Kamis, 08 Oktober 2026

FOSS Weekly #26.41: Open Source Trouble, More Rust in Ubuntu, Adobe Photoshop's Linux Clone, Rich CLI Tool and More

FOSS Weekly 26.41

Long-standing open source projects won't receive new DigitalOcean infrastructure credits after the company quietly ended its support program in a disruptive move that has affected many open source projects. Though they did have enough money to fund Omarchy. 🤷

I cannot confirm, but it could be related. Gentoo Linux is seeking new infrastructure sponsors after several long-term backers withdrew support. The project accepts donated machines, colocation space, virtual machines, physical servers, or funds.

Music copyright group IFPI has submitted yt-dlp, a general-purpose command-line downloader, to the EU's piracy watchlist, lumping it with dedicated ripping services. They named four maintainers while claiming the tool fuels copyright harm.

AI-generated spam flooded Google's open source bug bounty program, prompting the company to temporarily pause product vulnerability submissions. Supply chain reports are still welcome, with them teasing a revamped program by Q1 2027.

Siemens silently deleted the OpenRadioss repository, but AGPL licensing has saved it. Rocky Linux co-founder Brian Clemens forked it as OpenCourant within days; it's already shipping binaries for Linux and Windows.

Red Hat's Lightwell flips the security script. Instead of waiting for upstream patches, it backports fixes directly to production Java libraries. Having cleared 400 vulnerabilities, its on track to grow.

Sequoia PGP arrives in Ubuntu 26.10 as a modern Rust-based OpenPGP tool that sits alongside GnuPG. Both implementations coexist for now, but the plan is to eventually phase out the latter.

Tuta Mail now has an app in the Nextcloud App Store, and a separate Nextcloud plugin in Tuta lets users upload email attachments to Nextcloud and embed video conference links in calendar events.

This edition of FOSS Weekly is supported by Karakeep, an open source bookmark manager.

Karakeep is a self-hostable “bookmark-everything” app. Throw links, notes, images, and PDFs at it, and it helps you find them again.

It uses AI to automatically tag bookmarks and generate summaries, with blazingly fast search across everything you save.

Add content from your phone, browser, or RSS feeds, and build collections with friends or coworkers using collaborative lists.

It’s your private, carefully collected corner of the internet. A home for those 50 open browser tabs you're sure you might need later.

Explore Karakeep

🧠 What We’re Thinking About

Someone has used AI to create clones of Adobe Photoshop and other tools. I would not keep my hopes high. The project is in a very early stage of development, so there are many functions missing and the user experience is not close to the original. It will also be worth seeing if the project gets development a few months down the line. Because AI has made it easier to create software, so many people create something and then forget about maintaining it.

Carl Dong, a former Bitcoin Core contributor, explains why he built Obscura around distrust rather than promises.

🐧 Are You Playing Tuxdle?

Tuxdle is the Linux terms guessing game that I created two weeks ago. I am delighted to see that this tiny puzzle game gained a niche following of daily active users. After all, this is a fun way to keep your general Linux knoweldge in check.

🧮 Linux Tips, Tutorials, and Learnings

GitHub Desktop isn't officially available for Ubuntu, yet a community fork fills the gap. While it hasn't received a release recently, the project worked well to bring that app to my Linux setup.

S-TUI is a Python tool that monitors CPU frequency, temperature, and power use in your terminal. It can stress-test your processor and detect thermal throttling, with customizable display options and mouse support for navigation.

There is this handy tool that lets you get all kinds of system information in the terminal. Very helpful to know what's on your computer.

👷 AI, Homelab and Hardware Corner

ORICO's X50 is a sleek Thunderbolt 5 SSD enclosure that works seamlessly on Linux without requiring any prior configuration.

Then there's Raspberry Pi, who have finally released the Debian 13-based Raspberry Pi Desktop for PCs and Macs.

✨ Apps and Projects Highlights

If your gaming needs have been affected by the absurd increase in prices for memory, storage, and GPU, why not give cloud game streaming a try? NVIDIA already offers a native client for GeForce NOW on Ubuntu.

📽️ Videos for You

In the latest video, learn to make the command output in Linux terminal look pretty. It could also be useful in various cases when you have to vioew csv or code files.

💡 Quick Handy Tip

kde plasma nemo file manager tip

In the Nemo file manager, pressing F3 opens an extra pane to view two folders side-by-side, making it easy to drag, drop, copy, or move files between different directories without switching windows.

If you find the keyboard shortcut inconvenient, you can add a dedicated toggle button to your interface by going to Edit → Preferences and opening the "Toolbar" tab. Here, you can enable/disable the Extra Pane option. When enabled, it adds a split-window icon to your top toolbar, letting you control the view with a single click.

If you like what we do and would love to support our work, please become It's FOSS Plus member. It costs $49 a year (less than the cost of a McDonald's burger a month), and you get free ebooks, an ad-free reading experience with the satisfaction of helping the desktop Linux community.

Join It's FOSS Plus

🎋 Fun in the FOSSverse

Do you use Arch, btw? Can you solve our Pacman command quiz?

And here I thought Windows were only useful for ventilating a room. 🤭

linux windows iso meme

🗓️ Tech Trivia: Did you know? On September 30, 1980, Xerox, Intel, and DEC published the "Blue Book" as the first Ethernet specification. Ethernet had already been running at Xerox PARC for years, but this document helped turn a lab experiment into the networking technology we still use today.

🧑‍🤝‍🧑 From the Community: You might have heard about the Blanc Browser by now. It's creator has made an appearance in the forum, replying to an inquisitive thread by one of our Pro FOSSers, Bill.



from It's FOSS https://ift.tt/bRc2dT8
via IFTTT

Gentoo Needs Your Help! Several Sponsors Have Pulled Out

gentoo infrastructure sponsor call banner

Plenty of open source projects keep going on goodwill alone, with contributors putting in the hours and expecting nothing back. While others lean on outside support like cash, donated hardware, or someone else covering the hosting bill.

This kind of support rarely gets much attention, but these needs are some of the most foundational aspects of any project that's serious about growing.

Gentoo falls in the second group. The source-based Linux distribution, built around the Portage package manager, runs largely on sponsored infrastructure, as it can only manage to maintain a few vital machines.

Sadly, many sponsors that had backed Gentoo all these years have decided to stop making contributions. The project is now looking for replacements and has put out a call for infrastructure sponsors.

Currently, its sponsors page lists names such as Oregon State University's Open Source Lab, CDN77, HP, and Hetzner, but it may not yet reflect the dropouts.

Gentoo's search for sponsors

gentoo's sponsors list shown partially
Some of the listed sponsors of Gentoo.

There are five ways to help, as laid out on the sponsorship page of Gentoo's wiki, with preference being given to supporters who share the project's vision of software that respects choice and stays open to user-driven changes.

The first way is to accept donated machines for the project's hosting locations in the US. They are not asking for much; anything good enough to handle server-focused tasks in today's time is a good offering for them to use.

Next is Colocation, a type of physical hosting. The sponsor would provide rack space, power, and connectivity, while Gentoo finds the hardware to put in it. Capacity outside the US is their most urgent need at the moment, though offers from the US are welcome too.

Third are virtual machines, with a minimum of 2 vCPUs, 4GB of RAM, and 25GB of storage. The project says that it is leaning more on the cloud wherever it can, but many of its services are monolithic, and that Kubernetes would suit them poorly.

The fourth way is full-package hosted physical servers. The wiki gives two examples: a root server like the ones Hetzner offers, or a sponsor's older or unused servers with Gentoo getting full remote access.

In that second case, the sponsor would still own and manage the hardware, whereas Gentoo would take care of the operating system and remote management, only asking for advance notice before any migration events.

The last is plain old money. Any donated funds would go toward paying for colocation and hosting.

A call to act

Gentoo is far from the only project that needs this kind of backing.

Take LVFS, the firmware update service for Linux. It leaned heavily on the Linux Foundation and Red Hat, with Framework and the Open Source Firmware Foundation pitching in $10,000 a year.

Then Lenovo and Dell joined at the Premier tier, at $100,000 a year each, along with HP and NVIDIA, who followed soon after. I would call that a win for LVFS and a sign that sponsors are out there for projects that go looking.

Maybe your organization has spare rack space, or you have money lying around and want it to do some good. Either way, someone has to host the servers behind projects like this, and Gentoo's infrastructure team is available at infra@gentoo.org for any infrastructure sponsorship-related queries.


Suggested Read 📖: Google has shut down part of its Open Source Bounty Program thanks to AI.



from It's FOSS https://ift.tt/p7RSsKi
via IFTTT

Rabu, 07 Oktober 2026

Vinix is Not a Linux Distro, But it Can Run Games, Docker, and QEMU

vinix 3-picture banner

How does an operating system that isn't proprietary or powered by the Linux kernel manage to run Docker, you ask? Well, it would need features like namespaces and cgroups.

That's exactly what Vinix did, adding its own implementations of those plus overlayfs and seccomp, allowing the stock Alpine Linux Docker engine to run on ARM64.

It also runs QEMU 9.1.2, which can boot a second Vinix inside a window of the first, and for gaming, it can run DOOM, a DOOM 3 demo, Gothic II's demo via OpenGothic, and Minecraft Java Edition.

There are still some limitations.

For instance, the Docker support lacks bridge networking and iptables rules, and QEMU runs on software emulation for now. Minecraft runs in interpreter mode on one CPU core, and DOOM 3 manages about 13 FPS under software rendering.

🚧
This is early-stage software that is not meant to be used daily or in production environments.

Yet another OS?

vinix desktop view

Vinix exists to give MacBooks a fast, minimal, open source OS, with the project's motivation being tied to macOS getting slower and bloated with every passing release. They are initially targeting Apple Silicon devices to eventually cover the whole M-series lineup, though only the M1 is supported right now.

While Linux users have little reason to switch to it, Vinix aims for a setup without systemd and a kernel small enough for one person to read through.

Beyond that, nothing runs in the background unless you start it, and the system sticks to a single init system, desktop, package manager, and binary format. The kernel handles memory manually instead of using a garbage collector, so a cleanup pass can't interrupt a system call or the compositor.

All of it runs on a V programming language foundation, which was picked for its fast compiles and small, readable design. The project doubles as a testbed for bare metal programming in V too!

The security model of the OS is modeled after OpenBSD, with pledge and unveil available, though apps must opt in, and user memory can't be both writable and executable by default. Verifying the bootloader, kernel, and root filesystem isn't supported yet.

It runs Linux apps

At its core, Vinix is a monolithic kernel booted through Limine, with its drivers built into the image. Most of it is V, alongside some C and assembly.

It features a native desktop built with V UI2 that renders through the framebuffer, with X.org and Hyprland sessions as options on ARM64. The developers claim that the OS takes up 50 MB of RAM after boot and roughly 1 GB of disk once installed.

Alpine Linux, the distro behind that Docker engine from earlier, is lightweight and security-focused, and it's built around musl and BusyBox. Vinix targets its aarch64 packages.

Thanks to that, Vinix is able to run Linux apps because it answers the system calls they make, plus the ELF format and musl behavior they rely on, and those binaries run natively, without a VM or an emulator.

New applications can be installed with pkg, a command-line tool that pulls packages from Alpine's aarch64 repositories. Apps like Chromium, GIMP, Sublime Text, and Gnumeric are known to work, as is Wine, the widely adopted compatibility layer.

The catch is that this is limited to ARM64 and selected packages. Software that relies on a Linux kernel feature Vinix doesn't have yet may not run properly.

Additionally, support for the M3, M4, and M5 is coming soon, while GPU drivers are still a work in progress.

Who's behind it?

hyprland demo of vinix
The Hyprland demo for Vinix.

Vinix's history spans many years, with the first commits on GitHub dating back to March 2021 and the original kernel core being the work of Mintsuki, the creator of Limine.

Development then paused for around two years before Alexander Medvednikov, the author of V, took over as maintainer.

Mintsuki's core covered the physical and virtual memory managers and the scheduler, but since the handover, Vinix has gained storage, networking, input, and graphics support, along with a Unix-style userspace and the Alpine compatibility we saw earlier.

Get Vinix

You will find that the official website offers a .dmg installer file for M1 Macs, whereas the project repository hosts two distinct ISOs, one for ARM64 (targeted at QEMU and VirtualBox on Apple Silicon Macs) and the other for x86_64 (targeted at Intel and AMD systems).

If you want to test it on a virtual machine, the requirements are quite modest. Vinix needs at least 4 GB of memory and 4 GB or more storage space. Building from source is also an option.



from It's FOSS https://ift.tt/QtrLFVB
via IFTTT

Google Has Shut Down Part of its Open Source Bounty Program

google bug hunters oss vrp discontinuation banner

Since 2022, Google's Open Source Software Vulnerability Reward Program (OSS VRP) has been the path for outside researchers to get paid for reporting security flaws in the company's open source code, including projects like Flutter, Angular, Go, and Fuchsia.

With an announcement on X, they have now decided to discontinue the product-facing side of it.

They are calling the change temporary, while supply chain reports remain open and anything submitted before October 1 stays unaffected.

What's closed, what's not?

Product vulnerabilities are bugs in the projects themselves, like a failing HTML sanitizer, memory corruption issues in file format parsers, or insecure code examples in documentation.

The updated rules do not limit the change to a specific project tier, as they just won't be accepting any reports related to this.

Supply chain reports, on the other hand, cover vulnerabilities in how the software is built and shipped. Exposed package manager credentials used to publish build artifacts is one case the rules page lists. It remains unaffected by this change.

There's also an exception for some Google Cloud repositories. If a bug there affects a Cloud product, Google may still accept the report, but through its Cloud VRP.

Why did it come to this?

Back in March, a post on the Bug Hunters blog from Google engineers said AI-generated reports were flooding the program. Some were serving up hallucinated information, while others were flagging legit coding errors that had little to no impact on the security posture of the targeted project.

Google's first response was to raise the bar on memory corruption reports for its two top project tiers. Researchers had to either reproduce the bug through an existing OSS-Fuzz fuzz target or point to a patch that maintainers had already merged.

An update to the same post the following month went further. The standard and low-priority tiers, OT2 and OT3, stopped offering rewards or credit for product vulnerabilities and other security issues. The top supply chain reward for OT2 projects also fell to $3,133.70.

Supply chain reports still pay, from $500 on OT2 projects up to $31,337 on flagship ones.

As an alternative, Google points to the Patch Rewards Program, which pays between $100 and $15,000, though only for patches that have stayed in a project for a month without being reverted.

An open question

Google has not said when or in what form product vulnerability reports will return. Their announcement only promises an update in the first quarter of 2027 while they continue reworking that part of the program.

There's also a loose end. At the time of writing, the OSS VRP page still lists reward ranges for product vulnerabilities, up to $7,500. Though, as you saw earlier, the rules page for it has already been updated, so it shouldn't be long before this is addressed.


Suggested Read 📖: cURL gets rid of its bug bounty program due to AI.



from It's FOSS https://ift.tt/lgY8EIO
via IFTTT

Selasa, 06 Oktober 2026

Red Hat's Lightwell Doesn't Wait for Upstream Maintainers to Act

redhat and ibm log on left, lightwell written on right

Lightwell is Red Hat and IBM's response to a specific problem in enterprise open source security. Vulnerabilities sit in production library versions that upstream maintainers haven't patched and, in some cases, won't.

More than 90% of enterprise application code traces back to open source or third-party libraries, per figures Red Hat cites, and a typical enterprise codebase carries over 500 known vulnerabilities at any given time.

They say that attacks on known vulnerabilities arrive, on average, a week before any patch exists.

Lightwell's approach is to bypass that timeline. Rather than waiting for upstream maintainers to push fixes to the library versions enterprises are actually running, it backports those fixes directly, delivering them through secure package repositories.

Red Hat reached out recently to share how far it has come.

400 down, more to come

To date, Lightwell has already managed to clear 400 previously unknown vulnerabilities across foundational Java libraries, going beyond reported CVEs and contributing fixes upstream in line with responsible disclosure protocols.

The primary target so far has been organizations running Java environments with pinned dependency versions that can't be safely updated. Lightwell patches those in place, leaving the pinned version intact.

Coverage is also set to expand beyond Java, with Python, JavaScript, and .NET on the roadmap. Each will follow the same approach, with fixes backported to the versions already in production and applicable patches being contributed upstream.

The Clearinghouse opens up

a slide from red hat's technical demo for lightwell

Then there's Clearinghouse Premier, which has so far operated on restrictive terms. Before today, it was reserved for a pre-selected group of organizations in critical infrastructure sectors.

That restriction is now lifted, as it has reached general availability, which means any enterprise can sign up for Clearinghouse directly without waiting on an infrastructure designation to clear access.

You see, Lightwell runs across two access tiers. The Lightwell Network, which reached general availability in July as a self-service subscription open to any organization. It provides access to the backported patches and their compliance documentation.

What Clearinghouse Premier offers is more tailored. Organizations can specify which vulnerabilities matter most to their environment, get early notice before issues go public, and know exactly when fixes will arrive.

As a whole, Lightwell sits within IBM and Red Hat's $5 billion commitment to open source security, with both companies pointing to AI-assisted tooling raising the stakes on older, unpatched open source dependencies.

That stance is further strengthened by Gunnar Hellekson, Vice President and General Manager for Lightwell at Red Hat, who stated that:

AI agents shifted the threat landscape overnight, exploiting old dependencies at machine speed. They do not care if a codebase is ten years old or otherwise considered stable, because one small crack is all it takes to chain an attack together.

If you are interested in what's being offered, a closer look before committing is possible via Red Hat's technical demo, which will walk you through the patching workflow.



from It's FOSS https://ift.tt/mqTQyWK
via IFTTT

Senin, 05 Oktober 2026

Siemens Abruptly Takes Down OpenRadioss, But a Fork is Already Live

opencourant launch banner

The globally recognized tech and engineering company has quietly shut down the OpenRadioss project at the start of this month, keeping the GitHub page around but completely removing the repository.

I sound complainy because usually when an open project is discontinued, the maintainers put it into a read-only, public archive state, which allows other developers to learn and fork off it.

OpenRadioss was the open source release of Radioss, a finite element solver Altair Engineering developed for crash testing, blast response, impact analysis, and other structure loading scenarios.

They had released it in September 2022, drawing in a multinational community of researchers, software developers, and industry contributors who extended the solver and built upon the code.

Siemens, which acquired Altair last year, kept the repo and its contents publicly available for more than a year after the acquisition before abruptly deleting it and redirecting people to its transition page for Simcenter Radioss.

A fork appears

Brian Clemens, the co-founder of Rocky Linux has already got an OpenRadioss fork up and running, which carries the full OpenRadioss commit history, ships under the same GNU AGPLv3 license, and is hosted on GitHub.

It's called OpenCourant, named after mathematician Richard Courant and the Courant-Friedrichs-Lewy (CFL) condition, a stability criterion central to solvers like this one.

In fact, this fork owes its existence to the AGPL. You see, Siemens is legally within its rights to take down the repository, but the license applying to every commit gave anyone the right to fork, distribute, and build on the code.

It's just sad to see how abruptly the takedown was carried out; makes you think they didn't want people to get a heads-up.

Also worth noting is that OpenCourant is an independent community project, and it is actively looking for past OpenRadioss contributors to pitch in.

What's already shipping?

a placeholder image that shows the opencourant download page on its website

Initially, the upstream build pipeline that depended on proprietary Siemens infrastructure could not be transferred. That was rebuilt from scratch, and the results appear promising.

Just days since its inception, the project is already distributing Linux and Windows x86_64 packages.

And before that, a closed-source hm_reader input-reader binary that was never committed to the git history disappeared along with the upstream OpenRadioss repository.

Thankfully, an unnamed community member who had kept a copy came forward, the OpenCourant team independently verified it, and it now ships in every build. Though they are still looking for specific release archives to start work on ARM64 support and improve current platform compatibility.

If you are interested in OpenCourant, then its package options include the Starter and Engine offerings in single and double precision, SMP builds, and converters for animation files and time history data.

You can download the latest builds from the official downloads page.

If you get lost, the INSTALL.md file can be a good resource, though keep in mind it is still the OpenRadioss version, as the OpenCourant team has yet to update it to reflect the new project.



from It's FOSS https://ift.tt/yUl6TpK
via IFTTT

Ubuntu 26.10 Will Have a Rust-based GnuPG Replacement

ubuntu gnupg and sequoia pgp banner

You already know that Canonical has been selectively replacing Ubuntu's C-based system components with Rust-written equivalents that don't compromise in terms of functionality, most of the time.

Now it looks like the distro's OpenPGP implementation is next, with Sequoia PGP coming preinstalled in Ubuntu 26.10. Canonical wants it to eventually replace GnuPG as the default toolchain, though that switch has not happened yet.

What's OpenPGP?

Before getting into Sequoia, it helps to know what OpenPGP actually is. It's not a tool but rather a widely adopted standard.

Phil Zimmermann created the original PGP in 1991, and the IETF now maintains the open version of that work. The specification defines how software should encrypt, decrypt, sign, and verify data so that any two implementations following it can work with each other's data.

On Linux, GnuPG has been the dominant implementation of that standard. Written in C, it implements RFC 4880 and offers the gpg and gpgv commands on the platform. These handle everything from encryption and key management to standalone signature verification.

Sequoia PGP is different

It was started in 2017 by three former GnuPG developers who chose to build a new OpenPGP implementation in Rust rather than keep evolving GnuPG’s existing codebase.

Sequoia PGP is designed as a library that other software can use directly, rather than a standalone command-line tool. sq sits on top of that for encryption, decryption, signing, and key management, and sqv handles signature verification, filling in for gpg and gpgv in GnuPG.

Sequoia also implements RFC 9580, the 2024 revision of the OpenPGP standard, whereas GnuPG has continued from the RFC 4880 branch, pursuing its own newer extensions and the LibrePGP specification rather than adopting RFC 9580 as its primary standard.

What's already in?

Ubuntu 26.10 "Stonking Stingray" already pulls in Sequoia PGP from the main archive (look under rust-sequoia-xx) as part of the default installation. I ran sq and sqv on a development build of 26.10, and both were working correctly.

Here, sq acts as the main interface for encryption, decryption, signing, and key management, while sqv handles signature verification. And typing gpg and gpgv still routes to GnuPG, so these two OpenPGP implementations sit alongside each other.

If Sequoia PGP is made the default, you can expect those commands and other GnuPG ones to route to Sequoia instead, similar to how we saw with sudo-rs.

Still a long way to go

The release notes for Ubuntu 26.10 and a recent announcement clearly mention that Sequoia PGP becoming Ubuntu's default OpenPGP toolchain is a future goal, not something that's already the default experience.

The coreutils transition started in 2025 and only reached 100% with 26.10. The sudo-rs switch was shown off well in advance before it became the default. Each of these components had to earn their place over multiple release cycles before anything changed for users.

Sequoia PGP is at the start of that process. Landing in the main archive is the first milestone. Whether it eventually replaces GnuPG as the default remains to be seen.

Canonical has not shared a specific inclusion timeline. Given how carefully they have moved on every other Rust transition so far, that caution is unlikely to disappear for something as foundational as OpenPGP.



from It's FOSS https://ift.tt/A1XpmIr
via IFTTT