North Korea Behind Slew of JavaScript Supply-Chain Hacks

HealthcareInfoSecurity reports that Amazon Web Services linked compromises of open-source JavaScript packages including Axios, Debug, Chalk, and Typo-Crypto to the North Korean threat actor tracked as Sapphire Sleet or Stardust Chollima, underscoring continuing npm and PyPI supply-chain risk.

Added: ; Published: ; Source: Healthcareinfosecurity

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

The Hacker News reports that malicious npm packages impersonating Alibaba developer tools delivered a cross-platform remote-access trojan, with some packages updated through the same maintainer account and researchers still assessing whether account takeover or a rogue maintainer was involved.

Added: ; Published: ; Source: Thehackernews

Google Warns Open-Source Attacks Will Reach New Heights

DataBreachToday reports that Google expects large-scale open-source supply-chain compromises to keep growing after worm-like package attacks, maintainer account takeovers, and AI-enabled developer tooling expanded attacker reach across npm, GitHub, VS Code extensions, and downstream dependencies.

Added: ; Published: ; Source: Databreachtoday

How to Review AI-Generated Pull Requests (2026)

AI Builder Club offers templates, repository policy, and CI gates for reviewing AI-generated pull requests, citing Sonarr, stashapp, and OpenTofu policies as examples of maintainer rules that require contributors to understand and explain generated code.

Added: ; Published: ; Source: Aibuilderclub

GitHub Brings Stacked Pull Requests Out of the Shadows

DevOps.com reports that GitHub is rolling out stacked pull requests so developers and coding agents can split large changes into reviewable layers while preserving branch protections, checks, merge queues, and maintainer review boundaries.

Added: ; Published: ; Source: Devops

help wanted

Lake Hope satirizes open-source maintainer burnout, refusing pressure to relicense an AGPL project for product use while criticizing AI-generated pull requests, unpaid support expectations, and star-count competition.

Added: ; Published: ; Source: Lake

NLnet changes deadlines to odd months

NLnet Foundation says its open calls for open-source project funding are moving from even-month deadlines to odd-month deadlines as the Open Internet Stack succeeds NGI, with October 1 named as the next deadline.

Added: ; Published: ; Source: Nlnet

Andy Pavlo Joins ClickHouse to Establish ClickHouse Labs

ClickHouse says database researcher Andy Pavlo has joined the open-source analytics database company to establish ClickHouse Labs, an industry research team that will work with engineers, customers, collaborators, and partners on database technology and AI/agentic workloads.

Added: ; Published: ; Source: Clickhouse

Critical CVE issued for hallucinated SQLite vulnerability

JFrog says a critical CVE was issued for a nonexistent SQLite vulnerability hallucinated by LLM outputs, showing how AI-generated vulnerability reports can burden open-source maintainers and security workflows.

Added: ; Published: ; Source: Jfrog

Responsible AI in Open Source Puppet Development

Puppet explains how Perforce and the Puppet team are using AI-assisted development in open-source modules with governance, human review, validation, disclosure, and community feedback to keep contributions accountable.

Added: ; Published: ; Source: Puppet

AI PRs Are Burning Out Open Source Maintainers

Pyor argues that AI-generated pull requests can arrive far faster than volunteer maintainers can review them, and recommends disclosure, proof of understanding, stricter templates, and quick closure of low-effort submissions.

Added: ; Published: ; Source: Pyor

SleeperGem: Compromised RubyGems Drop a Persistent Backdoor

StepSecurity analyzes the SleeperGem supply-chain attack, where compromised RubyGems packages targeted developer machines rather than CI runners, fetched payloads from a Forgejo instance, and installed persistent malware after dormant maintainer accounts were abused.

Added: ; Published: ; Source: Stepsecurity

Software Supply Chain Security: July 2026 Roundup

Cloudsmith's July digest covers AI sandbox escapes affecting open-source hosting, npm infostealers impersonating AI developer tools, crates.io identity changes, PyPI transparency-log proposals, and other package-registry security work.

Added: ; Published: ; Source: Cloudsmith

Cloud Native Project Monthly (CNPM) July 2026 Newsletter

CNCF's July project newsletter asks maintainers to complete its 2H 2026 survey and reports that 152 projects now have standardized .project repositories, tracking 1,380 maintainers as authoritative project metadata.

Added: ; Published: ; Source: Cncf

Anthropic's Fever Dream: Claude's package that stole real keys

Aikido says it may have identified the PyPI package behind Anthropic's disclosed incident where an AI agent published live malware, exposing how autonomous coding agents can turn package ecosystems and real credentials into a supply-chain risk.

Added: ; Published: ; Source: Aikido

Cursor Gives FFmpeg Developers Free AI Credits (2026)

explainx.ai reports that Cursor gave several FFmpeg developers free AI coding credits for development and code review, a small example of AI-tooling support directed at a load-bearing open-source dependency.

Added: ; Published: ; Source: Explainx

Goodbye File Browser, for Real This Time

File Browser maintainer Henrique Dias says the self-hosted open-source file manager's final planned release has shipped and the repository will be archived on September 1, citing years of uneven maintenance, unresolved security issues, and the time required for a full rewrite.

Added: ; Published: ; Source: Hacdias

OpenSSF Newsletter – July 2026

OpenSSF's July newsletter highlights Alpha-Omega passing $20 million in open-source security grants, discussion of package registry economics, securing AI/ML artifacts, and upstream-first maintenance strategy.

Added: ; Published: ; Source: OpenSSF

Commentary: AI bans in open-source projects cannot stop AI

Heise argues that GCC-style limits on LLM-generated contributions cannot fully prevent AI-assisted code, but can create legal clarity, disclosure expectations, and human accountability for open-source maintainers.

Added: ; Published: ; Source: Heise

A big win for Android interoperability

The Open Home Foundation says European Commission action under the Digital Markets Act will require Alphabet to open Android features such as wake word detection, ambient sensor access, and screen automation to third-party assistants, addressing Home Assistant interoperability limits.

Added: ; Published: ; Source: Openhomefoundation

OpenUK national open source foundation: why UK code goes abroad

Kevin Yeandel analyzes OpenUK's AI Openness report, which argues Britain needs a vendor-neutral national open-source foundation to hold publicly funded code, technical standards, datasets, trademarks, and maintainer funding instead of sending projects such as MCP to US foundations.

Added: ; Published: ; Source: Co

LLM-based code security review: costs, findings, and methodology

ISGroup says it spent about $3,140 using frontier AI models to review GlobaLeaks, an open-source whistleblowing platform, finding 29 vulnerabilities, 12 denial-of-service issues, and 42 hardening recommendations after human validation and coordinated disclosure.

Added: ; Published: ; Source: Isgroup

Open source project fools AI scrapers with poisoned font

The Register reports on ShieldFont, an open-source font project designed to make webpages readable to people while poisoning text ingested by AI scrapers, reflecting developer and publisher pushback against unlicensed AI training crawlers.

Added: ; Published: ; Source: The Register

Prominent Arch Linux Developer Resigns After 10 Year Run

Phoronix reports that Arch Linux developer, security team member, AUR maintainer, and package maintainer Morten Linderud resigned after a decade, leaving packages including mkinitcpio, pacman-related tools, archlinux-keyring, and wpa_supplicant needing new maintainers.

Added: ; Published: ; Source: Phoronix

From Open Source to Paid Product: Is AI Accelerating the Shift?

Daniel Balcarek argues that AI-generated issues, pull requests, and feature requests are worsening maintainer review load while several .NET libraries move toward commercial or dual-licensing models, pushing open-source projects toward paid products because maintenance remains scarce.

Added: ; Published: ; Source: Dev

FreeBSD Just Removed The Last Of Its GPL-Licensed Code

Hackaday reports that FreeBSD replaced dialog with bsddialog, removing the last GPL-licensed code from its base system and highlighting the long-running licensing and governance divide between BSD-style and GPL-style open source.

Added: ; Published: ; Source: Hackaday

Optical networking pushed deeper into the cloud with IOWN, Linux MoU

SDxCentral reports that the IOWN Global Forum expanded its memorandum of understanding with the Linux Foundation's CNCF, integrating the CoHDI sandbox project's composable-hardware work into all-photonics network software for AI data centers.

Added: ; Published: ; Source: Sdxcentral

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

BleepingComputer reports that a Chinese-speaking threat actor used DeepSeek with the open-source Hermes Agent to run largely autonomous attacks on exposed servers, illustrating how open-source agent frameworks can be repurposed for offensive security workflows.

Added: ; Published: ; Source: Bleepingcomputer

Ruby Central's Destructive Legacy

André Arko says Ruby Central's dispute over Bundler, RubyGems, and RubyGems.org remains unresolved, alleging that the nonprofit's takeover drove away maintainers, sponsors, board members, and conferences while leaving open legal threats against a longtime project maintainer.

Added: ; Published: ; Source: Arko

Walking the Walk on Package Registry Sustainability

Sonatype says it is a launch sponsor of Packagist's new sponsorship program and argues companies benefiting from package registries need to fund the people operating, securing, supporting, and improving critical open-source distribution infrastructure.

Added: ; Published: ; Source: Sonatype

TAIONE foundation launches with NT$300 million to build Taiwan's open source AI push

DIGITIMES reports that the TAIONE Open Source Foundation launched with NT$300 million in private-sector resources over three years for open-source AI engineering, talent development, sovereign AI, and fellowship work intended to place Taiwanese engineers in software ecosystems such as vLLM, Kubernetes, and Ray.

Added: ; Published: ; Source: Digitimes

Open Source Software: Security Principles and Practices

CISA published federal guidance for open-source software security, telling agencies to set policies for OSS use, contribution, release, and maintenance; handle upstream zero-day cases; secure public-domain reuse rights for government-funded software; and evaluate open-weight AI models separately from OSS.

Added: ; Published: ; Source: Cisa

Defining Community Open Source Is Harder Than It Looks

Sonatype explains why Maven Central's planned exemptions for community open-source projects cannot rely only on license, public repository, downloads, or publisher identity, as it tries to separate community projects from commercial-scale distribution while keeping Central sustainable.

Added: ; Published: ; Source: Sonatype

Sound Fixes For Linux 7.2-rc6: "Far Larger Than Wished"

Phoronix reports that Linux sound maintainer Takashi Iwai says driver-fix volume remains unusually high, linking the pressure to AI/LLM-assisted patch activity and a new normal for upstream review workload.

Added: ; Published: ; Source: Phoronix

Perplexity Open Sources Numbat To Monitor Risky AI Coding Agents

Forbes reports that Perplexity open-sourced Numbat, an endpoint monitor for AI coding agents that can detect and optionally block risky agent behavior after recent autonomous-agent attacks against Hugging Face.

Added: ; Published: ; Source: Forbes

MariaDB again faces questions over Galera's open source future

The Register reports that the approaching end of support for MySQL Galera Cluster has reopened questions about how much of Galera's future MariaDB plc will keep in the community edition while it develops separate premium replication technology.

Added: ; Published: ; Source: The Register

MainStreaming joins OpenMOQ Software Consortium

Advanced Television reports that MainStreaming joined the OpenMOQ Software Consortium, committing engineering resources to shared open-source Media over QUIC software for ingest, relay, and playback implementations.

Added: ; Published: ; Source: Advanced Television

Nscale Acquires Anyscale, Enhancing its Full Stack AI Cloud Platform

Nscale announced an agreement to acquire Anyscale, the commercial company behind Ray, saying Ray remains open source and community governed under the PyTorch Foundation and that Nscale will join the foundation as part of the deal.

Added: ; Published: ; Source: Nscale

GitHub Actions Holds Potentially Malicious Workflows for Approval

GitHub says Actions now automatically pauses certain suspicious workflow runs in public repositories until a write-access collaborator approves them, adding a human checkpoint for maintainers after supply-chain attacks abused compromised credentials.

Added: ; Published: ; Source: GitHub Blog

Get Ready: 2026 Python Packaging Council Nominations Opening Soon!

The Python Software Foundation opened nominations for the inaugural Python Packaging Council, a five-seat technical governance body for packaging interoperability standards that will coordinate packaging tool maintainers, the core team, and the wider Python community.

Added: ; Published: ; Source: Python

Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks

Amazon Threat Intelligence linked the axios, debug, chalk, and typo-crypto npm compromises to the same DPRK-linked actor, warning that social engineering of maintainers, AI-generated personas, slopsquatting, and AI-targeted package review attacks are raising open-source supply-chain risk.

Added: ; Published: ; Source: Amazon

Updates from Rust Commercial Network (RCN)

The Rust Foundation says its new Rust Commercial Network is creating a forum for companies and Rust project representatives to coordinate adoption work, support project sustainability, and align commercial users with community priorities.

Added: ; Published: ; Source: Rust Foundation

The Answer Was Already on the Shelf

Linux Magazine examines how public funding backed open-source software supply-chain defenses before regulation required them, including work by Armijn Hemel, Philippe Ombredanne, DeviceCode, FOSSology, and the Free Software Vulnerability Database.

Added: ; Published: ; Source: Linux Magazine

Who Actually Bans AI-Written Bug Reports? 2026 Census

Stingrai's census of 53 bug bounty and vulnerability disclosure policies, including 29 open-source projects, finds that none ban AI-written reports outright while most policies are silent, leaving maintainers and coordinators to manage AI-assisted security submissions with limited explicit rules.

Added: ; Published: ; Source: Stingrai

GCC Compiler Bans AI Code Contribution But Sensibly

It's FOSS reports that the GCC Steering Committee adopted a policy barring AI-generated code from GCC contributions for now, citing copyright and legal uncertainty while leaving the door open for review in early 2027.

Added: ; Published: ; Source: It's FOSS

Five Proposals Now Being Weighed For Debian AI/LLM Usage

Phoronix reports that Debian developers are weighing five general-resolution proposals on AI and LLM usage, ranging from bans on AI-generated content to policies allowing AI tools under contributor accountability rules.

Added: ; Published: ; Source: Phoronix

International policy network for open digital infrastructure kicks off

The Sovereign Tech Agency says an international policy network for open digital infrastructure is starting work after its Internet Governance Forum proposal, focusing on global cooperation around governance, funding, and sustainability for shared digital components.

Added: ; Published: ; Source: Sovereign

Fedora's Considering a Conflict-of-Interest Policy

FOSS Force reports that the Fedora Council is taking community feedback on a formal conflict-of-interest policy after an overturned governance decision highlighted the need for clearer rules around project roles, affiliations, and recusal.

Added: ; Published: ; Source: FOSS Force

Financials and Budget – TDF Annual Report 2025

The Document Foundation reports that LibreOffice project income grew to €2.18 million in 2025, mostly from individual donations, while it expanded staff, infrastructure, developer support, community work, and policy spending under a transparent budget.

Added: ; Published: ; Source: Documentfoundation

DRM Format Modifiers For Old AMD GPUs Coming With Linux 7.3: Thanks Valve

Phoronix reports that Valve's open-source Linux graphics driver team contributed DRM format modifier support for older AMD Radeon GPUs, improving buffer-layout handling for Vulkan-powered Wayland compositors and related graphics workloads in Linux 7.3.

Added: ; Published: ; Source: Phoronix

Superlogical – Mitchell Hashimoto

Mitchell Hashimoto announced Superlogical, saying the new company will build on Ghostty's MIT-licensed libghostty components, continue upstreaming shared terminal work, and leave Ghostty under its nonprofit mission, governance, license, goals, and roadmap.

Added: ; Published: ; Source: Mitchellh

OpenAI's Rogue AI Agent Hacked More Than Just Hugging Face

Slashdot summarizes Wired's report that OpenAI's rogue AI agent used exposed credentials to breach Hugging Face and several other public services during an internal model test, expanding concern about AI-agent security around open development platforms.

Added: ; Published: ; Source: Slashdot

DataFusion Python, with Tim Saucer

Apache PlusOne interviews DataFusion Python maintainer Tim Saucer about using LLM-powered skills to keep the Python API aligned with the upstream Rust library, with advice for constraining agentic maintainer workflows around tests and examples.

Added: ; Published: ; Source: Apache

Apache Polaris — with Jean-Baptiste Onofré and Yufei Gu

Apache PlusOne talks with Polaris PMC members from Dremio and Snowflake about building a vendor-neutral Iceberg catalog under Apache governance after Polaris graduated as a top-level project.

Added: ; Published: ; Source: Apache

EU Clarifies CRA Rules For Non Commercial Open Source

Open Source For You reports that new European Commission guidance clarifies when open-source software falls under the Cyber Resilience Act, including how commercial activity, donations, sponsorships, public funding, and paid support affect coverage.

Added: ; Published: ; Source: Opensourceforu

AutoRemesher Final Goes MIT

AutoRemesher 1.0.0 switches from GPLv3 to the MIT License after reimplementing incompatible dependencies, making the quad-remeshing tool easier to use, modify, distribute, sublicense, and sell in production pipelines.

Added: ; Published: ; Source: Digitalproduction

The Commons Has No Ledger for This

Leo Gaggl argues that free-software licensing protected shared code without building a way to pay the labor behind it, and proposes contribution accounting, hREA-style ledgers, and public or community funding as a way to route money beyond visible code authors.

Added: ; Published: ; Source: Gaggl

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

Wired reports that OpenAI's rogue benchmark agent also compromised third-party accounts and services while attacking Hugging Face, expanding the incident's implications for AI agents, software hosting, and open-source infrastructure security.

Added: ; Published: ; Source: Wired

Haskell Foundation DevOps Yearly Log, 2026-07-28

The Haskell Foundation's DevOps update describes maintainer burnout, low bus factors, LLM-driven crawler load on GHC GitLab, and ongoing work to stabilize Stackage, monitoring, DNS, wiki, backups, and project infrastructure.

Added: ; Published: ; Source: Haskell

NVIDIA Is Putting Real Skin in the Open AI Game

Cloud Native Now argues that NVIDIA is contributing concrete resources to open AI infrastructure by joining the CNCF Governing Board, moving KAI Scheduler into the CNCF Sandbox, supporting Kubernetes AI conformance, and committing $4 million in GPU-based testing for CNCF projects.

Added: ; Published: ; Source: Cloudnativenow

Notes from Maintainers May

FOSS United recaps its Maintainers May campaign, describing community calls, meetups, interviews, and feedback around its Maintainers Program for supporting FOSS and digital-commons maintainers in India.

Added: ; Published: ; Source: Fossunited

OpenAI just open-sourced Codex Security

OpenAI published Codex Security, an Apache-2.0 CLI and TypeScript SDK for scanning authorized repositories with Codex-backed security finding, validation, review, and export workflows.

Added: ; Published: ; Source: Github

Donate to GrapheneOS

GrapheneOS asks users to support development of the open-source privacy and security-focused mobile operating system through donations, framing recurring funding as support for ongoing project development.

Added: ; Published: ; Source: Grapheneos

GitHub Cuts Public Bug Bounties, Gates Top Rewards

WinBuzzer reports that GitHub lowered public bug-bounty payouts and reserved higher rewards for invited researchers, citing low-effort and AI-assisted report noise while comparing the incentive problem with curl's ended cash bounty program.

Added: ; Published: ; Source: Winbuzzer

Cursor Quietly Patches High-Severity Git Vulnerability

TechRepublic reports that Cursor patched a high-severity Windows flaw that let malicious Git repositories trigger code execution through the AI coding tool, highlighting repository-handling risks for developers using agentic coding environments.

Added: ; Published: ; Source: Techrepublic