The subject this post names, from the same vocabulary
the directory files beliefs under, and the words it uses that this site has seen
least often elsewhere. Posts are matched on those words alone —
nothing here is a summary of this one.
Rarer is better, but I still think the right rate of misbehaviors on the level of social engineering to put malicious packages into a public registry is still zero.
Open source in its current form doesn’t make sense anymore. “Given enough eyeballs, all bugs are shallow” is still true but now we have artificial eyeballs
even when given a benign task to retrieve public information, your AI agents could still spontaneously decide to do so via hacking third party websites with malicious software packages.
Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.
migrations (e.g. replacing one service with a new one, or switching database engines, or whatever) are part and parcel of software engineering and are a skill that you should invest in and get good at, not avoid or treat as special one-offs.
Codex lets you use any model you want (not just OpenAI) and harness is open source - Claude Code doesn’t and is closed source Given this is the two leading AI labs, notable difference in approaches
Open source training data Blender beats all its competitors because it's optimal in the most important dimension: agents can train on it and use it efficiently. OSS wins.
in this whole USA vs China thing OpenAI and Anthropic aren't relevant because they're positioned differently
them building better models doesn't hurt china at all
the competitor has to be
- american
- open source
- enough compute to do inference at scale
that can shift things
I am telling you this is inevitable, which means I am also saying that “banning open source,” or for that matter any other regulation, will not solve the problem. Given the inevitability of this outcome, I think it is in fact plausible to argue that we should want more open-weight models to maximally empower our self-defense.
however at any given point in time I think the systems we need to worry most about by far are the frontier systems. By the time open source systems can do something like the hugging face attack, frontier systems are going to be on a whole another level doing something even crazier than that.
I'm not sure I like agree exactly with the oversight benefit you named of like you know open source systems keeping frontier systems in check feels more unrealistic to me because they're going to be so much dumber than the frontier systems.
But it actually means that if you take the median programmer and their pull requests towards an average open source project, they're already getting outclassed by agents. I would rather get an agent-written pull request to one of my projects than I'd get one written by a human, and it's not just because the quality's better. It's also because I feel a lot less bad if I just reject it.
So, in my opinion, this is the absolute best time to ever have been an open source software maintainer. Not only do we get this wealth of glorious pull requests made by agents with all the boxes ticked, we also get to tap into a creativity of people who did not have access to contribute to a project before.
if the US wants to lead in artificial intelligence, we have to have a vibrant closed and open source ecosystem, and that's the only way they can all work together.
Every lab will sell you an agent. Open claw is the alternative. Open source runs everywhere, works with any model. And if you run local models, your data never has to leave your device.
Software is kind of unique in having the third kind of the practitioner conference where we are just meeting to get better at what we do. We also are really the only kind to really focus heavily on like open source in making our knowledge freely available.
we want we want to encourage everybody and every company to build their own AIs. And and and who knows what innovation will come from the fact that it's open source.
I read a bunch of blog posts about how it is totally fine to use SQLite in production for a small site and I think it is totally fine, but what I did not fully appreciate is that SQLite is still a database, databases are complicated, and I do not know a lot about operating databases.
All you really need today to build a business is 100% free open source software that charges you $0/mo a VPS server an API to do some required AI stuff some R2/S3 file hosting
Since I mostly work on Laravel projects or packages, I usually enable the Laravel Idea plugin. It's a paid plugin, but it's definitely worth the money since it can provide stuff like auto-completions for route names, request fields and more.
In terms of science, I think it really makes sense and we're deeply committed to open source. Um, there are obviously interesting considerations on this that are important too because there's a lot of considerations around biosafety and things like that that we're going to need to balance and think through how to how to handle.
the competitive dynamic in China is more intense because it's more intense. Everyone's chosen to go open source and that creates a system that in my mind is capable of innovating far faster than the competitive system we have here. All the models learn from one another.
And we we full well knew that there was absolutely zero chance that we would appeal to the JavaScript ecosystem with a proprietary programming language licensed from Microsoft. No. No one was going to come. It had to be open source. There was just no two ways about it, right?
You know, there's open source and there's open development. And and and we were technically open source in the beginning, but it was not open development. We would sort of lob the source code out in this repository and scrape the issues off of that and put it into our internal issue tracker.
Going forward, I think the future will be filled with software abundance, or, more accurately, I'd call it "software proliferation". That is, centralized development will be history. Software will be highly personalized, especially for open source software.
And now suddenly people are building databases on top of object stores, for example. And now the replication happens at the object store level, no longer at the database level.
You can give it a Bash tool so it can ripgrep its way through the codebase. You can give it some queryable codebase index, an LSP server, a vector database. In the end it doesn't matter much. The bigger the codebase, the lower the recall. Low recall means that your agent will, in fact, not find all the code it needs to do a good job.
So you get this rapid, incredible great talent, rapid innovation because of open source and just, you know, the nature of friends, and, and insane competition. Among the company, what emerges is incredible stuff. And so this is the fastest innovating country in the world today
And if everything is proprietary, it's hard to do research and it's hard to innovate on top of, around, with. And so… Open source is fundamentally necessary for many industries to join the AI revolution.
But also, I'm very excited to, like, make this into a version that I can get to a lot of people because I think this is the year of personal agents, and that's the future. And the fastest way to do that is teaming up with one of the labs.
It significantly lowered the bar to production. It is how we got the whole
society to run on software. If you make it harder for hobbyists maintainers, you
are going to crash society.
FOSS solve that problem far more than it solves “we don’t want to pay”. Most
corporations would be surprised by how cheap it would cost them to pay
for the FOSS software they use.
it's kind of like databases right it's always the thing it's like hey can one database be the one that just is used everywhere except it's not uh there are multiple types of databases that are getting deployed uh for different use cases.
The panel had a generally positive view of Phoenix, with one panelist calling it one of his “favorite open source eval tools.” The tool is positioned as a developer-first, notebook-centric platform.
You need reproducible builds in order to verify that the app really does what it claims, really encrypts data in a way that it is described on its website. For that you need to make your apps open source for any researchers to have a look at it.
With Web forms, the burden is on people to adapt to databases. Today's AI models, however, can flip this requirement. That is, they allow people to provide information in whatever form they like and use AI do the work necessary to put that information into the right structure for a database.
And actually the reason I think it's exciting is if you look at like the database space right now there's not one database. If you want to do largecale data analytics you'll choose one thing. If you want to do a transactional data store you'll do another. I think we're moving to that area of models
What you need is interoperability. Interoperability can happen through a blockchain, it can happen through a database, it can happen through standards bodies with defining standards and protocols. And we've been doing it for hundreds of years since the railroads were standardized. And it's not something that totally requires a novel technological solution.
I think there's this whole idea, I call it a denial of attention. I think there's an entire attack vector that's going to be happening. We're using LLMs to generate fake bug reports, fake all these things to just actually effectively to demotivate and hurt open source maintainers.
until there are feedback loops of open source AI, it seems like mostly an ideological mission. People like Mark Zuckerberg, which is like America needs this and I agree with him, but in the time where the motivation ideologically is high, we need to capitalize and build this ecosystem around, what benefits do you get from seeing the language model data?
And my contrarian opinion is that full-time jobs are not the best way to monetize the skill that you have. It's one of the packages that everybody should evaluate and take advantage of, but too many people blindly default to that package
I think it’s fantastic when businesses are built on open source, the WordPress ecosystem is at least 10B+ a year; Automattic and WP Engine are less than 5% of that.
This isn’t a money grab: it’s an expectation that any business making hundreds of millions of dollars off of an open source project ought to give back, and if they don’t, then they can’t use its trademarks.
If WP Engine wants to find another open source project with a more permissive license and no trademarks, they are free to do so; if they want to benefit from the WordPress community, then they need to respect WordPress trademark and IP.
Clients still pay a fixed monthly retainer to ensure the professional maintenance of the whole portfolio, and to get access to the expertise of all of Geomys’ maintainers.
From the onset, I envisioned small firms of professional maintainers with thematic portfolios, accommodating diverse maintainers and project sizes, just like the specialized firms of other professionals.
I started with a rather non-consensus hypothesis: companies want to pay for their critical open source dependencies, but most projects are not selling them a legible way to do so.
No such restrictions are found in free or open source software licenses, be they permissive or copyleft – all FOSS licenses permit the use of the software for any purpose without restriction.
I think that was an unfortunate move because their goal is mainly to extract profit from the software project rather than to uphold the ideals of Free and Open Source Software.
Just dumping the code on GitHub is not open source. Open source is a culture. Open source means that your issues are not all one year old, stale issues. Open source means developing in public.
This experiment started from the observation that despite being critical for the functioning of the Internet—and, by extension, the economy—the role of open-source maintainer has not yet found a sustainable manifestation.
We are not suppliers. All the people writing and maintaining these projects, we are not suppliers. We do not have a business relationship with all these organisations.
I used to think that this was unequivocally a win for open source. That to fight for attention with the commercial alternatives, we had to adopt the commercial playbook. Now I think it’s at the very least a mixed blessing.
WinMerge just gets better and better. It's free, it's open source and it'll compare files and folders and help you merge your conflicted source code files like a champ.
The fast route — venture capital funded — is going to impose constraints on your business that will ultimately make it difficult to remain true to your open-source mission.
I’ve seen recurring comments to the effect of “This is great, but individuals aren’t where the money’s at, it’s companies”, which is a position I’ve also previously taken.
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com.
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.