frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

The Anthropic Hive Mind

https://steve-yegge.medium.com/the-anthropic-hive-mind-d01f768f3d7b
1•gozzoo•2m ago•0 comments

A Horrible Conclusion

https://addisoncrump.info/research/a-horrible-conclusion/
1•todsacerdoti•2m ago•0 comments

I spent $10k to automate my research at OpenAI with Codex

https://twitter.com/KarelDoostrlnck/status/2019477361557926281
1•tosh•3m ago•0 comments

From Zero to Hero: A Spring Boot Deep Dive

https://jcob-sikorski.github.io/me/
1•jjcob_sikorski•4m ago•0 comments

Show HN: Solving NP-Complete Structures via Information Noise Subtraction (P=NP)

https://zenodo.org/records/18395618
1•alemonti06•9m ago•1 comments

Cook New Emojis

https://emoji.supply/kitchen/
1•vasanthv•11m ago•0 comments

Show HN: LoKey Typer – A calm typing practice app with ambient soundscapes

https://mcp-tool-shop-org.github.io/LoKey-Typer/
1•mikeyfrilot•14m ago•0 comments

Long-Sought Proof Tames Some of Math's Unruliest Equations

https://www.quantamagazine.org/long-sought-proof-tames-some-of-maths-unruliest-equations-20260206/
1•asplake•15m ago•0 comments

Hacking the last Z80 computer – FOSDEM 2026 [video]

https://fosdem.org/2026/schedule/event/FEHLHY-hacking_the_last_z80_computer_ever_made/
1•michalpleban•16m ago•0 comments

Browser-use for Node.js v0.2.0: TS AI browser automation parity with PY v0.5.11

https://github.com/webllm/browser-use
1•unadlib•17m ago•0 comments

Michael Pollan Says Humanity Is About to Undergo a Revolutionary Change

https://www.nytimes.com/2026/02/07/magazine/michael-pollan-interview.html
1•mitchbob•17m ago•1 comments

Software Engineering Is Back

https://blog.alaindichiappari.dev/p/software-engineering-is-back
1•alainrk•18m ago•0 comments

Storyship: Turn Screen Recordings into Professional Demos

https://storyship.app/
1•JohnsonZou6523•18m ago•0 comments

Reputation Scores for GitHub Accounts

https://shkspr.mobi/blog/2026/02/reputation-scores-for-github-accounts/
1•edent•21m ago•0 comments

A BSOD for All Seasons – Send Bad News via a Kernel Panic

https://bsod-fas.pages.dev/
1•keepamovin•25m ago•0 comments

Show HN: I got tired of copy-pasting between Claude windows, so I built Orcha

https://orcha.nl
1•buildingwdavid•25m ago•0 comments

Omarchy First Impressions

https://brianlovin.com/writing/omarchy-first-impressions-CEEstJk
2•tosh•30m ago•1 comments

Reinforcement Learning from Human Feedback

https://arxiv.org/abs/2504.12501
2•onurkanbkrc•31m ago•0 comments

Show HN: Versor – The "Unbending" Paradigm for Geometric Deep Learning

https://github.com/Concode0/Versor
1•concode0•32m ago•1 comments

Show HN: HypothesisHub – An open API where AI agents collaborate on medical res

https://medresearch-ai.org/hypotheses-hub/
1•panossk•35m ago•0 comments

Big Tech vs. OpenClaw

https://www.jakequist.com/thoughts/big-tech-vs-openclaw/
1•headalgorithm•37m ago•0 comments

Anofox Forecast

https://anofox.com/docs/forecast/
1•marklit•37m ago•0 comments

Ask HN: How do you figure out where data lives across 100 microservices?

1•doodledood•38m ago•0 comments

Motus: A Unified Latent Action World Model

https://arxiv.org/abs/2512.13030
1•mnming•38m ago•0 comments

Rotten Tomatoes Desperately Claims 'Impossible' Rating for 'Melania' Is Real

https://www.thedailybeast.com/obsessed/rotten-tomatoes-desperately-claims-impossible-rating-for-m...
3•juujian•40m ago•2 comments

The protein denitrosylase SCoR2 regulates lipogenesis and fat storage [pdf]

https://www.science.org/doi/10.1126/scisignal.adv0660
1•thunderbong•41m ago•0 comments

Los Alamos Primer

https://blog.szczepan.org/blog/los-alamos-primer/
1•alkyon•44m ago•0 comments

NewASM Virtual Machine

https://github.com/bracesoftware/newasm
2•DEntisT_•46m ago•0 comments

Terminal-Bench 2.0 Leaderboard

https://www.tbench.ai/leaderboard/terminal-bench/2.0
2•tosh•46m ago•0 comments

I vibe coded a BBS bank with a real working ledger

https://mini-ledger.exe.xyz/
1•simonvc•47m ago•1 comments
Open in hackernews

Greg Kroah-Hartman explains the Cyber Resilience Act for open source developers

https://www.theregister.com/2025/09/30/cyber_reiliance_act_opinion_column/
46•CrankyBear•4mo ago

Comments

whitehexagon•4mo ago
"As long as a project is not organized as a legal or commercial entity, the CRA requires only a basic "readme" with a security contact."

I share code for the good of the industry and society. A lot of what developers do, is solving problems, and the solutions can often be time consuming and difficult to find. So there is a lot of value in Open Source.

What I will not do, is accept personal liability in any way for those solutions I share. Then it becomes a professional partnership, and I will expect a contract and compensation.

CRA has a simple effect for me, I will no longer share code. I have deleted my github account because of this trend to "know your developer", and as a small stand agAInst our rush towards AGI. I wonder where the liability lies for all this AI/LLM regurgitated copyrighted code?

detaro•4mo ago
did you read the sentence after the one you quoted?
whitehexagon•4mo ago
sure, I have no control if the software is monetized or not. And this is still a fundamental change in how open source works. A name behind every line of code.
detaro•4mo ago
The one selling it is the one that has the obligations. If a company grabs open-source code from you and sells it (e.g. as part of a bigger product) to someone else, they have to assume liability towards their customer, you don't have to be involved at all if you don't want to. That's the good thing about the carve-outs established, it's not your problem if you are just publishing your code for fun, the ball is entirely in the court of people that want to profit from it.
whitehexagon•4mo ago
I understand that part. But I could read 'monetized' as a project the received a donation.
Borealid•4mo ago
I think that's how it's intended to be read.

If you allow yourself to make money from the code, you're accepting liability for it. If you choose not to accept money in exchange for it, you don't have to accept liability.

This seems fair to me - the law doesn't let you both "sell" it (however low the minimum price is) and refuse to give any rights to the people who gave you money.

hcfman•4mo ago
The big problem is reward risk. Risk is 15,000,000 euros. Reward is peanuts.

In the past we could choose to work for peanuts with low risk. Now we can't. We have to work for nothing or work for a lot to have a chance of covering compliance.

jeroenhd•4mo ago
The GDPR carries a fine risk of up to 20 million, but usually the fines are a few hundred/thousand euros depending on the entity. Think "300 euro fine to a driving school" rather than "300 million euro fine to Google".

And even then, you have to be unlucky enough to actually get caught and investigated by market surveillance authorities. I think you're going to be more likely to get caught up in income/donation/gift tax bracket fraud investigation than to ever feel the impact of the CRA as a hobby open source dev.

iamnothere•4mo ago
It would be foolish to ignore the risk, however, especially if you work on something potentially controversial, such as encryption, privacy tools, or any software that may have uses that the EU frowns upon. I strongly suspect that this will eventually be used as a cudgel against disfavored projects/devs to compel project changes or even kill the project outright (or force it to move overseas).

If you’re a FOSS dev in the EU who works on something controversial, and you accept donations, it would be better to outsource the project “ownership” to someone unnamed or outside of EU jurisdiction.

pixl97•4mo ago
This is a rather big maybe.

Now, from a US perspective rather than an EU one, even being investigated in the US carries a huge risk. It is especially bad in the case that someone wants to prove a point against you. You could suddenly find yourself having to spend huge amounts of money defending yourself because someone wants to make a name for themselves, or you pissed a large political donor off.

iamnothere•4mo ago
Patreon/LiberaPay style individual sponsorship should be a simple path around this. If I am sponsoring an individual because I like the work they do in general, I am not contributing towards a single “project”. Especially if the dev contributes to more than one project. The wider the grey area the better.

Perhaps the future is shadowy projects led by an anonymous figure who merely merges pull requests, while named devs contribute work and receive support from their fans/supporters.

jkaplowitz•4mo ago
Greg K-H's explanation (as paraphrased by the journalist) confirms that, for example, receiving payment for an article which is accompanied by a software example would not trigger the requirements that come with monetization. Here's the exact quote - look at the "even when" part:

"There is no legal risk for individual contributors simply sharing code online or in publications, even when they receive payment for writing an article, as long as the software itself is not monetized or organized."

So, maybe EU developers would have to learn the safe wording through which to solicit and accept donations, but at the very least, donations supporting their software activities in general (and not tied to a specific software program) will likely not increase CRA requirements - and maybe even voluntary donations to support development of a specific software program but which are not in any way mandatory.

eduction•4mo ago
The sentence says you can fall under more onerous terms if the project is “organized,” whatever that means, and even under the loosest terms you are required to report security issues to an outside organization. So there is liability if you don’t. And virtually any project has arguable security issues.
SAI_Peregrinus•4mo ago
CYA & report all issues to said outside organization? Any bug where a feature doesn't work is a denial of service on that feature, and therefore a security issue. Lack of accessibility features is a DoS against people who need those features and thus a security issue, and so adding screenreader support is a security fix. Etc, etc.
eduction•4mo ago
If people knew about all the vulns in their software the vulns wouldn’t exist. You can’t disclose if you don’t know. And establishing when you “should” know or what counts as an actionable report will require basically a lawyer to untangle. CYA = hire a lawyer for your open source code. No thanks I think I’ll keep it on my drive and off GitHub.
iamnothere•4mo ago
You have another alternative: share the code on a Radicle node hosted as a Tor onion site. Nobody needs to know who you are.

I am hoping an anonymous ecosystem springs up due to the increasingly hostile legal environment around development.

ale42•4mo ago
Or put code in the public domain?
eduction•4mo ago
This shouldn’t be downvoted. “I do not accept liability” is literally the core of every open source license. Go look. Even MIT.
pitdicker•4mo ago
Software engineering takes surprisingly little responsibility compared to other engineering disciplines. This seems like a good development to me.

Of course you can't expect someone who just put something online as a hobby project to take much responsibility. But to ask some basic security/reliability from companies, foundations etc... Shouldn't that just be normal?

whitehexagon•4mo ago
A lot of software is built on layer upon layer of unknown code and black boxed silicon. It is hard to know how that would work in practice.
pitdicker•4mo ago
To give an example from my software at work, structural engineering: You make a 3D-model (BIM, Building Information Model) of the steel skeleton of some project. The software can than generate 2D drawings, the blueprints. All beams, colums etc should be labeled in the drawing with the steel profile and quality (if non-standard).

However the software has a terrible label placement algorithm that happily switches around the labels of adjacent elements. And it does so without notice after some changes to the model. That is behavior that can lead to pretty dangerous mistakes.

The reply of the software company: you have to check it anyway. That is why you get paid, right?

dhx•4mo ago
The overloaded "software engineering" label can also refer to formal software engineering centered around examples of DO-178C for aviation software, IEC 61508 for railway software, ISO 26262 for road vehicle software, EAL5+ for cybersecurity related software, etc. It's somewhat unfortunate the label is also applied to CRUD websites and mobile applications, even there there is a world of difference in the various levels of formal engineering applied.
ChrisMarshallNY•4mo ago
> CRUD websites and mobile applications

These can be quite intense (but, to be fair there's a ton of dross, there, as well). Probably best to avoid the broad brush.

pixl97•4mo ago
It's somewhat unfortunate the label is also applied to CRUD websites and mobile applications,

These websites and applications can still have vast security implications depending on what kind of data is being collected.

The advertising industry has done security a huge disfavor by collecting every bit of data they can about everyones actions all the time. Adding some ad library to your website or app now could turn it into a full time tracking device. And phone manufactures like Google don't want this to change as the more information they get, the more ads they can stuff in your face.

hulitu•4mo ago
> ISO 26262

This is only about safety. As i told to my coleagues in a former workplace: Safety first (that was one of company's mottos), quality second.

hulitu•4mo ago
> But to ask some basic security/reliability from companies, foundations etc... Shouldn't that just be normal?

For SW ? No way. For electronic components, yes, for mechanical components, yes, but not for software. It is not cool. Fixing bugs is much, much harder than modifying UI elements (hello Google, Microsoft) with every release.

throw7•4mo ago
Even the requirement of a security email contact in a readme is a liability put on the hobbyist. It's antithetical to making code available "as is".

Greg KH says it's going to be great... let me ask, can I /dev/null the email Greg?

simon04•4mo ago
Video: https://youtu.be/U7pZbCnJxEw?t=6105 (Kernel Recipes 2025 - Day 2)