Nelson: rust-lang/rust is adopting an LLM policy
The Rust language team has adopted a new policy regarding the use of Large Language Models (LLMs) in the project. Under the policy, contributors are not required to use LLMs, reviewers are not obligated to review LLM-generated pull requests, and any LLM-generated output in public documentation, PR descriptions, or GitHub comments must be explicitly marked.
LWN · 09 August 2026 · Read the original →
The return of Shai-Hulud: How SonarQube detects and contains the npm worm
A new wave of the self-propagating Shai-Hulud worm is actively spreading through the npm ecosystem. The worm targets developer and CI/CD credentials to compromise accounts and republish itself inside additional packages, creating a cascading security risk across dependencies.
Tidelift · 09 August 2026 · Read the original →
The Software Stewardship Lab launches
The Software Stewardship Lab, a new nonprofit based in Scotland, has launched to address critical issues in the open-source ecosystem. The organization's initial research focuses on mapping hidden dependency graphs to monitor critical packages in real time and publishing reports on maintainer burnout.
LWN · 09 August 2026 · Read the original →
LightDM lives: version 1.33.0 released
After four years of inactivity under Canonical's sponsorship, the LightDM display manager has been transferred to a new community-led repository. The project is now actively maintained by independent community members, resulting in the release of version 1.33.0 with Qt6 support and various optimizations.
LWN · 09 August 2026 · Read the original →
Why Sonar signed the Open Weights and American AI Leadership letter
Sonar has signed the Open Weights and American AI Leadership letter, advocating for an AI ecosystem built around open-weight models. The letter argues that practical, secure, and sustainable AI adoption across the economy depends on organizations being able to freely download, run, and modify model weights.
Tidelift · 09 August 2026 · Read the original →
npm 'Shai-Hulud' Worm Compromises Packages
Security researchers identified an active supply chain attack involving the 'ChainDrop' / 'Shai-Hulud' malware family, which compromised over 1,300 npm package versions, including Keyv and related caching libraries. The malware steals developer credentials and self-propagates by republishing modified packages.
microsoft.com · 09 August 2026 · Read the original →
EU CRA Reporting Deadline Nears
The EU Cyber Resilience Act's (CRA) mandatory incident and vulnerability reporting requirements formally kick in on September 11, 2026. Manufacturers marketing connected products in the EU must report actively exploited vulnerabilities or severe incidents within 24 hours of discovery. The European Commission published practical guidance on July 27, 2026, and the Eclipse Foundation and OWASP united for CRA Open Source Security on August 5, 2026.
openssf.org · 09 August 2026 · Read the original →
Another week of writing policies for the code we didn't write in the first place.
7 stories, every Friday
Published here every week. Follow by RSS to get it as it lands.