#source-code-access

[ follow ]
#github
Software development
fromInfoQ
2 days ago

GitHub Copilot CLI Reaches General Availability

GitHub's Copilot CLI is now generally available, enhancing AI-assisted development in software through natural language commands and autonomous workflows.
Information security
fromDevOps.com
1 week ago

GitHub Adds 37 New Secret Detectors in March, Extends Scanning to AI Coding Agents - DevOps.com

GitHub expanded secret scanning with 37 new detectors, enhanced push protection, and introduced scanning for AI coding agents in March.
JavaScript
fromTheregister
2 hours ago

GitHub recalls Phabricator with preview of Stacked PRs

GitHub's Stacked PRs feature simplifies the review process for large pull requests by allowing them to be organized in a manageable stack.
Software development
fromInfoQ
2 days ago

GitHub Copilot CLI Reaches General Availability

GitHub's Copilot CLI is now generally available, enhancing AI-assisted development in software through natural language commands and autonomous workflows.
Information security
fromDevOps.com
1 week ago

GitHub Adds 37 New Secret Detectors in March, Extends Scanning to AI Coding Agents - DevOps.com

GitHub expanded secret scanning with 37 new detectors, enhanced push protection, and introduced scanning for AI coding agents in March.
Information security
fromTechzine Global
9 hours ago

Attackers are targeting developers via Slack and Google Sites

A targeted phishing campaign exploits trust in the open-source community, tricking developers into providing credentials and installing malicious software.
EU data protection
fromInfoQ
1 day ago

How SBOMs and Engineering Discipline Can Help You Avoid Trivy's Compromise

SBOMs are essential for developers to enhance security and comply with new legislative requirements.
#ai-governance
fromInfoWorld
1 month ago
Artificial intelligence

Open source maintainers are being targeted by AI agent as part of 'reputation farming'

Software contribution is becoming programmable, shifting the attack surface from code to governance; machine-verifiable AI governance with provenance and auditable controls is required.
fromInfoWorld
1 month ago
Artificial intelligence

Open source maintainers are being targeted by AI agent as part of 'reputation farming'

Privacy professionals
fromSecurityWeek
1 day ago

BrowserGate: Claims of LinkedIn 'Spying' Clash With Security Research Findings

LinkedIn allegedly scans users' computers to collect data on browser extensions, raising concerns about corporate espionage.
Silicon Valley
fromThe Nation
1 day ago

The Death of an AI Whistleblower

Suchir Balaji, a whistleblower against OpenAI, claimed the company violated copyright laws by using vast amounts of internet data for its AI models.
#ai
fromFuturism
1 week ago
Intellectual property law

Anthropic Suddenly Cares Intensely About Intellectual Property After Realizing With Horror That It Accidentally Leaked Claude's Source Code

Intellectual property law
fromFuturism
1 week ago

Anthropic Suddenly Cares Intensely About Intellectual Property After Realizing With Horror That It Accidentally Leaked Claude's Source Code

Anthropic's copyright takedown request for its AI model's source code highlights hypocrisy in its stance on copyright laws.
Software development
fromTheregister
1 week ago

AI slop got better, so now maintainers have more work

AI-generated reports improve quality but increase workload for maintainers, necessitating more reviewers in open-source projects.
Information security
fromwww.theguardian.com
6 days ago

Anthropic says its latest AI model can expose weaknesses in software security

Claude Mythos exposes thousands of software vulnerabilities, prompting Anthropic to limit its release and collaborate with cybersecurity specialists.
DevOps
fromInfoQ
4 days ago

CNCF and Kusari Partner to Strengthen Software Supply Chain Security Across Cloud-Native Projects

CNCF and Kusari collaborate to enhance software supply chain security for cloud-native projects using AI-powered tools.
France news
fromTechCrunch
4 days ago

France to ditch Windows for Linux to reduce reliance on US tech | TechCrunch

France plans to transition government computers from Microsoft Windows to Linux to reduce reliance on U.S. technology.
#open-source
fromYcombinator
3 hours ago
Information security

Show HN: OpenParallax: OS-level privilege separation for AI agent execution | Hacker News

Software development
fromZDNET
1 week ago

How AI has suddenly become much more useful to open-source developers

AI tools are becoming increasingly useful for open-source maintainers, but legal and quality issues remain.
DevOps
fromZDNET
2 months ago

7 open-source apps I'd happily pay for - because they're that good

Many high-quality open-source applications exist across Linux, MacOS, and Windows; some are indispensable enough that users would willingly pay for them.
Software development
fromInfoWorld
2 months ago

Is AI killing open source?

AI-generated pull requests are overwhelming open-source maintainers by creating low-quality, context-free code that increases maintenance burden and risks project health.
Information security
fromYcombinator
3 hours ago

Show HN: OpenParallax: OS-level privilege separation for AI agent execution | Hacker News

An open-source AI agent was developed with a secure, sandboxed architecture to prevent data exfiltration and unauthorized actions.
Python
fromThe Hacker News
1 week ago

The State of Trusted Open Source Report

AI is reshaping software development and security, influencing container image usage and vulnerability management.
Software development
fromZDNET
1 week ago

How AI has suddenly become much more useful to open-source developers

AI tools are becoming increasingly useful for open-source maintainers, but legal and quality issues remain.
#linux
Software development
fromZDNET
20 hours ago

The new rules for AI-assisted code in the Linux kernel: What every dev needs to know

Torvalds and Linux maintainers establish a formal policy for AI-assisted code contributions, emphasizing human responsibility and accountability.
Software development
fromZDNET
1 day ago

This Linux distro offers an easy DNS switcher - but there's more to it that I like

iDealOS is a new MXLinux-based distribution offering two editions, emphasizing choice and the potential for paid Linux models.
Software development
fromZDNET
20 hours ago

The new rules for AI-assisted code in the Linux kernel: What every dev needs to know

Torvalds and Linux maintainers establish a formal policy for AI-assisted code contributions, emphasizing human responsibility and accountability.
Software development
fromZDNET
1 day ago

This Linux distro offers an easy DNS switcher - but there's more to it that I like

iDealOS is a new MXLinux-based distribution offering two editions, emphasizing choice and the potential for paid Linux models.
#ai-security
Artificial intelligence
fromTheregister
4 days ago

Project Glasswing and open source: The good, bad, and ugly

Project Glasswing aims to enhance open source software security with $100 million and the Mythos AI program to identify vulnerabilities.
fromDevOps.com
5 days ago
Information security

LayerX: Anthropic's Claude Code Can Easily Be Easily Weaponized - DevOps.com

Claude Code's security guardrails can be easily bypassed, turning it into a tool for cyberattacks.
Artificial intelligence
fromTheregister
4 days ago

Project Glasswing and open source: The good, bad, and ugly

Project Glasswing aims to enhance open source software security with $100 million and the Mythos AI program to identify vulnerabilities.
#openai
Privacy professionals
fromThe Verge
4 days ago

Florida launches investigation into OpenAI

Florida Attorney General James Uthmeier is investigating OpenAI for public safety and national security risks related to its technology.
Information security
fromThe Hacker News
1 day ago

OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident

OpenAI's macOS apps were affected by a supply chain attack, but no user data or internal systems were compromised.
Privacy professionals
fromThe Verge
4 days ago

Florida launches investigation into OpenAI

Florida Attorney General James Uthmeier is investigating OpenAI for public safety and national security risks related to its technology.
Information security
fromThe Hacker News
1 day ago

OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident

OpenAI's macOS apps were affected by a supply chain attack, but no user data or internal systems were compromised.
DevOps
fromTheregister
5 days ago

AWS: Agents shouldn't be secret, so we built a registry

AWS Agent Registry enhances visibility and control over AI agents in corporate environments.
Information security
fromTheregister
1 day ago

Fake Linux Foundation leader using Slack to phish devs

A malware campaign targets open source developers via Slack, impersonating a Linux Foundation official to steal credentials and compromise systems.
European startups
fromTechCrunch
6 days ago

I can't help rooting for tiny open source AI model maker Arcee | TechCrunch

Arcee has released Trinity Large Thinking, a 400B-parameter open-source LLM aimed at providing a competitive alternative to Chinese models.
Artificial intelligence
fromTechCrunch
3 days ago

Anthropic temporarily banned OpenClaw's creator from accessing Claude | TechCrunch

OpenClaw's future compatibility with Anthropic models is uncertain after a temporary account suspension and new pricing changes for third-party tools.
Information security
fromTechCrunch
37 minutes ago

Someone planted backdoors in dozens of WordPress plugins used in thousands of websites | TechCrunch

Dozens of WordPress plugins were compromised by a backdoor, distributing malicious code after a change in ownership of the plugin maker.
DevOps
fromDevOps.com
1 week ago

Survey Surfaces Increased Reliance on Open Source Software to Build Apps - DevOps.com

Open source software adoption is prevalent, with 49% of IT professionals reporting increased usage, primarily due to cost savings and avoiding vendor lock-in.
Information security
fromThe Hacker News
1 hour ago

New PHP Composer Flaws Enable Arbitrary Command Execution - Patches Released

Two high-severity vulnerabilities in Composer could allow arbitrary command execution through command injection flaws in the Perforce VCS driver.
fromTheregister
1 day ago

Linux 7.0 debuts as Linus Torvalds ponders AI's impact

The last week of the release continued the same 'lots of small fixes' trend, but it all really does seem pretty benign, so I've tagged the final 7.0 and pushed it out.
Software development
Artificial intelligence
fromInfoQ
5 days ago

Choosing Your AI Copilot: Maximizing Developer Productivity

Most developers are at an intermediate level of AI-assisted coding, with around 50% generating little to no code using AI.
fromTheregister
5 days ago

Microsoft locks out top open source devs, blames process

Microsoft did not send me any emails or prior warnings. I have received no explanation for the termination and their message indicates that no appeal is possible. I have tried to contact Microsoft through various channels but I have only received automated replies and bots. I was unable to reach a human.
Software development
Python
fromRealpython
2 weeks ago

How to Use Git: A Beginner's Guide - Real Python

Git is a version control system that tracks changes locally, while GitHub is an online platform for hosting Git repositories.
DevOps
fromApp Developer Magazine
2 weeks ago

Private Repository Secures the AI-driven Development Boom

ActiveState Curated Catalog provides a secure repository of vetted open source components for organizations, reducing risks associated with public registries.
Web frameworks
fromMedium
1 month ago

My 8-Year-Old Open-Source Project was a Victim of a Major Cyber Attack

A popular open-source project fell victim to a supply-chain attack through a development workflow loophole, threatening years of work and project reputation.
#cybersecurity
Information security
fromThe Hacker News
1 day ago

Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More

A critical zero-day vulnerability in Adobe Acrobat Reader is actively exploited, alongside state-sponsored cyber threats targeting U.S. infrastructure.
Information security
fromThe Hacker News
4 days ago

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

A new Zig dropper in the GlassWorm campaign stealthily infects all IDEs on a developer's machine through a malicious VS Code extension.
#ai-in-open-source
fromZDNET
1 month ago
Miscellaneous

Why AI is both a curse and a blessing to open-source software - according to developers

fromZDNET
1 month ago
Artificial intelligence

Why AI is both a curse and a blessing to open-source software - according to developers

fromZDNET
1 month ago
Miscellaneous

Why AI is both a curse and a blessing to open-source software - according to developers

Artificial intelligence
fromZDNET
1 month ago

Why AI is both a curse and a blessing to open-source software - according to developers

AI can benefit open source when properly applied for security analysis, but causes harm when generating low-quality automated bug reports that overwhelm maintainers with false positives.
Information security
fromTechCrunch
1 day ago

Hack at Anodot leaves over a dozen breached companies facing extortion | TechCrunch

Hackers stole data from multiple companies after breaching Anodot, exposing customers to extortion and potential data publication.
Software development
fromInfoWorld
6 days ago

GitHub Copilot CLI adds Rubber Duck review agent

Rubber Duck enhances problem-solving in coding, particularly for complex issues, achieving notable performance improvements with Claude Sonnet 4.6 and GPT-5.4.
Intellectual property law
fromArs Technica
1 month ago

AI can rewrite open source code-but can it rewrite the license, too?

A developer rewrote open-source code using AI while having prior exposure to the original codebase, claiming the AI-generated version is structurally independent and not a derivative work despite not following traditional clean room practices.
Software development
fromInfoQ
6 days ago

State of Play: AI Coding Assistants

Context engineering has evolved significantly in AI coding, focusing on curating information for better results with coding agents.
Software development
fromDevOps.com
6 days ago

Google's Next Coding Agent Could Change How Developers Think About Their Work - DevOps.com

Google's Jitro project aims to revolutionize coding agents from task execution to outcome-driven development.
#claude-code
Software development
fromArs Technica
1 week ago

Entire Claude Code CLI source code leaks thanks to exposed map file

Claude Code's complexity and architecture provide valuable insights for competitors and pose security risks for Anthropic.
Information security
fromTheregister
1 week ago

Claude Code's source reveals extent of system access

Claude Code has significant control over devices, raising concerns about data retention and potential misuse in sensitive environments.
Software development
fromArs Technica
1 week ago

Entire Claude Code CLI source code leaks thanks to exposed map file

Claude Code's complexity and architecture provide valuable insights for competitors and pose security risks for Anthropic.
Information security
fromTheregister
1 week ago

Claude Code's source reveals extent of system access

Claude Code has significant control over devices, raising concerns about data retention and potential misuse in sensitive environments.
Software development
fromArs Technica
1 week ago

Anthropic says its leak-focused DMCA effort unintentionally hit legit GitHub forks

Anthropic's DMCA takedown mistakenly removed legitimate forks of its code, leading to backlash and a request for reinstatement of affected repositories.
Software development
fromDevOps.com
1 week ago

Why Code Validation is the Next Frontier - DevOps.com

Shared staging environments are inadequate for modern development; isolated, on-demand setups are needed for effective validation.
Miscellaneous
fromTheregister
1 month ago

Open source package repositories face sustainability crisis

Open source repositories face unsustainable demand from companies misusing them as CDNs, prompting consideration of tiered payment systems where heavy users pay while individual developers remain free.
Software development
fromFortune
2 weeks ago

Anthropic leaks its own AI coding tool's source code in second major security breach | Fortune

Anthropic leaked the source code for Claude Code, exposing 500,000 lines of code due to a packaging error, raising cybersecurity concerns.
Information security
fromSecurityWeek
2 weeks ago

Critical Vulnerability in OpenAI Codex Allowed GitHub Token Compromise

OAuth tokens pose significant security risks, especially when long-lived, as they can lead to widespread breaches across multiple organizations.
fromTheregister
1 month ago

Gentoo moves to Codeberg amid GitHub Copilot concerns

Gentoo's official migration from Microsoft-owned GitHub to Codeberg is underway, as the Linux distribution fulfills a pledge to ditch the code shack due to "continuous attempts to force Copilot usage for our repositories." The decision was made public last month, when Gentoo confirmed it intended to migrate repository mirrors and pull request contributions to the new home. On February 16, the organization revealed it now had a presence on Codeberg, where contributions could be submitted.
Miscellaneous
Software development
fromInfoWorld
4 weeks ago

How AI is changing open source

Open source shifted focus from consumer visibility to critical infrastructure layers like Kubernetes, observability, and platform engineering that power AI and cloud-native systems.
Information security
fromMedium
4 weeks ago

Your AWS Credentials Are Still on GitHub Even After You Delete Them

Prevent credential exposure through .gitignore, environment variables, git-secrets pre-commit hooks, and AWS IAM roles instead of hardcoding credentials in code.
Information security
fromSecurityWeek
4 weeks ago

Tech Giants Invest $12.5 Million in Open Source Security

The Linux Foundation received $12.5 million in grants from major tech companies to advance open source security through AI-powered solutions and maintainer support.
Artificial intelligence
fromDevOps.com
1 month ago

GitHub Tests AI Agents to Handle Repository Maintenance

Agentic Workflows embed AI agents into GitHub Actions to automate routine repository maintenance, translating plain-language Markdown into executable automation while preserving human review.
Software development
fromTechRepublic
1 month ago

OpenAI Reportedly Eyes a GitHub Alternative - TechRepublic

OpenAI is building an internal GitHub alternative to optimize for AI-driven development, reduce vendor dependency, and offer customers a specialized repository platform.
Information security
fromSecurityWeek
1 month ago

Over 100 GitHub Repositories Distributing BoryptGrab Stealer

BoryptGrab, an information stealer distributed through over 100 GitHub repositories, harvests browser data, cryptocurrency wallets, and system information while some variants deploy a TunnesshClient backdoor for remote access.
Software development
fromInfoQ
1 month ago

GitHub's Points to a More Global, AI-Challenged Open Source Ecosystem in 2026

Open source faces unprecedented scale with 36 million new developers joining GitHub in 2025, requiring formal governance structures and strategies to manage AI-generated low-quality contributions.
fromTechzine Global
1 month ago

AI code undermines control over open source and IP

While AI tools are lowering the barrier to development, the gap between speed and manageability is growing. In just over a year and a half, AI code assistants have grown from an experiment to an integral part of modern development environments. They are driving strong productivity growth, but organizations are not keeping up with the associated security and governance issues.
Information security
Software development
fromInfoWorld
2 months ago

GitHub previews support for Claude and Codex coding agents

GitHub agents run inside repositories and tools to surface trade-offs, keep context, and create draft pull requests for standard code review.
fromInfoQ
2 months ago

GitHub Reworks Layered Defenses After Legacy Protections Block Legitimate Traffic

GitHub engineers recently traced user reports of unexpected "Too Many Requests" errors to abuse-mitigation rules that had accidentally remained active long after the incidents that prompted them. According to GitHub, the affected users were not generating high-volume traffic; they were "making a handful of normal requests" that still tripped protections. The investigation found that older incident rules were based on traffic patterns that were strongly associated with abuse at the time, but later began matching some legitimate, logged-out requests.
Information security
fromTechCrunch
1 month ago

For open-source programs, AI coding tools are a mixed blessing | TechCrunch

AI coding tools have caused as many problems as they have solved, according to industry experts. The easy-to-use and accessible nature of AI coding tools has enabled a flood of bad code that threatens to overwhelm projects. Building new features is easier than ever, but maintaining them is just as hard and threatens to further fragment software ecosystems. The result is a more complicated story than simple software abundance.
Software development
fromInfoWorld
2 months ago

For agentic AI, other disciplines need their own Git

Software engineering didn't adopt AI agents faster because engineers are more adventurous, or the use case was better. They adopted them more quickly because they already had Git. Long before AI arrived, software development had normalized version control, branching, structured approvals, reproducibility, and diff-based accountability. These weren't conveniences. They were the infrastructure that made collaboration possible. When AI agents appeared, they fit naturally into a discipline that already knew how to absorb change without losing control.
Software development
Information security
fromTheregister
2 months ago

Too much open-source AI is exposing itself to the web

Exposed, homogenous Ollama open-source AI deployments form a monoculture vulnerable to zero-day exploits, remote compromise, resource hijacking, and unnoticed abuse.
Software development
fromTheregister
2 months ago

Vibe coding may be hazardous to open source

AI coding tools reduced Tailwind documentation traffic by about 40%, cutting commercial exposure and causing Tailwind Labs to lay off three workers.
[ Load more ]