Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Open Source

09 August 2026

23 new posts across 3 open source sources — 7 worth your time.

One week of Open Source, 7 stories, as published.

Governance

Nelson: rust-lang/rust is adopting an LLM policy

The Rust language team has adopted a new policy regarding the use of Large Language Models (LLMs) in the project. Under the policy, contributors are not required to use LLMs, reviewers are not obligated to review LLM-generated pull requests, and any LLM-generated output in public documentation, PR descriptions, or GitHub comments must be explicitly marked.

Why it matters — It establishes a clear boundary for maintainers, protecting reviewers from being overwhelmed by unmarked AI-generated content while ensuring participation remains accessible to those who do not use AI tools.

LWN · 09 August 2026 · Read the original →

Supply Chain

The return of Shai-Hulud: How SonarQube detects and contains the npm worm

A new wave of the self-propagating Shai-Hulud worm is actively spreading through the npm ecosystem. The worm targets developer and CI/CD credentials to compromise accounts and republish itself inside additional packages, creating a cascading security risk across dependencies.

Why it matters — It highlights how credential theft in CI/CD pipelines can be automated to rapidly compromise downstream open-source dependencies without direct code injection by the original maintainers.

Tidelift · 09 August 2026 · Read the original →

Foundations

The Software Stewardship Lab launches

The Software Stewardship Lab, a new nonprofit based in Scotland, has launched to address critical issues in the open-source ecosystem. The organization's initial research focuses on mapping hidden dependency graphs to monitor critical packages in real time and publishing reports on maintainer burnout.

Why it matters — It introduces a structured, research-backed approach to identifying hidden single points of failure in the global software supply chain before they lead to systemic failures or maintainer burnout.

LWN · 09 August 2026 · Read the original →

Governance

LightDM lives: version 1.33.0 released

After four years of inactivity under Canonical's sponsorship, the LightDM display manager has been transferred to a new community-led repository. The project is now actively maintained by independent community members, resulting in the release of version 1.33.0 with Qt6 support and various optimizations.

Why it matters — It demonstrates a successful transition path for abandoned corporate-sponsored projects moving to independent community governance to resume active maintenance.

LWN · 09 August 2026 · Read the original →

Licensing

Why Sonar signed the Open Weights and American AI Leadership letter

Sonar has signed the Open Weights and American AI Leadership letter, advocating for an AI ecosystem built around open-weight models. The letter argues that practical, secure, and sustainable AI adoption across the economy depends on organizations being able to freely download, run, and modify model weights.

Why it matters — It frames the availability of open-weight models as a critical licensing and operational requirement for organizations seeking to avoid vendor lock-in and maintain control over their AI infrastructure.

Tidelift · 09 August 2026 · Read the original →

Supply Chain

npm 'Shai-Hulud' Worm Compromises Packages

Security researchers identified an active supply chain attack involving the 'ChainDrop' / 'Shai-Hulud' malware family, which compromised over 1,300 npm package versions, including Keyv and related caching libraries. The malware steals developer credentials and self-propagates by republishing modified packages.

Why it matters — Organizations using Node.js must immediately review dependencies, treat credentials on affected systems as compromised, and remove malicious package versions from all environments.

microsoft.com · 09 August 2026 · Read the original →

Regulation

EU CRA Reporting Deadline Nears

The EU Cyber Resilience Act's (CRA) mandatory incident and vulnerability reporting requirements formally kick in on September 11, 2026. Manufacturers marketing connected products in the EU must report actively exploited vulnerabilities or severe incidents within 24 hours of discovery. The European Commission published practical guidance on July 27, 2026, and the Eclipse Foundation and OWASP united for CRA Open Source Security on August 5, 2026.

Why it matters — Manufacturers of products with digital elements sold in the EU must implement structural shifts in product security and establish rapid incident reporting processes by September 11, 2026.

openssf.org · 09 August 2026 · Read the original →

Another week of writing policies for the code we didn't write in the first place.

7 stories, every Friday

Published here every week. Follow by RSS to get it as it lands.

Next issue →