Supply chain attack on arrayref (Rust blog)
A malicious Rust crate named proc-macro1 was uploaded to crates.io, and the popular arrayref crate was republished to depend on it. The registry maintainers intervened by removing the malicious version and restoring the safe versions of arrayref that had been yanked.
LWN · 21 August 2026 · Read the original →
[$] Debian weighs eight options in vote on LLM usage
The Debian Project is voting on eight proposals regarding the use of large language models (LLMs) for project contributions. The vote was triggered by an initial proposal to completely ban LLM-assisted contributions, which led to intense community discussion and alternative options.
LWN · 21 August 2026 · Read the original →
[$] Fedora prepares for the end of AF_ALG
The Fedora Project plans to restrict the use of the Linux kernel's user-space Crypto API interface (AF_ALG) due to its link to recent high-profile security vulnerabilities like Copy Fail. This follows the kernel community's decision to deprecate the interface earlier in the year.
LWN · 21 August 2026 · Read the original →
OSI Governance Survey
The Open Source Initiative (OSI) is conducting a governance survey to gather community feedback on how its Board of Directors should be selected and seated. The initiative aims to inform the future governance structure of the non-profit organization.
Open Source Initiative · 21 August 2026 · Read the original →
Mark J. Wielaard receives 2ⁿᵈ Annual Distinguished Service Award in Software Freedom
The Software Freedom Conservancy honored Mark J. Wielaard with the second annual Distinguished Service Award in Software Freedom for his decades of work as a GNU contributor, Valgrind and Elfutils maintainer, and Sourceware volunteer. The award includes a symbolic cash prize of one billion binary USD.
Software Freedom Cons. · 21 August 2026 · Read the original →
Why Openness Matters More Than Ever
The Open Source Initiative's August 2026 newsletter discusses the relationship between open source and AI, noting that modern AI models rely heavily on open-source code, infrastructure, and research. The organization emphasizes the importance of openness as these technologies continue to make headlines.
Open Source Initiative · 21 August 2026 · Read the original →
Malicious Rust Crates Published via Account Takeover
On August 20, 2026, malicious versions of three popular Rust crates—arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9—were published to crates.io. An attacker compromised a maintainer account and added a typosquatted dependency that executed a remote payload during compilation. The malicious versions were removed within hours.
The Hacker News · 21 August 2026 · Read the original →
The work of securing and governing open source continues.
7 stories, every Friday
Published here every week. Follow by RSS to get it as it lands.