<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Open Source Watch</title>
    <description>What&#39;s what with open-source news.</description>
    
    <link>https://opensourcewatch.beehiiv.com/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/nE82wpr2Mi.xml" rel="self"/>
    
    <lastBuildDate>Sat, 16 May 2026 03:31:04 +0000</lastBuildDate>
    <pubDate>Thu, 07 May 2026 20:59:19 +0000</pubDate>
    <atom:published>2026-05-07T20:59:19Z</atom:published>
    <atom:updated>2026-05-16T03:31:04Z</atom:updated>
    
      <category>Business</category>
      <category>Programming</category>
      <category>Technology</category>
    <copyright>Copyright 2026, Open Source Watch</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/479c6f06-175e-4e93-9da8-13db93b55923/sjvn.jpeg.256x256_q100_crop-smart.jpg</url>
      <title>Open Source Watch</title>
      <link>https://opensourcewatch.beehiiv.com/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>Here&#39;s why data center company IREN bought cloud-native power Mirantis</title>
  <description>In a word: AI. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d543df84-9c3a-467c-8f8f-f3671bf668bc/IREN_Mirantis.jpg" length="94624" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis</guid>
  <pubDate>Thu, 07 May 2026 20:59:19 +0000</pubDate>
  <atom:published>2026-05-07T20:59:19Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d543df84-9c3a-467c-8f8f-f3671bf668bc/IREN_Mirantis.jpg?t=1778186357"/></div><p class="paragraph" style="text-align:left;">Australian AI infrastructure provider <a class="link" href="https://www.mirantis.com/blog/a-new-chapter-for-mirantis/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">IREN is acquiring cloud‑native software specialist Mirantis</a> in an all‑stock deal valued at about $625 million. Now you may be wondering: Why? The answer&#39;s simple: <a class="link" href="https://iren.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">IREN</a>, best known for its large‑scale data center footprint, wants to be an AI powerhouse. To make that happen, the company is betting that integrating its data centers and <a class="link" href="https://www.mirantis.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">Mirantis</a>&#39;s Kubernetes and cloud-native software stack will give it an edge in the surging AI infrastructure market. </p><p class="paragraph" style="text-align:left;">With Mirantis’ software and services, IREN aims to shift from simply offering GPU‑rich facilities to selling a full AI cloud platform that includes orchestration, observability, lifecycle management, and enterprise support. The hope is that a full data center and software infrastructure stack will command higher margins and appeal to enterprises looking for alternatives to hyperscale public clouds for AI workloads.</p><p class="paragraph" style="text-align:left;">What Mirantis brings to the plan is its comprehensive open-source, cloud-native software stack. It started as an <a class="link" href="https://www.openstack.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">OpenStack</a> integrator and has evolved into a broader cloud‑native infrastructure company centered on Kubernetes, multi‑cloud operations, developer tools, and, more recently, AI‑focused platforms. Its portfolio now spans Kubernetes management, container platforms, and the <a class="link" href="https://www.mirantis.com/blog/ai-infrastructure-stack/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">k0rdent AI infrastructure stack</a>, all of which have been validated under <a class="link" href="https://www.nvidia.com/en-us/data-center/isv-validation-program/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">NVIDIA’s AI Cloud Ready program</a>.</p><p class="paragraph" style="text-align:left;">Mirantis also brings over 1,500 enterprise customers to the table. This gives IREN a ready‑made channel into organizations already running cloud‑native workloads. For Mirantis, the acquisition pairs its software and operational expertise with the large‑scale GPU, power, and data center capacity that many of its AI‑minded customers are seeking but cannot easily put together on their own.</p><p class="paragraph" style="text-align:left;">For those of you who are new to Mirantis&#39;s AI plans, K0rdent AI is the company&#39;s enterprise platform for building, deploying, and operating AI applications and inference services on top of Kubernetes. It sits on top of the <a class="link" href="https://k0rdent.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">open-source k0rdent project</a>. This stack is aimed at platform engineers, MLOps teams, and service providers who need to manage AI workloads at scale across clouds and on‑prem.</p><p class="paragraph" style="text-align:left;">Oh, and for those who&#39;ve been wondering about this newly merged company and Mirantis&#39;s open-source plans, Mirantis CTO Shaun O&#39;Meara wants you to know that the company&#39;s staying loyal to its open-source roots. In a blog post, O&#39;Meara said, &quot;<a class="link" href="https://www.mirantis.com/blog/on-the-acquisition/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">Our contributions to k0rdent, Kubernetes, k0s, OpenStack, and more continue</a>. The maintainers and contributors working on those projects stay in place. k0rdent remains open source. K0s will continue to be curated. Our participation in community governance, our upstream contributions, and our commitment to open standards are not transitional. They are structural to how we build products and how we engage with the ecosystem. That does not change.&quot;</p><p class="paragraph" style="text-align:left;">As for everything else, Mirantis, Alex Freedland, Mirantis&#39;s co-founder and CEO, wants to <a class="link" href="https://www.mirantis.com/blog/a-new-chapter-for-mirantis/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">assure customers, partners, and employees that the company will be staying its course</a>. There will be no radical changes, except now. If you need data center power, Mirantis can provide that as well. In short, the deal is a strategic match between “infrastructure at scale” and the software needed to make that infrastructure useful for AI workloads. </p><p class="paragraph" style="text-align:left;">Since this deal was signed, <span style="color:rgb(0, 0, 0);font-family:Lyon, Helvetica, Arial, sans-serif;font-size:18px;"><a class="link" href="https://nvidianews.nvidia.com/news/nvidia-and-iren-announce-strategic-partnership-to-accelerate-deployment-of-up-to-5-gigawatts-of-ai-infrastructure?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">Nvidia announced a partnership </a></span><span style="font-size:18px;"><a class="link" href="https://nvidianews.nvidia.com/news/nvidia-and-iren-announce-strategic-partnership-to-accelerate-deployment-of-up-to-5-gigawatts-of-ai-infrastructure?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">under which IREN</a></span><span style="font-size:18px;"> will provide up to 5 gigawatts of Nvidia DSX designs to power AI workloads across its global data centers</span><span style="color:rgb(0, 0, 0);font-family:Lyon, Helvetica, Arial, sans-serif;font-size:18px;">. This bodes well for the pairing of IREN and Mirantis. </span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/open-source-repositories-are-being-overwhelmed-but-there-is-an-answer/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=here-s-why-data-center-company-iren-bought-cloud-native-power-mirantis" target="_blank" rel="noopener noreferrer nofollow">10 trillion downloads are crushing open-source repositories - here&#39;s what they&#39;re doing about it</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/meta-abandons-llama-spark/?utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick&utm_medium=referral&utm_source=opensourcewatch.beehiiv.com" target="_blank" rel="noopener noreferrer nofollow">Meta abandons open-source Llama for proprietary Muse Spark</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/warp-open-source-client/?utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick&utm_medium=referral&utm_source=opensourcewatch.beehiiv.com" target="_blank" rel="noopener noreferrer nofollow">Warp’s gamble: Going open source to take on closed-source rivals</a></p></li></ul><h3 class="heading" style="text-align:left;" id="every-headline-satisfies-an-opinion">Every headline satisfies an opinion. Except ours.</h3><div class="image"><a class="image__link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_alphanumeric_id}}&utm_content=prospecting_every_headline&_bhiiv=opp_04a85931-3638-4fc1-96eb-5f49b9566992_1b75ca79&bhcl_id=61d8ec40-c6f9-4a0c-a723-2186b974da75_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ba04f022-af6b-4db8-aaad-ddf5b3b21c89/1440_January-Static-Image-ODY-38056_1x1_V1.png?t=1769711583"/></a></div><p class="paragraph" style="text-align:left;">Remember when the news was about what happened, not how to feel about it? <a class="link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_alphanumeric_id}}&utm_content=prospecting_every_headline&_bhiiv=opp_04a85931-3638-4fc1-96eb-5f49b9566992_1b75ca79&bhcl_id=61d8ec40-c6f9-4a0c-a723-2186b974da75_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">1440&#39;s Daily Digest</a> is bringing that back. Every morning, they sift through 100+ sources to deliver a concise, unbiased briefing — no pundits, no paywalls, no politics. Just the facts, all in five minutes. For free.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_alphanumeric_id}}&utm_content=prospecting_every_headline&_bhiiv=opp_04a85931-3638-4fc1-96eb-5f49b9566992_1b75ca79&bhcl_id=61d8ec40-c6f9-4a0c-a723-2186b974da75_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Read the newsletter trusted by 4.5 million fact-seekers.</a></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=b6df2af3-bbc1-49f9-ab50-e25e58cb44c4&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>New Airbyte Agents: Cleaning up messy data for AI Agents</title>
  <description>According to Airbyte, AI agents are failing in the real world because of sloppy data. Their new Airbyte Agents can straighten out the data. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8f6249f4-6f96-4176-8450-c7e16d188de0/Airbyte_Agent.jpg" length="8598" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/new-airbyte-agents-cleaning-up-messy-data-for-ai-agents</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/new-airbyte-agents-cleaning-up-messy-data-for-ai-agents</guid>
  <pubDate>Wed, 06 May 2026 12:00:00 +0000</pubDate>
  <atom:published>2026-05-06T12:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">If you know <a class="link" href="https://airbyte.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Airbyte</a>, you know it as an important open-source data integration and <a class="link" href="https://aws.amazon.com/compare/the-difference-between-etl-and-elt/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Extract, Load, Transform (ELT)</a> platform that you use to move data from many sources, e.g., APIs, databases, SaaS apps, and files into data warehouses, lakes, and databases. Now, the company is using its data superpowers to provide AI agents with a unified, query-ready view of enterprise data before they even start working with the data.</p><p class="paragraph" style="text-align:left;">The company uses <a class="link" href="https://docs.airbyte.com/ai-agents?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Airbyte Agents to do this</a>. Instead of having agents orchestrate chains of ad hoc API calls at runtime, Airbyte Agents pre-replicate data into a search-optimized index, a &quot;context layer&quot; that can be accessed in one or two calls.</p><p class="paragraph" style="text-align:left;">Why? Airbyte argues that most production issues with AI agents are rooted not in model quality but in unreliable data access. Agents built on traditional runtime API orchestration. These often require chaining together five or six calls across disconnected systems to answer a single question. This drives up latency, burns tokens, and increases the likelihood that your Agents deliver stale or contradictory answers. By shifting the problem to the data layer, Airbyte is betting it can make agents more robust and predictable.</p><p class="paragraph" style="text-align:left;">As Michel Tricot, Airbyte co-founder and CEO, said in a statement, &quot;Most agent projects stall for the same reason: The model is fine, the data is a mess. Five disconnected systems, inconsistent entities, no shared state. Airbyte Agents gives every agent a unified view of the business, replicated and ready to query. That is what separates an agent that can do the work from one that just talks about it.&quot;</p><p class="paragraph" style="text-align:left;">At the heart of the new offering is what Airbyte calls the <a class="link" href="https://docs.airbyte.com/ai-agents/concepts/context-store?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Context Store</a>. This is a replicated, search-optimized index that unifies data from across business systems in advance. For example, it can retrieve and clean up Salesforce customer records, Zendesk tickets, Jira issues, and Slack conversations into a single queryable store. With context assembled in advance, agents query the Context Store directly rather than “chasing” live APIs, typically shrinking those five or six network calls down to one or two while cutting token consumption.</p><p class="paragraph" style="text-align:left;">Early adopters say the approach is already speeding up development. Nate Chambers, chief product officer at <a class="link" href="https://goorca.ai/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">ORCA Analytics,</a> said <a class="link" href="https://docs.airbyte.com/ai-agents?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Airbyte’s Agent Engine</a> compressed what the company thought would be a six-month roadmap into the first week of its beta test. According to Chambers, Airbyte is shipping the pieces needed for production-grade agentic workflows and delivering new connections faster than his team can integrate them on their own, making it easier to stop building custom pipelines and focus on product features.</p><p class="paragraph" style="text-align:left;">Airbyte Agents are available through two primary interfaces. The first is support for the <a class="link" href="https://www.zdnet.com/article/what-is-model-context-protocol-the-emerging-standard-bridging-ai-and-data-explained/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Model Context Protocol (MCP)</a>. With this approach, you can connect sources to Airbyte once, then build and run agents within clients like Claude, ChatGPT, and Cursor, or any MCP-compatible interface. With this approach, the company claims you won&#39;t need to do any coding at all. </p><p class="paragraph" style="text-align:left;">The second is an Agent SDK aimed at engineering teams that want to build custom agents and applications directly on top of the Context Store. With this approach, you get more control over your data&#39;s retrieval logic, permissions, and state.</p><p class="paragraph" style="text-align:left;">In either case, Michel Tricot, Airbyte&#39;s co-founder and CEO, explained, “Most agent projects stall for the same reason: The model is fine, the data is a mess. Five disconnected systems, inconsistent entities, no shared state.” He argued that giving every agent a unified, replicated view of business data is what separates agents that can actually execute work from those that merely generate plausible-sounding responses.</p><p class="paragraph" style="text-align:left;">Tricot added, &quot;We’ve spent years solving how to move and standardize data across systems. What’s changed is how that data gets used. Instead of powering dashboards, it’s now powering decisions and actions through AI agents. The underlying problem hasn’t changed—only the interface has.”</p><p class="paragraph" style="text-align:left;">You may be asking, why not just use Retrieval-Augmented Generation (RAG) and APIs? Don&#39;t they let you fetch data when you need it, too? Well, yes, they do. But, Tricot said,  What’s missing is a persistent, structured layer that maintains relationships and state across systems. Without that, agents are constantly reconstructing context at runtime, which is inefficient and error-prone.” He&#39;s got a point. </p><p class="paragraph" style="text-align:left;">At launch, Airbyte Agents ships with 50 connectors that can feed the Context Store from commonly used enterprise systems. The company plans to bring its catalog of over 600 connectors to Context Store in the coming months. </p><p class="paragraph" style="text-align:left;">Many of these integrations are evolving beyond read-only access: an increasing number support write actions, enabling agents to update records, create support tickets, or post messages directly into systems of record. All connectors are designed to honor OAuth-based authentication and row-level permissions so that agents see only the data their invoking users are authorized to access.</p><p class="paragraph" style="text-align:left;">Airbyte is also previewing a complementary feature called <a class="link" href="https://docs.airbyte.com/ai-agents/interfaces/ui/automations?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Automations</a>. This is a single pane of glass for composing and running agents directly inside the Airbyte platform. Built on the same Context Store foundation, Automations allows teams to design agentic workflows across connected systems without writing code. Automations is expected to reach general availability in a future release.</p><p class="paragraph" style="text-align:left;">To encourage customers to test the new capabilities, Airbyte is offering existing Airbyte users three months of access to Airbyte Agents with defined usage limits. Usage is metered in “Agent Operations.” This measuring stick bundles reads, searches, actions, and reasoning calls against the Context Store. This gives you a clear way to track and manage consumption as they bring agents into production.</p><p class="paragraph" style="text-align:left;">The key question is: Will this work? Well, there&#39;s one way to find out, and that&#39;s to give it a try. What I can say is that the approach certainly sounds promising to me. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Noteworthy AI stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://devops.com/when-ai-goes-really-really-wrong-how-pocketos-lost-all-its-data/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">When AI Goes Really, Really Wrong: How PocketOS Lost All Its Data</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/canonical-ai-approach-thoughtful-microsoft-should-take-note/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Canonical&#39;s approach to AI is refreshingly thoughtful - Microsoft should take note</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.theregister.com/2026/04/28/locked_stocked_and_losing_budget/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=new-airbyte-agents-cleaning-up-messy-data-for-ai-agents" target="_blank" rel="noopener noreferrer nofollow">Locked, stocked, and losing budget: AI vendor lock-in bites back</a></p></li></ul><h3 class="heading" style="text-align:left;" id="become-an-ai-expert-in-just-5-minut">Become An AI Expert In Just 5 Minutes</h3><div class="image"><a class="image__link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_1fb3c717-b373-4985-97b1-0562759913bd_12ba3285&bhcl_id=9f916bff-df6c-4c25-9ee0-8306ec4b570a_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/92c7ce90-e2c8-4d1a-a474-b31fa3759647/Vintage_11.png?t=1757641001"/></a></div><p class="paragraph" style="text-align:left;">If you’re a decision maker at your company, you need to be on the bleeding edge of, well, everything. But before you go signing up for seminars, conferences, lunch ‘n learns, and all that jazz, just know there’s a far better (and simpler) way: <a class="link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_1fb3c717-b373-4985-97b1-0562759913bd_12ba3285&bhcl_id=9f916bff-df6c-4c25-9ee0-8306ec4b570a_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Subscribing to The Deep View.</a></p><p class="paragraph" style="text-align:left;">This daily newsletter condenses everything you need to know about the <a class="link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_1fb3c717-b373-4985-97b1-0562759913bd_12ba3285&bhcl_id=9f916bff-df6c-4c25-9ee0-8306ec4b570a_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">latest and greatest AI developments</a> into a 5-minute read. Squeeze it into your morning coffee break and before you know it, you’ll be an expert too. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_1fb3c717-b373-4985-97b1-0562759913bd_12ba3285&bhcl_id=9f916bff-df6c-4c25-9ee0-8306ec4b570a_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Subscribe right here</a>. It’s totally free, wildly informative, and trusted by 600,000+ readers at Google, Meta, Microsoft, and beyond.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=00641a63-4a7e-4359-86b1-8d326025239e&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Fix &quot;Copy Fail&quot; before your Linux system gets sick</title>
  <description>The newly disclosed Linux kernel vulnerability dubbed “Copy Fail” allows any local user to become root on most mainstream Linux systems. Yow! But the fix is in, so patch it already! </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c68448cc-069c-480b-a831-47a4985577a8/Sick_Tux.png" length="824697" type="image/png"/>
  <link>https://opensourcewatch.beehiiv.com/p/fix-copy-fail-before-your-linux-system-gets-sick</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/fix-copy-fail-before-your-linux-system-gets-sick</guid>
  <pubDate>Tue, 05 May 2026 12:00:00 +0000</pubDate>
  <atom:published>2026-05-05T12:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><a class="link" href="https://copy.fail/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Copy Fail </a>isn&#39;t the worst Linux bug that was ever discovered, but it&#39;s more than bad enough. This local privilege escalation (LPE) flaw enables an unprivileged local user to easily obtain root. That&#39;s never good news. Worse still, this isn&#39;t a theoretical bug. Both Microsoft and the <a class="link" href="https://www.cisa.gov/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity and Infrastructure Security Agency (CISA)</a> both report spotting attacks in the wild. Oh joy!</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://theori.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Theori</a> and <a class="link" href="https://code.xint.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Xint Code</a> AI-assisted security researchers discovered <a class="link" href="https://nvd.nist.gov/vuln/detail/CVE-2026-31431?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">CVE‑2026‑31431</a>, a logic flaw in the Linux kernel’s crypto subsystem. This hole enabled a tiny 732‑byte Python script to become a reliable root exploit across major distributions, including Ubuntu, Amazon Linux, RHEL, SUSE, and others.</p><p class="paragraph" style="text-align:left;">The bug sits in the authencesn cryptographic template and the AF_ALG userspace crypto socket path. The problem was that a design change made in 2017 allowed page‑cache pages from read‑only files to be treated as writable buffers.</p><p class="paragraph" style="text-align:left;">By abusing this path, an unprivileged user can make the kernel perform a controlled 4‑byte overwrite in the page cache of any file they can read, such as a setuid‑root binary, such as /usr/bin/su.</p><p class="paragraph" style="text-align:left;">Adding insult to injury, because the corruption only touches the in‑memory page cache and never marks the underlying file as dirty, on‑disk checksums and standard integrity tools see a clean file even while the live system is executing attacker‑supplied code.</p><p class="paragraph" style="text-align:left;">The proof‑of‑concept exploit published by the researchers uses only standard Python 3.10 libraries and works unchanged on the four distributions they tested, turning a regular user shell into root in a single run. A demo showed the same script producing root shells on Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16 in one continuous session.</p><p class="paragraph" style="text-align:left;">Kernel privilege‑escalation bugs are not new. But the researchers argue that Copy Fail combines properties that make it unusually severe. Unlike race‑condition‑driven exploits such as 2016&#39;s <a class="link" href="https://www.redhat.com/es/blog/understanding-and-mitigating-dirty-cow-vulnerability?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Dirty COW</a> or 2022&#39;s <a class="link" href="https://dirtypipe.cm4all.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Dirty Pipe</a>, Copy Fail is a straightforward logic bug with no timing window, no crash‑prone retry loop, and no per‑distro offsets.</p><p class="paragraph" style="text-align:left;">Critically, the vulnerability requires only local code execution as a non‑privileged user. It doesn&#39;t need special kernel debugging options or pre‑existing exploitation primitives to successfully attack a system.</p><p class="paragraph" style="text-align:left;">Worse still, the exploit primitive can work across containers. Since the page cache is shared across all of a host&#39;s processes, a compromised container can corrupt a host‑level setuid binary, allowing it to break out of Kubernetes or other multi‑tenant container platforms.</p><p class="paragraph" style="text-align:left;">This is bad news with a capital B. </p><p class="paragraph" style="text-align:left;">The underlying error dates back over a decade. It&#39;s the result of three different Linux kernel changes, all of which were harmless by themselves. Together, they equaled trouble. </p><p class="paragraph" style="text-align:left;">First, support for the authencesn <a class="link" href="https://docs.kernel.org/crypto/api-aead.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Authenticated Encryption With Associated Data (AEAD)</a> algorithm used by IPsec ESP with extended sequence numbers landed in 2011. This enabled the caller’s destination buffer to be used as scratch space to reshuffle sequence number bytes for <a class="link" href="https://www.geeksforgeeks.org/computer-networks/what-is-hmachash-based-message-authentication-code/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Hash-based Message Authentication Code (HMAC)</a> processing.</p><p class="paragraph" style="text-align:left;">Next, in 2015, the kernel added AEAD support to AF_ALG, the socket interface that exposes crypto operations to userspace. This change also refactored authencesn to a newer AEAD interface that writes four bytes past the nominal output buffer into what it assumes is expendable scratch. So far, so harmless.</p><p class="paragraph" style="text-align:left;">The final deadly step came in 2017, when an optimization in algif_aead switched decryption to operate “in‑place,” chaining tag data from page‑cache‑backed file pages directly into the writable scatterlist and then setting the same list as both the source and destination for the crypto operation. Once that change shipped, authencesn’s four‑byte scratch write crossed the boundary into page‑cache pages of arbitrary readable files, turning the design quirk into a universal local privilege‑escalation bug.</p><p class="paragraph" style="text-align:left;">Whoops!</p><p class="paragraph" style="text-align:left;">The upstream fix removes the 2017 in‑place optimization and restores out‑of‑place operation for algif_aead, ensuring that page‑cache pages from splice() calls reside only in the source scatterlist, not the writable destination. This cleanly severs the path that allowed authencesn to scribble into cached file contents while leaving user‑visible crypto behavior intact.</p><p class="paragraph" style="text-align:left;">Since then, distributions have raced to ship patched kernels that incorporate the upstream change. </p><p class="paragraph" style="text-align:left;">As of May 4th, here&#39;s the status of the major Linux distros.</p><ul><li><p class="paragraph" style="text-align:left;">Arch Linux and Gentoo: Both are rolling‑release and pulled the upstream fix into their default kernels shortly after the 7.0 / 6.19‑series patch landed.</p></li><li><p class="paragraph" style="text-align:left;">Amazon Linux 2 / 2023: Amazon has released updated kernel packages that include the Copy‑Fail fix for affected versions.</p></li><li><p class="paragraph" style="text-align:left;">Debian: Updated kernel packages (e.g., Linux 6.12.85‑1 and later) for supported suites such as Bookworm and Trixie carry the patch once you pull from the *-security repo.</p></li><li><p class="paragraph" style="text-align:left;">Fedora: Recent Fedora 42+ kernels pulled in the upstream revert commit, so systems on recent updates are already protected.</p></li><li><p class="paragraph" style="text-align:left;">RHEL / AlmaLinux / Rocky:</p><ul><li><p class="paragraph" style="text-align:left;">AlmaLinux has released patched kernels for all supported streams (8, 9, and 10) via its main production repos. You can pull the new kernel-4.18.0-553.121.1.el8_10‑style packages and above.</p></li><li><p class="paragraph" style="text-align:left;">CloudLinux provides KernelCare live patches (e.g., K20260501_10 for Alma/Rocky 9) that apply the Copy‑Fail fix without rebooting.</p></li><li><p class="paragraph" style="text-align:left;">Red Hat and Rocky have been slower. Red Hat released its fix late on May 4th, and it&#39;s expected that Rocky will quickly floor. </p></li></ul></li><li><p class="paragraph" style="text-align:left;">SUSE / openSUSE: SUSE‑branded kernels for recent SLES and openSUSE releases have been updated with the Copy‑Fail patch, which is exposed via the normal zypper/zypper patch channels.</p></li><li><p class="paragraph" style="text-align:left;">Ubuntu: Canonical has published updated kernel packages for all affected releases (including 18.04, 20.04, 22.04, 24.04, and 26.04) that include the Copy‑Fail fix.</p></li></ul><p class="paragraph" style="text-align:left;">Once you have the patch installed, reboot your system, and all should be well. Don&#39;t wait. Since the exploit is both trivial, tiny, and public, you can assume that weaponized scripts will quickly appear in real‑world attack chains.</p><p class="paragraph" style="text-align:left;">Can&#39;t patch it yet? I recommend disabling the algif_aead module as a temporary mitigation.  That can be done by adding a modprobe rule that replaces the module with a no‑op and then unloading it from the running kernel:</p><p class="paragraph" style="text-align:left;">bash</p><p class="paragraph" style="text-align:left;">echo &quot;install algif_aead /bin/false&quot; | sudo tee /etc/modprobe.d/disable-algif.conf</p><p class="paragraph" style="text-align:left;">sudo rmmod algif_aead 2&gt;/dev/null</p><p class="paragraph" style="text-align:left;">For most environments, this mitigation shouldn&#39;t hurt a bit. However, if you know you use AF_ALG, for example, with <a class="link" href="https://github.com/cotequeiroz/afalg_engine?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">OpenSSL’s afalg engine, you should</a> weigh the trade‑off between risk and performance. Since I think we can safely assume attacks are already underway, you should lock down my system right now. </p><p class="paragraph" style="text-align:left;"><b>Noteworthy Linux and open-source stories:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/meta-abandons-llama-spark/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Meta abandons open-source Llama for proprietary Muse Spark</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/warp-open-source-client/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Warp’s gamble: Going open source to take on closed-source rivals</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/microsoft-open-sources-dos-1-0-much-more-than-the-code/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=fix-copy-fail-before-your-linux-system-gets-sick" target="_blank" rel="noopener noreferrer nofollow">Microsoft finally open sources DOS 1.0 - and it&#39;s so much more than the code</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><h3 class="heading" style="text-align:left;" id="become-an-ai-expert-in-just-5-minut">Become An AI Expert In Just 5 Minutes</h3><div class="image"><a class="image__link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_4b05f267-2dec-4b9d-a602-8dfe6eacf6f1_12ba3285&bhcl_id=56c876b7-1c0b-4d7b-9e95-ef261056f15f_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/92c7ce90-e2c8-4d1a-a474-b31fa3759647/Vintage_11.png?t=1757641001"/></a></div><p class="paragraph" style="text-align:left;">If you’re a decision maker at your company, you need to be on the bleeding edge of, well, everything. But before you go signing up for seminars, conferences, lunch ‘n learns, and all that jazz, just know there’s a far better (and simpler) way: <a class="link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_4b05f267-2dec-4b9d-a602-8dfe6eacf6f1_12ba3285&bhcl_id=56c876b7-1c0b-4d7b-9e95-ef261056f15f_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Subscribing to The Deep View.</a></p><p class="paragraph" style="text-align:left;">This daily newsletter condenses everything you need to know about the <a class="link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_4b05f267-2dec-4b9d-a602-8dfe6eacf6f1_12ba3285&bhcl_id=56c876b7-1c0b-4d7b-9e95-ef261056f15f_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">latest and greatest AI developments</a> into a 5-minute read. Squeeze it into your morning coffee break and before you know it, you’ll be an expert too. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://subscribe.thedeepview.com/?utm_campaign={{publication_alphanumeric_id}}&utm_source=beehiiv&utm_medium=newsletter&_bhiiv=opp_4b05f267-2dec-4b9d-a602-8dfe6eacf6f1_12ba3285&bhcl_id=56c876b7-1c0b-4d7b-9e95-ef261056f15f_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Subscribe right here</a>. It’s totally free, wildly informative, and trusted by 600,000+ readers at Google, Meta, Microsoft, and beyond.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=a40ed741-843c-4e26-b197-6065a2c5710f&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The Open Invention Network looks to the future of open-source patent protection </title>
  <description>OIN 2.0 has arrived, with its refreshed license and expanded Linux System definition. This updated take on the Open Invention Network reflects the biggest change in the patent non‐aggression consortium’s 20‐year history.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a631c60c-9bb1-4545-a2a0-5ae22df2290a/Keith_Bergelt.jpg" length="27130" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/the-open-invention-network-looks-to-the-future-of-open-source-patent-protection</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/the-open-invention-network-looks-to-the-future-of-open-source-patent-protection</guid>
  <pubDate>Tue, 27 Jan 2026 13:10:16 +0000</pubDate>
  <atom:published>2026-01-27T13:10:16Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h1 class="heading" style="text-align:left;" id="legally-linux-and-opensource-softwa">Legally, Linux and open-source software owe an enormous debt of gratitude to the <a class="link" href="https://docs.google.com/document/d/1g1XhrAYaGss6HJ3sBwcJKl3E_P_f2SKjTm7J1MdqBiQ/edit?tab=t.0&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection#heading=h.p6ouiwxp9ucz" target="_blank" rel="noopener noreferrer nofollow">Open Invention Network (OIN)</a>. The organization, the largest patent non-aggression community in the world, has protected open-source patents from patent trolls for over twenty years. Now, with <a class="link" href="https://openinventionnetwork.com/license-agreement-2/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">OIN 2.0</a>, members formally commit to share their Linux System patents and applications royalty‑free with all other OIN 2.0 participants worldwide.</h1><p class="paragraph" style="text-align:left;">The scope of that commitment is defined by <a class="link" href="https://openinventionnetwork.com/linux-system/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">OIN’s Linux System Definition</a>, which covers both the Linux kernel and an ever-growing set of adjacent programs that are now critical to modern infrastructure. The Linux System definition page explicitly anchors the 2.0 framework, distinguishing 2.0 Participants from those still on predecessor releases of the license.</p><p class="paragraph" style="text-align:left;">Over the last 18 months, OIN has systematically broadened the Linux System to cover more of the stack that enterprises actually deploy, from cloud and observability to automotive and IoT. Recent updates pulled in cloud‑native components such as <a class="link" href="https://istio.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Istio</a>, <a class="link" href="https://falco.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Falco</a>, <a class="link" href="https://argoproj.github.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Argo</a>, <a class="link" href="https://grafana.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Grafana</a>, and <a class="link" href="https://spire.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Spire</a>, alongside existing coverage for <a class="link" href="https://kubernetes.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Kubernetes</a> and <a class="link" href="https://www.openstack.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">OpenStack</a>, and added <a class="link" href="https://atlas.apache.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Apache Atlas</a> and <a class="link" href="https://solr.apache.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Apache Solr</a> on the enterprise data side.</p><p class="paragraph" style="text-align:left;">Networking, embedded, and automotive coverage have been beefed up with packages like <a class="link" href="https://openthread.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">OpenThread</a>, <a class="link" href="https://layers.openembedded.org/layerindex/recipe/348941/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">agl‑compositor</a>. and <a class="link" href="https://github.com/eclipse-archived/kuksa.val?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">kukusa.val</a>, reflecting the surge of Linux‑based systems in cars and connected devices. OIN describes these Linux System expansions as incremental, conservative additions designed to keep pace with open source innovation without destabilizing the cross‑license baseline that members rely on.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/oin-marks-20-years-of-defending-linux-and-open-source-from-patent-trolls/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">OIN turned 20 in 2025</a>, and it used the anniversary to underline the scale behind the 2.0 shift: community membership has grown to more than 4,000 participants from 157 countries and virtually every industry. Collectively, OIN community members now control more than 3 million patents and patent applications that are cross‑licensed royalty‑free within the Linux System scope.</p><p class="paragraph" style="text-align:left;">As Keith Bergelt, OIN&#39;s CEO, explained, &quot;For over 20 years, our mission has not wavered. We’ve protected open source, reduced patent litigation risks; provided an exclusive cross-license through our evolving Linux System definition; supported key open-source projects; contributed leadership and insights to the open-source ecosystem; empowered the continued growth of Open Source; and offered a suite of defense strategies for our global community of 4,000+ and growing members.&quot;</p><p class="paragraph" style="text-align:left;">The OIN also established and funded, with <a class="link" href="https://www.unifiedpatents.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Unified Patents</a>, the Open Source Zone. This organization has helped invalidate or review dozens of harmful patents since 2019. </p><p class="paragraph" style="text-align:left;">Today, needing more funding, OIN 2.0 has introduced its first fee structure. This was forced on the OIN because patent troll litigation cases increased by 20% in 2024, and each case costs between $2 and $4 million to fight. </p><p class="paragraph" style="text-align:left;">In a statement, Michael Lee, Google&#39;s Director and Head of Patents, explained, </p><p class="paragraph" style="text-align:left;">“The unparalleled success of open source has created a shared responsibility to ensure its future. OIN 2.0 represents a necessary evolution in how we collectively steward this resource. By transitioning to a shared, community-driven funding model, we ensure that OIN remains sustainable, robust, and capable of protecting the open-source commons.”</p><p class="paragraph" style="text-align:left;">These <a class="link" href="https://openinventionnetwork.com/oin-2-0/participation-fees/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">new fees</a> still cost companies with less than $10-million annual revenue and individuals not a penny. Even the largest companies, those with more than $500-million in revenue, only pay $24-thousand a year. This provides potent patent protection at a dirt-cheap price. There is no automatic enrollment in OIN 2.0. <a class="link" href="https://openinventionnetwork.com/join-oin-2-0/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Existing OIN members must sign up for OIN 2.0.</a></p><p class="paragraph" style="text-align:left;">So far, 129 companies and groups have joined OIN 2.0. These range from tech giants such as IBM/Red Hat, Google, and Microsoft to small community open-source groups such as <a class="link" href="https://www.gnu.org/software/parallel/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">GNU Parallel</a>, <a class="link" href="https://freebsdfoundation.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">The FreeBSD Foundation</a>, and <a class="link" href="https://www.documentfoundation.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">The Document Foundation</a> (<a class="link" href="https://www.libreoffice.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">LibreOffice</a>).</p><p class="paragraph" style="text-align:left;">For developers, vendors, and users, OIN 2.0 effectively raises the bar for would-be patent aggressors by binding more participants, in more jurisdictions, into a single non‑aggression pact around a broader slice of the open source stack. OIN is also pushing to lower the friction of joining: its membership form and 2.0 license can now be executed entirely online through its regional portals, reflecting a shift from back‑room IP deals to a more transparent, web-first enrollment process.</p><p class="paragraph" style="text-align:left;">From here, the success of OIN 2.0 will be measured less by splashy announcements than by what doesn’t happen: Patent lawsuits that never get filed, trolls that look elsewhere, and open-source projects that can ship without an in‑house patent war chest. For an ecosystem that now depends on Linux from phone to car to cloud cluster, that kind of peace may be the most important news of all.</p><p class="paragraph" style="text-align:left;"><b>Noteworthy Linux and open-source stories:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/drowning-in-ai-slop-reports-curl-ends-bug-bounties/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Drowning in AI slop, cURL ends bug bounties</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/why-ai-runs-on-linux/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">This OS quietly powers all AI - and most future IT jobs, too</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.theregister.com/2026/01/16/linus_torvalds_vibe_coding/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank" rel="noopener noreferrer nofollow">Just because Linus Torvalds vibe codes doesn&#39;t mean it&#39;s a good idea</a></p></li></ul><div class="embed"><a class="embed__url" href="https://www.beehiiv.com?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-invention-network-looks-to-the-future-of-open-source-patent-protection" target="_blank"><img class="embed__image embed__image--left" src="https://media.beehiiv.net/static_assets/defaults/beehiiv-thumbnail.png"/><div class="embed__content"><p class="embed__title"> beehiiv — The newsletter platform built for growth </p><p class="embed__description"> Access the best tools available in email, helping your newsletter scale and monetize like never before. </p></div></a></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=5e1c9f9a-72e8-4774-916d-9d84af801dcd&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Airbyte Enterprise Flex enables you to keep your AI data safe</title>
  <description>How do you keep your cloud data safe if you want to use it in an external AI program? Airbyte has an answer.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/48ab4529-a52f-49ed-a9e0-29dccce990fa/AirByte_Logo.jpg" length="15506" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe</guid>
  <pubDate>Thu, 25 Sep 2025 12:00:00 +0000</pubDate>
  <atom:published>2025-09-25T12:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/48ab4529-a52f-49ed-a9e0-29dccce990fa/AirByte_Logo.jpg?t=1758751521"/></div><p class="paragraph" style="text-align:left;">AI, in theory, can be a big help in getting work done. The reality, as we now know, is messier. One of the problems keeping AI from being more useful, though, is the inability of AI to safely use your private data is being addressed by <a class="link" href="https://airbyte.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Airbyte</a>, the open-source data company, with its newest program: <a class="link" href="https://airbyte.com/v2?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Enterprise Flex</a>.</p><p class="paragraph" style="text-align:left;">Enterprise Flex delivers data sovereignty and cloud flexibility for enterprises deploying AI and analytics at a global scale. It enables organizations to manage and activate their data with complete control via a unified cloud-based control plane while ensuring that critical data never leaves your company’s environment. With it, even if you have data silos located in multiple regions and infrastructure types—on-premises, private cloud, or multi-cloud — you can manage all their data safely. </p><p class="paragraph" style="text-align:left;">How? By decoupling the control plane (management interface) from the data plane (where data physically moves), you can manage integrations in the cloud while your actual data stays within their secure infrastructure.</p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">With this approach, your sensitive data remains within a company’s regional infrastructure. This way, you can continue to meet each location&#39;s strict regulatory and privacy requirements.</p><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/75bd381d-ded8-4e14-8cd4-7332c2e8f0f2/Airbyte_Enterprise_Flex_Diagram.jpg?t=1758751564"/><div class="image__source"><span class="image__source_text"><p>How Airbyte Enterprise Flex works.</p></span></div></div><p class="paragraph" style="text-align:left;">The program serves as a bridge between AI applications and data. This bridge is built from &quot;source connectors,&quot; which connect to the APIs, files, databases, or data warehouses from which you want to pull data. &quot;Destination connectors&quot; are the data warehouses, data lakes, databases, or analytics tools to which you want to push data. Airbyte and its partners supply over 600 of these connectors with a no-code AI-powered connector builder, so you can easily deploy them wherever you need them.</p><p class="paragraph" style="text-align:left;">The platform’s new Data Activation feature, AKA often referred to as reverse Extract, Transform, Load (ETL), enables users to move their data back and forth into business-critical applications for AI and analytics use cases. This lets you push insights directly from data warehouses into business apps, such as Salesforce, HubSpot, an in-house AI engine, or what have you. As the company boasts, this gives &quot;<a class="link" href="https://airbyte.com/ai?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Your AI agents context in minutes.</a>&quot;</p><p class="paragraph" style="text-align:left;">Earlier versions enabled you to replicate your data from a list of source connectors (APIs, DBs, files, or your own custom connector) to destination connectors (data warehouses, lakes, or databases). It integrates with dbt for the transformation part at the destination level, and with data orchestrators such as <a class="link" href="https://www.prefect.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Prefect</a>, <a class="link" href="https://dagster.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Dagster</a>, and <a class="link" href="https://airflow.apache.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Airflow</a>. This latest version, with the rise of AI, was the next logical step.</p><p class="paragraph" style="text-align:left;">Companies can deploy Enterprise Flex globally and train AI models within their own environment. With data activation and increased speed, AI innovation continues to progress rapidly, accompanied by enhanced data protection. This is in addition to the logistical and support advantages Airbyte Flex offers by decoupling the control plane, which determines how data is managed, routed, and processed, from the data plane, which is responsible for actually moving the data.</p><p class="paragraph" style="text-align:left;">To keep the data safe, all data pipelines use enterprise-grade encryption for data in transit, including TLS/SSL and HTTPS channels, to prevent unauthorized access during transfers. Airbyte also supports granular, role-based access control (RBAC) and single sign-on (SSO), letting administrators restrict who can interact with connections and datasets. Finally, it includes comprehensive audit logging and workspace isolation, helping teams maintain visibility and separation across projects and roles, strengthening security postures.</p><p class="paragraph" style="text-align:left;">Airbyte Flex uses the quasi-open-source <a class="link" href="https://www.elastic.co/licensing/elastic-license?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Elastic License 2.0 (ELv2)</a>. The core difference between this and a true open-source license is that you can&#39;t offer the program&#39;s resources as a managed service. You can, of course, use it within your own company. </p><p class="paragraph" style="text-align:left;">If you can live with that license, Airbyte’s open-core architecture offers all its important features, including deployment flexibility, data connectors, and protocol support, as part of a single, unified, community-driven codebase. Enterprises can access, self-host, and extend the software without vendor lock-in.</p><p class="paragraph" style="text-align:left;">Airbyte, as I&#39;m sure you figured out by now, will be happy to run <a class="link" href="https://airbyte.com/pricing?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Flex Enterprise for you</a>. The service is available now. </p><p class="paragraph" style="text-align:left;">Michel Tricot, CEO and co-founder of Airbyte, explained, “Flex simplifies data infrastructure, taking deployments from months to days while delivering true data sovereignty to solve the fragmentation problem that prevents organizations from realizing the full value of their data. With hybrid deployments, organizations can integrate and activate data wherever it lives, cloud or on-prem,  without the burden of heavy infrastructure management. Flex makes that data AI-ready by default, enabling companies to power AI securely and seamlessly.”</p><p class="paragraph" style="text-align:left;"><b>Noteworthy Linux and open-source stories:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/just-got-linux-mint-22-2-two-more-versions-are-coming-soon-and-theyre-big/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">Just got Linux Mint 22.2? Two more versions are coming soon - and they&#39;re big</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/how-to-easily-switch-your-pc-from-windows-to-linux-for-free/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">How to easily switch your PC from Windows to Linux Mint - for free</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/the-open-source-initiatives-executive-director-departs-what-it-means-for-the-osaid-debate/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=airbyte-enterprise-flex-enables-you-to-keep-your-ai-data-safe" target="_blank" rel="noopener noreferrer nofollow">The Open Source Initiative&#39;s executive director departs - what it means for the OSAID debate</a></p></li></ul></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=fc12955a-4fb9-4441-b143-dc883323e3b2&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Desktop Linux makes gains</title>
  <description>Desktop Linux grows, open-source WordPress battles and open source vs AI</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1a837d7a-7f2e-41cb-84c1-2dd9b8c2d810/linux-desktop-hits-6-market-share-mark.jpg" length="212812" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/desktop-linux-makes-gains-d748</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/desktop-linux-makes-gains-d748</guid>
  <pubDate>Mon, 21 Jul 2025 14:41:50 +0000</pubDate>
  <atom:published>2025-07-21T14:41:50Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><a class="image__link" href="https://www.zdnet.com/article/linux-has-over-6-of-the-desktop-market-yes-you-read-that-right-heres-how/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1a837d7a-7f2e-41cb-84c1-2dd9b8c2d810/linux-desktop-hits-6-market-share-mark.jpg?t=1753106659"/></a></div><h3 class="heading" style="text-align:left;" id="linux-has-over-6-of-the-desktop-mar"><a class="link" href="https://www.zdnet.com/article/linux-has-over-6-of-the-desktop-market-yes-you-read-that-right-heres-how/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">Linux has over 6% of the desktop market? Yes, you read that right</a></h3><p class="paragraph" style="text-align:left;">At long last, after years of waiting for the &quot;Year of the Linux desktop,&quot; we&#39;re getting somewhere. </p><p class="paragraph" style="text-align:left;">According to the <span style="text-decoration:underline;"><a class="link" href="https://analytics.usa.gov/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(8, 10, 18)">US Federal Government Website and App Analytics</a></span>, which I trust more than StatCounter, 6% of its visitors over the last month were using Linux operating systems.</p><p class="paragraph" style="text-align:left;">This website keeps track of US government website visits and analyzes them. On average, there have been 1.6 billion sessions in the last 30 days, with millions of users participating daily.</p><p class="paragraph" style="text-align:left;">If you add in Android (16.2%) and Chromebooks (0.8%), you&#39;re talking about 23% of visitors using Linux, which puts it above MacOS (11.7%), Windows 10 (15.7%), and <span style="text-decoration:underline;"><a class="link" href="https://www.zdnet.com/article/the-ultimate-windows-11-upgrade-guide-everything-you-need-to-know/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(8, 10, 18)">Windows 11</a></span> (15.3%), which is downright impressive. Take that, Windows!</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/linux-has-over-6-of-the-desktop-market-yes-you-read-that-right-heres-how/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">More&gt;</a></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/wordpress-turmoil-and-the-fair-package-manager/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">WordPress Turmoil and the FAIR Package Manager</a></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">I’d been a happy </span><a class="link" href="https://wordpress.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">WordPress</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;"> user since I switched from the Vignette content management system (CMS) for WordPress in 2003. Many others quickly joined me. Today, </span><a class="link" href="https://w3techs.com/technologies/details/cm-wordpress?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">43.5% of all websites use WordPress.</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;"> But, then in 2024, WordPress co-founder Matt Mullenweg, who founded and is the CEO of </span><a class="link" href="https://automattic.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">Automattic</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">, WordPress’s parent company, declared that WordPress hosting power </span><a class="link" href="https://wpengine.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">WP Engine</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;"> was a </span><a class="link" href="https://www.theregister.com/2024/09/24/wp_engine_claims_automattic_ceo/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">“cancer to WordPress”</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;"> and things got really ugly really fast.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">…</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">In the meantime, </span><a class="link" href="https://thenewstack.io/the-wordpress-saga-does-matt-mullenwegg-wants-a-fork-or-not/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">Automattic stopped contributing</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;"> to the </span><a class="link" href="https://solidwp.com/blog/wordpress-core/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">WordPress Core</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;"> code and associated projects such as Gutenberg, the default WordPress editor. In late May, </span><a class="link" href="https://automattic.com/2025/05/29/returning-to-core/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">Automattic started contributing code again</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">. Mullenweg has also</span><a class="link" href="https://www.therepository.email/matt-mullenweg-reverses-course-on-blocking-accounts-in-surprise-wordpress-jubilee?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)"> restored some, but not all, of his critics’ WordPress accounts</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">. However, the conflict, both inside and outside WordPress, has continued to leave developers and users worried about the program’s fate.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">Thus, the </span><a class="link" href="https://training.linuxfoundation.org/training/course-catalog/?utm_content=inline+mention&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)">Linux Foundation</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;"> decided to get involved by launching the</span><a class="link" href="https://github.com/fairpm?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(255, 50, 135)"> FAIR Package Manager</a><span style="color:rgb(20, 38, 64);font-family:-apple-system, system-ui, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;font-size:17px;">. FAIR, which stands for Federated And Independent Repositories. It is led by WordPress developers, including some of its internal critics. It’s meant to address the problem that, practically speaking, WordPress is under Mullenweg’s control since he’s both CEO of the WordPress company and the “steward” of the WordPress non-profit organization.</span></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/wordpress-turmoil-and-the-fair-package-manager/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">More&gt; </a></p><h3 class="heading" style="text-align:left;" id="fed-up-with-ai-scraping-your-conten"><a class="link" href="https://www.zdnet.com/article/fed-up-with-ai-scraping-your-content-this-open-source-bot-blocker-can-help-heres-how/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">Fed up with AI scraping your content? This open-source bot blocker can help - here&#39;s how</a></h3><p class="paragraph" style="text-align:left;">Anyone who runs a <span style="text-decoration:underline;"><a class="link" href="https://www.zdnet.com/article/cloudflare-just-changed-the-internet-and-its-bad-new-for-the-ai-giants/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(8, 10, 18)">website knows how annoying AI bots</a></span> are these days. </p><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><a class="link" href="https://www.f5.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(8, 10, 18)">F5</a></span>, the application delivery network company, found that more than <span style="text-decoration:underline;"><a class="link" href="https://www.f5.com/labs/articles/threat-intelligence/2025-advanced-persistent-bots-report?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(8, 10, 18)">half of all web visits come not from people but from data scrapers</a></span>, including OpenAI, Anthropic, Google, and Perplexity AI bots. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(8, 10, 18);font-family:suisseintl, helvetica, sans-serif;font-size:18px;">People are sick and tired of wasting money on their sites only to have AI companies rip off everything of value. So, Xe Iaso, a technical educator and part-time bot fighter, wrote an open-source program, </span><span style="text-decoration:underline;"><a class="link" href="https://github.com/TecharoHQ/anubis?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(8, 10, 18)">Anubis</a></span><span style="color:rgb(8, 10, 18);font-family:suisseintl, helvetica, sans-serif;font-size:18px;">, to stop AI bots in their tracks.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(8, 10, 18);font-family:suisseintl, helvetica, sans-serif;font-size:18px;"><a class="link" href="https://www.zdnet.com/article/fed-up-with-ai-scraping-your-content-this-open-source-bot-blocker-can-help-heres-how/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">More&gt;</a></span></p><h3 class="heading" style="text-align:left;" id="other-noteworthy-linux-and-opensour"><b>Other noteworthy Linux and open-source stories:</b></h3><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/bash-53-has-some-big-improvements-heres-how-you-can-test-it/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">Bash 5.3 Has Some Big Improvements</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/open-source-is-too-important-to-dilute/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">Open Source Is Too Important To Dilute</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/red-hat-expands-free-access-to-rhel-for-business-developers/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=desktop-linux-makes-gains" target="_blank" rel="noopener noreferrer nofollow">Red Hat just expanded free access to RHEL for business developers</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=096990fb-b435-4a7b-9fbb-552a913eff72&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Akamai becomes the official distributor of the Linux kernel</title>
  <description>Someone needs to host the Linux kernel code, and going forward, it will be the content delivery network Akamai.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3e66bfd1-496a-4540-8fab-5705b0a6e0ed/Tux_handing_out_a_file.jpg" length="127576" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/akamai-becomes-the-official-distributor-of-the-linux-kernelw-post</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/akamai-becomes-the-official-distributor-of-the-linux-kernelw-post</guid>
  <pubDate>Thu, 27 Mar 2025 22:31:01 +0000</pubDate>
  <atom:published>2025-03-27T22:31:01Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3e66bfd1-496a-4540-8fab-5705b0a6e0ed/Tux_handing_out_a_file.jpg?t=1743114031"/><div class="image__source"><span class="image__source_text"><p>Tux handing out the code.</p></span></div></div><p class="paragraph" style="text-align:left;">When I was a young--well, younger anyway--squirt, I ftped my Linux kernel code from Ted T’so, one of the first Linux kernel developers, personal PC, <a class="link" href="https://tsx-11.mit.edu?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">tsx-11.mit.edu</a>. I was glad to do it! Before T&#39;so set up his repository, you had to download the files from Linus Toravalds&#39; machine in Helsinki, Finland, which was s l o w.  Mind you, at the time, I recall I downloaded it at a &quot;blazing&quot; fast 64 Kilobits per second (Kbps) over an ISDN line. Hey, it was great in its day. </p><p class="paragraph" style="text-align:left;">Things have gotten orders of magnitude faster since those days! Now, <a class="link" href="https://www.akamai.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Akamai</a>, the well-known content delivery network (CDN) and cloud company, has announced a multi-year partnership with the <a class="link" href="https://www.kernel.org/nonprofit.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Linux Kernel Organization</a>. This collaboration aims to provide critical infrastructure support for the development and distribution of the Linux kernel, ensuring uninterrupted access for its global network of developers.</p><p class="paragraph" style="text-align:left;">Akamai will leverage its infrastructure to support <a class="link" href="https://kernel.org?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">kernel.org</a>, the primary platform for Linux kernel source code distribution. This partnership is crucial for maintaining Linux security and performance.</p><p class="paragraph" style="text-align:left;">The first version of Linux weighed in at 10,239 lines of code. Today, it weighs in at about  28 million lines of code. Akamai&#39;s infrastructure will enable these developers to access kernel sources quickly and reliably, regardless of their location. This support is provided at no cost, reflecting Akamai&#39;s commitment to giving back to the open-source community.</p><p class="paragraph" style="text-align:left;">&quot;Akamai depends on Linux, just like the rest of the world,&quot; noted Alex Chircop, Chief Architect of Akamai Cloud. &quot;By supporting <a class="link" href="https://kernel.org?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">kernel.org</a>, we are contributing to the preservation of the world&#39;s most widely deployed open-source software.&quot;</p><p class="paragraph" style="text-align:left;">Chris Aniszczyk, Chief Technology Officer of the <a class="link" href="https://www.cncf.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Cloud Native Computing Foundation (CNCF)</a>, highlighted Akamai&#39;s deep roots in the open-source community, citing their contributions to projects like OpenTelemetry and Prometheus. Akamai&#39;s recent pledge of $1 million to CNCF projects further underscores its commitment to open-source stewardship.</p><p class="paragraph" style="text-align:left;">In addition to supporting the Linux kernel, Akamai also provides infrastructure support for <a class="link" href="https://www.alpinelinux.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Alpine Linux</a>, a popular, lightweight Linux distribution. <a class="link" href="https://github.com/akamai/akamai-docker?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Alpine is Akamai&#39;s preferred DevOps Linux architecture</a>. This is all of a piece with Akamai&#39;s recent embrace of Linux-based cloud offerings, such as its <a class="link" href="https://www.zdnet.com/article/with-linode-akamai-expands-into-edge-cloud-computing-development/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">2022 acquisition of Linux cloud pioneer Linode</a> and its 2023 acquisition of the Linux and Kubernetes-based, cloud-native storage software company <a class="link" href="https://www.akamai.com/newsroom/press-release/akamai-announces-intention-to-acquire-cloud-company-ondat?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Ondat</a>. </p><p class="paragraph" style="text-align:left;"><b>Noteworthy Linux and open-source stories:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/want-to-learn-linux-from-legends-this-mentorship-pairs-you-with-top-developers/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Want to learn Linux from legends? This mentorship pairs you with top developers</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/linux-kernel-6-14-is-a-big-leap-forward-in-performance-and-windows-compatibility/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Linux kernel 6.14 is a big leap forward in performance and Windows compatibility</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/linux-foundations-trust-scorecards-aim-to-battle-rising-open-source-security-threats/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=akamai-becomes-the-official-distributor-of-the-linux-kernel" target="_blank" rel="noopener noreferrer nofollow">Linux Foundation&#39;s trust scorecards aim to battle rising open-source security threats</a></p></li></ul><h3 class="heading" style="text-align:left;" id="the-gold-standard-of-business-news">The gold standard of business news</h3><div class="image"><a class="image__link" href="https://morningbrew.com/daily/subscribe?utm_campaign={{publication_alphanumeric_id}}&utm_medium=paid_newsletter&utm_source=beehiiv&_bhiiv=opp_fdc20473-382f-4dca-a3b0-14093b3403f8_652e2efc&bhcl_id=8b22569e-ba04-4356-8e92-dd1c21ea24a1_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0efd20c8-2441-489a-899e-ee3ea1ece6bf/Option_1.png?t=1734723179"/></a></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://morningbrew.com/daily/subscribe?utm_campaign={{publication_alphanumeric_id}}&utm_medium=paid_newsletter&utm_source=beehiiv&_bhiiv=opp_fdc20473-382f-4dca-a3b0-14093b3403f8_652e2efc&bhcl_id=8b22569e-ba04-4356-8e92-dd1c21ea24a1_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Morning Brew</a> is transforming the way working professionals consume business news.</p><p class="paragraph" style="text-align:left;">They skip the jargon and lengthy stories, and instead serve up the news impacting your life and career with a hint of wit and humor. This way, you’ll actually enjoy reading the news—and the information sticks. </p><p class="paragraph" style="text-align:left;">Best part? <a class="link" href="https://morningbrew.com/daily/subscribe?utm_campaign={{publication_alphanumeric_id}}&utm_medium=paid_newsletter&utm_source=beehiiv&_bhiiv=opp_fdc20473-382f-4dca-a3b0-14093b3403f8_652e2efc&bhcl_id=8b22569e-ba04-4356-8e92-dd1c21ea24a1_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Morning Brew’s</a> newsletter is completely free. Sign up in just 10 seconds and if you realize that you prefer long, dense, and boring business news—you can always go back to it. </p><p class="paragraph" style="text-align:left;"><a class="link" href="https://morningbrew.com/daily/subscribe?utm_campaign={{publication_alphanumeric_id}}&utm_medium=paid_newsletter&utm_source=beehiiv&_bhiiv=opp_fdc20473-382f-4dca-a3b0-14093b3403f8_652e2efc&bhcl_id=8b22569e-ba04-4356-8e92-dd1c21ea24a1_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Join 4.3 Million Readers Now</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=502cb2b9-1a1c-450e-922d-c9ce2e1af8d5&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The Open Source Initiative Election is over</title>
  <description>The debate about the election and the definition of open-source AI, however, is far from over.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/418678a0-b2d7-41c5-b330-2b8ad719710c/OSI_Election.jpg" length="72661" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/the-open-source-initiative-election-is-over</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/the-open-source-initiative-election-is-over</guid>
  <pubDate>Mon, 24 Mar 2025 12:05:00 +0000</pubDate>
  <atom:published>2025-03-24T12:05:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/418678a0-b2d7-41c5-b330-2b8ad719710c/OSI_Election.jpg?t=1742748729"/><div class="image__source"><span class="image__source_text"><p>Open Source Initiative Election</p></span></div></div><p class="paragraph" style="text-align:left;">The <a class="link" href="https://opensource.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Open Source Initiative (OSI)</a> has confirmed the <a class="link" href="https://opensource.org/blog/announcing-the-new-directors-of-osi-board?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">results of its recent board elections</a>. The winners and new affiliate directors are <a class="link" href="https://www.linkedin.com/in/carlopiana/?originalSubdomain=it&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Carlo Piana</a>, an Italian corporate attorney who helped write the controversial <a class="link" href="https://opensource.org/ai/open-source-ai-definition?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Open Source AI Definition (OSAID)</a>, and <a class="link" href="https://www.linkedin.com/in/ruthsuehle?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Ruth Suehle</a>, <a class="link" href="https://www.sas.com/en_us/home.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">SAS</a> Open Source Director and President of the <a class="link" href="https://www.apache.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Apache Software Foundation.</a> At the same time, <a class="link" href="https://www.linkedin.com/in/mccoysmith/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">McCoy Smith</a>, an American intellectual property (IP) lawyer, will join as an individual director. The election was conducted using the <a class="link" href="https://www.electoral-reform.org.uk/voting-systems/types-of-voting-system/single-transferable-vote/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Scottish Single Transferable Vote (STV) system</a>.</p><p class="paragraph" style="text-align:left;">In the Affiliate director polls, Piana and Suehle emerged as winners from a field of four valid candidates. The election saw 48 ballots, 47 being valid and one empty. Suehle was recommended by OSI Affiliates, while Piana secured his position through the Affiliate vote.</p><p class="paragraph" style="text-align:left;">Smith, recommended by Individual supporters, won the Individual director seat from a pool of five candidates. The Individual polls received 159 ballots, with 148 being valid and 11 empty. Stefano Maffulli, the OSI&#39;s Executive Director, lauded the new board members, writing on LinkedIn that &quot;<a class="link" href="https://www.linkedin.com/feed/update/urn:li:activity:7308801618299256832/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">a strong community [had]  selected them,</a> [so]  you know you&#39;re on the path to continue improving.&quot;</p><p class="paragraph" style="text-align:left;">For the record, the OSI board consists of four directors elected by OSI individual members for two-year terms; four directors elected by OSI affiliate members for three-year terms; and four directors appointed for two-year terms by the board itself. Once elected, the board oversees the organization, approves its budget, and supports the executive director and staff in fulfilling its mission.</p><p class="paragraph" style="text-align:left;">However, the OSI also stated in the election results, &quot;Three candidates have been excluded from the final tally: Two were ineligible as they did not sign the current board agreement; one returned the signed agreement after the deadline passed.&quot;</p><p class="paragraph" style="text-align:left;">The <a class="link" href="https://opensource.org/wp-content/uploads/2006/07/Board-Member-Agreement.pdf?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">OSI Board Agreement</a> simply states the board&#39;s responsibilities and duties. It also requires them to keep disagreements inside the board once a decision has been made, and they&#39;ll obey the <a class="link" href="https://opensource.org/codeofconduct?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">OSI Code of Conduct</a>. The specific language, which will become a bone of contention, is &quot;Disagree during Board deliberation but support publicly all Board decisions, especially those that do not have unanimous consent.&quot;</p><p class="paragraph" style="text-align:left;">Matfulli explained the OSI had insisted that candidates sign on to the OSI Board Agreement because &quot;While the polls were open, we’ve heard that there may be <a class="link" href="https://discuss.opensource.org/t/board-agreement-required-post-vote-for-all-candidates/929/4?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">candidates with no intention to sign the board agreement</a>, which has become a <a class="link" href="https://opensource.org/board?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">mandatory</a> <a class="link" href="https://opensource.org/about/board-of-directors/elections?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">requirement</a>.&quot;</p><p class="paragraph" style="text-align:left;">Both <a class="link" href="https://www.linkedin.com/in/richardfontana/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Richard Fontana</a>, <a class="link" href="https://www.openshift.com/try?utm_content=inline+mention&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Red Hat’s</a> principal commercial counsel and a former OSI board member, and  <a class="link" href="https://en.wikipedia.org/wiki/Bradley_M._Kuhn?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Bradley M. Kuhn</a>, Policy Fellow & Hacker-in-Residence at <a class="link" href="https://sfconservancy.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Software Freedom Conservancy</a>, disagreed with the &quot;support publicly&quot; clause. In Fontana&#39;s <a class="link" href="https://codeberg.org/OSI-Reform-Platform/platform?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over#readme" target="_blank" rel="noopener noreferrer nofollow">Shared Platform for OSI Reform</a>, he stated, &quot;While obviously well-intentioned, the quoted provision goes too far. Under it, Directors agree to a code of silence — a self-imposed gag order covering all issues (great and small) for which the Board did not have unanimous consent. We insist that this provision be reformulated with less sweeping and more conventional language.&quot;</p><p class="paragraph" style="text-align:left;">The result was, as <a class="link" href="https://www.linkedin.com/in/tracyhinds?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Tracy Hinds</a>, the OSI chair, told me at the <a class="link" href="https://events.linuxfoundation.org/lf-member-summit/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Linux Foundation Members Summit</a> in Napa, CA, &quot;We had to remove three ineligible candidates from our list before we ran the tally.&quot; <a class="link" href="https://www.linkedin.com/in/thierry-carrez-652662a/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Thierry Carrez</a>, the OSI vice-chair and General Manager of the <a class="link" href="https://openinfra.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Open Infrastructure Foundation</a>, added, &quot;It&#39;s the first time that we had candidates running that would not sign the board agreement.&quot;</p><p class="paragraph" style="text-align:left;">Specifically, Hinds added, &quot;Bradley Kuhn and Richard Fontana refused to sign the board agreement Code of Conduct, and therefore decided to make themselves ineligible.</p><p class="paragraph" style="text-align:left;">This board agreement has existed for five years in its current form, but it is the first</p><p class="paragraph" style="text-align:left;">time that candidates decided to run while publicly communicating they would not sign it. A third candidate, Bentley Hensel, signed it but well past the communicated deadline, and were therefore also removed from the final results tally.&quot;</p><p class="paragraph" style="text-align:left;">Kuhn, however, claimed in a blog post that <a class="link" href="https://ebb.org/bkuhn/blog/2025/03/19/a-sign-board-agreement.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">he and Fontana had signed the OSI Board agreement</a>. In both signed documents, however, both had struck out the controversial clause. Hence, Hinds and the OSI had ruled that they hadn&#39;t officially signed off and were thus ineligible. </p><p class="paragraph" style="text-align:left;">Kuhn later insisted that this was sufficient and that the &quot;<a class="link" href="https://floss.social/@osi@opensource.org?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">@osi</a> proceeded to <a class="link" href="https://floss.social/@bkuhn/114200910448773392?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">tamper with the ballots anyway.</a>&quot; Matfulli replied, &quot;The agreement you and<a class="link" href="https://floss.social/@richardfontana@mastodon.social?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow"> @richardfontana</a> signed <a class="link" href="https://floss.social/@ed@opensource.org/114200926322821079?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">was not the one the board sent you</a> and, most importantly, is not the one everyone else (candidates and sitting directors) signed. This is my last message on the topic.&quot;</p><p class="paragraph" style="text-align:left;">Looking ahead, the newly elected directors will be formally welcomed at the OSI&#39;s April board meeting. Additionally, the Board Development Committee has been tasked with conducting a retrospective by April 19, 2025, to provide recommendations for future election improvements. </p><p class="paragraph" style="text-align:left;">Needless to say, this isn&#39;t the last word. Kuhn is asking concerned people to reach out to him to &quot;<a class="link" href="https://mastodon.social/@bkuhn@floss.social/114201493363811191?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">discuss what&#39;s happened</a> with other concerned parties and make a plan on how we should organize to respond.&quot;</p><p class="paragraph" style="text-align:left;"><b>Other noteworthy Linux and open-source stories:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://lwn.net/Articles/1014603/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">OSI election ends with unsatisfying results</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/open-source-initiative-ai-debate-roils-board-elections/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow">Open Source Initiative: AI Debate Roils Board Elections</a></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(17, 85, 204);"><a class="link" href="https://thenewstack.io/open-infrastructure-foundation-joins-forces-with-linux-foundation/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=the-open-source-initiative-election-is-over" target="_blank" rel="noopener noreferrer nofollow"><span style="text-decoration:underline;">Open Infrastructure Foundation Joins Forces With Linux Foundation</span></a></span></p></li></ul></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=980b70b0-be6b-4b04-b140-dc4de424ef9f&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Popular Python AI library Ultralytics compromised with a crypto miner</title>
  <description>Another day, another major Python Package Index compromise leads to a major security problem. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/478a132e-8013-49a0-bd23-db867ea90a9e/Bad_Bitcoin_Miner.png" length="397760" type="image/png"/>
  <link>https://opensourcewatch.beehiiv.com/p/popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner</guid>
  <pubDate>Mon, 09 Dec 2024 13:00:00 +0000</pubDate>
  <atom:published>2024-12-09T13:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/478a132e-8013-49a0-bd23-db867ea90a9e/Bad_Bitcoin_Miner.png?t=1733696218"/></div><p class="paragraph" style="text-align:left;">I am getting sick and tired of <a class="link" href="https://pypi.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">Python Package Index (PyPI)</a> being used as a malware pipeline. In the latest supply-chain violation, the popular AI/computer vision library <a class="link" href="https://www.ultralytics.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">Ultralytics</a>, known for its YOLO (You Only Look Once) object detection model, fell victim to a sophisticated supply-chain attack.</p><p class="paragraph" style="text-align:left;">Ultralytics, for those of you who don&#39;t know the library, is used in all kinds of applications. These range from the obvious—finding objects in a video stream, satellite surveillance, and autonomous driving—to the obscure—crop and livestock monitoring and wildlife surveying. So, it&#39;s no surprise that when there&#39;s a new release, <a class="link" href="https://www.bleepingcomputer.com/news/security/ultralytics-ai-model-hijacked-to-infect-thousands-with-cryptominer/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">the library has had over 260,000 downloads from PyPI in a single 24-hour period</a>.</p><p class="paragraph" style="text-align:left;">Thus, it was bad news with a capital B when the software supply chain security company <a class="link" href="https://www.reversinglabs.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">ReversingLabs</a> found malicious attackers had compromised its build environment. The result? The new version 8.3.41 contained malicious code that, once installed, would deploy a cryptocurrency miner.</p><p class="paragraph" style="text-align:left;">The good news was that the project maintainers caught it and immediately released a patched version, 8.3.42. The bad news was that they hadn&#39;t caught the real problem. So, the &quot;fixed&quot; edition came with the same trojan hidden inside. At least this time, they quickly realized they hadn&#39;t really fixed the problem. So, on the same day, the maintainers released a clean version, 8.3.43. </p><p class="paragraph" style="text-align:left;">This happened because the attackers had exploited a known vulnerability in <a class="link" href="https://github.com/features/actions?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">GitHub Actions</a> that enabled the attacker to <a class="link" href="https://github.com/ultralytics/actions/security/advisories/GHSA-7x29-qqmq-v6qc?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">inject malicious code during the automated build process</a>. This clever maneuver bypassed the usual code review safeguards, as the malicious code was only present in the package pushed to PyPI, not in the GitHub repository itself.</p><p class="paragraph" style="text-align:left;">The impact was immediate and widespread. Users who installed the compromised versions experienced sudden spikes in CPU usage, a telltale sign of cryptocurrency mining activity. The Ultralytics team, led by founder and CEO Glenn Jocher, quickly sprang into action upon receiving reports of the suspicious behavior.</p><p class="paragraph" style="text-align:left;">This incident sent shockwaves through Ultralytics&#39;s community. It also highlighted the potential for software supply chains to be abused and served as a stark reminder of the potential for seemingly trustworthy packages to be weaponized, potentially affecting millions of users and systems worldwide.</p><p class="paragraph" style="text-align:left;">The Ultralytics compromise underscored the need for enhanced security measures in package distribution and the importance of vigilance in the open-source ecosystem. It&#39;s yet another cautionary tale that we can&#39;t just trust our dependencies, no matter how reliable they&#39;ve been in the past. Instead, we must verify every last lousy update before pushing any outside code into production. </p><p class="paragraph" style="text-align:left;">I wish it weren&#39;t that way, but it is what it is. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Other noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/the-next-lts-linux-kernel-is-no-surprise-but-it-is-packed-with-goodies/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">The next LTS Linux kernel is no surprise but it is packed with goodies</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/jim-zemlin-head-janitor-of-open-source-marks-20-years-at-linux-foundation/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">Jim Zemlin, &#39;head janitor of open source,&#39; marks 20 years at Linux Foundation</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/nearly-half-of-gen-ai-adopters-want-it-open-source-heres-why/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=popular-python-ai-library-ultralytics-compromised-with-a-crypto-miner" target="_blank" rel="noopener noreferrer nofollow">Nearly half of Gen AI adopters want it open source - here&#39;s why</a></p></li></ul><h3 class="heading" style="text-align:left;" id="securing-top-talent-with-our-guide-">Securing top talent with our guide is a click away</h3><div class="image"><a class="image__link" href="https://www.deel.com/resources/international-hiring/?utm_medium=sponsored-newsletter&utm_source=beehiiv&utm_term={{publication_alphanumeric_id}}&utm_campaign=ww_engage_download_beehiiv_sponnewsletter_fin-intlhiringguide-oct24_all_all&utm_content=engage_all_sponnewsletter_intlhiringguide-sponnews500-fin_en&_bhiiv=opp_e22864b9-b999-4f29-aed4-f4693a03632d_383b54ac&bhcl_id=0e18661d-bff3-4f78-843f-6d3a0f8d3993_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2f881be1-500d-452f-9d8b-d768cb1b3170/Intl_Hiring.png?t=1728950389"/></a></div><ul><li><p class="paragraph" style="text-align:left;">Finding and attracting global talent</p></li><li><p class="paragraph" style="text-align:left;">Processing international payroll on time</p></li><li><p class="paragraph" style="text-align:left;">Staying compliant with employment & tax laws abroad</p></li></ul><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.deel.com/resources/international-hiring/?utm_medium=sponsored-newsletter&utm_source=beehiiv&utm_term={{publication_alphanumeric_id}}&utm_campaign=ww_engage_download_beehiiv_sponnewsletter_fin-intlhiringguide-oct24_all_all&utm_content=engage_all_sponnewsletter_intlhiringguide-sponnews500-fin_en&_bhiiv=opp_e22864b9-b999-4f29-aed4-f4693a03632d_383b54ac&bhcl_id=0e18661d-bff3-4f78-843f-6d3a0f8d3993_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Get the Guide</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=85616047-8ca4-45ec-b239-474a5e9d8828&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>When Infrastructure as Code met DevOps: Spacelift</title>
  <description>In cloud infrastructure management&#39;s ever-evolving landscape, Spacelift has emerged as a pioneering force, reshaping how organizations approach Infrastructure as Code.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c6ec5bb8-a10c-4948-9f97-1b579c53560a/Spacelift_Logo.jpg" length="37111" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/when-infrastructure-as-code-met-devops-spacelift</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/when-infrastructure-as-code-met-devops-spacelift</guid>
  <pubDate>Wed, 04 Dec 2024 14:00:00 +0000</pubDate>
  <atom:published>2024-12-04T14:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c6ec5bb8-a10c-4948-9f97-1b579c53560a/Spacelift_Logo.jpg?t=1733273155"/></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://spacelift.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Spacelift</a> is not a SpaceX rival nor a science-fiction fansite. No, it&#39;s an innovative infrastructure orchestration platform that has been making waves in the cloud computing industry since its inception four years ago. The company&#39;s mission is to streamline the management of Infrastructure as Code (IaC), bridging the gap between provisioning and long-term configuration management.</p><p class="paragraph" style="text-align:left;">As Dimitri Vlachos, Spacelift&#39;s CMO, told me at <a class="link" href="https://events.linuxfoundation.org/kubecon-cloudnativecon-north-america/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">KubeCon North America </a>in Salt Lake City, while IaC tools such as <a class="link" href="https://www.terraform.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Terraform </a>and <a class="link" href="https://opentofu.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">OpenTofu</a> have dominated the provisioning aspect of cloud-native environments, Spacelift recognized a crucial missing piece: The integration of provisioning with long-term configuration management.</p><p class="paragraph" style="text-align:left;">At its core, Spacelift allows organizations to seamlessly integrate DevOps and IaC programs, including Terraform, OpenTofu, <a class="link" href="https://terragrunt.gruntwork.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Terragrunt</a>, <a class="link" href="https://docs.google.com/document/u/0/d/1tmkodITTxjCvAb-MnMhnMsWZvAvkTJ2qWPn9mxO4FVg/edit?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Kubernetes</a>, <a class="link" href="https://www.ansible.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Ansible</a>, <a class="link" href="https://www.pulumi.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Pulumi</a>, and Amazon Web Services (AWS) <a class="link" href="https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/Welcome.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">CloudFormation</a>. This multi-tool support sets Spacelift apart from many competitors, providing a unified platform for managing diverse infrastructure needs.</p><p class="paragraph" style="text-align:left;">&quot;What we&#39;re seeing is an evolution,&quot; Vlachos explained. &quot;People start by playing with IaC, then they mature it, and finally, they try to scale it out.&quot; This progression has led to a growing demand for solutions that can handle the entire infrastructure lifecycle, from initial deployment to ongoing management and governance.</p><p class="paragraph" style="text-align:left;">Spacelift&#39;s special sauce in its comprehensiveness. The platform allows users to seamlessly transition from provisioning infrastructure to configuring it, all within a single workflow. This integration extends to popular DevOps tools such as Ansible. </p><p class="paragraph" style="text-align:left;">This addresses a long-standing pain point in the industry: The disconnect between cloud provisioning and on-premises configuration management.</p><p class="paragraph" style="text-align:left;">But Spacelift&#39;s vision goes beyond mere integration. The company is tackling one of the most significant challenges in infrastructure management: Visibility and control at scale. </p><p class="paragraph" style="text-align:left;">For example, with Ansible, Spacelift&#39;s Application Programming Interface (API)-level integration with Ansible playbooks addresses the challenges of visibility and execution speed in the following ways:</p><ul><li><p class="paragraph" style="text-align:left;">Visibility: Spacelift provides enhanced visibility into the execution of Ansible playbooks, especially at scale. The platform gives users better diagnostics and insights into the status of their Ansible deployments, allowing them to understand where failures are occurring and troubleshoot more effectively.</p></li></ul><ul><li><p class="paragraph" style="text-align:left;">Execution Speed: Spacelift aims to improve the speed of running Ansible playbooks at a large scale. By managing the execution of the playbooks through its platform, Spacelift can optimize the process and address the performance challenges that organizations often face when running Ansible across many resources.</p></li></ul><p class="paragraph" style="text-align:left;">The key is that Spacelift&#39;s integration goes beyond running the playbooks. It provides a centralized management and observability layer that gives users more control and visibility over their Ansible-based infrastructure automation. This helps address the common pain points around large-scale Ansible deployments.</p><p class="paragraph" style="text-align:left;">This focus on observability and governance sets Spacelift apart in a crowded market. The platform provides robust policy controls, allowing organizations to define who can deploy what and under what conditions. This balance between speed and control is at the heart of Spacelift&#39;s philosophy, addressing the core tension in many DevOps practices.</p><p class="paragraph" style="text-align:left;">In addition, Vlachos said Spacelift is not just &quot;provisioning the whole life cycle of your infrastructure.&quot; We allow them to do this in one workflow, go from provisioning your infrastructure to configuring it, and then have a very robust governance layer that allows you to write policies so you can control what gets deployed and who has to approve it.&quot;</p><p class="paragraph" style="text-align:left;">Using <a class="link" href="https://www.openpolicyagent.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Open Policy Agent (OPA)</a>, Spacelift allows organizations to implement fine-grained control over their infrastructure deployments. These policies can govern everything from resource creation and parameters to approval processes and notifications.</p><p class="paragraph" style="text-align:left;">Looking to the future, Spacelift is positioning itself at the forefront of hybrid cloud management. While many of their current customers are cloud-native, Vlachos sees a growing opportunity in bridging the gap between on-premises and cloud infrastructure. &quot;We really think hybrid is the future,&quot; he stated, highlighting Spacelift&#39;s position to offer a unified management solution for both environments.</p><p class="paragraph" style="text-align:left;">As the infrastructure management landscape continues to evolve, Spacelift stands out as a visionary player. By combining provisioning, configuration, and governance in a single platform and extending its reach across cloud and on-premises environments, Spacelift is not just solving today&#39;s problems; it&#39;s anticipating the challenges of tomorrow&#39;s hybrid, multi-cloud world.</p><p class="paragraph" style="text-align:left;">So, if you don&#39;t want a high-maintenance cloud experience, give Spacelift a try. You&#39;ll be glad you did. </p><p class="paragraph" style="text-align:left;"><b>Other noteworthy Linux and open-source stories:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/even-the-linux-foundation-has-cyber-monday-deals-get-60-off-tech-training-courses/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Even the Linux Foundation has Cyber Monday deals - get 60% off tech training courses</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/ebpf-foundation-releases-security-threat-model-and-audit-reports/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">eBPF Foundation Releases Security Threat Model and Audit Reports</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/beyond-upstream-first-the-linux-kernel-contribution-maturity-model/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=when-infrastructure-as-code-met-devops-spacelift" target="_blank" rel="noopener noreferrer nofollow">Beyond Upstream First: The Linux Kernel Contribution Maturity Model</a></p></li></ul><h3 class="heading" style="text-align:left;" id="theres-a-reason-400000-professional">There’s a reason 400,000 professionals read this daily. </h3><div class="image"><a class="image__link" href="https://magic.beehiiv.com/v1/31a7c576-0eb2-4ef3-abc7-bc75ede786fe?email={{email}}&utm_source=beehiiv&utm_campaign={{publication_name_param}}_{{publication_alphanumeric_id}}&_bhiiv=opp_2daaa5b8-f8b5-4000-993a-5fd81209eeeb_65769d95&bhcl_id=ddbb9f3d-7698-4bc6-aadb-8c266f8d7cbe_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0b0ebefb-2cf6-4b9c-ae4a-8e80d23b01e3/Ad_The_AI_report.png?t=1742251212"/></a></div><p class="paragraph" style="text-align:left;">Join <a class="link" href="https://magic.beehiiv.com/v1/31a7c576-0eb2-4ef3-abc7-bc75ede786fe?email={{email}}&utm_source=beehiiv&utm_campaign={{publication_name_param}}_{{publication_alphanumeric_id}}&_bhiiv=opp_2daaa5b8-f8b5-4000-993a-5fd81209eeeb_65769d95&bhcl_id=ddbb9f3d-7698-4bc6-aadb-8c266f8d7cbe_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">The AI Report</a>, trusted by 400,000+ professionals at Google, Microsoft, and OpenAI. Get daily insights, tools, and strategies to master practical AI skills that drive results.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://magic.beehiiv.com/v1/31a7c576-0eb2-4ef3-abc7-bc75ede786fe?email={{email}}&utm_source=beehiiv&utm_campaign={{publication_name_param}}_{{publication_alphanumeric_id}}&_bhiiv=opp_2daaa5b8-f8b5-4000-993a-5fd81209eeeb_65769d95&bhcl_id=ddbb9f3d-7698-4bc6-aadb-8c266f8d7cbe_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Sign up now for free and work smarter, not harder.</a></p><p class="paragraph" style="text-align:left;"></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=4cb20c00-8b90-4ebe-a468-0190973ce6e8&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>An old cloud learns new tricks:  OpenStack Dalmation</title>
  <description>The classic Infrastructure-as-a-Service OpenStack cloud is finding new uses as a VMWare replacement, and it&#39;s integrating better than ever with Linux and Kubernetes.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bbd6f0b7-d8c9-40ed-beba-d529e37c6204/OpenStack_Dalmation.jpg" length="132410" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/an-old-cloud-learns-new-tricks-openstack-dalmation</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/an-old-cloud-learns-new-tricks-openstack-dalmation</guid>
  <pubDate>Mon, 07 Oct 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-10-07T12:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bbd6f0b7-d8c9-40ed-beba-d529e37c6204/OpenStack_Dalmation.jpg?t=1728252742"/><div class="image__source"><a class="image__source_link" href="https://www.openstack.org/software/openstack-dalmatian?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" rel="noopener" target="_blank"><span class="image__source_text"><p>OpenInfra has let the OpenStack Dalmatian dogs out. </p></span></a></div></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://releases.openstack.org/dalmatian/index.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">OpenStack Dalmatian</a>, the 30th release of the popular open-source Infrastructure-as-a-Service (IaaS) cloud, has bounded onto the scene, bringing with it a host of enhancements tailored for AI workloads, improved security, and a refined user experience.</p><p class="paragraph" style="text-align:left;">For years, <a class="link" href="https://www.openstack.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">OpenStack</a> has been the cloud of choice for telecoms deploying 5G. In recent years, however, it&#39;s expanded well beyond that marketplace. Today, more than 45 million cores are in production. OpenStack has been embraced by thousands of users of all sizes and across industries, including mega-users such as Walmart, Hyundai, GEICO, and Yahoo. <a class="link" href="https://www.openstack.org/vmware-migration-to-openstack-white-paper?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">It is becoming a popular replacement for VMWare</a>. </p><p class="paragraph" style="text-align:left;">With the Dalmatian release, OpenStack has also been expanding into Artificial Intelligence (AI) and High-Performance Computing (HPC) markets. </p><p class="paragraph" style="text-align:left;">Specifically, <a class="link" href="https://wiki.openstack.org/wiki/Blazar?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Blazar</a>,  OpenStack&#39;s resource reservation service, now supports reserving GPU instances on  <a class="link" href="https://docs.openstack.org/nova/latest/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Nova</a>, OpenStack&#39;s compute flavors. In addition, in Nova, with the <a class="link" href="https://libvirt.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">libvirt</a> driver, the open-source application programming interface (API) virtualization daemon and management tool and libvirt version 7.3.0 or newer, mediated devices for vGPUs are now persisted across reboots of a compute host. This offers more convenience and efficiency improvements for machine learning (ML) systems.</p><p class="paragraph" style="text-align:left;">In addition, OpenStack&#39;s security has been improved.  For example, the <a class="link" href="https://ironicbaremetal.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Ironic bare-metal provisioning service</a> now requires hashed rescue passwords and mandates HTTPS for inter-service communication. Nova can also now detect virtual Trusted Platform Module (vTPM) support for compute services running libvirt version 8.0.0 or higher.</p><p class="paragraph" style="text-align:left;">The Skyline dashboard is also now fully production-ready. It&#39;s also added support for <a class="link" href="https://wiki.openstack.org/wiki/Masakari?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Masakari</a> (high-availability instance recovery), <a class="link" href="https://docs.openstack.org/designate/latest/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Designate, DNS-as-a-Service</a>, and <a class="link" href="https://www.fortinet.com/resources/cyberglossary/firewall-as-a-service-fwaas?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Firewall-as-a-Service (FWaaS)</a>. The Skyline dashboard also provides a more intuitive and user-friendly interface, making OpenStack more accessible to organizations transitioning from VMware.</p><p class="paragraph" style="text-align:left;">Indeed, in August 2024, <a class="link" href="https://www.rackspace.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Rackspace</a> announced its newest service, <a class="link" href="https://c212.net/c/link/?t=0&l=en&o=4267655-1&h=378469108&u=https%3A%2F%2Fwww.rackspace.com%2Fnewsroom%2Frackspace-technology-launches-openstack-enterprise&a=Rackspace+OpenStack+Enterprise&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">Rackspace OpenStack Enterprise</a>, which will include Skyline as its dashboard instead of the older Horizon. Kevin Carter, Rackspace&#39;s product director, said,  &quot;At Rackspace, we are all about simplifying the management of cloud systems. OpenStack Skyline, with its intuitive and user-friendly interface, simplifies the complex task of managing cloud services. It creates beautiful administrative experiences allowing users to manage services at scale, with ease and efficiency.&quot; That sounds good to me!</p><p class="paragraph" style="text-align:left;">OpenStack is also adding yet more compatibility with other open-source cloud-native systems. Thierry Carrez, the <a class="link" href="https://openinfra.dev/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">OpenInfra Foundation</a>&#39;s general manager, said. &quot;Also reflected in the Dalmatian release is the community&#39;s determination to integrate with a wide variety of open-source tools and platforms as well as cutting-edge hardware. We want to thank all of the organizations and individuals who actively use and contribute to OpenStack, especially the 487 contributors who submitted 7,640 changes over the past six months to keep OpenStack powering advancement and innovation all over the world.&quot;</p><p class="paragraph" style="text-align:left;">At the same time, though, OpenStack remains solid and mature. The Dalmatian changes are improvements that are building on what has gone before. As <span style="color:rgb(8, 10, 18);">Mark Collier, OpenStack&#39;s COO,</span> told me at <a class="link" href="https://2024.openinfraasia.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=an-old-cloud-learns-new-tricks-openstack-dalmation" target="_blank" rel="noopener noreferrer nofollow">OpenInfra Summit Asia</a> in Suwon, South Korea, &quot;OpenStack has been proven to work. It&#39;s been bulletproof for so many years.&quot; In addition, &quot;Thanks to the best practices being documented and the software&#39;s maturity, we have one company where each OpenStack administrator covers two data centers. The number of people it takes to operate this stuff has just gone way down. That, in turn, means when the CFO says, &#39;Can we do it in-house?&#39; The answer is yes.&quot; </p><p class="paragraph" style="text-align:left;">If your question is, &quot;Can OpenStack Dalmation help me with my private cloud? Can it replace VMWare? Can I use it to deploy AI and ML in my company?&quot; The answer is, again, yes.  </p><p class="paragraph" style="text-align:left;"></p><h3 class="heading" style="text-align:left;" id="beat-black-friday-with-bill">Beat Black Friday with BILL</h3><p class="paragraph" style="text-align:left;">Take a demo of <a class="link" href="https://bill.com/offers/black-friday?utm_source=beehiiv&utm_medium=sponsored-email&utm_campaign=20241105-wf-dc-se-6410-demo-black-friday-promotion_{{publication_alphanumeric_id}}&_bhiiv=opp_8532256e-7f4c-4f45-a5e0-ba6da50772e0_3c02a0de&bhcl_id=bfbefd40-2ebe-4754-80b6-39ab6e486bf0_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">BILL Spend & Expense</a> by the end of the month to see why so many businesses choose BILL to streamline their finances.</p><p class="paragraph" style="text-align:left;">Then choose your exclusive gift—a Nintendo Switch, Apple AirPods Pro, Samsung 50&quot; TV, or Xbox Series S—and show Black Friday who&#39;s boss<sup>1</sup> .</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://bill.com/offers/black-friday?utm_source=beehiiv&utm_medium=sponsored-email&utm_campaign=20241105-wf-dc-se-6410-demo-black-friday-promotion_{{publication_alphanumeric_id}}&_bhiiv=opp_8532256e-7f4c-4f45-a5e0-ba6da50772e0_3c02a0de&bhcl_id=bfbefd40-2ebe-4754-80b6-39ab6e486bf0_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Request a demo</a></p><h6 class="heading" style="text-align:left;"><sup>1</sup> Terms and Conditions apply. See offer page for more details.<br>BILL Divvy Card is issued by Cross River Bank, Member FDIC, and is not a deposit product.</h6><p class="paragraph" style="text-align:left;"></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=46ec7863-5c36-4d23-8184-b6683921424a&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Winamp opens its code, but it doesn&#39;t open source its code</title>
  <description>Nostalgic tech enthusiasts will love that WinAmp&#39;s source code is available for personal use. Developers, not so much once they look at the license. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/47604e4e-7f30-45be-bdb2-b76d4cb02669/winapp-classic.jpg" length="219042" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/winamp-opens-its-code-but-it-doesn-t-open-source-its-code</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/winamp-opens-its-code-but-it-doesn-t-open-source-its-code</guid>
  <pubDate>Tue, 24 Sep 2024 16:58:14 +0000</pubDate>
  <atom:published>2024-09-24T16:58:14Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/47604e4e-7f30-45be-bdb2-b76d4cb02669/winapp-classic.jpg?t=1727196285"/><div class="image__source"><a class="image__source_link" href="https://winamp.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" rel="noopener" target="_blank"><span class="image__source_text"><p>WinAmp Classic</p></span></a></div></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.llama-group.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">Llama Group</a>, owners of <a class="link" href="https://winamp.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">Winamp</a>, the media player that defined the digital music experience for a generation, has &quot;sort of&quot; opened its code. While they claim to be open-sourced, the code is not open at all.</p><p class="paragraph" style="text-align:left;">Even a quick look at the <a class="link" href="https://github.com/WinampDesktop/winamp/blob/community/LICENSE.md?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">Winamp Collaborative License (WCL) Version 1.0</a> reveals the following non-open-source rules.</p><p class="paragraph" style="text-align:left;">  * No Distribution of Modified Versions: You may not distribute modified versions of the software, whether in source or binary form.</p><p class="paragraph" style="text-align:left;">    * No Forking: You may not create, maintain, or distribute a forked version of the software.</p><p class="paragraph" style="text-align:left;">    * Official Distribution: Only the maintainers of the official repository are allowed to distribute the software and its modifications.</p><p class="paragraph" style="text-align:left;">Llama knows exactly what it&#39;s doing. They&#39;re open-washing the program to get attention. It worked. As I write this, the <a class="link" href="https://news.ycombinator.com/from?site=github.com%2Fwinampdesktop&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">GitHub site for this &quot;open&quot; project is the top YComb story</a>. But, the released WinAmp source code is in no way, shape, or form open source. </p><p class="paragraph" style="text-align:left;">Indeed Winamp CEO Alexandre Saboundjian said, &quot;<a class="link" href="https://about.winamp.com/press/article/winamp-open-source-code?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">Winamp will remain the owner of the software</a> and will decide on the innovations made in the official version.&quot; </p><p class="paragraph" style="text-align:left;">Open washing, by the way, is when a company pretends its product is open source, but it&#39;s not. Companies do this because &quot;open source&quot; sounds good to developers and buyers alike these days. In addition, in the European Union, programs that can pass for open source can take advantage of the recently passed <a class="link" href="https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">Cyber Resilience Act (CRA)</a>, which <a class="link" href="https://www.forbes.com/councils/forbestechcouncil/2024/09/10/the-cyber-resilience-act-what-it-means-for-open-source/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">protects open-source development from onerous regulations</a>.</p><p class="paragraph" style="text-align:left;">This new code is meant for only Windows. The Mac, Android, and iOS editions will continue to be entirely proprietary. That said, with the code in hand, you could, in theory, fork it for your personal use and port it to another platform while still staying within Winamp&#39;s new license rules. </p><p class="paragraph" style="text-align:left;">Winamp users who still love their old music player with its user-friendly interface, customizable skins, and robust functionality will probably like it. At its peak, Winamp boasted a staggering 90 million users, so there are still millions who like it. </p><p class="paragraph" style="text-align:left;">Since its heyday in the late &#39;90s and early &#39;00s, when it went hand-in-hand with the once wildly popular <a class="link" href="https://www.napster.com/us/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">Napster</a> peer-to-peer file-sharing program, Winamp&#39;s journey has had its ups and downs. After being acquired by AOL in 1999 for $80 million, the software faced stiff competition from emerging technologies like the iPod. Despite this, Winamp maintained a dedicated user base, with many preferring its flexibility and customization options over newer alternatives.</p><p class="paragraph" style="text-align:left;">In 2013, AOL announced plans to discontinue Winamp. But the software found new life when Radionomy, a Belgian online media company now known as Llama, acquired it. Since then, development has been sporadic, with significant updates few and far between. </p><p class="paragraph" style="text-align:left;">Now, Winamp is hoping for a renaissance. By opening its source code, the company aims to leverage the creativity and expertise of the global developer community. Good luck with that. Its parent company also promises that new freemium releases will be coming out much more often.  The newer versions also offer streaming and cloud support that the classic editions lacked. </p><p class="paragraph" style="text-align:left;">We&#39;ll see. As Winamp embarks on this new journey, it faces a dramatically different digital landscape than the one it dominated decades ago. With streaming giants like Spotify and Apple Music now ruling the market, Winamp&#39;s challenge will be to carve out a niche that combines its nostalgic appeal with modern functionality. I&#39;d feel a lot better about its chances if it actually open-sourced its code rather than play games with its licensing. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Other noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/aws-transfers-opensearch-to-the-linux-foundation/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">AWS Transfers OpenSearch to the Linux Foundation</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/5-linux-commands-you-should-never-run-and-why/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">5 Linux commands you should never run (and why)</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/linux-kernel-6-11-is-out-with-its-own-bsod/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=winamp-opens-its-code-but-it-doesn-t-open-source-its-code" target="_blank" rel="noopener noreferrer nofollow">Linux kernel 6.11 is out - with its own BSOD</a></p></li></ul></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=df9749c4-334b-456b-9d54-c76ae64712d5&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Valkey 8 sets a new bar for open-source in-memory NoSQL data storage</title>
  <description>Redis has reason to be worried as Valkey 8 moves beyond its parent program. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9cf86c75-0df4-4adb-9a68-c589fe185126/Valkey.png" length="12461" type="image/png"/>
  <link>https://opensourcewatch.beehiiv.com/p/valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage</guid>
  <pubDate>Thu, 19 Sep 2024 15:57:07 +0000</pubDate>
  <atom:published>2024-09-19T15:57:07Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9cf86c75-0df4-4adb-9a68-c589fe185126/Valkey.png?t=1726760810"/><div class="image__source"><a class="image__source_link" href="https://github.com/valkey-io/valkey?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" rel="noopener" target="_blank"><span class="image__source_text"><p>Valkey 8</p></span></a></div></div><p class="paragraph" style="text-align:left;"><b>Vienna, Austria:</b> <a class="link" href="https://valkey.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Valkey</a>, the <a class="link" href="https://redis.io/de/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Redis</a> fork, is kicking rump and taking names. At <a class="link" href="https://events.linuxfoundation.org/open-source-summit-europe/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Open Source Summit Europe</a>, the <a class="link" href="https://www.linuxfoundation.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Linux Foundation</a> announced the release of <a class="link" href="https://valkey.io/blog/valkey-8-ga/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Valkey 8.0</a>, a giant step forward to the open-source in-memory NoSQL data store. This release focuses on enhancing performance, reliability, and observability, marking a major milestone for the project initially forked from Redis due to licensing changes.</p><p class="paragraph" style="text-align:left;">While Valkey 8.0 is fully compatible with Redis OSS 7.2.4, it also includes features that Redis users have been waiting for for years. As <a class="link" href="https://www.linkedin.com/in/madelyn-olson-6a5053b6/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Madelyn Olson</a>, an <a class="link" href="https://aws.amazon.com/?utm_content=inline+mention&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Amazon Web Services (AWS)</a> principal engineer, <a class="link" href="https://www.linkedin.com/feed/update/urn:li:activity:7176350563071139840/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">former longtime Redis maintainer,</a> and one of the co-launchers of Valkey, said earlier this year, &quot;The previous <a class="link" href="https://thenewstack.io/linux-foundation-forks-the-open-source-redis-as-valkey/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Redis core team was actually pretty technically conservative.</a>&quot; This new crew is not conservative in the least, and the results are impressive.</p><p class="paragraph" style="text-align:left;">Valkey 8.0&#39;s updates include:</p><ul><li><p class="paragraph" style="text-align:left;">Performance Enhancements: Intelligent multi-core utilization <a class="link" href="https://valkey.io/blog/unlock-one-million-rps-part2/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">and asynchronous I/O threading boost throughput to 1.2 million requests per second</a>, tripling the performance of previous versions. By switching from Redis&#39;s archaic single-thread event loop threading model to a sophisticated, I/O operations multithreaded approach, Valkey has vastly increased its speed.</p></li><li><p class="paragraph" style="text-align:left;">Improved Scalability and Reliability: The update introduces dual-channel replication and enhanced cluster scaling.</p></li><li><p class="paragraph" style="text-align:left;">Advanced Observability: Comprehensive metrics for performance monitoring, including pubsub clients and event loop latency, are now available.</p></li><li><p class="paragraph" style="text-align:left;">Memory Efficiency: Optimized key storage reduces memory overhead by up to 10%.</p></li></ul><p class="paragraph" style="text-align:left;">Automatic Failover: Automatic failover ensures that if a primary server or shard fails, a backup can take over immediately, reducing downtime and maintaining service availability.</p><p class="paragraph" style="text-align:left;">Users and programmers alike were impressed by the new release. A software engineer, not connected with Valkey, told me, &quot;This is what Redis should have been doing all along.&quot;  As <a class="link" href="https://www.linkedin.com/in/dirkhohndel/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Dirk Hohnde</a>l, a Linux kernel developer and long-time open-source leader, said at the <a class="link" href="https://events.linuxfoundation.org/kubecon-cloudnativecon-open-source-summit-ai-dev-china/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">KubeCon + CloudNativeCon + Open Source Summit China 2024 Summit China</a> a few weeks  ago, on his small Valkey-powered aircraft tracking system, “I see roughly a <a class="link" href="https://thenewstack.io/valkey-is-a-different-kind-of-fork/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">threefold improvement in performance</a>, and I stream a lot of data, 60 million data points a day.”</p><p class="paragraph" style="text-align:left;">He wasn&#39;t the only one who liked what he saw. The release has garnered support from major tech companies like AWS, Google Cloud, and Oracle, indicating strong industry backing for this open-source initiative.</p><p class="paragraph" style="text-align:left;">Indeed, while Valkey may not be the most successful fork of all time, it&#39;s certainly the fastest to move from a dead stop to greatly improved performance and mass-market acceptance. </p><p class="paragraph" style="text-align:left;">Just look at the record. In March, <a class="link" href="https://redis.io/blog/redis-adopts-dual-source-available-licensing/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Redis announced</a> that it was dumping the open source <a class="link" href="https://opensource.org/license/bsd-3-clause?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">BSD 3-clause license</a> for its <a class="link" href="https://devops.com/redis-labs-extends-reach-of-in-memory-database/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Redis in-memory key-value database</a> for a “source-available” <a class="link" href="https://redis.com/legal/rsalv2-agreement/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Redis Source Available License</a> (RSALv2) and <a class="link" href="https://redis.com/legal/server-side-public-license-sspl/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Server Side Public License</a> (SSPLv1). That made both <a class="link" href="https://www.theregister.com/2024/03/22/redis_changes_license/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">developers and users unhappy</a>. </p><p class="paragraph" style="text-align:left;">So, as open-source people do, community members immediately <a class="link" href="https://www.theregister.com/2024/04/12/linux_foundation_opinion/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">forked the code into Valkey</a> with the support of the Linux Foundation. Redis might have been wiser not to announce this move during <a class="link" href="https://events.linuxfoundation.org/kubecon-cloudnativecon-europe/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">KubeCon Europe 2024</a> in Paris, where literally all the top Redis developers were meeting with their cloud-native computing buddies. </p><p class="paragraph" style="text-align:left;">In days, with the help of the Linux Foundation, they set up their own foundation, <a class="link" href="https://www.valleyfoundation.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Valkey Community Foundation</a>. In weeks, they launched the first release of Valkey. <a class="link" href="https://www.linkedin.com/in/michaelkdolan/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Michael Dolan</a>, the Linux Foundation&#39;s SVP and GM of Projects, and I agreed. We&#39;d never seen a fork project move so quickly, and between us, we&#39;ve seen a ton of projects. </p><p class="paragraph" style="text-align:left;">Looking ahead, the future is bright for Valkey. As for Redis, I foresee nothing but storm clouds ahead.  </p><p class="paragraph" style="text-align:left;"><b>Other noteworthy Linux and open-source stories:</b></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/wind-river-unveils-linux-distro-for-ai-and-critical-workloads/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Wind River Unveils Linux Distro for AI and Critical Workloads</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/20-years-later-real-time-linux-makes-it-to-the-kernel-really/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">20 years later, real-time Linux makes it to the kernel - really</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/linus-torvalds-muses-about-maintainer-gray-hairs-and-the-next-king-of-linux/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valkey-8-sets-a-new-bar-for-open-source-in-memory-nosql-data-storage" target="_blank" rel="noopener noreferrer nofollow">Linus Torvalds muses about maintainer gray hairs and the next &#39;King of Linux&#39;</a></p></li></ul><h3 class="heading" style="text-align:left;" id="looking-for-unbiased-factbased-news">Looking for unbiased, fact-based news? Join 1440 today.</h3><div class="image"><a class="image__link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_name_param}}_{{publication_alphanumeric_id}}&utm_content=prospecting_winner_loser&_bhiiv=opp_54b44f21-40ec-4aba-a8f1-b60b1e62ddc0_1b75ca79&bhcl_id=f0c3282f-793b-4a8c-b945-11777ab9c96a_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fa74d669-e47e-4540-84f0-1a0f3ed64b89/1aae14d18ebe7ada398a3688410a72a3.png?t=1715814737"/></a></div><p class="paragraph" style="text-align:left;">Upgrade your news intake with <a class="link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_name_param}}_{{publication_alphanumeric_id}}&utm_content=prospecting_winner_loser&_bhiiv=opp_54b44f21-40ec-4aba-a8f1-b60b1e62ddc0_1b75ca79&bhcl_id=f0c3282f-793b-4a8c-b945-11777ab9c96a_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">1440</a>! Dive into a daily newsletter trusted by millions for its comprehensive, 5-minute snapshot of the world&#39;s happenings. We navigate through over 100 sources to bring you fact-based news on politics, business, and culture—minus the bias and absolutely free.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_name_param}}_{{publication_alphanumeric_id}}&utm_content=prospecting_winner_loser&_bhiiv=opp_54b44f21-40ec-4aba-a8f1-b60b1e62ddc0_1b75ca79&bhcl_id=f0c3282f-793b-4a8c-b945-11777ab9c96a_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Subscribe to 1440 today.</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=861c711a-ca49-46d2-b08f-80e36ca46e5f&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>AlmaLinux Adds New Hardware Certification Program</title>
  <description>AlmaLinux wants to be taken seriously by enterprise hardware vendors. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/702af92f-a71a-4062-862e-e12314dcb9e9/AlmaLinux_certification.jpg" length="103825" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/almalinux-adds-new-hardware-certification-program</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/almalinux-adds-new-hardware-certification-program</guid>
  <pubDate>Thu, 12 Sep 2024 16:55:54 +0000</pubDate>
  <atom:published>2024-09-12T16:55:54Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><a class="image__link" href="https://almalinux.org/certification/hardware-certification/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/702af92f-a71a-4062-862e-e12314dcb9e9/AlmaLinux_certification.jpg?t=1726159611"/></a><div class="image__source"><span class="image__source_text"><p>AlmaLinux Hardware Certification</p></span></div></div><p class="paragraph" style="text-align:left;">To bolster its position in the enterprise Linux market, the <a class="link" href="https://wiki.almalinux.org/Transparency.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">AlmaLinux OS Foundation </a>has unveiled a comprehensive <a class="link" href="https://almalinux.org/certification/hardware-certification/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">Hardware Certification Program.</a> It aims to ensure seamless compatibility between <a class="link" href="https://almalinux.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">AlmaLinux</a> and a wide range of hardware configurations.</p><p class="paragraph" style="text-align:left;">This is done via an <a class="link" href="https://wiki.almalinux.org/sigs/Certification.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">AlmaLinux certification for hardware special interest group (SIG)</a>l. Jonathan Wright, the infrastructure team lead for AlmaLinux, will serve as SIG’s first chair. </p><p class="paragraph" style="text-align:left;">It&#39;s noteworthy that AlmaLinux has long been interested in hardware support. For example, <a class="link" href="https://opensourcewatch.beehiiv.com/p/almalinux-boosts-legacy-hardware-support-latest-linux-release?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">AlmaLinux has extended support for older gear that Red Hat no longer supports</a>.</p><p class="paragraph" style="text-align:left;">The AlmaLinux Hardware Certification Program will verify and certify AlmaLinux OS hardware compatibility. </p><p class="paragraph" style="text-align:left;">The certification process involves several key steps:</p><p class="paragraph" style="text-align:left;">1. Submission of hardware for testing</p><p class="paragraph" style="text-align:left;">2. Rigorous testing by AlmaLinux or an authorized partner</p><p class="paragraph" style="text-align:left;">3. Issuance of certification upon successful completion of tests</p><p class="paragraph" style="text-align:left;">4. Listing of <a class="link" href="https://almalinux.org/certification/ecosystem-catalog/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">certified hardware in AlmaLinux&#39;s official catalog</a></p><p class="paragraph" style="text-align:left;">This program offers two distinct certification levels:</p><p class="paragraph" style="text-align:left;">1. AlmaLinux Compatible: This basic level confirms that the hardware functions correctly with AlmaLinux OS.</p><p class="paragraph" style="text-align:left;">2. AlmaLinux Certified: A more rigorous certification that guarantees the hardware works and meets specific performance and reliability standards.</p><p class="paragraph" style="text-align:left;">“The creation of the Certification SIG and the program around it illustrates that AlmaLinux continually empowers its community and enables action based on the feedback from users all around the world,”  said benny Vasquez, chair of the AlmaLinux OS Foundation.  “Our users depend upon and appreciate the interactive approach to governance that leads to ongoing advancements in the community. We&#39;re committed to providing a clear and consistent path toward hardware certification.”</p><p class="paragraph" style="text-align:left;">The new certification SIG offers a simple yet comprehensive certification procedure that will take days, not months. It aims to establish a streamlined, collaborative framework for Independent Hardware Vendors (IHVs) and the AlmaLinux OS Foundation to certify hardware compatibility with AlmaLinux OS. The program leverages an open-source certification toolkit developed by ALOSF, built upon various open-source hardware and software testing projects and tools. </p><p class="paragraph" style="text-align:left;">The certification program offers numerous advantages to AlmaLinux ecosystem stakeholders:</p><p class="paragraph" style="text-align:left;"><b>Hardware Vendors</b>: Gain a competitive edge by demonstrating their products&#39; compatibility with AlmaLinux.</p><p class="paragraph" style="text-align:left;"><b>System Integrators</b>: Can confidently build and deploy AlmaLinux-based solutions on certified hardware.</p><p class="paragraph" style="text-align:left;"><b>End Users</b>: Enjoy peace of mind knowing their hardware choices are fully supported by AlmaLinux.</p><p class="paragraph" style="text-align:left;">This move by AlmaLinux is expected to enhance its appeal to enterprise users and hardware manufacturers significantly. AlmaLinux is positioning itself as a robust alternative in the enterprise Linux space by ensuring hardware compatibility and performance. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Other noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/the-rocky-road-to-upgrading-ubuntu-linux-24-04/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">The rocky road to upgrading Ubuntu Linux 24.04</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/ceph-20-years-of-cutting-edge-storage-at-the-edge/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">Ceph: 20 Years of Cutting-Edge Storage at the Edge</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/red-hat-unleashes-enterprise-linux-ai-and-its-truly-useful/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=almalinux-adds-new-hardware-certification-program" target="_blank" rel="noopener noreferrer nofollow">Red Hat unleashes Enterprise Linux AI - and it&#39;s truly useful</a></p></li></ul><h3 class="heading" style="text-align:left;" id="this-cannabis-startup-pioneered-rap">This cannabis startup pioneered “rapid onset” gummies</h3><div class="image"><a class="image__link" href="https://www.clkmg.com/wellput-io/86879luvrv9u1/86879-529////?utm_medium={{publication_name_param}}&_bhiiv=opp_f7843469-399b-4359-bf99-fc71eab38539_2521b9ef&bhcl_id=d368b938-ef1a-4397-a515-0c101a5280db_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c5630173-f63e-42a3-b894-dde0418fa04d/Mood_1.jpeg?t=1712607496"/></a></div><p class="paragraph" style="text-align:left;">Most people prefer to smoke cannabis but that isn’t an option if you’re at work or in public. </p><p class="paragraph" style="text-align:left;">That’s why we were so excited when we found out about Mood’s new Rapid Onset THC Gummies. They can take effect in as little as 5 minutes without the need for a lighter, lingering smells or any coughing. </p><p class="paragraph" style="text-align:left;">Nobody will ever know you’re enjoying some THC.</p><p class="paragraph" style="text-align:left;">We recommend you try them out because they offer a 100% money-back guarantee. And for a limited time, you can receive 20% off with code FIRST20.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.clkmg.com/wellput-io/86879luvrv9u1/86879-529////?utm_medium={{publication_name_param}}&_bhiiv=opp_f7843469-399b-4359-bf99-fc71eab38539_2521b9ef&bhcl_id=d368b938-ef1a-4397-a515-0c101a5280db_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Shop Now.</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=9bcc5d52-5c56-4a82-b85b-ef62ade7b967&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Valve Steam Deck as a stepping stone to the Linux desktop</title>
  <description>This Linux-powered handheld gaming console is great for gamers and is a gateway to Linux desktop users.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5666ab98-09e8-4503-aab7-df63c2cdc3e2/Valve_Steam_Deck_OLED.jpg" length="46556" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/valve-steam-desk-stepping-stone-linux-desktop</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/valve-steam-desk-stepping-stone-linux-desktop</guid>
  <pubDate>Mon, 02 Sep 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-09-02T12:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><a class="image__link" href="https://store.steampowered.com/steamdeck?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5666ab98-09e8-4503-aab7-df63c2cdc3e2/Valve_Steam_Deck_OLED.jpg?t=1725260508"/></a><div class="image__source"><span class="image__source_text"><p>Steam Deck</p></span></div></div><p class="paragraph" style="text-align:left;">Over a decade ago, Gabe Newell, CEO of <a class="link" href="http://www.valvesoftware.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Valve</a> and its <a class="link" href="http://store.steampowered.com/about/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Steam game platform</a>, said, &quot;<a class="link" href="https://www.zdnet.com/article/valve-ceo-why-linux-is-the-future-of-gaming/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Linux is the future of gaming.</a>&quot; It was a great idea, but it didn&#39;t work out that way. However, Valve&#39;s Linux-powered, handheld <a class="link" href="https://store.steampowered.com/steamdeck?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Steam Deck</a> console has carved out a niche in the gaming market.</p><p class="paragraph" style="text-align:left;">True, Steam Deck sales, an estimated 4 million units globally in 2024, are modest compared to its closest rival, the Nintendo Switch, with approximately 200 million units in the hands of gamers. Still, the people who have Steam Decks really like them. Valve says <a class="link" href="https://gamerant.com/valve-steam-deck-owners-preference-popularity/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">nearly half of all Steam Deck owners prefer it to other gaming platforms</a>. </p><p class="paragraph" style="text-align:left;">They prefer it because it gives them access to the large <a class="link" href="https://store.steampowered.com/libraryupdate?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Steam library of games</a>. In addition, you can use the <a class="link" href="https://kotaku.com/valve-steam-deck-pc-steamos-linux-jsaux-games-desktop-1849407251?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Steam console as a computer in its own right</a>. With its larger screen, a 7.4” diagonal on the OLED models, 3-12 hours of gameplay, and top-notch haptic feedback, it&#39;s a pleasure to use. The <a class="link" href="https://www.theverge.com/2021/7/15/22578917/valve-steam-deck-nintendo-switch-xbox-series-x-ps5-spec-comparison?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Steam Deck also offers more powerful hardware than the Switch</a>.</p><p class="paragraph" style="text-align:left;">The Steam Deck comes in three different models. The entry-level $399 256GB LCD Model comes with 256GBs of NVMe SSD storage, a 7&quot; diagonal 1280 x 800 LCD, a 2.4-3.5GHz AMD Zen 2 CPU, an 8 RDNA GPU, and 16GBs of RAM. The $549 512GB OLED Model and the $649 1TB OLED Model offer better graphics, a 7.4&quot; OLED  diagonal display, greater storage, and a larger battery for more gaming time.</p><p class="paragraph" style="text-align:left;">I also like that the Steam Deck is an excellent bridge to the Linux desktop. Indeed, the Steam Deck is also a <a class="link" href="https://store.steampowered.com/steamos?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">SteamOS</a>, an <a class="link" href="https://archlinux.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Arch Linux</a> distro variant, powered PC with a <a class="link" href="https://kde.org/plasma-desktop/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">KDE Plasma interface</a>. Perhaps the biggest argument against the Linux desktop has long been that you can&#39;t play games on it. Thanks to the technology behind Steam Desk, however, you can now play Windows games on Linux without any fuss or muss.</p><p class="paragraph" style="text-align:left;">That’s due to an open-source software translation layer called <a class="link" href="https://github.com/ValveSoftware/Proton?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Proton</a>. With it, you can run Windows games on Linux distributions, not just the Valve Deck. Valve developed Proton in collaboration with <a class="link" href="https://www.codeweavers.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">CodeWeavers</a>. Proton is built upon the <a class="link" href="https://www.winehq.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Wine</a> project, which has long enabled users to run Windows programs on Linux. Here&#39;s how it works:</p><ul><li><p class="paragraph" style="text-align:left;">Translation of Windows API Calls: Proton translates Windows application programming interface (API) calls into Linux-compatible Portable Operating System Interface (POSIX) calls. There&#39;s no emulation or virtualization, which makes it quite fast for running Windows applications on Linux.</p></li><li><p class="paragraph" style="text-align:left;">Direct3D to Vulkan Translation: A significant part of Proton&#39;s functionality is its ability to translate <a class="link" href="https://learn.microsoft.com/en-us/windows/win32/direct3d11/d3d11-graphics-reference?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Direct3D API </a>calls, which are used by Windows games, into <a class="link" href="https://www.vulkan.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">Vulkan API </a>calls that Linux can natively use. This is achieved through tools like <a class="link" href="https://github.com/doitsujin/dxvk?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">DXVK</a> for Direct3D 9, 10, and 11 and <a class="link" href="https://github.com/HansKristian-Work/vkd3d-proton?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">VKD3D-Proton</a> for Direct3D 12.</p></li><li><p class="paragraph" style="text-align:left;">Integration with Steam: Proton is integrated directly into the Steam client as part of Steam Play, allowing users to install and play Windows games on Linux without manually configuring compatibility settings. This seamless integration is a major advantage for users who want to play games without bothering with the technical complexities under the hood.</p></li></ul><p class="paragraph" style="text-align:left;">Most of you don&#39;t need to worry about the technical details. In practice, all a Linux user needs to know is to install and use Proton on Linux using the following simple steps.</p><ol start="1"><li><p class="paragraph" style="text-align:left;">Install Steam: First, you must install the Steam client on your Linux distribution. On modern distros, that consists of little more than searching for it and clicking the install button. Proton is integrated into Steam, so once you have Steam, Proton is already built in.</p></li><li><p class="paragraph" style="text-align:left;">Enable Steam Play: In the Steam client, go to Settings and navigate to the Steam Play section. Here, you can enable Steam Play for all titles and select the latest version of Proton from the dropdown menu.</p></li><li><p class="paragraph" style="text-align:left;">Install and Play Games: Once Steam Play is enabled, you can install Windows games from your Steam library. Steam will automatically use Proton to run these games on your Linux system.</p></li></ol><p class="paragraph" style="text-align:left;">That&#39;s it. That&#39;s all. </p><p class="paragraph" style="text-align:left;">Of course, not all games are created equal for the platform. Some games will work perfectly out of the box, while others may require additional tweaks or not work due to issues such as anti-cheat software incompatibility. To find out what&#39;s what, go to <a class="link" href="https://www.protondb.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=valve-steam-deck-as-a-stepping-stone-to-the-linux-desktop" target="_blank" rel="noopener noreferrer nofollow">ProtonDB</a> to check out the compatibility of specific games with Proton and Linux. </p><p class="paragraph" style="text-align:left;">So, if you like gaming and want a portable system, whether you care about Linux or not, I urge you to try the Steam Deck. If you like it, I suggest you try a Linux desktop for desktop gaming. I think you may just find that the Linux desktop is a fine gaming platform that also works darn well as a production desktop. </p><h3 class="heading" style="text-align:left;">For Those Who Seek Unbiased News.</h3><div class="image"><a class="image__link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_name_param}}&utm_content=prospecting_turtleneck&_bhiiv=opp_5286a93b-ba31-4cc8-b7a4-a9b11c93083a_1b75ca79&bhcl_id=c537e300-4111-4a18-9af6-aff82a9a1691_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d40472ec-5bdb-4069-8942-e6d0bdae63cb/dbcd9478d1335623e8506e7ed6273a88.png?t=1715814779"/></a></div><p class="paragraph" style="text-align:left;">Be informed with <a class="link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_name_param}}&utm_content=prospecting_turtleneck&_bhiiv=opp_5286a93b-ba31-4cc8-b7a4-a9b11c93083a_1b75ca79&bhcl_id=c537e300-4111-4a18-9af6-aff82a9a1691_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">1440</a>! Join 3.5 million readers who enjoy our daily, factual news updates. We compile insights from over 100 sources, offering a comprehensive look at politics, global events, business, and culture in just 5 minutes. Free from bias and political spin, get your news straight.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://l.join1440.com/bh?utm_source=beehiiv&utm_medium=cpc&utm_campaign={{publication_name_param}}&utm_content=prospecting_turtleneck&_bhiiv=opp_5286a93b-ba31-4cc8-b7a4-a9b11c93083a_1b75ca79&bhcl_id=c537e300-4111-4a18-9af6-aff82a9a1691_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Join for free today!</a></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=2c551898-8279-4477-b061-b9b4d3d665cb&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Canonical&#39;s Shifts to Up-to-Date Linux Kernels in Ubuntu</title>
  <description>Ubuntu is very popular, but it has never been a Linux distro that uses the most modern Linux kernels... until now. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7d34e493-f3bd-40b2-b0fd-49c335d2514b/Young_and_Old_Tux.jpg" length="513907" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/canonicals-shifts-uptodate-linux-kernels-ubuntu</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/canonicals-shifts-uptodate-linux-kernels-ubuntu</guid>
  <pubDate>Tue, 13 Aug 2024 22:41:49 +0000</pubDate>
  <atom:published>2024-08-13T22:41:49Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7d34e493-f3bd-40b2-b0fd-49c335d2514b/Young_and_Old_Tux.jpg?t=1723588593"/><div class="image__source"><span class="image__source_text"><p>A fresh, young Tux Linux kernel is ready for Ubuntu.</p></span></div></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://canonical.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Canonical</a>, the company behind the popular Linux distribution <a class="link" href="https://ubuntu.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Ubuntu</a>, has announced a significant change in its approach to integrating Linux kernels into its operating system. Moving forward with the forthcoming <a class="link" href="https://discourse.ubuntu.com/t/ubuntu-desktop-s-24-10-dev-cycle-the-roadmap/45120?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Ubuntu 24.10</a>, Oracular Oriole release, <a class="link" href="https://discourse.ubuntu.com/t/kernel-version-selection-for-ubuntu-releases/47007?u=d0od&utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Canonical will be using more up-to-date Linux kernels</a>.</p><p class="paragraph" style="text-align:left;">Traditionally, Ubuntu has opted for stability by including the most recent stable Linux kernel available at the time of the release freeze. This approach, while ensuring reliability, often meant that Ubuntu releases did not feature the very latest kernel versions, sometimes missing out on new features and hardware support that newer kernels provide. Other popular distros, such as <a class="link" href="https://fedoraproject.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Fedora</a>, opted for cutting-edge kernels. </p><p class="paragraph" style="text-align:left;">Canonical&#39;s new strategy involves shipping the latest upstream Linux kernel available at the time of the Ubuntu release freeze date, even if the kernel is still in a Release Candidate (RC) status. </p><p class="paragraph" style="text-align:left;">This shift is expected to make dissatisfied users who want the latest features and hardware compatibility happier. By adopting newer kernels, Ubuntu aims to better support bleeding-edge hardware and align more closely with the rapid development pace of the Linux kernel itself.</p><p class="paragraph" style="text-align:left;">However, this approach also introduces potential challenges. Using a kernel in RC status could pose stability risks if unforeseen issues arise before the kernel reaches a stable release. Canonical has acknowledged this risk and plans to manage any such occurrences promptly</p><p class="paragraph" style="text-align:left;">For users of Ubuntu&#39;s interim releases, Canonical will provide a &quot;bridge kernel&quot; if the latest kernel turns out to have issues. This will ensure stability while still allowing access to new features. </p><p class="paragraph" style="text-align:left;">Long-term support (LTS) release users won&#39;t need a bridge kernel, as updates are disabled until stabilization is complete. Additionally, users of <a class="link" href="https://ubuntu.com/pro?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Ubuntu Pro</a>&#39;s Livepatch service will continue to receive seamless updates without disruption. This change is coming after <a class="link" href="https://opensourcewatch.beehiiv.com/p/canonical-unveils-12-years-support-ubuntu-lts?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Canonical announced that it would support its Linux distros for 12 years</a>. </p><p class="paragraph" style="text-align:left;">As Ubuntu continues to evolve, this new approach promises to enhance the user experience by delivering the kernel&#39;s latest capabilities alongside stability. I think this is a smart move that both Ubuntu fans and administrators will appreciate. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Other noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/almalinux-makes-in-place-upgradeseasier-for-centos-users/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">AlmaLinux Makes In-Place Upgrades Easier for CentOS Users</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/meet-openshift-lightspeed-redhats-ai-tool-for-kubernetes-admins/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Meet OpenShift Lightspeed, Red Hat&#39;s AI tool for Kubernetes admins</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/could-ebpf-save-us-from-crowdstrike-style-disasters/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=canonical-s-shifts-to-up-to-date-linux-kernels-in-ubuntu" target="_blank" rel="noopener noreferrer nofollow">Could eBPF Save Us From CrowdStrike-Style Disasters?</a></p></li></ul><h3 class="heading" style="text-align:left;" id="we-put-your-money-to-work">We put your money to work</h3><div class="image"><a class="image__link" href="https://www.betterment.com/investing?utm_campaign={{newsletter_name_param}}&utm_medium=display&utm_source=beehiv&utm_content=investing&offer_campaign_id=No&_bhiiv=opp_cb5afae1-2b02-42e1-9ac4-e816751d9e0f_58b249c7&bhcl_id=772778bf-0d89-4275-b14f-ad40c6bc0080_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7ba2818b-3ad1-4ff6-96e1-2627ba542b5f/INV_beehiiv_Newsletter.png?t=1720799747"/></a></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.betterment.com/investing?utm_campaign={{newsletter_name_param}}&utm_medium=display&utm_source=beehiv&utm_content=investing&offer_campaign_id=No&_bhiiv=opp_cb5afae1-2b02-42e1-9ac4-e816751d9e0f_58b249c7&bhcl_id=772778bf-0d89-4275-b14f-ad40c6bc0080_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Betterment’s</a> financial experts and automated investing technology are working behind the scenes to make your money hustle while you do whatever you want.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.betterment.com/investing?utm_campaign={{newsletter_name_param}}&utm_medium=display&utm_source=beehiv&utm_content=investing&offer_campaign_id=No&_bhiiv=opp_cb5afae1-2b02-42e1-9ac4-e816751d9e0f_58b249c7&bhcl_id=772778bf-0d89-4275-b14f-ad40c6bc0080_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Learn more</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=0072fe4a-43bd-4874-8ce1-c9940d48475a&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Endor Labs makes  open-source software security patches easier</title>
  <description>Endor’s new features are helping ease the burden of managing security vulnerabilities in open-source software.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f0754bbd-25d0-4fc3-9beb-20e203135421/Patched_Up_Tux.jpg" length="167016" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/endor-labs-makes-opensource-software-security-patches-easier</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/endor-labs-makes-opensource-software-security-patches-easier</guid>
  <pubDate>Wed, 07 Aug 2024 17:24:25 +0000</pubDate>
  <atom:published>2024-08-07T17:24:25Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cda374d5-21c6-47e4-999d-cc2c0f6fc6a7/Patched_Up_Tux.jpg?t=1723050636"/><div class="image__source"><span class="image__source_text"><p>Patching up open-source software made easier.</p></span></div></div><p class="paragraph" style="text-align:left;">Endor’s new features are helping ease the burden of managing security vulnerabilities in open-source software.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.endorlabs.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=endor-labs-makes-open-source-software-security-patches-easier" target="_blank" rel="noopener noreferrer nofollow">Endor Labs</a>, a software supply chain security leader, announced the launch of two new, innovative capabilities, &quot;Upgrade Impact Analysis&quot; and &quot;Endor Magic Patches,&quot; at <a class="link" href="https://www.blackhat.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=endor-labs-makes-open-source-software-security-patches-easier" target="_blank" rel="noopener noreferrer nofollow">Black Hat</a> in Las Vegas. These two features aim to streamline the process of upgrading software versions and mitigating security vulnerabilities in open-source software (OSS) dependencies.</p><p class="paragraph" style="text-align:left;">We must often upgrade software versions to fix critical vulnerabilities in OSS. However, such upgrades can be challenging and risk causing breaking existing applications. Fear of this and the complexity of determining what effect a patch will have on programs can deter administrators from implementing necessary upgrades. That&#39;s a mistake. </p><p class="paragraph" style="text-align:left;">Endor quotes a Director of AppSec Operations at a major Fintech company, explaining, “Developers fear upgrades because of breaking changes. Imagine if the product could emulate an upgrade to show which upgrade could impact which packages. With this information, I could prioritize fixes based on how hard the upgrade will be and how many other packages will be affected.”</p><p class="paragraph" style="text-align:left;">In response, Endor Labs has released its new Upgrade Impact Analysis feature. This tool provides detailed insights into the potential difficulties and consequences of a given upgrade, enabling AppSec teams to have informed discussions with engineering teams about the scope of security fixes and set service-level agreements (SLAs). When an upgrade is deemed too costly or complex, teams can opt to mitigate the vulnerability with a backported security patch maintained by Endor Labs.</p><p class="paragraph" style="text-align:left;">This feature extends Endor Labs&#39; program analysis engine to identify unintended consequences, such as breaking changes to an application. AppSec teams can now manage risk in the context of upgrade difficulty, improving the return on investment of remediation efforts, reducing developer manual research, and enabling IT teams to address risks more swiftly. In short, it reduces the pain. </p><p class="paragraph" style="text-align:left;">In addition, Endor Magic Patches enables security patches to be backported to the vulnerable version of the software, eliminating the need for difficult upgrades. These patches include source code, tests, build, and deployment steps, ensuring reproducibility and security. This capability allows AppSec teams to respond quickly to emerging threats, balance developer workloads, and support FedRAMP compliance.</p><p class="paragraph" style="text-align:left;">Marcelo Oliveira, VP of Product Management at Endor Labs, emphasized the significance of these new tools: “One of the best characteristics of OSS is the degree of constant improvement—there’s a regular flow of upgrades to just about every package. However, the merits can often be outweighed by the dangers. With these new capabilities, teams can clear this hurdle by sharply reducing the work required to understand the impact of dependency upgrades and stay safe when the risk of upgrades is too high. It’s always been our mission to make security less of a burden on software engineers, and with this launch, we continue to help security teams become better partners”.</p><p class="paragraph" style="text-align:left;">I wouldn&#39;t go that far. The merits almost always outweigh the dangers. That said, there&#39;s no question that upgrading code always comes with some measure of menace. Yes, I&#39;m looking at you <a class="link" href="https://www.theregister.com/2024/07/26/crowdstrike_meets_murphys_law/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=endor-labs-makes-open-source-software-security-patches-easier" target="_blank" rel="noopener noreferrer nofollow">CrowdStrike</a>. So, tools like these certainly have their place for any DevOpsSec team. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Other noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/meet-openshift-lightspeed-redhats-ai-tool-for-kubernetes-admins/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=endor-labs-makes-open-source-software-security-patches-easier" target="_blank" rel="noopener noreferrer nofollow">Meet OpenShift Lightspeed, RedHat&#39;s AI tool for Kubernetes admins</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/can-ai-even-be-open-source-its-complicated/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=endor-labs-makes-open-source-software-security-patches-easier" target="_blank" rel="noopener noreferrer nofollow">Can AI even be open source? It&#39;s complicated</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/russ-cox-steps-down-as-tech-lead-of-go-programming-language/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=endor-labs-makes-open-source-software-security-patches-easier" target="_blank" rel="noopener noreferrer nofollow">Russ Cox Steps Down as Tech Lead of Go Programming Language</a></p></li></ul><h3 class="heading" style="text-align:left;" id="we-put-your-money-to-work">We put your money to work</h3><div class="image"><a class="image__link" href="https://www.betterment.com/investing?utm_campaign={{newsletter_name_param}}&utm_medium=display&utm_source=beehiv&utm_content=investing&offer_campaign_id=No&_bhiiv=opp_f7cfb385-bd42-4934-b42f-59070c1b098d_58b249c7&bhcl_id=199c1c27-7f79-4034-be32-26d4264026e9_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="border-radius:0px 0px 0px 0px;border-style:solid;border-width:0px 0px 0px 0px;box-sizing:border-box;border-color:#E5E7EB;" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7ba2818b-3ad1-4ff6-96e1-2627ba542b5f/INV_beehiiv_Newsletter.png?t=1720799747"/></a></div><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.betterment.com/investing?utm_campaign={{newsletter_name_param}}&utm_medium=display&utm_source=beehiv&utm_content=investing&offer_campaign_id=No&_bhiiv=opp_f7cfb385-bd42-4934-b42f-59070c1b098d_58b249c7&bhcl_id=199c1c27-7f79-4034-be32-26d4264026e9_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Betterment’s</a> financial experts and automated investing technology are working behind the scenes to make your money hustle while you do whatever you want.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.betterment.com/investing?utm_campaign={{newsletter_name_param}}&utm_medium=display&utm_source=beehiv&utm_content=investing&offer_campaign_id=No&_bhiiv=opp_f7cfb385-bd42-4934-b42f-59070c1b098d_58b249c7&bhcl_id=199c1c27-7f79-4034-be32-26d4264026e9_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Learn more</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=7a398efc-0625-48cd-8f21-6f5093d09a76&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Open Source is not a business model; it never was</title>
  <description>It never will be. But, it&#39;s a great development model. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4a59df1d-7470-4832-9111-9891fff2e13b/Open_Souce_Business_Decisions.jpg" length="233613" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/open-source-not-business-model-never</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/open-source-not-business-model-never</guid>
  <pubDate>Mon, 29 Jul 2024 12:05:00 +0000</pubDate>
  <atom:published>2024-07-29T12:05:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4a59df1d-7470-4832-9111-9891fff2e13b/Open_Souce_Business_Decisions.jpg?t=1722207484"/><div class="image__source"><span class="image__source_text"><p>Decisions! Decisions!</p></span></div></div><p class="paragraph" style="text-align:left;">The other day, Dan Lorenc, CEO and co-founder of the software supply chain company <a class="link" href="https://www.chainguard.dev/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Chainguard</a>, wrote on <a class="link" href="https://www.linkedin.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> that &quot;open source is not a good strategy for startups.&quot;</p><p class="paragraph" style="text-align:left;">What? Do you think I was going to disagree because I&#39;m a big open-source fan? Think again!</p><p class="paragraph" style="text-align:left;">Yep, it&#39;s a great development model, but it never has been, isn&#39;t now, and never will be a business model. I am so, so tired of seeing people confusing them. </p><p class="paragraph" style="text-align:left;">Lorenic continued, &quot;There are many open-source strategies that can lead to financial success, and some are easier than others or more relevant to certain use cases than others.&quot;</p><p class="paragraph" style="text-align:left;">That&#39;s true, too. Just ask <a class="link" href="https://www.redhat.com/en?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Red Hat</a>. <a class="link" href="https://www.zdnet.com/article/red-hat-the-first-billion-dollar-linux-company-has-arrived/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">A dozen years ago, Red Hat became the first billion-dollar </a>open-source company not because it offered a great Linux distro—although <a class="link" href="https://www.redhat.com/en/technologies/linux-platforms/enterprise-linux?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Red Hat Enterprise Linux (RHEL)</a> certainly is that—but because the company paired it with an excellent support offering.</p><p class="paragraph" style="text-align:left;">Let me take you back to 2003. Red Hat is selling Red Hat Linux in retail boxes. It was a business, but it wasn&#39;t a big business.  As Paul Cormier, then Red Hat&#39;s vice president of engineering, told me years later, &quot;The people who were here during that period sometimes forget the leap we took, and there&#39;s a lot of people who are at Red Hat now who don&#39;t understand what a big moment that was in our history. We literally stopped our product line.&quot;</p><p class="paragraph" style="text-align:left;">Needless to say, at this remove it all worked out. </p><p class="paragraph" style="text-align:left;">However, it was the enterprise support model that made Red Hat its cash, not the open-source model per se.</p><p class="paragraph" style="text-align:left;">You can also use open source as a <a class="link" href="https://useinsider.com/glossary/top-of-the-funnel/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">top-of-the-funnel</a> offering to get customers to pay for your company&#39;s other offerings. <a class="link" href="https://strapi.io/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Strapi</a>, for example, does well by using its eponymous headless content management system (CMS) <a class="link" href="https://www.karllhughes.com/posts/open-source-companies?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">to get its customers to buy into its other offerings</a>.  </p><p class="paragraph" style="text-align:left;">A close relative and more popular version of this take is open core. Here, the idea is to offer a free, open-source version of a core program and then offer commercial proprietary versions or add-ons. More companies than I can name use this model. Their numbers include <a class="link" href="https://automattic.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Automatic</a>, <a class="link" href="https://www.docker.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Docker</a>, and <a class="link" href="https://gitlab.com/users/sign_in?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">GitLab</a>.</p><p class="paragraph" style="text-align:left;">Another, less-talked-about model is one I call building-block open source. Here, the company doesn&#39;t offer its core program as open source. Instead, it offers useful open-source components and libraries that you could build a useful program from, but it&#39;s just easier and cheaper to use the company&#39;s offering. </p><p class="paragraph" style="text-align:left;">Joe Morrison, a map specialist, has pointed out that <a class="link" href="https://www.mapbox.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Mapbox</a>, a custom online map vendor for websites and applications, has been very successful with this approach. As he wrote, &quot;<a class="link" href="https://joemorrison.medium.com/three-models-for-commercializing-open-source-software-84d3130c82cd?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">You’ve seen their maps</a>, even if you don’t know it — their clients range from Snapchat to Tableau to the New York Times. They aim their product at developers trying to build an app that just happens to need a map interface in order to make sense — which in today’s world of phones perennially in pockets, is honestly kind of hard to avoid.&quot;</p><p class="paragraph" style="text-align:left;">Notice something about all these business plans? They&#39;re all fairly sophisticated. </p><p class="paragraph" style="text-align:left;">Lorenc observed that many &quot;open-source&quot; startups are &quot;afraid of sales and selling.&quot; </p><p class="paragraph" style="text-align:left;">It took all their courage to get venture capitalist or angel investment funding. After all, they&#39;re developers first and business people a long way second.</p><p class="paragraph" style="text-align:left;">That seems to be endemic in tech startups. Way back before open source even existed, when I first started working in tech, I saw business after business fail. Why? Their founders may have been great network engineers, developers, or system administrators, but they were helpless as babies at Business 101. In particular, they were clueless about sales. </p><p class="paragraph" style="text-align:left;">If you don&#39;t know the nuts and bolts of turning your great idea into sales, find someone to partner with who does. </p><p class="paragraph" style="text-align:left;">As Lorenc pointed out, &quot;It&#39;s never easy to monetize an open-source project. It&#39;s <i>doable</i>, but it&#39;s not easy. If you&#39;re not 100 percent sure on how you&#39;re going to monetize, with evidence that it will work, future-you is in for a world of hurt.&quot; He&#39;s right.</p><p class="paragraph" style="text-align:left;">Lorenc doesn&#39;t think building a community will help you in the long run because &quot;they will inevitably slow you down.&quot; Here, we disagree.</p><p class="paragraph" style="text-align:left;">I think, though, that simply assuming a community will somehow miraculously help you turn your open-source project into a viable business is foolish. Find an open-source community expert like my friend <a class="link" href="https://www.jonobacon.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Jono Bacon</a> and read books such as <a class="link" href="https://www.amazon.com/People-Powered-Communities-Supercharge-Business/dp/1400214882?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">People Powered</a> and <a class="link" href="https://www.jonobacon.com/books/artofcommunity/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">The Art of Community</a>. Once you know what a community can—and can&#39;t—do for you, then you can make an intelligent, informed opinion. </p><p class="paragraph" style="text-align:left;">Finally, Lorenc and I are in complete agreement when he wrote if you &quot;do open-source your core product, please, please, please don&#39;t start getting bitter and referring to users (or competitors) that make use of the licenses you provided as freeloaders or complain that they&#39;re taking advantage of you.&quot;</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.theregister.com/2023/10/27/open_source_vs_sort_of_open_source/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Dumping open source ends up ticking off your customers and partners</a>, and you&#39;ll never be welcome in open-source circles again. And, then, where will you find programmers for your next &quot;can&#39;t miss project?&quot;</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);font-family:Helvetica, Arial, sans-serif;font-size:16px;"><b>Other noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/ive-tried-a-zillion-desktop-distros-it-doesnt-get-any-better-than-linux-mint-22/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">I&#39;ve tried a zillion desktop distros - it doesn&#39;t get any better than Linux Mint 22</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/meta-inches-toward-open-source-ai-with-new-llama-3-1/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">Meta inches toward open source AI with new LLaMA 3.1</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/openela-liberates-red-hat-enterprise-linux-source-code/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=open-source-is-not-a-business-model-it-never-was" target="_blank" rel="noopener noreferrer nofollow">OpenELA Liberates Red Hat Enterprise Linux Source Code</a></p></li></ul><h3 class="heading" style="text-align:left;" id="take-a-demo-get-a-blackstone-griddl">Take a demo, get a Blackstone Griddle</h3><div class="image"><a class="image__link" href="https://www.bill.com/offers/rapid-fire-blackstone-griddle/?utm_source=beehiv&utm_medium=sponsored-email&utm_campaign=ONGO2024-PRM-DC-SE-5462-demo-Rapid-Fire-Blackstone-Griddle&_bhiiv=opp_74c8d693-ad02-4dfb-9002-ea9c8c50b995_5518e0ef&bhcl_id=0ace3b68-3fb0-44b5-abb6-987e76310f6f_{{subscriber_id}}_{{email_address_id}}" rel="noopener" target="_blank"><img class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/466db204-4ca2-4429-8b54-59e671814691/Email__1_.png?t=1719967436"/></a></div><ul><li><p class="paragraph" style="text-align:left;">Automate expense reports so you can focus on strategy</p></li><li><p class="paragraph" style="text-align:left;">Uncapped virtual corporate cards</p></li><li><p class="paragraph" style="text-align:left;">Access scalable credit lines from $500 to $15M</p></li></ul><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.bill.com/offers/rapid-fire-blackstone-griddle/?utm_source=beehiv&utm_medium=sponsored-email&utm_campaign=ONGO2024-PRM-DC-SE-5462-demo-Rapid-Fire-Blackstone-Griddle&_bhiiv=opp_74c8d693-ad02-4dfb-9002-ea9c8c50b995_5518e0ef&bhcl_id=0ace3b68-3fb0-44b5-abb6-987e76310f6f_{{subscriber_id}}_{{email_address_id}}" target="_blank" rel="noopener noreferrer nofollow">Request a demo</a></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=658098b3-31d6-46b2-ac45-5ca30d9aaab9&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Apache Software Foundation is Retiring its Feather Logo</title>
  <description>The Apache Software Foundation feather logo is well known and loved, but it comes with some baggage so the group will change its branding. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bb80a51f-78df-4fbd-9f92-0f13fdd4c9f1/The_Originial_Apache_HTTP_Server_Logo.jpg" length="34241" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/apache-software-foundation-retiring-feather-logo</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/apache-software-foundation-retiring-feather-logo</guid>
  <pubDate>Thu, 18 Jul 2024 15:00:00 +0000</pubDate>
  <atom:published>2024-07-18T15:00:00Z</atom:published>
    <dc:creator>Steven Vaughan-Nichols</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><div class="image"><a class="image__link" href="https://www.apache.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bb80a51f-78df-4fbd-9f92-0f13fdd4c9f1/The_Originial_Apache_HTTP_Server_Logo.jpg?t=1721255318"/></a><div class="image__source"><span class="image__source_text"><p>The original Apache HTTP Server Logo</p></span></div></div><p class="paragraph" style="text-align:left;">The <a class="link" href="https://www.apache.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">Apache Software Foundation (ASF)</a> has announced plans to evolve its corporate logo and brand system to better represent its &quot;community over code&quot; ethos and promote inclusivity. Why? Because the <a class="link" href="https://opensourcewatch.beehiiv.com/p/apache-foundation-faces-name-opposition-american-indian-activists?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">ASF took seriously concerns raised by Natives in Tech</a> and other members of the open-source community regarding the appropriateness of using Indigenous imagery.</p><p class="paragraph" style="text-align:left;">So, the ASF will retire its iconic feather logo, which has been a central part of the foundation&#39;s identity since 1999. The organization acknowledges that, as a non-Indigenous entity, it is inappropriate to continue using Indigenous themes or language in its branding. The group also realizes that the logo has been very popular for almost 30 years, but they feel this is the right thing to do. This comes after ASF  changed the name of its flagship event to <a class="link" href="https://communityovercode.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">Community Over Code</a> from ApacheCon. </p><p class="paragraph" style="text-align:left;">The ASF&#39;s Marketing and publicity team, along with a Branding Steering Committee composed of ASF Members, is collaborating with branding and design vendors to develop a new logo. This new visual identity will embody the Foundation&#39;s history of providing software for the public good while reflecting its global contributor base.</p><p class="paragraph" style="text-align:left;">The decision to update the brand extends beyond the logo. Changes also apply to ASF open-source projects that currently use Indigenous imagery. It will not--I and the ASF repeat--not change the <a class="link" href="https://www.apache.org/licenses/LICENSE-2.0?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">Apache License</a> or any released software.</p><p class="paragraph" style="text-align:left;">While the logo and branding are changing, the Apache name will not change, for now, at least. That&#39;s because changing its name would cause too much legal, technical, and financial trouble. This may sound like a small matter to you, but  ASF leadership feels it would divert significant resources from the group&#39;s primary mission of providing software for the public good.</p><p class="paragraph" style="text-align:left;">They&#39;re not wrong. I know enough about trademarks, logos, and names to know that changing an organization&#39;s branding is complicated and expensive. </p><p class="paragraph" style="text-align:left;">If it goes well, the new logo and brand identity will be unveiled at the <a class="link" href="https://communityovercode.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">Community Over Code NA conference</a> in Denver, Colorado, in October 2024. Do you have any ideas for its new logo? The ASF wants to hear from you. </p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);">Other noteworthy Linux and open-source stories:</span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.theregister.com/2024/07/15/opinion_open_source_attract_devs/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">The graying open-source community needs fresh blood</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://thenewstack.io/whats-new-with-the-just-released-linux-6-10-kernel/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">What’s New With the Just-Released Linux 6.10 Kernel</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/how-open-source-attracts-some-of-the-worlds-top-innovators/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=apache-software-foundation-is-retiring-its-feather-logo" target="_blank" rel="noopener noreferrer nofollow">How open source attracts some of the world&#39;s top innovators</a></p></li></ul><p class="paragraph" style="text-align:left;"></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=d28c7b1d-f4dd-484e-b983-e38808719cf8&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Nasty Linux Bug, CVE-2024-1086, is on the loose</title>
  <description>I thought we&#39;d fixed this, but recent reports indicate it&#39;s alive, well, and screwing systems over everywhere.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b25157dc-a462-46d7-9b0a-fc2397fa0c8e/Bug_vs._Tux.jpg" length="189943" type="image/jpeg"/>
  <link>https://opensourcewatch.beehiiv.com/p/nasty-linux-bug-cve20241086-loose</link>
  <guid isPermaLink="true">https://opensourcewatch.beehiiv.com/p/nasty-linux-bug-cve20241086-loose</guid>
  <pubDate>Mon, 03 Jun 2024 12:02:00 +0000</pubDate>
  <atom:published>2024-06-03T12:02:00Z</atom:published>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"></p><div class="image"><img alt="Tux vs. Bug" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b25157dc-a462-46d7-9b0a-fc2397fa0c8e/Bug_vs._Tux.jpg?t=1717370564"/><div class="image__source"><span class="image__source_text"><p>Yow!</p></span></div></div><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;">A few months back, <a class="link" href="https://github.com/Notselwyn/CVE-2024-1086?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">CVE-2024-1086</a>, a nasty use-after-free vulnerability in the Linux kernel&#39;s <a class="link" href="https://www.netfilter.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">netfilter</a>, was revealed. With a  Common Vulnerability Scoring System (CVSS) score of 7.8, this bug, with the foundation for most Linux network firewall and Network Address Translation (NAT) programs, was a nasty little security hole. With it, Netfliter&#39;s table component could be exploited to achieve local privilege escalation. </p><p class="paragraph" style="text-align:left;">Worse still, you didn&#39;t need to be terribly clever to use it, so a local attacker could escalate privileges from a regular user to root in no time flat. Adding insult to injury, this vulnerability was present in pretty much all the major Linux distributions, including <a class="link" href="https://debian.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Debian</a>, <a class="link" href="https://fedoraproject.org/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Fedora</a>, <a class="link" href="https://www.redhat.com/en?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Red Hat</a>, and <a class="link" href="https://ubuntu.com/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Ubuntu</a>. In short, pretty much any Linux distribution using any kernel version between 5.14 and 6.6.14 could be hacked.</p><p class="paragraph" style="text-align:left;">Ouch!</p><p class="paragraph" style="text-align:left;">But, the fix has been in place since January 2024, when the flaw was patched. So, if we&#39;ve been good little system administrators, we shouldn&#39;t have anything to worry about, right? Right!?</p><p class="paragraph" style="text-align:left;">Wrong. </p><p class="paragraph" style="text-align:left;">The US <a class="link" href="https://www.cisa.gov/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Cybersecurity and Infrastructure Security Agency (CISA)</a> has flagged it and added it to the <a class="link" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Known Exploited Vulnerabilities (KEV)</a> catalog. It turns out that it&#39;s being actively exploited in the wild.</p><p class="paragraph" style="text-align:left;">Now, if this were happening back in March, I wouldn&#39;t be surprised. That&#39;s when the flaw finder, who went by the name <a class="link" href="https://github.com/Notselwyn/CVE-2024-1086?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Notselwyn, published a CVE-2024-1086  proof-of-concept exploit</a>. He reported that it had a 99.4% success rate on kernel 6.4.16 and provided a detailed technical report. His method, called Dirty Pagedirectory, builds on the earlier <a class="link" href="https://yanglingxi1993.github.io/dirty_pagetable/dirty_pagetable.html?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Dirty Pagetable</a> technique, allowing unlimited, stable read/write access to all memory pages in a Linux system.</p><p class="paragraph" style="text-align:left;">I don&#39;t think you need to be a security expert to know that&#39;s bad. </p><p class="paragraph" style="text-align:left;">NIST reports that &quot;<a class="link" href="https://nvd.nist.gov/vuln/detail/CVE-2024-1086?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">This vulnerability has been modified</a> and is currently undergoing reanalysis. Please check back soon to view the updated vulnerability summary.&quot;</p><p class="paragraph" style="text-align:left;">I wonder, though, I really do, whether it&#39;s really been updated or whether it&#39;s just that there&#39;s now a bot toolkit using it. As a result, thousands of automated attempts are discovering that far too many people never patched their Linux machines in the first place. As <a class="link" href="https://fs.blog/mental-model-hanlons-razor/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Hanlon&#39;s Razor</a> explains, &quot;Never attribute to malice that which is adequately explained by stupidity.</p><p class="paragraph" style="text-align:left;">So, may I suggest you check to see if your distro is still open to the original attack? You can do that by running the command:</p><p class="paragraph" style="text-align:left;">$ uname -r</p><p class="paragraph" style="text-align:left;">In your terminal. </p><p class="paragraph" style="text-align:left;">If the output of any of these commands shows a kernel version between 3.15 and 6.8-rc1, your system is potentially vulnerable to CVE-2024-1086. For instance, if uname—r returns 5.13.0-39-generic, your system is within the affected range and should be updated.</p><p class="paragraph" style="text-align:left;">The patched kernels for the major Linux distros include:</p><h2 class="heading" style="text-align:left;" id="debian"><a class="link" href="https://security-tracker.debian.org/tracker/CVE-2024-1086?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Debian</a></h2><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">Kernel-Version: 6.1.76-1</span></p></li></ul><h2 class="heading" style="text-align:left;" id="ubuntu"><a class="link" href="https://ubuntu.com/security/CVE-2024-1086?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Ubuntu</a></h2><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">Ubuntu 18.04: 4.15.0-223.235</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">Ubuntu 20.04: 5.4.0-174.193</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">Ubuntu 22.04: 5.15.0-101.111</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">Ubuntu 23.10: 6.5.0-26.26</span></p></li></ul><h2 class="heading" style="text-align:left;" id="red-hat-and-red-hatbased-distros"><a class="link" href="https://access.redhat.com/errata/RHSA-2024:1086?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Red Hat</a><span style="color:rgb(19, 52, 59);"> and Red Hat-based distros:</span></h2><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">RHEL 7: 3.10.0-1062.4.1.el7</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">RHEL 8: 4.18.0-147.el8</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">RHEL 9: 5.14.0-362.24.2.el9_3</span></p></li></ul><h2 class="heading" style="text-align:left;" id="suse"><a class="link" href="https://www.suse.com/support/update/announcement/2024/suse-su-20240463-1/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">SUSE</a></h2><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">There are various fixed kernel versions for the SUSE Linux Enterprise distros.</span></p></li></ul><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">To be safe, update your systems and then reboot them with the following commands: </span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(19, 52, 59);">Update Package Lists:</span></p><p class="paragraph" style="text-align:left;">$ sudo apt update  # For Debian/Ubuntu</p><p class="paragraph" style="text-align:left;">$ sudo yum update  # For Red Hat/CentOS</p><p class="paragraph" style="text-align:left;">$ sudo zypper refresh  # For SUSE</p><p class="paragraph" style="text-align:left;">$ sudo dnf update  # For AlmaLinux/Rocky Linux</p><p class="paragraph" style="text-align:left;">Upgrade Kernel:</p><p class="paragraph" style="text-align:left;">$ sudo apt upgrade  # For Debian/Ubuntu</p><p class="paragraph" style="text-align:left;">$ sudo yum update kernel  # For Red Hat/CentOS</p><p class="paragraph" style="text-align:left;">$ sudo zypper update  # For SUSE</p><p class="paragraph" style="text-align:left;">$ sudo dnf update kernel  # For AlmaLinux/Rocky Linux</p><p class="paragraph" style="text-align:left;">Reboot System: </p><p class="paragraph" style="text-align:left;">$ sudo reboot</p><p class="paragraph" style="text-align:left;">All should be well.  </p><p class="paragraph" style="text-align:left;">But, if you can&#39;t patch it or think there may indeed be a new version of the vulnerability out there? In that case, you can mitigate it by disabling the ability for unprivileged users to create namespaces. To do this temporarily, in the Debian/Ubuntu world run:</p><p class="paragraph" style="text-align:left;">$ sudo sysctl -w kernel.unprivileged_userns_clone=0</p><p class="paragraph" style="text-align:left;">To disable it for once and all:</p><p class="paragraph" style="text-align:left;"> echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf</p><p class="paragraph" style="text-align:left;">Personally, I&#39;ve never been keen on granting unprivileged users the ability to create namespaces. As a wise admin once said, <a class="link" href="https://security.stackexchange.com/questions/209529/what-does-enabling-kernel-unprivileged-userns-clone-do?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">&quot;Unless you truly need it, just disable it.</a>&quot;</p><p class="paragraph" style="text-align:left;"><span style="color:rgb(34, 34, 34);"><b>Noteworthy Linux and open-source stories:</b></span></p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/article/are-all-linux-vendor-kernels-insecure-a-new-study-says-yes-but-theres-a-fix/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Are all Linux vendor kernels insecure? A new study says yes, but there&#39;s a fix</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/home-and-office/home-entertainment/winamp-is-not-going-open-source-heres-what-it-is-doing-and-why/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">Winamp is not going open source. Here&#39;s what it is doing - and why</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.zdnet.com/home-and-office/work-life/more-than-money-open-source-pros-want-these-2-things-from-their-next-jobs/?utm_source=opensourcewatch.beehiiv.com&utm_medium=newsletter&utm_campaign=nasty-linux-bug-cve-2024-1086-is-on-the-loose" target="_blank" rel="noopener noreferrer nofollow">More than money, open-source pros want these 2 things from their next jobs</a></p></li></ul><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p><p class="paragraph" style="text-align:left;"></p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=a393bc94-6128-4646-bed4-4983ed20e763&utm_medium=post_rss&utm_source=open_source_watch">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
