2026-04-28 08:51:23
Starlette, an open-source Python framework underpinning FastAPI, has a vulnerability, called BadHost, that can allow hackers to bypass authorization (Dan Goodin/Ars Technica)
https://arstechnica.com/information-te
Open source isn’t free. We’re just not paying for it: Who maintains the maintainers?
A lot of things don’t add up in the world of software. The skills gap remains stubbornly wide, with IT and data skills the hardest to recruit for five consecutive years. Yet, at the same time, entry level roles are declining as employers redeploy existing employees rather than hiring new ones.
🧑💻
Keine Alterskontrolle für Linux
Gesetze, die eine Altersverifikation in Betriebssystemen vorsehen, nehmen zumindest in Kalifornien und Colorado wohl Open-Source aus.
https://www.heise.de/news/Keine-Alterskont…
Insurance tech startup Corgi denies accusations that it used Papermark's open source software code to develop its software and present it as its own (Julie Bort/TechCrunch)
https://techcrunch.com/2026/06/26/corg
#superproductivity app is great. There aren't many apps I can run on my locked down computer at work. But this one is possible to sync via webdav so I installed a minimal webdav just to syncronize the json and md file the app generates. It work flawlessly! I have finally found a way to take my todo's between work and home.
Age makes remembering things more and more tr…
Wie informieren Solawis ihre Mitglieder digital über den Inhalt und die Verwendung des Ernteanteils?
Wie können Ernteteilende ihren Anteil online anpassen oder pausieren?
Wir stellen beim Online-Stammtisch im Juni Open Source Web-Apps vor, die Solawis nutzen können.
🗓️ 17.06., 19:30 Uhr | ohne Anmeldung
Open source has become critical digital infrastructure over the past 25 years, but its future depends on human resilience as much as code. Contributor burnout, funding gaps, and new regulations are real challenges, and Ruth has spent nearly two decades at the heart of open source communities working through exactly these kinds of problems. It's a session to look forward to!
Join us for Berlin Buzzwords on June 7-9 at Kulturbrauerei or online. Get your tickets! https://2026.berlinbuzzwords.de/
I like to think this is due to the single email I sent to my state representative.
https://ostechnix.com/colorado-california-age-verification-law-open-source-exempt/
OpenAI releases Symphony, an open-source spec for agent orchestration that turns a project-management board like Linear into a control plane for coding agents (OpenAI)
https://openai.com/index/open-source-codex-orchestration-symphony
For the #ttrpg bubble
Oh, did I even tell you that I've put the scripts I'm using for my TranscriptOMatic #roleplaying session transcription proof-of-concept into a Git repository?
👥 This isn't just open source for show. Nearly 1M developers told the #Warp team: "If you open this up, we will help you build it." Five years after the initial preview — and with a working business model in place — they finally made it happen. #opensource
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s MythoOpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
https://www.wired.com/story/openai-launche
Europe builds Microsoft-alternative ‘Euro-Office’ to reclaim digital sovereignty
The open-source initiative promises seamless document compatibility, transparent governance, and reduced dependency on non-European platforms.
https://tech.eu/2026/03/27/europe-bui…
🇺🇦 #NowPlaying on BBCRadio3's #TheEarlyMusicShow
George Frideric Handel, Crispian Steele‐Perkins, James Bowman & The King's Consort:
🎵 Eternal Source of Light Divine Ode for the Birthday of Queen Anne, HWV.74]
https://open.spotify.com/track/0drHxdDHQr20RWySE9TM7I
Don’t Do Team Meetings
Regular team meetings are often treated as a default part of work. They are seen as a sign of coordination, alignment, and healthy communication. In practice, they often reveal the opposite.
A recurring team meeting where everyone goes around the room to explain what they did last week is usually not a good use of time. It turns communication into a performance instead of a real exchange of useful information. If the team needs a formal meeting just to lear…
RE: https://dice.camp/@realms/116459545804565917
I'd argue that "AI"-based development creates a bigger attack surface on closed source/proprietary software than open source software:
1. It's more likely that internal software development uses LLMs as they're most affordable to companies; leaving them more vulnerable to prompt injection and other types of attacks targeting LLM use.
2. It's more likely that internal commits aren't vetted as much (or even purely vibe-coded) as ones in open source projects.
3. It's more likely that attacks on open source projects are discovered quicker.
Also a reminder that the "Mythos" thing—like all the other doomerist things coming out of "AI" companies—is a marketing stunt to get Anthropic free press coverage.
Fortune: #DeepSeek unveils V4 model, with rock-bottom prices and close integration with Huawei’s chips https://fortune.com/2026/04/24/deepseek-v4-ai-model-price-perfor…
➡️ Scrapy - Open-source framework for efficient web scraping and data extraction
#bookmarks
from my link log —
Gecko: a fast GLR parser with automatic syntax error recovery.
https://vnmakarov.github.io/parsing/compilers/c/open-source/2026/04/22/gecko-glr.html
saved 2026-04-23
Xiaomi open sources MiMo-V2.5 and MiMo-V2.5-Pro under the MIT License, saying both models are among the most efficient available for agentic "claw" tasks (Carl Franzen/VentureBeat)
https://venturebeat.com/ai/open-source…
RE: https://mastodon.social/@hyc/116816916444068291
This entirely unnecessary NDA culture has been commercial poison for me for the past 15 years and also a huge problem for the open source projects themselves. NDAs are a legalese subversion of open so…
Fiktives Vertriebsgespräch eines Dienstleisters für $OPEN_SOURCE: "Sie müssen wissen, Herr $KUNDE, bei uns arbeitet einer der drei Haupt-Entwickler der Software. Wissen und Support sozusagen aus erster Hand." – "Schön und gut. Aber wenn ich $CLOSED_SOURCE beim $HERSTELLER kaufe, dann arbeiten ALLE Entwickler da, nicht nur einer der Haupt-Entwickler." #justthinkin
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
🇺🇦 #NowPlaying on KEXP's #VarietyMix
Jump Source ft. Loukeman:
🎵 Affect
#JumpSourceftLoukeman
https://jumpsource.bandcamp.com/track/affect-ft-loukeman
https://open.spotify.com/track/2Qd5NnEFHNh1qAeiPenjnu
{tesseract} allows you to read text from images https://docs.ropensci.org/tesseract/ it can also be combined with {magick} https://ropen…
#Zürich hat geprüft, ob #OpenDesk #Microsoft365 in der Verwaltung ersetzen kann.
Das Ergebnis: Für viele Büroaufgaben reicht die Open-Source-Lösung bereits aus, etwa bei Mail, Kalender, …
We're beyond excited to announce that @suehle, Director of Open Source at SAS and President of the Apache Software Foundation, is joining #bbuzz26 as the keynote speaker!
Learn more on our blog post: https://2026.berlinbuzzwords.de/2026/05/13/ruth-suehle-to-hold-keynote/
This AI Tool Rips Off Open Source Software Without Violating Copyright https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/
EOLE Evento europeo sul diritto all'open source e al software libero. Workshop di apertura online domani 25 giugno 2026 (dalle 15:00 alle 17:30 CEST)
L'Europa ha riscoperto la "sovranitŠ" attraverso un'ondata di nuove regolamentazioni - Legge sulla resilienza informatica, Legge sull'IA, gare d'appalto per la sovranitŠ del cloud. EOLE 2026 adotta un punto di partenza opposto: il Software Libero, l'Open Source e l'IA aperta perseguono l'autonomia…
My neurologist advised that I should try EEG Neurofeedback. Unfortunately public health insurance doesn't cover it.
Well, I'm just going to DIY it. I just ordered an open source Neurofeedback device with some electrodes.
https://www.olimex.com/Products/EEG/OpenEE
https://open-source-wettbewerb.de/
> das Bundesministerium für Digitales und Staatsmodernisierung übernimmt erneut die Schirmherrschaft für den Open Source Wettbewerb.
> Der Wettbewerb zeichnet Projekte aus, die digitale Verwaltungsprozesse verbessern, die Zusammenarbeit in der Verwaltung …
from my link log —
Open access to standards documents.
https://discourse.llvm.org/t/rfc-open-access-to-standards-documents/90856
saved 2026-05-21
OpenPINT: Open-source Planning for Isoeffective Nuclear Treatments in BNCT research
Ian Postuma, Sara J. Gonz\'alez, Setareh Fatemi, Cristina Pezzi, Carolina Ruzzon, Oreste Nicrosini, Valerio Vercesi, Silva Bortolussi
https://arxiv.org/abs/2606.21476 https://arxiv.org/pdf/2606.21476 https://arxiv.org/html/2606.21476
arXiv:2606.21476v1 Announce Type: new
Abstract: Objective: Present OpenPINT (Open-source Planning for Isoeffective Nuclear Treatments), an open-source treatment planning system for nuclear therapies that integrates Monte Carlo dose calculations with modular dosimetric and radiobiological models for photon-isoeffective dose evaluation.
Approach: We describe the software architecture, implementation choices, and data flow from segmented geometry and source configuration to NIfTI dose outputs. We define BNCT-relevant dosimetric metrics and evaluate the workflow with reproducible analytic and voxelized cylindrical-phantom benchmarks, supplemented by a geometric patient-positioning example.
Main results: The module provides a reproducible and scriptable path for generating MCNP-ready inputs, extracting component-wise BNCT dose maps, and computing analysis-ready outputs for quality checks and decision support. Fine-resolution voxelized configurations reproduced the 1 mm analytic reference within 0.13% for the brain-limited irradiation-time endpoint, whereas the full voxelized sweep exposed deviations up to 4.42% in coarse 8--10 mm configurations. Patient-wide gamma pass rates were at least 99.60% for the evaluated mesh/interpolation cases, while low-dose DVH-tail quantities remained sensitive to boundary discretization.
Significance: This first paper isolates and validates the simulation-preparation and dosimetric-analysis core of an open-source BNCT treatment-planning platform. It establishes a foundation for subsequent work on optimization, biological weighting, and clinical workflow integration.
toXiv_bot_toot
Right, time to crank out some open source PR's out
No puede haber una IA de código abierto si todas sus partes no son de código abierto, y eso significa que también deben de ser accesibles los datos utilizados para entrenarla https://opensource.org/ai/open-source-ai-definition
I believe that we in the US will begin to face a hard question:
We will soon, I hope, begin cleaning up the trump/maga mess.
Given that the trump/maga actors have engaged in inhumane, unlawful, and racist destruction of people and institutions I wonder about the following:
Should those people be protected by our Constitutional norms or will we want to, or need to, bypass our legal protections and procedures as we pursue punishment, disgorgement of ill gains, and compensatio…
@… my context was:
― the The AI/ML Security Working Group.
The working group is an Open Source Security Foundation project. The OpenSSF is a project of the Linux Foundation.
If you must use extreme, inflammatory phrases such as "the beast" and "shitcan" in the future:
― be clearer about the meanings.
Cc
On May 26, 2026, at 14:00 UTC, the CrowdStrike Counter Adversary Operations team executed a coordinated takedown of the Glassworm botnet, a global threat targeting software developers through the open-source supply chain.
https://www.crowdstrike.com/en-us/blog/ins…
Datacurve releases the DeepSWE coding benchmark, a 113-task test across 91 open-source repositories and five languages, and says GPT-5.5 is the leader at 70% (Michael Nuñez/VentureBeat)
https://venturebeat.com/technology/dee…
«#Zürich will sich von teurer #Microsoft-Software lösen – doch da gibt es ein Problem:
Die Zürcher Stadtverwaltung soll sich aus dem #M365-Würgegriff lösen und auf eine europäische
The Irish Council for Civil Liberties (#ICCL) has released an open source tool designed to reduce LLM hallucinations.
If my 15-year-old PC had a GPU I'd be tempted to give it a try.
https://www.
I like to think this is due to the single email I sent to my state representative.
https://ostechnix.com/colorado-california-age-verification-law-open-source-exempt/
OpenAI unveils an updated GPT-5.5-Cyber model, launches the Patch the Planet initiative in partnership with Trail of Bits to fix open source bugs, and more (Lily Hay Newman/Wired)
https://www.wired.com/story/openai-launche
🇺🇦 #NowPlaying on KEXP's #MidnightInAPerfectWorld
Jump Source ft. POiSON GiRL FRiEND:
🎵 Close
#JumpSourceftPOiSONGiRLFRiEND
https://jumpsource.bandcamp.com/track/close-ft-poison-girl-friend
https://open.spotify.com/track/6CVubsu8aHYG5QztcKmsLz
Una lettera aperta agli utenti di suite per ufficio, poco prima dell'annuncio di Euro-Office
«Negli ultimi giorni avrete letto diversi articoli che annunciano l'arrivo di EuroOffice, presentato come la prima suite per ufficio open source sviluppata in Europa. Ci sentiamo in dovere – seppur a malincuore, poiché l'open source dovrebbe basarsi sulla trasparenza e non sull'inganno – di correggere questa affermazione. La prima suite per ufficio open source sviluppata in Euro…
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
Are they right? 🤔
"Euro-Office defaults to the fully proprietary OOXML document format, developed and controlled solely by Microsoft. This makes it a de facto ally of Microsoft in its content lock-in strategy, with control remaining firmly in Redmond and far from Europe."
https://blog.do…
from my link log —
Can we trust Microsoft with Open Source?
https://dusted.codes/can-we-trust-microsoft-with-open-source
saved 2021-10-23
«Ladybird-Browser stoppt öffentliche Code-Beiträge:
Wegen KI-generierter Beiträge schließt das Open-Source-Projekt Ladybird seine öffentlichen Pull-Requests, um die Sicherheit des Browsers zu garantieren.»
Da sehen wir wie KI das Gegenteil von sicherer Produktion ist, wenn es blind als unstrukturiertes Pull-Request eingesetzt wird.
🌐
How tech companies are using open source initiatives to achieve critical strategic goals and how such efforts are reshaping industries like AI, AVs, and more (Bill Gurley/Bill's Substack)
https://p3institute.substack.com/p/from-open-source-software-to-open…
Some organizations are doing panicky things over Mythos.
NHS Goes To War Against Open Source
https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/
Microsoft has locked the lead developers of two prominent open source security projects out of their accounts.
https://www.computing.co.uk/news/2026/microsoft-locks-open-so…
Einige der zuletzt hier besonders häufig geteilten #News:
Stringman: Fest montierter Open-Source-Roboter räumt einzelne Räume auf
How hacker group TeamPCP exploited the open source trust model and distribution method to compromise and inject malware into over 1,000 software packages (Matt Kapko/CyberScoop)
https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/
«AI Slop oder besserer Code — GCC-Arbeitsgruppe für KI-Richtlinien gestartet:
Die Working Group for GCC AI Policy soll festlegen, inwiefern Contributors KI-Tools beim Entwickeln der GNU Compiler Collection nutzen dürfen.»
Da bin ich mal gespannt wie sich das auswirkt und ob dadurch die IT-Sicherheit im Open-Source Bereich wirklich erhöht wird.
🧑💻
After EV maker Fisker's collapse, ~4,000 car owners formed a nonprofit to keep their cars working by reverse-engineering software and building open-source tools (Fred Lambert/Electrek)
https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-aft…
Don't miss today's Metacurity for the most critical cybersecurity developments you might have missed over the weekend, including
--White House opens backchannel to Anthropic as Pentagon fight simmers,
--Anthropic gave NSA access to Mythos Preview,
--Anthropic's donation to open source developers highlights how under-sourced they are,
--Asian regulators urge banks to use Mythos,
--LayerZero-powered cross-chain bridge Kelp DAO lost $292m in DPRK exploit…
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
Münchens IT-Wende: Open Source ist für die neue Koalition der Normalfall
Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code (Steven Vaughan-Nichols/ZDNET)
https://www.zdnet.com/article/ai-security-worries-force-company-t…
Meta: Neue KI-Modelle sollen teils Open-Source werden
Meta plant, neue KI-Modelle zu veröffentlichen. Die sollen in Teilen unter Open-Source-Lizenzen herausgegeben werden.
https://www.heis…
As the US House probes Airbnb's use of Chinese AI models, CEO Brian Chesky says the company is not sharing data with Chinese firms and uses open-source models (Natalie Lung/Bloomberg)
https://www.bloomberg.com/news/articles/20
Moonshot introduces Kimi K2.6, an open-weight model that it says shows strong improvements in long-horizon coding tasks, available under a modified MIT License (Kimi AI)
https://www.kimi.com/blog/kimi-k2-6
Mirendil, founded by former Anthropic researchers and seeking to build self-improving AI for open-source developers, raised a $200M seed at a $1B valuation (Tina Li/Wall Street Journal)
https://www.wsj.com/tech/ai…
OpenDesk kann vieles, aber halt nicht alles. Das ist das Fazit einer Studie aus Zürich, die die Open-Source-Lösung als Microsoft 365-Alternative unter die Lupe genommen hat. 🔍
Zum Artikel: https://heise.de/-11303065?wt_mc=sm.red.…
Sources: Meta is preparing to release the first AI models developed under Alexandr Wang, with plans to offer versions of those models via an open source license (Ina Fried/Axios)
https://www.axios.com/2026/04/06/meta-open-source-ai-models
Einige der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Inference cloud startup DeepInfra raised a $107M Series B co-led by 500 Global and Georges Harik; it currently supports more than 190 open models (Mike Wheatley/SiliconANGLE)
https://siliconangle.com/2026/05/04/deepinfra-la…
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Anthropic commits up to $100M in usage credits for Project Glasswing, along with $4M in direct donations to open-source security organizations (Greg Otto/CyberScoop)
https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnera…
Europa hat jetzt sein eigenes Office – und das ist auch noch Open Source! 🚀
Zum Artikel: https://heise.de/-11320254?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
Servus, freie Software! 🥨 In München weht ein neuer Wind durchs Rathaus – und der riecht verdächtig nach Open Source.
Zum Artikel: https://heise.de/-11292444?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_sou…