Open Source
Licences, Governance & Supply Chain. Published every Friday, here and by RSS.
41 stories 7 issues 9 categories
Licensing Governance Forks & Splits Supply Chain Maintainers Foundations Regulation Security Reading
Top stories
RSSnpm 'Shai-Hulud' Worm Compromises Packages
Security researchers identified an active supply chain attack involving the 'ChainDrop' / 'Shai-Hulud' malware family, which compromised over 1,300 npm package versions, including Keyv and related caching libraries. The malware steals developer credentials and self-propagates by republishing modified packages.
microsoft.com · 09 August 2026 · Read the original →
Supply chain attack on arrayref (Rust blog)
A malicious Rust crate named proc-macro1 was uploaded to crates.io, and the popular arrayref crate was republished to depend on it. The registry maintainers intervened by removing the malicious version and restoring the safe versions of arrayref that had been yanked.
LWN · 21 August 2026 · Read the original →
Eight stable kernels with fix for a single vulnerability
The Linux kernel maintainers released eight stable kernel versions simultaneously to address a single vulnerability (CVE-2026-80590) that can cause a kernel panic. The vulnerability has been present in the codebase since Linux 2.6.27, affecting long-term stable releases spanning many years.
LWN · 28 August 2026 · Read the original →
Keyv npm Packages Compromised in Attack
A supply chain attack, starting August 4, 2026, compromised widely used npm packages like 'keyv' and 'cacheable' through a GitHub account takeover, injecting a self-propagating credential-stealing worm. This 'Mini Shai-Hulud' variant affected hundreds of packages with over 500 million weekly downloads.
Snyk · 04 September 2026 · Read the original →
Freedom for Hacking!!1
The Software Freedom Conservancy is participating in the triennial DMCA exemptions process to petition for the public's right to circumvent software access controls on their devices. This process aims to claw back digital autonomy and restore user rights over their own technology.
Software Freedom Cons. · 28 August 2026 · Read the original →
More committees, more metadata files, and the same unpaid maintainers keeping the lights on.
Weekly editions
Each edition is one week's digest exactly as it was published — a summary of the week, then the stories.
- 18 September 202625 new posts across 3 open source sources — 6 worth your time.6 stories →
- 11 September 202620 new posts across 4 open source sources — 5 worth your time.5 stories →
- 04 September 2026EU Cyber Resilience Act reporting obligations begin, while a major npm supply chain attack compromises popular packages.5 stories →
- 28 August 202623 new posts across 4 open source sources — 5 worth your time.5 stories →
- 21 August 202623 new posts across 4 open source sources — 7 worth your time.7 stories →
- 14 August 202626 new posts across 5 open source sources — 6 worth your time.6 stories →
- 09 August 202623 new posts across 3 open source sources — 7 worth your time.7 stories →