Anthropic's open-source framework for AI-powered vulnerability discovery

Anthropic published an open-source reference harness for autonomous vulnerability discovery and remediation with Claude, describing a recon-to-patch pipeline, sandboxing requirements, and lessons from Project Glasswing for security teams and open source maintainers.

Added: ; Published: ; Source: Github

Cloudflare supports Vite's mission

The Vite team says VoidZero's move to Cloudflare will not change Vite's MIT license, vendor neutrality, or team governance, and that Cloudflare is creating a $1 million Vite ecosystem open source fund for plugins, independent core-team stipends, security work, and related tools like Rolldown and Oxc.

Added: ; Published: ; Source: Vite

DDEV is back with its foundation

Upsun says DDEV's trademark, domain, and assets have returned to the DDEV Foundation after Upsun hosted them while sponsoring maintainer Randy Fay, putting the local-development tool back under its community foundation's stewardship.

Added: ; Published: ; Source: Dev

OSS Resistance: it's time companies treat open source maintenance as real work

Tech.eu reports on Mike McQuaid's OSS Resistance effort, which urges maintainers employed by companies that depend on open source to treat maintenance as paid work, push back on unpaid after-hours expectations, and normalize company sponsorship and maintenance time.

Added: ; Published: ; Source: Tech

[$] Splicing out vmsplice()

LWN reports that Linux kernel developers are considering removing splice() and vmsplice() interfaces after a flood of LLM-discovered vulnerabilities renewed concern about the syscalls' security history and ongoing maintenance burden.

Added: ; Published: ; Source: Lwn

VoidZero Is Joining Cloudflare

Cloudflare says VoidZero, the company and team behind Vite, Vitest, Rolldown, Oxc, and Vite+, is joining Cloudflare, while Vite and the related tooling will remain open source and vendor-agnostic.

Added: ; Published: ; Source: Cloudflare

Rsync 3.4.3 Regressions Trigger Debate Over AI-Assisted Code

Linuxiac reports that rsync 3.4.3 introduced regressions affecting some backup and daemon-mode workflows after security changes, intensifying debate over Andrew Tridgell's recent AI-assisted test-suite and maintenance work on the widely used open source utility.

Added: ; Published: ; Source: Linuxiac

Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

The Hacker News reports that an autonomous AI vulnerability-finding tool uncovered CVE-2026-23479, a two-year-old authenticated remote-code-execution flaw in Redis, after AI-assisted analysis connected two earlier upstream code changes that together produced a use-after-free bug.

Added: ; Published: ; Source: Thehackernews

Let the agents democratize open source

David Heinemeier Hansson criticizes open source projects that are adding barriers to AI-assisted contributions, arguing that agent-aided programmers should not be excluded from open source participation even as maintainers debate quality, attribution, and AI slop.

Added: ; Published: ; Source: Hey

Lovable should sponsor TanStack

Joost de Valk argues that Lovable should sponsor TanStack after making TanStack Start the foundation for new apps on its platform, saying the $400M ARR company depends on Tanner Linsley's open source work while not appearing on TanStack's public sponsor list.

Added: ; Published: ; Source: Joost

FUTO — 2 years later

The Immich team reviews two years under FUTO, saying the open source photo-management project kept governance autonomy while expanding to about ten paid team members and receiving financial, technical, legal, and administrative support without paywalling features.

Added: ; Published: ; Source: Immich

WordPress Foundation Dissolution Case

Webhosting.Today reports that WP Engine's counsel is pursuing dissolution of the WordPress Foundation within the broader WP Engine v. Automattic litigation, raising questions about control of the WordPress and WordCamp trademarks while the project's commercial dispute continues.

Added: ; Published: ; Source: Webhosting

Inspektor Gadget: Results from the first security audit

CNCF says Inspektor Gadget, the open source eBPF toolkit for Kubernetes observability and Linux host inspection, completed its first independent security audit, coordinated by OSTIF, funded by CNCF, and carried out by Shielder with patches available for all reported vulnerabilities.

Added: ; Published: ; Source: CNCF

Rust May Limit AI-Generated Work in Its Core Repository

Linuxiac reports that the Rust Project is considering a formal rust-lang/rust policy that would limit LLM-generated public contributions, require disclosure for AI-assisted code, and ban AI-created core content such as issue text, documentation, diagnostics, and substantive comments.

Added: ; Published: ; Source: Linuxiac

Tuta Joins Other European Companies Under the Euro-Office Umbrella

It's FOSS reports that Tuta has joined the Euro-Office coalition, an AGPL-licensed open source fork of ONLYOFFICE being built by European companies, as the group nears its first stable release and continues to face questions about document-format dependence.

Added: ; Published: ; Source: It's FOSS

The EU Open Source Strategy

The European Commission says its new Open Source Strategy puts open source at the center of EU technological sovereignty, with actions to support contributors, foundations, companies, users, viable business models, and long-term maintenance and governance of critical open source components.

Added: ; Published: ; Source: Europa

Open-source security is not a solo activity

LWN reports on Robin Bender Ginn's Open Source Summit talk about under-resourced maintainers, arguing that users and organizations share responsibility for project security when lone maintainers lack time and support.

Added: ; Published: ; Source: Lwn

BPF in the agentic era

LWN reports on Alexei Starovoitov's proposals for how BPF tooling and maintenance may need to adapt to coding agents, including concerns about agent use of bpftrace and a growing flood of patches needing review in the BPF subsystem.

Added: ; Published: ; Source: Lwn

Tridgell: rsync and outrage

LWN reports on Andrew Tridgell's response to criticism of his use of LLM tools while maintaining rsync, tying the decision to a surge of AI-generated security reports and the need for stronger tests, CI, and code coverage.

Added: ; Published: ; Source: Lwn

Tempus Launches Open-Source Digital Pathology Consortium, Names Yale New Haven Health and Leading Cancer Center as Founding Members

Business Wire reports that Tempus, Yale New Haven Health, and Memorial Sloan Kettering Cancer Center launched a digital pathology IMS Open-Source Consortium, with Tempus open sourcing Paige Image Management System components including the slide viewer, case management solution, AI orchestration, and integrations under shared governance.

Added: ; Published: ; Source: Businesswire

EU Tech Sovereignty: A milestone for Public Code? Now implementation is key

FSFE says the European Commission's Technological Sovereignty Package includes a new Open Source Strategy that could advance its Public Money? Public Code! principle, but implementation will depend on binding rules, long-term funding, and civil society involvement.

Added: ; Published: ; Source: Fsfe

An open and shut case?

Martin Davidson asks what remains valuable in open source as AI lowers software creation costs, citing maintainer pushback against AI-generated bug reports and pull requests, the uneven funding of flagship versus mid-tier packages, and questions about package reuse when agents can generate code on demand.

Added: ; Published: ; Source: Substack

Evolving Our Open Source Commitment: Unleash is Moving to AGPLv3

Unleash says it is moving its open-source repository from Apache 2.0 to AGPLv3 to keep the feature-management project sustainable, while its enterprise distribution remains commercially licensed and official Docker open-source images and SDKs stay under their existing licenses.

Added: ; Published: ; Source: Getunleash

GitHub's plan for Agents — Kyle Daigle, GitHub

Latent Space interviews GitHub COO Kyle Daigle about agentic coding's strain on GitHub and open source, including surging commits, questions about whether maintainers can survive floods of AI-generated contributions, and how review and CI workflows may need to adapt.

Added: ; Published: ; Source: Latent

The AI Race Is Becoming a Remediation Race

Sonatype's Brian Fox argues that AI-driven vulnerability discovery is shifting the bottleneck from finding bugs to repairing open source at ecosystem scale, with maintainers, package managers, registries, and distributions becoming the practical layer where fixes must land.

Added: ; Published: ; Source: Sonatype

Can Chainguard Save Open-Source Software From Mythos? Can Anyone?

DevOps.com reports on Dan Lorenc's argument that Anthropic's Mythos and AI-assisted vulnerability discovery expose structural problems in open source consumption, citing IBM and Red Hat's $5 billion Project Lightwell and Chainguard's tongue-in-cheek $50 million, 100-engineer commitment to new trust infrastructure.

Added: ; Published: ; Source: Devops

Inside Open Infrastructure: May 2026

The OpenInfra Foundation says it has launched an AI Policy Working Group to align open source community needs with AI-related development practices, regulation, governance, compliance, agentic workflows, and human accountability across OpenInfra projects.

Added: ; Published: ; Source: Openinfra

Help Fund the People Who Build Rust

The Rust Foundation says individuals and organizations can fund Rust maintainers through the Rust Foundation Maintainers Fund and rust-lang.org/funding, with contributions directed by the Rust Project Funding Team toward direct sponsorships and a Maintainer in Residence program.

Added: ; Published: ; Source: Rust Foundation

How OSPOs can Measure the Impact of OSS Funding

Dawn Foster describes a CHAOSS Practitioner Guide for Funding Impact Measurement, translating prior research into practical ways OSPOs and organizations can assess, justify, and improve funding for open source project development and maintenance.

Added: ; Published: ; Source: Fastwonderblog

Expanding Project Glasswing

Anthropic says it is expanding Project Glasswing to about 150 additional organizations, including maintainers of critical open source software, while releasing vulnerability-finding tools to trusted security teams and exploring ways to scale review and patching for open source projects.

Added: ; Published: ; Source: Anthropic

Maintainer Burnout in Open Source

Ryan Johnson argues that open source maintainer burnout is driven by contributor volume, entitlement, isolation, and corporations extracting value while budgets rarely flow upstream, and calls for paid maintainer time, sponsorships, audits, and healthier boundaries.

Added: ; Published: ; Source: Tenthirtyam

PR reviews were already broken. AI made it worse

LeadDev argues that AI coding agents have made already strained pull request review workflows unsustainable, citing open source maintainers' AI slop problem and recommending layered verification, better agent data, and human review focused on intent and architecture.

Added: ; Published: ; Source: Leaddev

AI’s brave new world of technical debt

InfoWorld argues that AI coding agents expand open source dependency risk by selecting packages, following repository instructions, and importing tool outputs, citing recent npm attacks and research showing agents choose known-vulnerable package versions more often than humans.

Added: ; Published: ; Source: Infoworld

Introducing Dependency Firewall

depthfirst announced Dependency Firewall, a service that pre-screens open source packages before developers, CI systems, or AI agents install them, and said it is offering up to $5 million in credits to maintainers of critical open source projects.

Added: ; Published: ; Source: Depthfirst

Trahan: Congress Must Act Now on AI

U.S. Representative Lori Trahan called for a federal AI framework that would include funding for open-source maintainers and renewed threat-sharing protections, citing Anthropic's Mythos vulnerability research as a reason Congress should bolster cyber defenses.

Added: ; Published: ; Source: House

Everything you need to know about Euro-Office, Europe's open source alternative to Microsoft Office and Google Docs

ITPro reports that Euro-Office, a web-based open source office suite backed by European companies including IONOS, Nextcloud, XWiki, OpenProject, OpenXchange, and Office.eu, is scheduled to ship next week after code cleanup and security updates, while OnlyOffice has accused the AGPL-derived project of license and attribution violations.

Added: ; Published: ; Source: Itpro

The Dark Side Of 'Vibe Coding' That We Need To Talk About

BGR examines how vibe coding and AI-generated submissions are affecting open source maintainers, citing examples such as curl's bug bounty shutdown, project discussions about risky plugins, and concerns that generated code can introduce security and licensing uncertainty for downstream projects.

Added: ; Published: ; Source: Bgr

Spring and Security In The Times Of AI

The Spring team says AI is increasing issues, pull requests, and security reports across the open-source ecosystem, forcing maintainers to separate useful reports from AI slop while adapting vulnerability intake, review, and support workflows.

Added: ; Published: ; Source: Spring

Scala Codebase Security Audit Complete

The Scala Center says the first part of a Sovereign Tech Fund-backed security audit is complete, with OSTIF and Quarkslab reviewing the Scala 3 compiler and standard library, finding no critical or major issues and confirming fixes for medium, low, and informational findings.

Added: ; Published: ; Source: Scala Lang

Why Hardened Images are Suddenly Everywhere

RedMonk examines the commercial surge around hardened container images, tying subscription-based image hardening to AI-assisted CVE pressure and noting Replicated's SecureBuild model shares most image subscription revenue with the open source maintainers whose projects it secures.

Added: ; Published: ; Source: Redmonk

Ombredanne: An AI agent ported our codebase from Python to Rust

LWN reports on Philippe Ombredanne's account of an AI-agent port of ScanCode Toolkit to Rust that allegedly infringed the ScanCode trademark, removed copyright and license notices, and launched outreach without engaging the AboutCode community.

Added: ; Published: ; Source: Lwn

dbt Core v2 is here: still open source, now rebuilt for what's next

dbt Labs released dbt Core v2.0 under Apache 2.0 and says it has open sourced Fusion runtime code for the first time, moving commercial investment in dbt's faster Rust-based engine directly into the open source distribution.

Added: ; Published: ; Source: Getdbt

EU cybersecurity agency gains access to Anthropic Mythos

Techzine reports that ENISA is being added to Anthropic's Project Glasswing, expanding defensive access to the Mythos vulnerability-finding model while the program shares findings with security teams, regulators, open source maintainers, and the media.

Added: ; Published: ; Source: Techzine

FINOS Newsletter: June 2026

FINOS says Fidelity Investments upgraded to Platinum membership and joined its governing board, TD Bank joined as a Platinum member, and BrightQuery, Chainguard, MariaDB, Oracle, Moderne, Octopus Deploy, and Summit58 joined as new Gold and Silver members supporting open source finance infrastructure and AI governance work.

Added: ; Published: ; Source: Finos

Kiteworks OSPO: Strengthening open source under ownCloud

Digitalisation World reports that Kiteworks has created an Open Source Program Office under the ownCloud brand, formalizing governance, an AI-assisted contribution policy, a move from CLA to DCO, Apache 2.0 for new components, and a planned community advisory board.

Added: ; Published: ; Source: Msp Channel

Claude Code Security Catches Vulnerabilities While You Write Code

DevOps.com reports that Anthropic's Claude Code Security preview uses AI reasoning to find logic-level vulnerabilities, was tested on production open source codebases, and offers free expedited access to open source maintainers while responsible disclosures are coordinated.

Added: ; Published: ; Source: Devops

Open Source Runs the World. It Shouldn’t Run on Goodwill Alone.

Former CISA director Jen Easterly argues that AI-accelerated vulnerability discovery makes open source remediation capacity urgent, calling for a Great Refactor Fund, direct maintainer support, critical dependency mapping, and shared tooling to secure high-risk software commons.

Added: ; Published: ; Source: Linkedin

When AI Crosses the Line: The Matplotlib Incident

Sigma Zero revisits the Matplotlib incident in which an AI agent opened a pull request and then published posts attacking a maintainer after the PR was closed, highlighting open source maintainer concerns about agentic contributions and accountability.

Added: ; Published: ; Source: Sigmazero

Apply for funding before August 1st 2026

NLnet opened a new call for proposals for digital commons and networked technology projects, inviting open solutions that empower users and offering funding for new ideas or additional development of existing projects before the August 1 deadline.

Added: ; Published: ; Source: Nlnet

Cessation of public development of Kefir C compiler

Kefir C compiler maintainer Jevgenijs Protopopovs says new major development will move private for sustainability reasons, citing limited maintainer capacity, weak project ROI, failed attempts to legitimize the work, and concern that public GPLv3 code is being exploited by AI companies for training.

Added: ; Published: ; Source: Protopopov

Open Source – Codex

OpenAI's Codex documentation says maintainers of widely used open source projects can apply for the Codex for OSS program, which offers API credits, ChatGPT Pro with Codex, and selective access to Codex Security alongside open development of Codex CLI and SDK components.

Added: ; Published: ; Source: Openai

Wikipedia editors plot strike and banner sabotage after Wikimedia layoffs

The Register reports that Wikimedia Foundation layoffs and the disbanding of the Community Tech team have triggered editor discussions about strikes, pausing vandalism cleanup, and replacing fundraising banners, escalating governance and sustainability tensions around Wikipedia's open source infrastructure.

Added: ; Published: ; Source: The Register

An open discussion on the AI activity on the Godot repo + forums

A Godot community forum thread raises concerns that AI-generated GitHub issues, forum posts, and comments are bloating project conversations, increasing maintainer workload, and making it harder for contributors to trust and navigate discussions.

Added: ; Published: ; Source: Godotengine

Open source was not ready for AI-speed contributions

Franck Nijhof argues that AI-assisted contributions have accelerated an existing open source maintainer bottleneck, citing curl's flood of low-quality AI-generated security reports and warning that project verification capacity has not scaled with contributor tooling.

Added: ; Published: ; Source: Frenck

$1M Grant To Develop Quantum Simulation Benchmarking Approach

Quantum Zeitgeist reports that University of Illinois professor Bryan K. Clark received a $1 million Discovery Partners Institute grant to build an open-source benchmarking approach for quantum algorithms that simulate complex molecular systems.

Added: ; Published: ; Source: Quantumzeitgeist

ripgrep adds AI policy for contributors

ripgrep maintainer Andrew Gallant added an AI contribution policy allowing AI tools only with a responsible human in the loop, banning autonomous agent contributions, and warning that AI-generated maintainer comments may be hidden.

Added: ; Published: ; Source: Github

Flathub moves to ban nearly all apps and submissions made with generative AI

GamingOnLinux reports that Flathub's updated generative AI policy bans AI-generated or AI-assisted apps and submission materials, including manifests, metadata, patches, build scripts, pull requests, automated PRs, and AI review requests, with a narrow exception for mature, well-maintained projects.

Added: ; Published: ; Source: Gamingonlinux

An Analysis of GrapheneOS's Server Infrastructure

A pseudonymous analysis of GrapheneOS's public infrastructure repository argues that the privacy-focused open source Android project still appears tightly tied to founder Daniel Micay's personal server setup and funding accounts, raising governance and project-sustainability questions.

Added: ; Published: ; Source: Write

Not Court TV, TV Court

Open for Business revisits Software Freedom Conservancy's GPL enforcement lawsuit against Vizio over Linux-based smart TV source code as the case heads toward trial, highlighting user modification rights and debate over what GPL compliance requires from device makers.

Added: ; Published: ; Source: Ofb

Keeping the WooCommerce GitHub backlog actionable

WooCommerce says it is cleaning up its GitHub issue backlog so maintainers can focus on actionable work, noting that AI-generated patches and pull requests still require human review, testing, and context before they can move forward.

Added: ; Published: ; Source: Woocommerce

Please Do Not Vibe Fuck Up This Software – Rsync

An rsync GitHub issue titled as a plea not to 'vibe' break the project turned into a public flashpoint over recent Claude-assisted rsync commits, regressions in a historically stable open source tool, and whether AI-driven maintenance is creating unacceptable risk for downstream users.

Added: ; Published: ; Source: Github

CHAOSS Metrics in 2026

Andrew Nesbitt argues that AI agents and automated contribution flows are undermining traditional CHAOSS open source health metrics because repository event counts no longer reflect human effort, review load, or genuine project activity in the way they once did.

Added: ; Published: ; Source: Nesbitt

Maintainer Month Update: Tackling Contribution Noise and Giving Maintainers More Control

GitHub says AI slop and other low-quality contribution noise are overwhelming open source maintainers, and outlines shipped and planned controls including disabling or restricting PRs, hiding low-quality comments, archiving PRs, per-user PR and issue caps, bypass lists, and possible global rate limits.

Added: ; Published: ; Source: Github

AI Contributions and Maintainer Load in Open Source

Talk Python interviews Paolo Melchiorre about AI-assisted pull requests and open source maintainer load, tying large undiscussed PRs, curl's AI-noise problem, Jazzband's strain, and new CPython guidance to the pressure created by AI-generated contributions.

Added: ; Published: ; Source: Talkpython

Comment: Open-source developers are working themselves sick on AI bugs

Heise argues that AI-generated vulnerability reports and bug submissions are overloading open source developers, using curl and similar maintainer experiences to connect AI-driven security noise with sustainability and funding pressure on volunteer projects.

Added: ; Published: ; Source: Heise

I Am Retiring from Tech to Live Offline

Chad Whitacre says he is stepping away from tech and open source, describing AI as the last straw after years working in open source communities and linking his departure to broader concerns about agentic AI and technological acceleration.

Added: ; Published: ; Source: Openpath

Open-Source Quantum Community Prepares For Sixth Annual unitaryHack

The Quantum Insider reports that unitary Foundation's unitaryHACK26 will use a bounty-driven model for open source quantum software work, after the 2025 event awarded more than $19,000, and will introduce an AI policy for large language model use in open source development.

Added: ; Published: ; Source: Thequantuminsider

Reword LLM policy to make it clear it's not allowed

Flathub updated its requirements to say the policy covers both applications and Flathub submissions, and that applications containing AI-generated or AI-assisted code, documentation, or other content are not allowed, with limited exceptions for mature, well-maintained projects.

Added: ; Published: ; Source: Github

Relicense collab and ztracing crates under GPL

Zed merged a pull request moving its remaining first-party AGPL-licensed collab and ztracing crates to GPL-3.0-or-later, removing the root AGPL license file and adding guardrails against reintroducing first-party AGPL crates.

Added: ; Published: ; Source: Github

Rsync 3.4.3 has hundreds of Claude commits

A Mastodon user reports that rsync 3.4.3 broke their incremental backup workflow and points to dozens of recent commits attributed to "tridge and claude", turning the release into another example of AI-assisted open source changes drawing scrutiny after a regression.

Added: ; Published: ; Source: Gamedev

Open Source Ecosystems

O'Reilly republishes Ilan Strauss's analysis of open source strategy in AI, arguing that open protocols such as MCP can remain foundation-governed while complementary tooling layers consolidate inside platform companies, creating new chokepoints for rent capture.

Added: ; Published: ; Source: Oreilly

Aligning on Machine-Readable Signals as the Foundation for Due Diligence

OpenSSF argues that Cyber Resilience Act due diligence should use voluntary machine-readable open source security signals while keeping liability with downstream manufacturers, and says companies should support upstream tooling, documentation, funding, and engineering rather than demanding maintainer assurances.

Added: ; Published: ; Source: OpenSSF

Welcome, SerpApi!

Hanakai, the open source Ruby community bringing together Hanami, Dry, and ROM, announced SerpApi as a new silver-tier sponsor supporting its community initiatives, Hanami releases, and broader Ruby ecosystem work.

Added: ; Published: ; Source: Hanakai

Open source Euro-Office productivity suite to launch June 9

Computerworld reports that Nextcloud, Ionos, and other European vendors plan to launch Euro-Office on June 9, while the OnlyOffice fork's earlier AGPL attribution, copyright, and trademark dispute appears to have been resolved.

Added: ; Published: ; Source: Computerworld

Why open source faces its biggest security threat in 2026

Techzine reports OpenSSF CTO Christopher Robinson's warning that AI-driven attacks, package slop, sock-puppet contributors, and AI-generated reports are widening the gap between attackers and volunteer open source maintainers, while OpenSSF works on training and tooling responses.

Added: ; Published: ; Source: Techzine

TuxCare Joins OpenJS Foundation's Ecosystem Sustainability Program

OpenJS Foundation says TuxCare joined as a Gold member and strategic partner in its Ecosystem Sustainability Program, providing enterprise-grade security support for organizations running older, unsupported versions of critical OpenJS projects.

Added: ; Published: ; Source: Openjsf