frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Bend 2 and the Vibe-Coding Trap

https://blog.liampwll.com/posts/bend_vibe_coding/
15•LiamPowell•20m ago•2 comments

OpenJev

https://openjev.com/
192•ilreb•2h ago•109 comments

ZCode, the GLM coding agent, silently uploads your Git history

https://tokenstead.ai/guides/zcode-silent-git-history-upload
96•cdnsteve•1h ago•17 comments

Jemalloc 5.4.0

https://github.com/jemalloc/jemalloc/releases/tag/5.4.0
198•gkfasdfasdf•8h ago•54 comments

Microsoft exec called AI scraping 'the largest theft of labor in human history'

https://techcrunch.com/2026/09/17/microsoft-exec-called-ai-scraping-the-largest-theft-of-labor-in...
294•pluc•2h ago•227 comments

The scourge of x86 emulation

https://fex-emu.com/Scourge-of-emulation/
181•dagmx•8h ago•37 comments

Cekura (YC F24) Is Hiring

https://www.ycombinator.com/companies/cekura-ai/jobs/AiWwUxI-forward-deployed-engineer-us
1•atarus•24m ago

Astra for Law

https://openai.com/index/astra-for-law/
516•vertigoruntime•16h ago•604 comments

Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint

https://prismml.com/news/bonsai-2-27b
478•JonSchneider•15h ago•145 comments

Replacing Pull Requests with Delta

https://zed.dev/blog/delta-public-beta
54•vquemener•1d ago•18 comments

Subnormal floating-point numbers are expensive on Intel processors

https://lemire.me/blog/2026/09/15/subnormal-floating-point-numbers-are-expensive-on-intel-process...
15•zdw•2d ago•3 comments

Bend – A language that blocks AI mistakes via proof, on CPU and GPU

https://bend-lang.com/
504•nicolas-siplis•15h ago•238 comments

Warren Buffett Steps Down as Berkshire Chairman, Names Son to Replace Him

https://www.nytimes.com/2026/09/18/business/warren-buffett-berkshire-chairman.html
44•saimiam•1h ago•18 comments

Qwen 3.8 Omni Flash

https://qwen.ai/blog?id=qwen3.8-omni-flash
257•jjcm•13h ago•90 comments

Hister: A private search engine for the pages you visit and the files you keep

https://github.com/asciimoo/hister
641•bookofjoe•19h ago•172 comments

Wax motor

https://en.wikipedia.org/wiki/Wax_motor
442•mhb•1d ago•76 comments

When the fractional part of a float fixes your shader

https://crocidb.com/post/when-the-fractional-part-of-a-float-fixes-your-shader/
54•vinhnx•1d ago•8 comments

Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA

https://global.fujitsu/en-global/pr/news/2026/09/14-02
609•my123•2d ago•236 comments

Pre-Greek: The lost language hidden within Ancient Greek

https://linguisticdiscovery.com/posts/pre-greek/
99•axiologist•9h ago•44 comments

Dr Julius Neubronner's Miniature Pigeon Camera

https://publicdomainreview.org/collection/dr-julius-neubronner-s-miniature-pigeon-camera/
15•vitonsky•2d ago•0 comments

How to Write with an LLM

https://sockpuppet.org/blog/2026/09/17/how-to-write-with-an-llm/
204•joeriddles•14h ago•131 comments

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

https://www.hacktron.ai/blog/hacking-openai
374•Handy-Man•9h ago•161 comments

Shapelearn Qwen 3.8 27B (13.1 GB VRAM)

https://byteshape.com/blogs/Qwen3.8-27B/
78•syntaxing•10h ago•17 comments

Ask A Monk – A digital wilderness for thoughts with no immediate answer

https://askamonk.online
50•13613288957•10h ago•27 comments

Flet 1.0 – Build cross-platform apps in Python

https://flet.dev/
136•absqueued•15h ago•69 comments

Telstra outage: The night a network decided the year was 2006

https://www.netnod.se/blog/telstra-outage-night-network-decided-year-was-2006
68•TMWNN•11h ago•29 comments

Diplodocus, Long Thought Exclusively American, Turns Up in Spain

https://www.sci.news/paleontology/spanish-diplodocus-15064.html
76•embedding-shape•3d ago•45 comments

Speeding up gearhash on ARM64

https://sam.dev/blog/gearhash-on-arm64
24•pranitha_m•2d ago•0 comments

Why I didn’t sign the Fields medallists’ letter

https://gowers.wordpress.com/2026/09/17/why-i-didnt-sign-the-fields-medallists-letter/
267•simianwords•1d ago•375 comments

The most important product decision is what you don't build

https://liamnugent.me/posts/what-you-dont-build/
122•ChrisArchitect•15h ago•41 comments
Open in hackernews

ZCode, the GLM coding agent, silently uploads your Git history

https://tokenstead.ai/guides/zcode-silent-git-history-upload
94•cdnsteve•1h ago

Comments

outloudvi•53m ago
LLM-paraphrased from the original post: https://blog.ferstar.org/en/posts/zcode-silent-workspace-sna...
Luc•36m ago
Indeed. Discussion here: https://news.ycombinator.com/item?id=49750694
mococa•48m ago
That’s explains the 300 million of tokens on the weekend only if you use their tool.
dude250711•47m ago
Is this a step forward compared to previous distillations or a step backwards?
theplumber•46m ago
Ohhh no another one found that agents don’t actually run locally. We already had the “grok uploads all my stuff to Google cloud bucket” news…

next I can’t wait to see news about “ai company is using my data without my consent” as well.

Aldipower•43m ago
That the article cannot distinguish between the git history 'git log' and the git repository, which is meant here, tells a lot.

Claude Fable uploads my git history (git log) every day to the Anthropic servers!

tancop•40m ago
Closed source agents are a red flag no matter if its China or America. Always use an open harness with a good reputation and enough users that someone will notice if they push malicious code like this one here. Right now that's Opencode and Pi.
hypfer•37m ago
I wouldn't list Opencode as "good reputation".

They had their own unbound "harness scans the whole user directory" oopsie and handled concerns about that by introducing code signing.

Which, yes, does have absolutely nothing to do with that issue.

I guess by now it is better, but to me they seem to lack the engineering culture necessary for a "good reputation" stamp.

__

Ref: https://github.com/anomalyco/opencode/issues/14925#issuecomm...

among other issues.

blfr•36m ago
Why?
edude03•35m ago
Their reputation is “bad” but not because of privacy concerns. I personally think they’re trustworthy
gwerbin•33m ago
How about the one where if you start a session outside of a Git repository, the "worktree root" is set to /. Bug report closed as "not planned".
hypfer
orf•35m ago
Ironic, given the various people here[1] extolling their trustworthiness because they have a “don’t train on my data” option.

1. https://news.ycombinator.com/item?id=49737922

api•34m ago
Lots of modern software plays it loose with privacy, but this IMO crossing a second line: doing so with zero notification whatsoever, in a massively intrusive way, against data that is almost certainly private and possibly illegal to exfiltrate, with no obvious way to turn it off.

That crosses into outright malware.

Makes me not want to use GLM or other Z.ai models either, since who knows what interesting easter eggs are embedded in their training data.

You know... (puts on foil hat)... I did notice that Z is also the weird Russian logo for their invasion of Ukraine and Russia and China have cooperated to some degree (or at least China is helping Russia in exchange for access to resources). I dismissed this when I first thought of it, but I will now leave it here. Still probably coincidence but my Bayesian priors were just updated in its direction very slightly.

menaerus•5m ago
How do you know this is not true with other vendors? I'm not defending them but I wouldn't believe anyone in this business unconditionally. Anthropic agent fwiw is not open source, gemini and codex are.
loh•34m ago
I recently began playing around with ZCode. Works pretty well. Super sketchy though if it is in fact silently uploading full git history of every user's projects. This is why we need not only open weight models, but open source harnesses as well. Luckily the project I'm trying ZCode on is already open source (Molecule.dev), and I'm already allowing full telemetry with my other agents/harnesses (e.g., Claude) for this particular project, so it's not a huge deal in my case, but it's obviously a huge deal for anything proprietary.
•
31m ago
FWIW, I don't think that they're being malicious. They instead just seem to have no idea nor do they care.

And the original comment I've replied to proves this strategy right! So from a business standpoint: excellent work.

mikkelam•10m ago
codex is also open source, though im not so sure about the reputation aspect.

The same can be said about opencode though.