Newsdesk
Engineering
Data & AI
Industries
Enterprise Systems
Go-to-Market
Longform
DesignIndiaAll stories

Open Source

21 August 2026

23 new posts across 4 open source sources — 7 worth your time.

One week of Open Source, 7 stories, as published.

Supply Chain

Supply chain attack on arrayref (Rust blog)

A malicious Rust crate named proc-macro1 was uploaded to crates.io, and the popular arrayref crate was republished to depend on it. The registry maintainers intervened by removing the malicious version and restoring the safe versions of arrayref that had been yanked.

Why it matters — Highlights how attackers can compromise the supply chain by republishing popular packages with malicious dependencies, requiring registry-level intervention to restore safe versions.

LWN · 21 August 2026 · Read the original →

Governance

[$] Debian weighs eight options in vote on LLM usage

The Debian Project is voting on eight proposals regarding the use of large language models (LLMs) for project contributions. The vote was triggered by an initial proposal to completely ban LLM-assisted contributions, which led to intense community discussion and alternative options.

Why it matters — Shows how major open-source distributions are establishing formal governance policies to regulate AI-generated contributions.

LWN · 21 August 2026 · Read the original →

Security

[$] Fedora prepares for the end of AF_ALG

The Fedora Project plans to restrict the use of the Linux kernel's user-space Crypto API interface (AF_ALG) due to its link to recent high-profile security vulnerabilities like Copy Fail. This follows the kernel community's decision to deprecate the interface earlier in the year.

Why it matters — Illustrates how downstream distributions must proactively restrict deprecated kernel interfaces to mitigate systemic security risks.

LWN · 21 August 2026 · Read the original →

Governance

OSI Governance Survey

The Open Source Initiative (OSI) is conducting a governance survey to gather community feedback on how its Board of Directors should be selected and seated. The initiative aims to inform the future governance structure of the non-profit organization.

Why it matters — Provides a mechanism for community stakeholders to directly influence the leadership selection process of the organization that defines open-source licensing standards.

Open Source Initiative · 21 August 2026 · Read the original →

Maintainers

Mark J. Wielaard receives 2ⁿᵈ Annual Distinguished Service Award in Software Freedom

The Software Freedom Conservancy honored Mark J. Wielaard with the second annual Distinguished Service Award in Software Freedom for his decades of work as a GNU contributor, Valgrind and Elfutils maintainer, and Sourceware volunteer. The award includes a symbolic cash prize of one billion binary USD.

Why it matters — Highlights how non-profit foundations are actively recognizing and supporting the long-term maintainers of critical, low-level open-source infrastructure.

Software Freedom Cons. · 21 August 2026 · Read the original →

Foundations

Why Openness Matters More Than Ever

The Open Source Initiative's August 2026 newsletter discusses the relationship between open source and AI, noting that modern AI models rely heavily on open-source code, infrastructure, and research. The organization emphasizes the importance of openness as these technologies continue to make headlines.

Why it matters — Underlines the critical dependency of the modern AI industry on open-source infrastructure and the ongoing efforts to define openness in AI.

Open Source Initiative · 21 August 2026 · Read the original →

Supply Chain

Malicious Rust Crates Published via Account Takeover

On August 20, 2026, malicious versions of three popular Rust crates—arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9—were published to crates.io. An attacker compromised a maintainer account and added a typosquatted dependency that executed a remote payload during compilation. The malicious versions were removed within hours.

Why it matters — Organizations using these Rust crates must audit their Cargo.lock files and immediately rotate any credentials exposed on systems that built affected versions.

The Hacker News · 21 August 2026 · Read the original →

The work of securing and governing open source continues.

7 stories, every Friday

Published here every week. Follow by RSS to get it as it lands.

← Previous issue Next issue →