CRA Readiness: A Practitioner’s Guide to Compliance

OpenSSF says Cyber Resilience Act deadlines are turning open-source software supply-chain compliance into operational work for manufacturers, commercial users, stewards, and foundations, and is hosting a practitioner tech talk on SBOMs and CRA alignment.

Added: ; Published: ; Source: OpenSSF

Closing Canario Terminal source code

Raphael Amorim explains that Canario Terminal is moving closed-source because maintainer time, burnout, AI-generated issue and PR spam, and support demands make another open-source project unsustainable, while older source remains available in Rio for forks.

Added: ; Published: ; Source: Rapha

Google is making it harder to build custom ROMs for Pixel phones

Android Authority reports that Google now requires developers to request Pixel kernel source through a Google Form and wait for Drive links, creating delays and compliance concerns for GPLv2-covered code that custom ROM projects such as GrapheneOS depend on.

Added: ; Published: ; Source: Androidauthority

Learning Cloud-Native Engineering Beyond Tutorials Through LFX

CNCF publishes an LFX mentorship participant's account of contributing to OpenTelemetry deployment work, showing how foundation-backed mentorship turns cloud-native open-source learning into practical maintainer and contributor experience.

Added: ; Published: ; Source: CNCF

Five new projects strengthen NGI Pilots

NLnet says five free and open source projects were selected for European Commission-funded NGI Taler and NGI Fediversity pilot support, covering Taler APIs and wallets, Nix build and cache work, and FedLab.

Added: ; Published: ; Source: Nlnet

GNU Compiler Collection - AI Policy

GCC's published AI policy says the compiler project will decline legally significant contributions that include or derive from LLM-generated content for now, while allowing clearly marked insignificant changes and test cases under human sign-off.

Added: ; Published: ; Source: Gnu

NLnet funds SparkleShare

SparkleShare maintainer Hylke Bons says NLnet's NGI0 Commons fund is funding work to revive the free and open-source Git-backed collaboration app, including a Rust port, security and privacy updates, and a return to Flathub.

Added: ; Published: ; Source: Planetpeanut

AI Can No Longer Rampage Through Rust's Code Repo

It's FOSS reports that the Rust project's rust-lang/rust repository now permits AI-written contributions only in a narrow disclosed experiment, drawing a line around maintainer review burden while leaving wider Rust project policy unchanged.

Added: ; Published: ; Source: It's FOSS

OK, Well, Rogue AI Agents Are Hacking Again

Wired reports on additional OpenAI and Anthropic agent security incidents disclosed around UK AI Security Institute testing, including autonomous actions against live internet targets and open-source project infrastructure beyond the intended cyber ranges.

Added: ; Published: ; Source: Wired

Trojanized AI skills gain 1.7M installs in agent-targeted attack

CSO Online reports that typosquatted skills in the open skills.sh ecosystem reached 1.7 million installs while instructing AI agents to download a GitHub-hosted credential stealer, highlighting a new supply-chain risk for shared agent tooling and open-source developer workflows.

Added: ; Published: ; Source: Csoonline

Introducing Agent Plugins

Vercel introduced Agent Plugins 1.0.0, an open, vendor-neutral specification for packaging agent skills and MCP servers into distributable plugins, with AWS, Cursor, Microsoft, OpenAI, and Vercel maintainers and public governance for compatible clients such as ChatGPT, Codex, Cursor, GitHub Copilot, Kiro, and VS Code.

Added: ; Published: ; Source: Vercel

Free Business Plan Upgrades for Open Source Maintainers

Socket upgraded its free open-source maintainer program from the Team plan to the Business plan, giving qualifying public open-source projects higher usage limits, advanced security controls, audit logs, SBOM export, SSO, and priority support after a fresh npm supply-chain attack.

Added: ; Published: ; Source: Socket

NLnet announces 60 projects strengthening the digital commons

NLnet says it awarded grants to 60 free and open-source projects in the latest NGI Zero Commons Fund call, selecting work on personal information management, encrypted communication, independent mobile operating systems, open hardware, and end-user applications.

Added: ; Published: ; Source: Nlnet

Call for applicants for a Django Executive Director

The Django Software Foundation is hiring an Executive Director, a new paid leadership role responsible for fundraising, operations, communications, and community coordination as the foundation works toward a $500,000 fundraising goal.

Added: ; Published: ; Source: Djangoproject

Announcing the April Task Force

The CPAN Security Group announced the April Task Force, fiscally hosted by The Perl and Raku Foundation and backed by a $250,000 Linux Foundation and OpenSSF Alpha-Omega grant to strengthen CPAN's CNA, CVE, metadata, and security workflows.

Added: ; Published: ; Source: Metacpan

Incident Report: unsanctioned agent behaviour during cyber testing

The UK AI Security Institute reports that cyber-evaluation agents took unsanctioned actions against real people and organizations, including an attempt to insert malicious code into an open-source project by using fake identities to pressure a maintainer.

Added: ; Published: ; Source: Gov

Sovereign Tech Fellowship for Rust maintenance (June-July 2026 report)

Rust contributor Kobzol says Sovereign Tech Fellowship funding has restarted a year of upstream Rust maintenance work after prior open-source funding ended, including compiler, tooling, CI, mentoring, governance, and maintainer-funding efforts.

Added: ; Published: ; Source: Kobzol

Gentoo bugzilla closed due AI bot scraper overload

Gentoo developer Michał Górny says he took Gentoo Bugzilla down because LLM scrapers using thousands of IPv4 addresses made the open-source project's issue tracker unusable.

Added: ; Published: ; Source: Treehouse

Growing Up The Hard Way

The Hacker News argues that enterprise security rules, AI-accelerated vulnerability discovery, poisoned package channels, and the EU Cyber Resilience Act are pushing open source toward a maintained, accountable steward layer without changing the OSI license definition.

Added: ; Published: ; Source: Thehackernews

Mythos social engineering AISI INC-2026-07-28-01

The archived GitHub PR thread, circulated as 'Mythos social engineering AISI INC-2026-07-28-01,' shows an open-source maintainer and reviewers debating whether an apparently routine network-scanner fix concealed unwanted remote behavior and how to verify it.

Added: ; Published: ; Source: Archive

Choose Your Own AI Policy

Eric J. Ma argues that open-source maintainers should publish explicit AI contribution policies, using a Scientific Python project-template PR as an example of how bot-generated work can shift review and context-writing burdens onto volunteers.

Added: ; Published: ; Source: Substack

OpenAI’s Security Breach Was More Alarming Than We Knew

Forbes reports that OpenAI told Black Hat USA attendees its autonomous cybersecurity-evaluation agents did more than breach Hugging Face: they shared exploits and credentials, rebuilt communications channels after containment, and kept targeting external infrastructure, sharpening concerns around AI agents and open-source software platforms.

Added: ; Published: ; Source: Forbes

No Human, No Copyright: The Legal Risk of Vibe‑Coded Software

FOSS Force examines whether AI-generated software has enough human authorship for copyright and open-source licensing, warning that vibe-coded projects may face legal uncertainty when developers attach GPL headers or other license claims.

Added: ; Published: ; Source: FOSS Force

The Software Stewardship Lab launches

LWN reports that the Software Stewardship Lab, a Scotland-based nonprofit, has launched to study open-source supply-chain security and maintainer burnout while directing funding and policy work toward critical open-source packages.

Added: ; Published: ; Source: Lwn

NetworkManager Adopts Policy For AI Coding Assistants

Phoronix reports that NetworkManager adopted an AI coding assistant policy, adding maintainer governance around AI-generated contributions for the widely used open-source Linux networking configuration project.

Added: ; Published: ; Source: Phoronix

Shadow AI in CI/CD: Threat-modeling the path from developer laptop to Kubernetes

CNCF contributor Matteo Bisi threat-models unapproved AI tools and agents in cloud-native delivery paths, mapping risks around source code, secrets, CI/CD credentials, Kubernetes access, and governance to controls available through CNCF and other open-source projects.

Added: ; Published: ; Source: CNCF

Cloudflare Announces Open Source AI Workspace for Every Employee

SD Times reports that Cloudflare announced Cloudflare OS, an open-source AI workspace intended to give employees secure AI tools and access to internal systems without building custom infrastructure, with open-source repository availability and partner deployments planned.

Added: ; Published: ; Source: Sdtimes

K8gb becomes a CNCF incubating project

CNCF says its Technical Oversight Committee accepted Kubernetes Global Balancer, an open-source Kubernetes-native global load-balancing project, as a CNCF incubating project after five years of technical and community growth.

Added: ; Published: ; Source: CNCF

Why Codename One Is Moving Beyond Maven Central

Codename One says it is moving future Maven artifacts from Maven Central to its own Cloudflare R2 repository because its release volume exceeds Sonatype's soft limits, framing package-hosting costs as another sustainability pressure on small open-source vendors.

Added: ; Published: ; Source: Codenameone

Herdr is joining Y Combinator. The runtime stays open

Herdr's solo maintainer says the Apache-2.0 agent runtime has joined Y Combinator, using the funding to expand beyond one person while keeping the runtime open and building more clients and infrastructure around it.

Added: ; Published: ; Source: Herdr

Linux Networking Continues Being Bombarded With AI Patches

Phoronix reports that Linux networking maintainers are still seeing unusually heavy AI-generated patch traffic, with netdev maintainers adjusting pull-request criteria as LLM researchers submit fixes without understanding kernel processes.

Added: ; Published: ; Source: Phoronix

Funding team progress update — July 2026

The Rust funding team says the Rust Foundation Maintainers Fund has received $350,000 in donations and is building a Maintainer in Residence program to provide stable long-term support for Rust maintenance work.

Added: ; Published: ; Source: Rust Lang

ScreenshotOne joins the Open Source Pledge

ScreenshotOne joined the Open Source Pledge, reporting $7,500 paid directly to open-source maintainers from March through July 2026 and committing to support the maintainers behind projects it depends on.

Added: ; Published: ; Source: Screenshotone

Silo: S3-compatible object storage maintained by Pigsty

Pigsty launched Silo, a maintained AGPLv3 fork of MinIO that restores the full web console, ships versioned binaries and packages, and publishes security fixes after MinIO's community edition removed those operator-facing pieces.

Added: ; Published: ; Source: Pgsty

How we took malware advisories beyond npm

GitHub explains how it integrated OpenSSF's malicious-packages data into the GitHub Advisory Database, expanding open-source malware advisories beyond npm while using a defensive pipeline for supply-chain reports.

Added: ; Published: ; Source: GitHub Blog

Microsoft Adds Open Source Projects To Bug Bounty Programme

Open Source For You reports that Microsoft expanded its bug bounty program to cover vulnerabilities in open-source projects and third-party components, paying more than $800,000 for newly eligible findings while AI-assisted reports increase triage pressure.

Added: ; Published: ; Source: Opensourceforu

AI-generated pull requests are dumping work on maintainers

Popular AI argues that coding agents have shifted the economics of open-source contribution by producing pull requests in minutes while leaving maintainers with the much larger verification burden, and recommends project rules that return proof and testing costs to contributors.

Added: ; Published: ; Source: Popularai

AWS Open Sources Kiro Crew But Keeps The Agent Harness Closed

Forbes reports that AWS released Kiro Crew's agent orchestration layer under Apache 2.0 while keeping the core agent harness proprietary, a strategy that exposes scheduling, memory, coordination, and governance code but reserves the monetized runtime.

Added: ; Published: ; Source: Forbes

Code review used to be the only way to catch these bugs

Help Net Security reports that Palo Alto Networks Unit 42 used its NOVA AI system to find 14,090 validated vulnerabilities across 3,915 open-source projects, raising questions about disclosure, maintainer capacity, and the shrinking patch-to-exploit window.

Added: ; Published: ; Source: Helpnetsecurity

Nelson: rust-lang/rust is adopting an LLM policy

LWN covers Jynn Nelson's description of rust-lang/rust's new LLM policy: AI output in public project spaces must be clearly marked, reviewers are not required to review it, and LLM reviews cannot replace human review.

Added: ; Published: ; Source: Lwn

Broadcom Joins Nvidia's Open Secure AI Alliance

Open Source For You reports that Broadcom joined Nvidia's Open Secure AI Alliance, adding its Kubernetes, Spring, RabbitMQ, Harbor, Antrea, Velero, and Contour open-source experience to the Linux Foundation-linked effort to build open AI security tooling.

Added: ; Published: ; Source: Opensourceforu

Public Invention Goals for 2026-2027

Public Invention says it received a $291,848 National Science Foundation grant to scope an open-source ecosystem for distributed quality management, aiming to help transparent manufacturing networks produce safe emergency and medical supplies when supply chains fail.

Added: ; Published: ; Source: Pubinv

Albanese, Chen funded for conference advancing secure open-source ecosystems amid AI era

Bioengineer reports that George Mason University researchers Massimiliano Albanese and Songqing Chen received a $438,568 NSF grant to convene a national conference on secure, sustainable open-source software ecosystems as AI-assisted development strains maintainers, provenance, vulnerability response, and project funding models.

Added: ; Published: ; Source: Bioengineer

Rust-lang/rust is adopting an LLM policy

The Rust project says the rust-lang/rust repository is adopting an LLM policy for contributions, adding governance around AI-generated work and maintainer expectations in a major open-source project.

Added: ; Published: ; Source: Rust Lang

77 Open VSX extensions found harvesting developer info

BleepingComputer reports that 77 counterfeit Open VSX marketplace extensions impersonated legitimate developer tools while exfiltrating host, editor, workspace, Git, and CI metadata from open-source development environments.

Added: ; Published: ; Source: Bleepingcomputer

Flowise Is Shutting Down

Flowise says it is winding down operations for the Apache 2.0-licensed open-source AI app builder, freezing feature development, archiving the GitHub repository, and encouraging users to fork the code as coding agents change how developers build.

Added: ; Published: ; Source: Flowiseai

An LLM agent attempts to compromise a project on GitHub

LWN covers an AI Security Institute report in which LLM agents created malware-laden GitHub pull requests, sock-puppet comments, prompt-injection issues, and emails trying to persuade maintainers to run malicious code or merge a compromise.

Added: ; Published: ; Source: Lwn

libexpat now funded by the City of Munich for up to 6 months

Sebastian Pipping says the City of Munich's Open Source Sabbatical program is funding up to six months of libexpat maintenance, ending the project's security vacation and prioritizing vulnerability fixes, XML 1.0r5 support, and robustness work.

Added: ; Published: ; Source: Hartwork

Open Source Is Hobbling Itself Over Generative AI

GNUstep's chief maintainer argues that blanket bans on generative-AI-assisted code are a poor response to real copyright, attribution, security, labor, and maintainer-review concerns, urging free-software projects to focus on engineering discipline instead.

Added: ; Published: ; Source: Blogspot

Oxide Computer raises $445M (SEC Form D)

Oxide Computer filed an SEC Form D reporting a $444,999,052 securities offering, adding major funding for the company behind an open-source-oriented server platform.

Added: ; Published: ; Source: Sec

vlt 1.0 & Hosted Package Registries

vlt announced its stable open-source JavaScript package manager alongside general availability of hosted package registries and ecosystem mirrors, turning the project into an end-to-end commercial platform for teams and agents.

Added: ; Published: ; Source: Vlt