open infrastructure, standards, and foundations can keep teams from depending on proprietary usage-billed platforms.

Added: ; Published: ; Source: Infoworld

CAS Vulnerability Disclosure

The Apereo CAS project disclosed and patched a security issue, then warned that AI-assisted vulnerability reports are increasing across open source and that maintainer capacity and automated deployment will shape how projects and adopters handle faster patch cycles.

Added: ; Published: ; Source: Apereo

OpenBao strides forward in the enterprise

Computer Weekly's Open Source Insider says OpenBao is seeing broader enterprise adoption after HashiCorp's move to the Business Source License, with Nvidia, Broadcom, GitLab, support vendors, and hired core maintainers backing the OpenSSF-hosted Vault fork.

Added: ; Published: ; Source: Computerweekly

CleverCrow: Community-funded coding agents for maintainers

CleverCrow launched a service for open source maintainers where community backers pool small pledges on issues to pay coding-agent compute, while maintainers approve plans, review draft PRs, and unused funds are refunded.

Added: ; Published: ; Source: Clevercrow

uriparser pauses vulnerability reports until August

The uriparser project joined curl's vulnerability-report break, asking AI, fuzzing, and security researchers to pause new reports until August 1 while inviting funders to support maintainer work.

Added: ; Published: ; Source: Github

The Vulnerability Report Is Dead. Long Live the Prompt!

Eclipse Foundation security lead Mikaël Barbero argues that AI-assisted vulnerability reports can help open source maintainers only when they provide concrete reproduction steps, proposed fixes, and validation instead of adding speculative report volume.

Added: ; Published: ; Source: Eclipse

Open source won. That is why LGTM stopped being enough

Home Assistant maintainer Franck Nijhof argues that open-source review now has higher stakes because projects have become critical infrastructure, with AI-generated pull requests amplifying older problems around context, trust, supply-chain risk, and maintainer workload.

Added: ; Published: ; Source: Frenck

Anthropic Mythos Finds 23,019 Vulnerability Candidates as Patching Lags

eWeek reports that Anthropic's gated Claude Mythos Preview produced 23,019 candidate vulnerabilities across more than 1,000 open-source projects, while only 97 upstream patches had landed, highlighting how AI-assisted discovery can outrun maintainer coordination and patch pipelines.

Added: ; Published: ; Source: Eweek

Beyond All Reason and Hooded Horse: a new chapter

The open-source RTS game Beyond All Reason signed a publishing partnership with Hooded Horse to fund its Steam release and long-term development, while saying the code stays open source, the BAR team keeps the IP, and the free multiplayer version remains available.

Added: ; Published: ; Source: Beyondallreason

The European Social Stack

The European Social Stack declaration calls on governments, municipalities, public-service media, and civic institutions to publish on open European social platforms and fund resilient decentralized technologies such as the Fediverse, Atmosphere, Matrix, and XMPP.

Added: ; Published: ; Source: European

Why African agri-tech keeps failing, and what open-source changes

Disrupt Africa says AgriOS, an open-source ERP for African agri-SMEs, has moved governance to the Linux Foundation as part of a distributed model meant to preserve shared infrastructure, let local service providers customize deployments, and sustain the project through downstream commercial users.

Added: ; Published: ; Source: Disruptafrica

ownCloud web-extensions Repo Is Now Apache 2.0. We're Going All In.

ownCloud said its web-extensions repository has been relicensed from AGPL-3.0 to Apache-2.0, the first result of a 108-repository OSPO-led relicensing program intended to make ownCloud more procurement-friendly and compatible with Apache Software Foundation policy.

Added: ; Published: ; Source: Owncloud

Minimus for Open Source

Minimus is offering qualified open source maintainers free access to thousands of hardened container images, including FedRAMP- and FIPS-ready images, custom image creation, supply-chain protection, compliance reporting, and signed SBOMs.

Added: ; Published: ; Source: Minimus

Open Source vs the Invisible Hand

Andrew Nesbitt argues that open source libraries behave like public goods with few exclusion mechanisms, leaving maintainers, governments, companies, package managers, and marketplaces still searching for sustainable funding and governance models.

Added: ; Published: ; Source: Nesbitt

AI policy and v1.1 CLA

OpenSSL told contributors that non-trivial AI-generated submissions must be declared with an Assisted-by trailer and require the updated v1.1 contributor license agreement with AI clauses, giving reviewers new labels for AI-related CLA handling.

Added: ; Published: ; Source: Github

The Raku Foundation is born

The Raku community launched an independent Raku Foundation to coordinate the language specification, support Rakudo, steward the ecosystem, and create dedicated representation and fundraising outside The Perl and Raku Foundation.

Added: ; Published: ; Source: Raku

Linux Foundation launches DocLang group for AI documents

IT Brief reports that the LF AI & Data Foundation launched the DocLang Specification Working Group, bringing IBM, NVIDIA, Red Hat, ABBYY, and HumanSignal together under Joint Development Foundation governance to develop an open AI-native document format.

Added: ; Published: ; Source: Com

Contargo makes logistics code available to everyone

Contargo released its internally developed containerLib Java library as open source in the Open Logistics Foundation repository, framing container-number and truck-plate validation as shared logistics infrastructure rather than a competitive advantage.

Added: ; Published: ; Source: Ajot

Flarum Audit joins the Open Source core

Flarum said it purchased the formerly premium Audit extension code and is releasing it as a first-party open source audit-log feature, removing the previous free/pro split and bundling it with new Flarum 2.0 installs.

Added: ; Published: ; Source: Flarum

OkHttp, Okio, Retrofit, and SQLDelight join Commonhaus!

The Commonhaus Foundation announced that OkHttp, Okio, Retrofit, and SQLDelight have joined under the lysine.dev banner, bringing widely used Java and Kotlin networking and database libraries into the foundation as member projects.

Added: ; Published: ; Source: Commonhaus

How pull request limits are cutting down the noise

GitHub introduced configurable pull request limits to help open source maintainers manage surging contribution volume, including AI-agent pull requests and low-quality PR spam, with issue limits and cross-repository controls planned.

Added: ; Published: ; Source: GitHub Blog

Maintain-a-thon 2.0 at UN Open Source Week 2026

The Sovereign Tech Agency and the UN Office for Digital and Emerging Technologies are convening open source maintainers at UN Open Source Week 2026 for a second maintain-a-thon focused on sustaining critical digital infrastructure.

Added: ; Published: ; Source: Sovereign

The Future of Session

The Session Technology Foundation said community donations kept the open-source private messaging project from winding down after financial constraints forced layoffs, and outlined a leaner development plan focused on libsession, Session Pro Beta, and future grants or public funding.

Added: ; Published: ; Source: Getsession

The OSI 2025 Annual Report Is Now Available

The Open Source Initiative published its 2025 annual report, covering licensing stewardship, policy work on cybersecurity and procurement, sustainability, financial performance, and calls for sponsor and member support.

Added: ; Published: ; Source: Opensource

Prismatic Open-Sources Its Entire Connector Library Under Apache-2.0

Prismatic open-sourced its pre-built application connector and data platform component library under Apache-2.0, saying AI has made connector creation less differentiating while its commercial value remains in operating customer integrations at scale.

Added: ; Published: ; Source: Globenewswire

eBPF Foundation opens 2026 Academic Research Grant Program

The eBPF Foundation opened applications for its 2026 Academic Research Grant Program, offering unrestricted grants of up to $50,000 for faculty pursuing original eBPF research in areas such as verification, security, and networking optimization.

Added: ; Published: ; Source: Ebpf

Why is wolfSSL reporting so many CVEs?

wolfSSL explains that AI-driven vulnerability discovery has sharply increased the volume and severity of CVEs it reports per release, while AI slop reports have strained open source maintainers and the CVE system.

Added: ; Published: ; Source: Wolfssl

Element recognised as a Digital Public Good

Element said the Digital Public Goods Alliance recognized Element as a Digital Public Good, and used the announcement to urge governments relying on Matrix-based open source communications to fund upstream vendors and the Matrix.org Foundation.

Added: ; Published: ; Source: Element

Announcing the Search for a DSF Executive Director

The Django Software Foundation said six Django agencies pledged $47,500 to fund the foundation's first Executive Director, a paid role intended to expand operations, fundraising, grants, and long-term framework sustainability.

Added: ; Published: ; Source: Djangoproject