<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Open Source on Osmond van Hemert</title><link>https://www.osmondvanhemert.nl/tags/open-source/</link><description>Recent content in Open Source on Osmond van Hemert</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© Osmond van Hemert. All rights reserved.</copyright><lastBuildDate>Thu, 09 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://www.osmondvanhemert.nl/tags/open-source/index.xml" rel="self" type="application/rss+xml"/><item><title>The xz Utils Aftermath — One Year Later, What Have We Actually Fixed?</title><link>https://www.osmondvanhemert.nl/posts/260409-xz-utils-supply-chain-anniversary/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/260409-xz-utils-supply-chain-anniversary/</guid><description>Nearly two years after the xz Utils backdoor shocked the open source world, the supply chain security landscape has changed — but not enough.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/260409-xz-utils-supply-chain-anniversary/featured.jpg"/></item><item><title>OpenTofu's Growing Pains — The State of Infrastructure as Code in 2026</title><link>https://www.osmondvanhemert.nl/posts/260226-opentofu-infrastructure-as-code/</link><pubDate>Thu, 26 Feb 2026 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/260226-opentofu-infrastructure-as-code/</guid><description>OpenTofu has matured significantly since its fork from Terraform. Here&amp;rsquo;s where things stand and what it means for teams managing cloud infrastructure.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/260226-opentofu-infrastructure-as-code/featured.jpg"/></item><item><title>Rust in the Linux Kernel — Two Years of Growing Pains and Real Progress</title><link>https://www.osmondvanhemert.nl/posts/260122-rust-linux-kernel-progress/</link><pubDate>Thu, 22 Jan 2026 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/260122-rust-linux-kernel-progress/</guid><description>Rust&amp;rsquo;s integration into the Linux kernel has moved beyond proof of concept into real subsystems, but the cultural and technical challenges remain fascinating.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/260122-rust-linux-kernel-progress/featured.jpg"/></item><item><title>Ultralytics Supply Chain Attack — When Your Dependencies Bite Back</title><link>https://www.osmondvanhemert.nl/posts/251218-ultralytics-supply-chain-attack/</link><pubDate>Thu, 18 Dec 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251218-ultralytics-supply-chain-attack/</guid><description>A supply chain attack on the popular Ultralytics YOLO package highlights the persistent vulnerability of the Python ecosystem&amp;rsquo;s distribution pipeline.</description></item><item><title>OpenTelemetry Reaches GA for Logs — The Three Pillars Are Finally Complete</title><link>https://www.osmondvanhemert.nl/posts/251204-opentelemetry-logs-ga-three-pillars/</link><pubDate>Thu, 04 Dec 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/251204-opentelemetry-logs-ga-three-pillars/</guid><description>OpenTelemetry&amp;rsquo;s logging API and SDK reaching general availability completes the observability trifecta. Here&amp;rsquo;s why this matters more than you might think.</description></item><item><title>The Bitnami Docker.io Deletion — When Your Infrastructure Disappears Overnight</title><link>https://www.osmondvanhemert.nl/posts/250828-bitnami-docker-deletion/</link><pubDate>Thu, 28 Aug 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250828-bitnami-docker-deletion/</guid><description>Broadcom&amp;rsquo;s deletion of Bitnami images from Docker Hub is a wake-up call about depending on container registries you don&amp;rsquo;t control.</description></item><item><title>uv Adds Code Formatting — Python's Tooling Consolidation Continues</title><link>https://www.osmondvanhemert.nl/posts/250821-uv-code-formatting-python-tooling/</link><pubDate>Thu, 21 Aug 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250821-uv-code-formatting-python-tooling/</guid><description>The uv package manager experimentally adds code formatting, continuing its ambitious push to become a single tool for the entire Python development workflow.</description></item><item><title>Google's Gemma 3 270M — Why Tiny Models Are the Real AI Story</title><link>https://www.osmondvanhemert.nl/posts/250814-gemma3-270m-small-models-big-impact/</link><pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250814-gemma3-270m-small-models-big-impact/</guid><description>Google releases Gemma 3 at 270M parameters, proving that smaller, more efficient models might matter more than the next big model launch.</description></item><item><title>OpenTofu at One — How the Terraform Fork Found Its Footing</title><link>https://www.osmondvanhemert.nl/posts/250529-opentofu-terraform-fork-maturing/</link><pubDate>Thu, 29 May 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250529-opentofu-terraform-fork-maturing/</guid><description>A year and a half after forking from Terraform, OpenTofu is proving that community-driven infrastructure tooling can thrive — but challenges remain.</description></item><item><title>Model Context Protocol — The Quiet Standard That Could Reshape AI Tooling</title><link>https://www.osmondvanhemert.nl/posts/250403-model-context-protocol-adoption/</link><pubDate>Thu, 03 Apr 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250403-model-context-protocol-adoption/</guid><description>Anthropic&amp;rsquo;s Model Context Protocol is gaining traction as a universal standard for connecting AI models to tools and data sources, and the implications for the developer ecosystem are worth watching.</description></item><item><title>Go 1.24 Released — Generics Maturity and the Evolution of a Pragmatic Language</title><link>https://www.osmondvanhemert.nl/posts/250213-go-124-release/</link><pubDate>Thu, 13 Feb 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250213-go-124-release/</guid><description>Go 1.24 brings generic type aliases, improved tool management, and Swiss Tables. A look at how Go keeps evolving without losing its identity.</description></item><item><title>DeepSeek R1 — Open-Source Reasoning Models Change the Game</title><link>https://www.osmondvanhemert.nl/posts/250123-deepseek-r1-open-source-reasoning/</link><pubDate>Thu, 23 Jan 2025 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/250123-deepseek-r1-open-source-reasoning/</guid><description>DeepSeek&amp;rsquo;s R1 reasoning model, released as fully open-source with an MIT license, demonstrates that frontier AI capabilities aren&amp;rsquo;t exclusive to US labs anymore.</description></item><item><title>WordPress vs WP Engine — When Open Source Gets Personal</title><link>https://www.osmondvanhemert.nl/posts/241017-wordpress-wp-engine-open-source-rift/</link><pubDate>Thu, 17 Oct 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/241017-wordpress-wp-engine-open-source-rift/</guid><description>The WordPress/WP Engine feud has escalated into a full-blown crisis, raising fundamental questions about open source governance and commercial ecosystems.</description></item><item><title>WordPress vs WP Engine — When Open Source Governance Gets Personal</title><link>https://www.osmondvanhemert.nl/posts/241003-wordpress-wp-engine-open-source-governance/</link><pubDate>Thu, 03 Oct 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/241003-wordpress-wp-engine-open-source-governance/</guid><description>The escalating conflict between Automattic and WP Engine raises fundamental questions about open source trademarks, governance, and what happens when a project&amp;rsquo;s founder picks a fight.</description></item><item><title>CUPS Overflows — A Critical Linux Printing Vulnerability Nobody Saw Coming</title><link>https://www.osmondvanhemert.nl/posts/240926-cups-vulnerability-linux-printing-security/</link><pubDate>Thu, 26 Sep 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240926-cups-vulnerability-linux-printing-security/</guid><description>A chain of vulnerabilities in CUPS, the Linux printing system, enables remote code execution — and highlights how forgotten infrastructure becomes a security liability.</description></item><item><title>Linux 6.11 Lands — Rust's Growing Presence in the Kernel</title><link>https://www.osmondvanhemert.nl/posts/240919-linux-kernel-6-11-rust-momentum/</link><pubDate>Thu, 19 Sep 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240919-linux-kernel-6-11-rust-momentum/</guid><description>Linux kernel 6.11 ships with expanding Rust support, signaling a real shift in systems programming&amp;rsquo;s most conservative codebase.</description></item><item><title>Rust 1.81 Drops — Core Error Trait, Sorted Lints, and Why Rust Keeps Getting Better</title><link>https://www.osmondvanhemert.nl/posts/240905-rust-1-81-release/</link><pubDate>Thu, 05 Sep 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240905-rust-1-81-release/</guid><description>Rust 1.81 brings the Error trait into core, stabilizes new lint sorting, and continues the language&amp;rsquo;s steady march toward broader adoption.</description></item><item><title>Llama 3.1 405B — Meta Goes All-In on Open-Source AI</title><link>https://www.osmondvanhemert.nl/posts/240725-meta-llama-3-1-open-source/</link><pubDate>Thu, 25 Jul 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240725-meta-llama-3-1-open-source/</guid><description>Meta releases Llama 3.1 with a 405 billion parameter model under a permissive license, making frontier-class AI genuinely open for the first time.</description></item><item><title>The Polyfill.io Supply Chain Attack — A Wake-Up Call for CDN Trust</title><link>https://www.osmondvanhemert.nl/posts/240627-polyfill-io-supply-chain-attack/</link><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240627-polyfill-io-supply-chain-attack/</guid><description>The polyfill.io domain was acquired by a Chinese company and began injecting malware into over 100,000 websites, exposing fundamental weaknesses in how we trust third-party CDN dependencies.</description></item><item><title>Meta Releases Llama 3 — Open Source AI Just Got Serious</title><link>https://www.osmondvanhemert.nl/posts/240418-meta-llama-3-release/</link><pubDate>Thu, 18 Apr 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240418-meta-llama-3-release/</guid><description>Meta&amp;rsquo;s Llama 3 arrives with 8B and 70B parameter models that rival closed-source competitors, reshaping the open-weight AI landscape.</description></item><item><title>Redis Goes Proprietary, the Community Forks — Enter Valkey</title><link>https://www.osmondvanhemert.nl/posts/240404-redis-relicensing-valkey-fork/</link><pubDate>Thu, 04 Apr 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240404-redis-relicensing-valkey-fork/</guid><description>Redis Labs switches from BSD to a dual SSPL/RSALv2 license, and the Linux Foundation responds by backing the Valkey fork.</description></item><item><title>The xz Utils Backdoor — Open Source's Worst Nightmare Almost Came True</title><link>https://www.osmondvanhemert.nl/posts/240328-xz-utils-backdoor-cve-2024-3094/</link><pubDate>Thu, 28 Mar 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240328-xz-utils-backdoor-cve-2024-3094/</guid><description>A sophisticated supply chain attack via the xz Utils compression library was caught just days before reaching stable Linux distributions.</description></item><item><title>The JavaScript Runtime Wars — Bun, Deno, and Node.js in 2024</title><link>https://www.osmondvanhemert.nl/posts/240314-javascript-runtime-wars-bun-deno-node/</link><pubDate>Thu, 14 Mar 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240314-javascript-runtime-wars-bun-deno-node/</guid><description>With Bun 1.0 maturing, Deno pushing Node compatibility, and Node.js evolving faster than ever, the JavaScript runtime landscape is more interesting than it&amp;rsquo;s been in years.</description></item><item><title>OpenTofu 1.6 GA — The Terraform Fork Grows Up</title><link>https://www.osmondvanhemert.nl/posts/240111-opentofu-1-6-terraform-fork-grows-up/</link><pubDate>Thu, 11 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240111-opentofu-1-6-terraform-fork-grows-up/</guid><description>OpenTofu hits its first GA release, proving that the open-source fork of Terraform is more than a protest — it&amp;rsquo;s a viable alternative.</description></item><item><title>OpenTofu and the Future of Open Source Infrastructure</title><link>https://www.osmondvanhemert.nl/posts/240104-opentofu-open-source-infrastructure/</link><pubDate>Thu, 04 Jan 2024 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/240104-opentofu-open-source-infrastructure/</guid><description>As OpenTofu approaches its first stable release, the HashiCorp license change continues to reshape how we think about open source infrastructure tooling.</description></item><item><title>OpenTofu Gains Momentum — The Terraform Fork Finding Its Feet</title><link>https://www.osmondvanhemert.nl/posts/231026-opentofu-terraform-fork/</link><pubDate>Thu, 26 Oct 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/231026-opentofu-terraform-fork/</guid><description>OpenTofu, the community fork of Terraform born from HashiCorp&amp;rsquo;s license change, is rapidly building momentum under the Linux Foundation.</description></item><item><title>OpenTofu — The Community Fights Back Against Terraform's License Change</title><link>https://www.osmondvanhemert.nl/posts/230831-opentofu-terraform-fork-open-source/</link><pubDate>Thu, 31 Aug 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230831-opentofu-terraform-fork-open-source/</guid><description>HashiCorp&amp;rsquo;s switch to the Business Source License has triggered a community fork of Terraform called OpenTofu, and the implications for infrastructure-as-code are enormous.</description></item><item><title>Code Llama — Meta's Open Source Bet on AI-Assisted Coding</title><link>https://www.osmondvanhemert.nl/posts/230824-code-llama-open-source-code-generation/</link><pubDate>Thu, 24 Aug 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230824-code-llama-open-source-code-generation/</guid><description>Meta releases Code Llama, a family of open-source code generation models, and it might just change the dynamics of AI-assisted development.</description></item><item><title>HashiCorp Switches Terraform to BSL — The Open Source World Reacts</title><link>https://www.osmondvanhemert.nl/posts/230810-hashicorp-terraform-bsl-license/</link><pubDate>Thu, 10 Aug 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230810-hashicorp-terraform-bsl-license/</guid><description>HashiCorp&amp;rsquo;s decision to relicense Terraform and other products under the Business Source License has sent shockwaves through the infrastructure community.</description></item><item><title>Meta Releases Llama 2 — Open Source AI Gets a Massive Boost</title><link>https://www.osmondvanhemert.nl/posts/230720-meta-llama2-open-source-llm/</link><pubDate>Thu, 20 Jul 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230720-meta-llama2-open-source-llm/</guid><description>Meta&amp;rsquo;s release of Llama 2 as a commercially-licensed open model changes the game for developers building with large language models.</description></item><item><title>Red Hat Locks Down RHEL Source Code — Open Source Has a Trust Problem</title><link>https://www.osmondvanhemert.nl/posts/230622-red-hat-rhel-source-code-controversy/</link><pubDate>Thu, 22 Jun 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230622-red-hat-rhel-source-code-controversy/</guid><description>Red Hat&amp;rsquo;s decision to restrict public access to RHEL source code sends shockwaves through the enterprise Linux ecosystem and raises fundamental questions about open source sustainability.</description></item><item><title>Meta Releases LLaMA — Open-Source AI Just Got Serious</title><link>https://www.osmondvanhemert.nl/posts/230223-meta-llama-open-source-llm/</link><pubDate>Thu, 23 Feb 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230223-meta-llama-open-source-llm/</guid><description>Meta&amp;rsquo;s release of LLaMA, a family of foundation language models available to researchers, could reshape the AI landscape by democratizing access to powerful LLMs.</description></item><item><title>Rust's Enterprise Momentum — From Systems Language to Industry Standard</title><link>https://www.osmondvanhemert.nl/posts/230216-rust-enterprise-adoption-momentum/</link><pubDate>Thu, 16 Feb 2023 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/230216-rust-enterprise-adoption-momentum/</guid><description>With Rust 1.67 freshly shipped and adoption accelerating across major tech companies, the language is crossing the threshold from promising to essential.</description></item><item><title>Mastodon's Moment — The Fediverse Gets Its Stress Test</title><link>https://www.osmondvanhemert.nl/posts/221117-mastodon-fediverse-stress-test/</link><pubDate>Thu, 17 Nov 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221117-mastodon-fediverse-stress-test/</guid><description>As millions flee Twitter for Mastodon, the decentralized social protocol ActivityPub faces its biggest real-world scalability challenge yet.</description></item><item><title>Mastodon's Moment — Can Decentralized Social Scale?</title><link>https://www.osmondvanhemert.nl/posts/221027-mastodon-decentralized-social-scaling/</link><pubDate>Thu, 27 Oct 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221027-mastodon-decentralized-social-scaling/</guid><description>As users flood to Mastodon following the Twitter acquisition, the open-source platform faces its biggest infrastructure test yet.</description></item><item><title>Ubuntu 22.10 Kinetic Kudu — What Matters for Server-Side Developers</title><link>https://www.osmondvanhemert.nl/posts/221020-ubuntu-2210-kinetic-kudu/</link><pubDate>Thu, 20 Oct 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/221020-ubuntu-2210-kinetic-kudu/</guid><description>Ubuntu 22.10 ships with updated toolchains and GNOME 43, but the real story is what it previews for the next LTS cycle.</description></item><item><title>Linux 6.0 Lands — A Milestone That's Less About the Number</title><link>https://www.osmondvanhemert.nl/posts/220929-linux-kernel-6-release/</link><pubDate>Thu, 29 Sep 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220929-linux-kernel-6-release/</guid><description>Linux 6.0 arrives with Rust language support, performance improvements, and new hardware enablement — but the real story is what the version bump signals about the kernel&amp;rsquo;s evolution.</description></item><item><title>Stable Diffusion Goes Open Source — And Changes Everything</title><link>https://www.osmondvanhemert.nl/posts/220908-stable-diffusion-open-source-ai/</link><pubDate>Thu, 08 Sep 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220908-stable-diffusion-open-source-ai/</guid><description>Stability AI&amp;rsquo;s open release of Stable Diffusion marks a watershed moment for generative AI, putting powerful image generation in the hands of every developer.</description></item><item><title>Stable Diffusion Goes Public — Open Source AI Image Generation Changes Everything</title><link>https://www.osmondvanhemert.nl/posts/220825-stable-diffusion-open-source-ai-art/</link><pubDate>Thu, 25 Aug 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220825-stable-diffusion-open-source-ai-art/</guid><description>Stability AI releases Stable Diffusion as open source, putting state-of-the-art image generation in the hands of anyone with a GPU. The implications are enormous.</description></item><item><title>Rust 1.63 Stabilizes Scoped Threads — A Quiet Revolution in Safe Concurrency</title><link>https://www.osmondvanhemert.nl/posts/220811-rust-163-scoped-threads/</link><pubDate>Thu, 11 Aug 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220811-rust-163-scoped-threads/</guid><description>Rust 1.63 brings scoped threads to stable, finally making it ergonomic to share stack references across threads without Arc or cloning.</description></item><item><title>Bun Enters the Ring — A New JavaScript Runtime Challenges Node</title><link>https://www.osmondvanhemert.nl/posts/220728-bun-javascript-runtime-shakes-up-ecosystem/</link><pubDate>Thu, 28 Jul 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220728-bun-javascript-runtime-shakes-up-ecosystem/</guid><description>Bun, a new JavaScript runtime built on JavaScriptCore and written in Zig, is making waves with extraordinary benchmark numbers. Is it the Node.js challenger we&amp;rsquo;ve been waiting for?</description></item><item><title>PyCon US 2022 — Python's Momentum Shows No Signs of Slowing</title><link>https://www.osmondvanhemert.nl/posts/220428-pycon-us-2022-python-momentum/</link><pubDate>Thu, 28 Apr 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220428-pycon-us-2022-python-momentum/</guid><description>PyCon US 2022 kicks off in Salt Lake City with Python riding high as the world&amp;rsquo;s most popular programming language.</description></item><item><title>The node-ipc Protestware Incident — When Open Source Becomes a Weapon</title><link>https://www.osmondvanhemert.nl/posts/220317-node-ipc-protestware-supply-chain/</link><pubDate>Thu, 17 Mar 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220317-node-ipc-protestware-supply-chain/</guid><description>A popular npm package was deliberately sabotaged by its own maintainer, raising urgent questions about supply chain trust in open source.</description></item><item><title>Rust in the Linux Kernel — From Experiment to Inevitability</title><link>https://www.osmondvanhemert.nl/posts/220310-rust-linux-kernel-progress/</link><pubDate>Thu, 10 Mar 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220310-rust-linux-kernel-progress/</guid><description>The Rust for Linux project continues gaining momentum with updated patch series and growing support from kernel maintainers. Memory safety in the kernel is getting real.</description></item><item><title>Alpha-Omega Project — The Linux Foundation Gets Serious About Open Source Security</title><link>https://www.osmondvanhemert.nl/posts/220217-alpha-omega-open-source-security/</link><pubDate>Thu, 17 Feb 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220217-alpha-omega-open-source-security/</guid><description>The Linux Foundation&amp;rsquo;s new Alpha-Omega Project, backed by Google and Microsoft, aims to systematically improve the security of critical open source software.</description></item><item><title>The White House Open Source Summit — When Log4j Gets Political</title><link>https://www.osmondvanhemert.nl/posts/220113-white-house-open-source-security-summit/</link><pubDate>Thu, 13 Jan 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220113-white-house-open-source-security-summit/</guid><description>The White House convened tech leaders to address open source security after Log4Shell. Here&amp;rsquo;s what was discussed and what it means for developers.</description></item><item><title>When a Maintainer Burns It Down — The faker.js and colors.js Incident</title><link>https://www.osmondvanhemert.nl/posts/220106-faker-colors-open-source-sabotage/</link><pubDate>Thu, 06 Jan 2022 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/220106-faker-colors-open-source-sabotage/</guid><description>A single developer deliberately corrupted two widely-used npm packages, exposing the fragility of the open source supply chain.</description></item><item><title>Log4Shell — The Zero-Day That Broke the Internet's Weekend</title><link>https://www.osmondvanhemert.nl/posts/211209-log4shell-zero-day/</link><pubDate>Thu, 09 Dec 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211209-log4shell-zero-day/</guid><description>A critical remote code execution vulnerability in Apache Log4j has sent the entire industry scrambling. Here&amp;rsquo;s what you need to know and do right now.</description></item><item><title>CentOS Stream 9 Lands — The Enterprise Linux Landscape Keeps Shifting</title><link>https://www.osmondvanhemert.nl/posts/211118-centos-stream-9-enterprise-linux-shift/</link><pubDate>Thu, 18 Nov 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211118-centos-stream-9-enterprise-linux-shift/</guid><description>CentOS Stream 9 has arrived as the successor to both CentOS 8 and the traditional CentOS model — and the enterprise Linux community is still adapting.</description></item><item><title>npm Supply Chain Under Siege — The coa and rc Package Compromises</title><link>https://www.osmondvanhemert.nl/posts/211111-npm-coa-rc-supply-chain-attacks/</link><pubDate>Thu, 11 Nov 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211111-npm-coa-rc-supply-chain-attacks/</guid><description>Popular npm packages coa and rc were hijacked to distribute malware, impacting thousands of projects and raising urgent questions about supply chain security.</description></item><item><title>ua-parser-js Compromised — Supply Chain Attacks Hit npm Again</title><link>https://www.osmondvanhemert.nl/posts/211021-ua-parser-js-npm-supply-chain-attack/</link><pubDate>Thu, 21 Oct 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211021-ua-parser-js-npm-supply-chain-attack/</guid><description>The popular ua-parser-js npm package was hijacked to deliver cryptominers and credential stealers, affecting millions of weekly downloads.</description></item><item><title>GitLab Goes Public — What an IPO Means for Open Source Business Models</title><link>https://www.osmondvanhemert.nl/posts/211014-gitlab-ipo-open-source-business/</link><pubDate>Thu, 14 Oct 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/211014-gitlab-ipo-open-source-business/</guid><description>GitLab&amp;rsquo;s successful IPO this week validates the open-core model and raises important questions about the future of open-source developer tooling.</description></item><item><title>GitHub Copilot and the Open Source Licensing Firestorm</title><link>https://www.osmondvanhemert.nl/posts/210812-github-copilot-open-source-debate/</link><pubDate>Thu, 12 Aug 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210812-github-copilot-open-source-debate/</guid><description>GitHub Copilot&amp;rsquo;s AI-powered code suggestions have sparked a fierce debate about open source licensing, training data consent, and the future of code ownership.</description></item><item><title>AlphaFold's Protein Database — When AI Delivers on the Hype</title><link>https://www.osmondvanhemert.nl/posts/210722-alphafold-protein-database-ai-science/</link><pubDate>Thu, 22 Jul 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210722-alphafold-protein-database-ai-science/</guid><description>DeepMind releases 350,000 protein structure predictions as an open database — a rare moment where AI genuinely accelerates scientific progress.</description></item><item><title>GitOps Goes Mainstream — ArgoCD, Flux, and the CNCF Bet</title><link>https://www.osmondvanhemert.nl/posts/210603-gitops-argocd-cncf-incubation/</link><pubDate>Thu, 03 Jun 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210603-gitops-argocd-cncf-incubation/</guid><description>With ArgoCD accepted into CNCF incubation and Flux reaching its own milestones, GitOps is transitioning from buzzword to standard practice for Kubernetes deployments.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210603-gitops-argocd-cncf-incubation/featured.jpg"/></item><item><title>PHP's Git Server Breach — A Supply Chain Wake-Up Call for Open Source</title><link>https://www.osmondvanhemert.nl/posts/210401-php-git-server-compromise/</link><pubDate>Thu, 01 Apr 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210401-php-git-server-compromise/</guid><description>Attackers pushed malicious commits to PHP&amp;rsquo;s official Git repository, exposing the fragile trust model behind open-source supply chains.</description></item><item><title>AWS Forks Elasticsearch — The OpenSearch Announcement and What It Means for Open Source</title><link>https://www.osmondvanhemert.nl/posts/210325-aws-opensearch-elasticsearch-fork/</link><pubDate>Thu, 25 Mar 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210325-aws-opensearch-elasticsearch-fork/</guid><description>Amazon announces OpenSearch, a fork of Elasticsearch, escalating the most consequential open source licensing battle in years.</description></item><item><title>The Rust Foundation Is Here — What It Means for Systems Programming</title><link>https://www.osmondvanhemert.nl/posts/210204-rust-foundation-systems-programming/</link><pubDate>Thu, 04 Feb 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210204-rust-foundation-systems-programming/</guid><description>The newly formed Rust Foundation, backed by AWS, Google, Huawei, Microsoft, and Mozilla, gives Rust the institutional stability it needs for the next phase of growth.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210204-rust-foundation-systems-programming/featured.jpg"/></item><item><title>Signal's Explosive Growth — What WhatsApp's Privacy Blunder Means for Messaging</title><link>https://www.osmondvanhemert.nl/posts/210121-signal-surge-whatsapp-privacy/</link><pubDate>Thu, 21 Jan 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210121-signal-surge-whatsapp-privacy/</guid><description>WhatsApp&amp;rsquo;s updated privacy policy drives millions to Signal, highlighting the growing demand for privacy-respecting open-source alternatives.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210121-signal-surge-whatsapp-privacy/featured.jpg"/></item><item><title>Elasticsearch Changes Its License — The Open Source vs. Cloud Provider Battle Heats Up</title><link>https://www.osmondvanhemert.nl/posts/210114-elasticsearch-license-change/</link><pubDate>Thu, 14 Jan 2021 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/210114-elasticsearch-license-change/</guid><description>Elastic&amp;rsquo;s decision to move Elasticsearch and Kibana from Apache 2.0 to dual SSPL/Elastic License reignites the debate about open source sustainability in the cloud era.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/210114-elasticsearch-license-change/featured.jpg"/></item><item><title>CentOS Is Dead, Long Live CentOS Stream — What Now for Enterprise Linux?</title><link>https://www.osmondvanhemert.nl/posts/201224-centos-stream-shift/</link><pubDate>Thu, 24 Dec 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/201224-centos-stream-shift/</guid><description>Red Hat&amp;rsquo;s decision to shift CentOS from a stable downstream rebuild to a rolling upstream preview has sent shockwaves through the server community.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/201224-centos-stream-shift/featured.jpg"/></item><item><title>Vue.js 3.0 'One Piece' — A Complete Rewrite Worth the Wait</title><link>https://www.osmondvanhemert.nl/posts/200924-vuejs-3-one-piece-rewrite/</link><pubDate>Thu, 24 Sep 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200924-vuejs-3-one-piece-rewrite/</guid><description>Vue.js 3.0 ships after two years of development with a TypeScript rewrite, Composition API, and significant performance improvements.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200924-vuejs-3-one-piece-rewrite/featured.jpg"/></item><item><title>Linux 5.8 — Linus Calls It One of the Biggest Releases Ever</title><link>https://www.osmondvanhemert.nl/posts/200806-linux-kernel-5-8-release/</link><pubDate>Thu, 06 Aug 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200806-linux-kernel-5-8-release/</guid><description>Linux 5.8 lands with a massive changeset. Linus Torvalds himself says it&amp;rsquo;s one of the biggest releases of all time — here&amp;rsquo;s what developers should care about.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200806-linux-kernel-5-8-release/featured.jpg"/></item><item><title>Linux Kernel 5.7 — A Quiet Release with Lasting Impact</title><link>https://www.osmondvanhemert.nl/posts/200604-linux-kernel-57-release/</link><pubDate>Thu, 04 Jun 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200604-linux-kernel-57-release/</guid><description>Linux 5.7 ships with split-lock detection, the new ExFAT driver, userfaultfd improvements, and a thermal management overhaul — a release that matters more than its headlines suggest.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200604-linux-kernel-57-release/featured.jpg"/></item><item><title>GitHub Free for Teams — What This Means for Open Source and Beyond</title><link>https://www.osmondvanhemert.nl/posts/200416-github-free-for-teams/</link><pubDate>Thu, 16 Apr 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200416-github-free-for-teams/</guid><description>GitHub drops pricing barriers for teams, making unlimited private repos and essential collaboration features free for everyone.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200416-github-free-for-teams/featured.jpg"/></item><item><title>GitHub Acquires npm — What This Means for the JavaScript Ecosystem</title><link>https://www.osmondvanhemert.nl/posts/200319-github-acquires-npm/</link><pubDate>Thu, 19 Mar 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200319-github-acquires-npm/</guid><description>GitHub&amp;rsquo;s acquisition of npm consolidates the JavaScript ecosystem&amp;rsquo;s most critical infrastructure under one roof. Here&amp;rsquo;s why that matters — and what could go wrong.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200319-github-acquires-npm/featured.jpg"/></item><item><title>Open Source Rallies — The Tech Community's Response to a Global Pandemic</title><link>https://www.osmondvanhemert.nl/posts/200312-open-source-pandemic-response/</link><pubDate>Thu, 12 Mar 2020 00:00:00 +0000</pubDate><guid>https://www.osmondvanhemert.nl/posts/200312-open-source-pandemic-response/</guid><description>As the WHO declares a pandemic, open source developers worldwide are mobilizing with tracking dashboards, distributed computing, and collaborative tools at unprecedented speed.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://www.osmondvanhemert.nl/posts/200312-open-source-pandemic-response/featured.jpg"/></item></channel></rss>