LWN reviews Ceph and Garage as open-source object-storage alternatives after MinIO's company put the project into maintenance mode and then archived it, leaving users to evaluate community-governed replacements.
Datavant joined the Linux Foundation-hosted Agentic AI Foundation, adding healthcare data interoperability, privacy, compliance, governance, and trusted-access requirements to the foundation's open standards work for agentic AI infrastructure.
The Rust Foundation launched its Trusted Training Program with Mainmatter, Integer 32, Wyliodrin, Doulos, and Ferrous Systems as founding providers, creating an accreditation mark for Rust education backed by the foundation.
Nominet opened a second application window for its DNS Fund, increasing available support to £650,000, adding multi-year awards and grants of up to £15,000 for individual open-source DNS maintainers, and focusing on sustainability for essential DNS infrastructure.
The Django Software Foundation explained how it became a CVE Numbering Authority, giving the foundation the ability to assign CVEs for Django and selected community projects while aligning security advisories with its existing release workflow.
Aisle says its AI-native security platform and research team found six of the 18 CVEs in curl's latest security-heavy release after Anthropic's Mythos discovery triggered a wave of AI-assisted vulnerability research against the open-source project.
Red Hat outlines a policy, skills, and automation framework for safer AI-assisted coding, tying enterprise security risk to the same maintainer burden open-source projects face when AI-generated pull requests arrive faster than humans can review them.
Palo Alto Networks, IBM, and Red Hat expanded Project Lightwell by pairing virtual patching with IBM and Red Hat's open-source software remediation work, aiming to shorten the gap between AI-accelerated vulnerability discovery and deployed fixes.
Tuskira analyzed Anthropic Mythos disclosure data and found 1,596 verified vulnerabilities across 281 open-source projects, with most not yet visible in CVE, NVD, GitHub advisory, or scanner workflows and only 6.1% marked patched despite broad maintainer acknowledgment.
OfficeChai reports that Justin Poehnelt says Google fired him after his open-source, agent-oriented Google Workspace CLI went viral, raising questions about corporate control of developer tooling as AI agents make Workspace APIs easier to automate.
ReversingLabs reports on calls for frontier AI companies to fund open-source security remediation as AI vulnerability discovery outpaces maintainer capacity, including proposals for a Great Refactor Fund and direct support for maintainers, reviewers, and security engineers.
Prusa Research released Open Community License v1.1 for CORE One CAD files and related projects, adding modular attribution and micro-business plugins while tightening derivative sharing to OCL-only terms and broadening internal business use.
Arsham Khosravani and Audris Mockus studied AI coding-agent traces across more than 180 million Git repositories, finding that single-signal measurements miss most agent activity and that Claude Code, Codex, Cursor, and other agents appear in distinct open-source contribution channels.
PostHog describes using parallel Claude Code sessions, property-based testing, and production shadow mode to replace its ANTLR-based SQL parser with a hand-rolled parser, illustrating a controlled AI-assisted workflow for a large open-source analytics codebase.
OpenSSF accepted AMPEL as a new sandbox project, moving the supply-chain policy engine toward Linux Foundation control so developers and downstream consumers can verify signed metadata about source, builds, dependencies, and releases.
LWN reports on Fedora's discussion of new two-factor authentication requirements for packagers after an alleged account compromise led to an AI agent causing problems for the project, highlighting open-source supply-chain and maintainer workflow pressures.
The Academy Software Foundation and the Visual Effects Society's Technology Committee launched a Wayland for Artists Working Group to coordinate open-source display-server work around artist and production-studio needs.
New Atlas reports that BMW, Mercedes-Benz, Volkswagen, Stellantis, and other automakers are pooling software through Eclipse S-Core to build an open-source software foundation for future vehicle operating systems.
Tetrate announced Envoy AI Gateway v1.0, an open-source AI gateway built on CNCF's Envoy Gateway project, with production-hardening and maintainer contributions from Bloomberg, Nutanix, Tetrate, and the broader Envoy community.
The Rust Foundation launched the Rust Commercial Network to connect commercial Rust users with foundation resources, encourage investment in the language ecosystem, and create a forum for companies relying on Rust in production.
Greptile describes a surge of low-quality AI-generated pull requests around the OpenClaw project and argues that open-source maintainers need new trust and moderation systems as AI agents make PR spam cheap.
Phoronix reports that Linux 7.2's KVM updates include no new ARM64 features because ARM maintainers were occupied reviewing and fixing AI-fueled changes, illustrating how AI-generated work is affecting open-source kernel maintenance.
Linuxiac reports on Software Freedom Conservancy guidance for LLM-assisted FOSS contributions, emphasizing human review and understanding, disclosure of AI use, avoidance of unattended generated patches, and maintainers' right to reject AI-assisted submissions.
The Recursive reports that SuperPlane raised €2.28 million in pre-seed funding to build an Apache-2.0 open-source control plane for AI-assisted production infrastructure workflows, with plans to expand product development, partnerships, community, and a hosted version.
CyberScoop reports that governments and industry are struggling to close open-source software security gaps, with experts pointing to chronic underinvestment, volunteer maintainer limits, and AI-driven vulnerability discovery that can outpace disclosure and patching.
InfoWorld argues that open-source maintainers should judge AI-assisted submissions by quality and license compliance rather than banning them outright, while acknowledging review overload, copyright questions, and GPL-compliance risks from agentic coding tools.
LTM joined Athena, a Chainguard-led coalition coordinating shared intelligence, pre-disclosure remediation, and upstream fixes for open-source software vulnerabilities as AI tools accelerate vulnerability discovery and exploitation pressure.
Timefold raised a $13 million Series A led by Alstin Capital to expand its scheduling and routing API platform, adding commercial backing for the company behind the Apache-2.0 Timefold Solver open-source optimization engine.
Upbound released Modelplane as an Apache-2.0 open-source control plane for AI inference fleets, saying it will develop the project in the open and plans to donate it to an open source foundation later this year.
Tiffany Farriss argues that projects such as Drupal have become shared digital infrastructure without operational funding for supply-chain security, product management, and CI, and proposes procurement and foundation cost models that move support from donations into operating budgets.
Dynatrace details its open-source investment across cloud-native observability projects, including engineering leadership in OpenTelemetry governance, donating Keptn to the CNCF, founding support for W3C Trace Context, and contributions to OpenFeature.
Filippo Valsorda argues that LLM-assisted vulnerability discovery has made bug reports less scarce and less confidential, changing how open-source maintainers should triage, prioritize, and disclose security findings.
The Hacker News reports on Squidbleed, a decades-old heap over-read in the open-source Squid proxy that can leak cleartext HTTP request fragments, with the researcher crediting Anthropic's Claude Mythos Preview for spotting the parser flaw.
The New Stack reports on GitLab's AI Accountability Report, finding that AI coding tools have shifted the bottleneck from writing code to reviewing and governing it, with many teams unable to reliably distinguish AI-generated code from human-written work.
Swift Package Index announced that it has joined Apple, moving the Swift package discovery service into Apple after operating as an independent community project.
GitHub joined a coalition seeking changes to California's AI Transparency Act, arguing that the law should avoid conflicts with open source licensing and align transparency obligations with international frameworks.
The Eclipse SDV Working Group says the European Commission cited it as a model for vendor-neutral industrial open source collaboration in automotive software, alongside plans to support shared open source building blocks and critical infrastructure for European technological sovereignty.
IBM and Red Hat announced Project Lightwell, a $5 billion commitment to build a trusted enterprise clearinghouse for open source software security, combining AI-assisted vulnerability validation, commercial subscriptions, and more than 20,000 engineers to patch supply-chain risks at scale.
OSI launched a two-year Open Source AI Fellowship with Duke University and launch sponsorship from Red Hat, AWS, Google, Automattic, and Mozilla to support research, policy work, and community consensus around open-source AI governance and standards.
The Linux Foundation announced its intent to launch Agent Name Service, an open standard for AI agent identity, verification, and discovery that extends DNS-style infrastructure for the agentic web.
Biometric Update reports that UNDP's Africa Accelerator for Digital Public Infrastructure will provide technical expertise, policy support, institutional strengthening, and investment facilitation for African governments adopting open-source digital public infrastructure instead of proprietary platforms.
Phoronix reports that fwupd 2.0.21 backports fixes for more than 250 potential security issues found by AI security scanners, giving conservative distributions access to hardening work already landing in the open-source firmware update tool's 2.1 series.
FINOS announced an AI Fund backed by founding premier members DTCC, Morgan Stanley, RBC, and NatWest to collectively invest in open-source AI governance, controls, specifications, reference implementations, and financial-services agentic workflows.
FINOS announced an AI Fund backed by founding premier members DTCC, Morgan Stanley, RBC, and NatWest to collectively invest in open-source AI governance, controls, specifications, reference implementations, and financial-services agentic workflows.
Hugging Face explains how the maintainers of the open-source huggingface_hub Python client moved to weekly releases using a GitHub Actions pipeline, open tools, open-weight models, and human review to draft changelogs, test downstream projects, and publish release notes.
Chainguard proposes a neutral maintainer-of-last-resort model for abandoned open-source projects, including patching, trusted builds, advisory coordination, and commercial support when upstream disclosure or maintenance fails.
Developer Tech reports that Alpha-Omega funding is supporting dedicated Rust security triage work to help the open-source ecosystem handle AI-assisted vulnerability reports, patch review, supply-chain monitoring, and maintainer load.
HeroDevs joined the Commonhaus Foundation's Open Source Sustainability Initiative as a founding Gold Partner, pairing its commercial long-term support for end-of-life open source software with Commonhaus communities including Hibernate, Jackson, and Quarkus.
Trail of Bits introduced Patch the Planet, an OpenAI Daybreak-backed initiative that pairs security engineers and AI tools with open-source maintainers to triage findings and submit fixes, reporting 64 pull requests and 51 issues across 19 projects in its first week.
Game Developer reports that Godot maintainers are clarifying the open-source engine's generative-AI contribution policy, allowing limited assistance but rejecting fully AI-generated or low-quality pull requests after community concern.
DDEV says AI-assisted answers are reducing community support interactions that maintainers rely on for feedback, while Upsun has transferred the DDEV trademark to the DDEV Foundation to support the local-development project's long-term independence.
The New Stack reports that Cursor acquired Continue, the open-source AI coding assistant with 34,000 GitHub stars, in a quiet acqui-hire that shuts down Continue's product while handing the codebase to the community.
The Rust Foundation welcomed Integer 32, Convex, Renesas, Peeriot, and the Processing Foundation as new member organizations, expanding foundation support for the Rust ecosystem.
xyflow launched Svelte Flow Pro and a unified Pro platform, expanding its paid advanced-example offering for the open-source React Flow and Svelte Flow libraries to support ongoing development.
David Revoy explains why drawing tablet vendors have not been collaborating on Linux FLOSS driver work, citing vendor reluctance around competitor-branded repositories and calling for companies to fund full-time developers for the shared driver infrastructure.
Mitchell Hashimoto pledged another $400,000 to the Zig Software Foundation, bringing his family's total pledged support to $700,000, and tied the donation to Zig's maintainership and community philosophy amid renewed discussion of its no-LLM contribution policy.
DevClass reports on a Checkmarx survey finding that most developers believe AI-generated code is more vulnerable while many still ship known-vulnerable code, with production applications relying heavily on open-source dependencies and maintainers facing AI-discovered vulnerability pressure.
InfoWorld argues that AI coding tools and cloud APIs are creating a new vendor-lock-in risk for software development, while open infrastructure, standards, and foundations can keep teams from depending on proprietary usage-billed platforms.
The Apereo CAS project disclosed and patched a security issue, then warned that AI-assisted vulnerability reports are increasing across open source and that maintainer capacity and automated deployment will shape how projects and adopters handle faster patch cycles.
Computer Weekly's Open Source Insider says OpenBao is seeing broader enterprise adoption after HashiCorp's move to the Business Source License, with Nvidia, Broadcom, GitLab, support vendors, and hired core maintainers backing the OpenSSF-hosted Vault fork.
The New Stack reports that Cursor's Origin, GitLab's Project Switch, and Zed's DeltaDB are trying to rebuild code-hosting and review workflows for AI-agent-generated code as GitHub struggles with agent-driven load, with one former GitHub leader saying agents are killing the will for doing open source.
The New Stack interviewed Nvidia's Nader Khalil about backing the open source OpenClaw agent-harness project, saying Nvidia has developers contributing full time as the project faces a mountain of pull requests and enterprises look for safer agent runtimes.
CleverCrow launched a service for open source maintainers where community backers pool small pledges on issues to pay coding-agent compute, while maintainers approve plans, review draft PRs, and unused funds are refunded.
The uriparser project joined curl's vulnerability-report break, asking AI, fuzzing, and security researchers to pause new reports until August 1 while inviting funders to support maintainer work.
TechTarget reports that Nvidia is now listed as an OpenBao adopter, signaling enterprise interest in the OpenSSF-backed open source Vault fork created after HashiCorp's move to the Business Source License.
FINOS announced a Citi-spearheaded open source contribution of an AI Governance Framework MCP Server, intended to give AI agents structured governance, risk, threat-modeling, and standards context for financial-services workflows while keeping humans accountable for review.
Eclipse Foundation security lead Mikaël Barbero argues that AI-assisted vulnerability reports can help open source maintainers only when they provide concrete reproduction steps, proposed fixes, and validation instead of adding speculative report volume.
Home Assistant maintainer Franck Nijhof argues that open-source review now has higher stakes because projects have become critical infrastructure, with AI-generated pull requests amplifying older problems around context, trust, supply-chain risk, and maintainer workload.
eWeek reports that Anthropic's gated Claude Mythos Preview produced 23,019 candidate vulnerabilities across more than 1,000 open-source projects, while only 97 upstream patches had landed, highlighting how AI-assisted discovery can outrun maintainer coordination and patch pipelines.
The open-source RTS game Beyond All Reason signed a publishing partnership with Hooded Horse to fund its Steam release and long-term development, while saying the code stays open source, the BAR team keeps the IP, and the free multiplayer version remains available.
The European Social Stack declaration calls on governments, municipalities, public-service media, and civic institutions to publish on open European social platforms and fund resilient decentralized technologies such as the Fediverse, Atmosphere, Matrix, and XMPP.
The New Stack reports that Project Valkey used AI agents to backport bug fixes for its 9.1 release and scan code provenance, letting maintainers spend less time on manual cherry-picking while keeping human review in the loop.
Disrupt Africa says AgriOS, an open-source ERP for African agri-SMEs, has moved governance to the Linux Foundation as part of a distributed model meant to preserve shared infrastructure, let local service providers customize deployments, and sustain the project through downstream commercial users.
The Babel team released Babel 8 and warned that donations and sponsorships have fallen sharply, saying recent Sovereign Tech Agency support and Igalia engineering time were key to maintaining the JavaScript compiler's quality bar.
ownCloud said its web-extensions repository has been relicensed from AGPL-3.0 to Apache-2.0, the first result of a 108-repository OSPO-led relicensing program intended to make ownCloud more procurement-friendly and compatible with Apache Software Foundation policy.
The R Project announced that five R Core Team members received the $1 million Rousseeuw Prize for Statistics, with half of the prize going to those laureates and half shared among other active R Core Team members.
Minimus is offering qualified open source maintainers free access to thousands of hardened container images, including FedRAMP- and FIPS-ready images, custom image creation, supply-chain protection, compliance reporting, and signed SBOMs.
Andrew Nesbitt argues that open source libraries behave like public goods with few exclusion mechanisms, leaving maintainers, governments, companies, package managers, and marketplaces still searching for sustainable funding and governance models.
OpenSSL told contributors that non-trivial AI-generated submissions must be declared with an Assisted-by trailer and require the updated v1.1 contributor license agreement with AI clauses, giving reviewers new labels for AI-related CLA handling.
The Raku community launched an independent Raku Foundation to coordinate the language specification, support Rakudo, steward the ecosystem, and create dedicated representation and fundraising outside The Perl and Raku Foundation.
OpenAI's Vaibhav Srivastav said the company is committing $160,000 to sponsor maintainers behind the Astral and Codex toolchains, alongside an ongoing $1 million fund providing free Codex access to open source maintainers.
IT Brief reports that the LF AI & Data Foundation launched the DocLang Specification Working Group, bringing IBM, NVIDIA, Red Hat, ABBYY, and HumanSignal together under Joint Development Foundation governance to develop an open AI-native document format.
Contargo released its internally developed containerLib Java library as open source in the Open Logistics Foundation repository, framing container-number and truck-plate validation as shared logistics infrastructure rather than a competitive advantage.
Snyk launched its Secure Developer Program, giving open source maintainers free access to its AI Security Platform and opening a Snyk Remediation Agent preview to help triage and fix vulnerabilities.
Flarum said it purchased the formerly premium Audit extension code and is releasing it as a first-party open source audit-log feature, removing the previous free/pro split and bundling it with new Flarum 2.0 installs.
The Commonhaus Foundation announced that OkHttp, Okio, Retrofit, and SQLDelight have joined under the lysine.dev banner, bringing widely used Java and Kotlin networking and database libraries into the foundation as member projects.
LWN reports that the Software Freedom Conservancy published recommendations for FOSS contributors using LLM-backed generative AI systems, covering how to reduce harm from proprietary tools and protect free-software development workflows.
GitHub introduced configurable pull request limits to help open source maintainers manage surging contribution volume, including AI-agent pull requests and low-quality PR spam, with issue limits and cross-repository controls planned.
The Sovereign Tech Agency and the UN Office for Digital and Emerging Technologies are convening open source maintainers at UN Open Source Week 2026 for a second maintain-a-thon focused on sustaining critical digital infrastructure.
Elena Rossini reports that W Social, a European Bluesky fork adopted by public institutions, appears to have moved from public source repositories to closed-source development despite marketing around digital sovereignty and open source.
The Session Technology Foundation said community donations kept the open-source private messaging project from winding down after financial constraints forced layoffs, and outlined a leaner development plan focused on libsession, Session Pro Beta, and future grants or public funding.
The Cloud Native Computing Foundation announced 14 new Silver Members, Silver End Users, and a Non-Profit Member, citing continued enterprise adoption of cloud native infrastructure for platform engineering and AI workloads.
The Open Source Initiative published its 2025 annual report, covering licensing stewardship, policy work on cybersecurity and procurement, sustainability, financial performance, and calls for sponsor and member support.
Prismatic open-sourced its pre-built application connector and data platform component library under Apache-2.0, saying AI has made connector creation less differentiating while its commercial value remains in operating customer integrations at scale.
Phoronix reports that the rise of AI- and LLM-generated patches on mailing lists slowed ARM64 Linux kernel feature work for the 7.2 cycle, with maintainers postponing some features while handling the added review burden.
The eBPF Foundation opened applications for its 2026 Academic Research Grant Program, offering unrestricted grants of up to $50,000 for faculty pursuing original eBPF research in areas such as verification, security, and networking optimization.
wolfSSL explains that AI-driven vulnerability discovery has sharply increased the volume and severity of CVEs it reports per release, while AI slop reports have strained open source maintainers and the CVE system.
Element said the Digital Public Goods Alliance recognized Element as a Digital Public Good, and used the announcement to urge governments relying on Matrix-based open source communications to fund upstream vendors and the Matrix.org Foundation.
The Django Software Foundation said six Django agencies pledged $47,500 to fund the foundation's first Executive Director, a paid role intended to expand operations, fundraising, grants, and long-term framework sustainability.
FOSS Force reports that Linux Foundation Alpha-Omega funding is backing FreeBSD's effort to use AI tools and paid security staff to find and fix vulnerabilities across its open-source codebase.