Edition No. 34 · 28 Sep 2026
Twelve repositories for cloning a voice, watching a database and sending an invoice
One binary that does everything to a PDF, a Postgres dashboard in one command, and seven well-known projects that quietly stopped.
Monday 28 September 2026 · GitHub Radar · a daily review of the best open-source software on GitHub
Twelve repositories, chosen for how good they are and not for what they have in common. There is no theme today, on purpose.
The title comes from something found while checking the alternatives to entry #1. coqui-ai/TTS has 45,998 stars and is the best-known open-source voice-cloning toolkit there is. Its last code landed on 16 August 2024, which is over two years ago. It carries no archived banner, so the page looks alive. Anyone who installs it today gets a project nobody is looking after, and nothing on the page says so.
We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.
Three things worth knowing, separate from the recommendations
Seven finished projects turned up in one morning, and that is a record for this report. They were all found by opening the alternatives to today's twelve, and not one of them carries an archived banner. coqui-ai/TTS at 45,998 stars stopped on 16 August 2024. Hopding/pdf-lib at 8,605 stars stopped on 17 July 2024 and is still the usual recommendation for PDF work in JavaScript. crater-invoice-inc/crater at 8,349 stars stopped on 10 August 2024. Then tnfe/FFCreator (3,159), q2a/question2answer (1,672), docopt/docopts (523) and ko1nksm/getoptions (522). The previous record in this archive was six, on 25 September. A star count is a record of how many people liked a project once, not a statement about whether anyone is still working on it.
A licence badge describes the code and not what the code runs. VoiceStudio's page says AGPL-3.0, and the licence file confirms it exactly. But the project's own README says the default pretrained voice weights are labelled CC-BY-NC, which forbids commercial use. The badge is accurate and the answer to "can I sell this" is still no, because the restriction is in a different artefact. This is a new shape for this archive, which has found custom licences hiding behind a sidebar summary four times. Here the sidebar is right and the model is the problem.
Directus's free tier is a promise, not a clause. The licence file, which lives at a lower-case path where nothing else in this archive keeps it, contains a Competing Use restriction, a prohibition on circumventing the licence key, and an automatic conversion to GPL-3.0 four years after each release. What it does not contain is the five-million-dollar revenue and fifty-employee thresholds that everyone quotes. Those live in the README and on a marketing page. Anyone relying on being under the threshold should get the grant terms in writing.
If you only do three things
- pdfcpu/pdfcpu (#9) — two minutes, one downloaded file, on PDFs that already exist. Merge, split, shrink, stamp, encrypt and read the text out of them, with one command each. It is the standout of the edition.
- bashly-framework/bashly (#5) — twenty minutes. Describe a command-line tool in a short settings file and it writes the shell script, including the help text and the argument checking that nobody enjoys writing.
- ankane/pghero (#7) — half an hour, one command, on a PostgreSQL database that already exists. It shows which queries are slow and which indexes are missing.
Every link in one place
| # | Repository | Website | Stars | Licence |
|---|---|---|---|---|
| 1 | debpalash/VoiceStudio | voicestudio.sh | 42,256 | AGPL-3.0 (model weights CC-BY-NC) |
| 2 | midrender/revideo | midrender.com/revideo | 4,100 | MIT |
| 3 | magnitudedev/magnitude | magnitude.dev | 4,700 | Apache-2.0 |
| 4 | vectorize-io/hindsight | hindsight.vectorize.io | 35,388 | MIT |
| 5 | bashly-framework/bashly 💎 | bashly.dev | 2,454 | MIT |
| 6 | kobaltedev/kobalte 💎 | kobalte.dev | 1,862 | MIT |
| 7 | ankane/pghero | in-repo guides/ | 8,933 | MIT |
| 8 | lldap/lldap | in-repo docs/ | 6,528 | GPL-3.0 |
| 9 | pdfcpu/pdfcpu 🥇 | pdfcpu.io | 8,746 | Apache-2.0 |
| 10 | directus/directus | directus.com | 37,943 | Monospace Sustainable Core 1.0 — not open source |
| 11 | apache/answer | answer.apache.org | 15,700 | Apache-2.0 |
| 12 | SolidInvoice/SolidInvoice 💎 | solidinvoice.co | 972 | MIT |
A voice cloner with 46,000 stars has taken no code since August 2024
Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.
42,256 stars · AGPL-3.0, read from /blob/main/LICENSE on 2026-09-28; the standard unmodified text, with section 13 the material obligation. SEPARATE AND STRICTER: the project's own README says the default OmniVoice pretrained weights are labelled CC-BY-NC, so the model forbids commercial use even though the code does not · v0.5.6 (2026-09-23), read from /releases/latest and confirmed by ungh to the second · Track this in Scout
Voice cloning, voice design, video dubbing, dictation, transcription and audiobook production, all running on the reader's own machine with no upload.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A desktop program and a local server that bundle several speech models behind one screen. It covers voice cloning, voice design, video dubbing, dictation, transcription and long-form audiobook production, and it claims 646 languages.
What it is good for. Anyone who records narration and is paying a per-minute fee to a cloud voice service. It removes the fee and the upload. It also suits people who cannot send recordings to a third party at all, because the audio never leaves the machine. Anyone recording in a language a cloud service handles badly may get a better result here, because the model can be swapped.
- No account, no key and no per-minute bill. The cost is electricity and the machine.
- One screen covers cloning, dubbing, dictation and audiobook output, so there is no chain of four separate tools to wire together.
- Analytics is off by default, and when it is switched on the project states it sends no text, no audio, no filenames and no voices.
- The licence on the code and the licence on the voice are different, and the second one is stricter. The code is AGPL-3.0, read from the LICENSE file. But the project's own README says the default pretrained weights are labelled CC-BY-NC, which means no commercial use. Selling anything made with the default voice means finding other weights first.
- It wants real hardware. The project asks for 8 GB of memory as a minimum and recommends 16 GB or more, plus 10 GB of free disk as a minimum and 20 GB on an SSD as the recommendation. A graphics card is optional, with 4 GB of video memory as the floor and 8 GB recommended.
- Narrow platform support. On macOS the local part runs on Apple Silicon only, and Linux needs glibc 2.39 or newer, which rules out older systems. The version is 0.5.6, so it is well before 1.0.
- coqui-ai/TTS
45,998 stars, the best-known toolkit for the same job, and its last code landed on 16 August 2024, over two years ago, with no archived banner to warn anyone.
Track this in Scout - fishaudio/fish-speech
32,725 stars, code on 16 September 2026; a strong speech model with voice cloning, but no dubbing, dictation or audiobook workflow around it.
Track this in Scout - myshell-ai/OpenVoice
36,911 stars, last code 19 April 2025; a cloning model on its own, with no screen and no pipeline, and quiet for about seventeen months.
Track this in Scout
# the project's own installer, macOS or Linux curl -fsSL https://voicestudio.sh/install | sh # or Docker (a way to run a program inside its own sealed box, # so it cannot break anything else on the machine) docker run -d -p 127.0.0.1:3900:3900 \ -v omnivoice-data:/app/omnivoice_data \ --name voicestudio palashdeb/omnivoice-studio:stable
4k stars · MIT · no releases at all · Track this in Scout
Create videos programmatically in TypeScript — the living successor to the dormant Motion Canvas.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A rendering engine that turns animation code into video files. It ships a headless renderer for running on a server, a browser preview player, and parallel rendering so one job can be split across workers.
What it is good for. Anyone producing many near-identical videos. Personalised clips, a weekly chart that has to be redrawn from new numbers, product videos generated per item. Doing that by hand in an editor is the work; doing it from code means changing one value and rendering again.
- MIT licensed, with no key, no watermark and nothing withheld for a paid edition.
- Built for headless rendering on a server, which is what makes generating videos in bulk practical.
- One command sets up a starting project, and the browser preview means there is something to look at while writing.
- It has never published a single release. Not one tag, ever, confirmed on the releases page and by a second source. That means no changelogs and no release notes, so working out what changed between versions means reading commits. The npm package
@revideo/coreis at 0.11.0, and that is the version to trust. - It has gone quiet. The last code landed on 15 July 2026, about two and a half months ago, and its ancestor project went quiet within two weeks of it. Meanwhile remotion-dev/remotion, which does the same job with 60,366 stars, pushed code three days ago.
- No memory or disk figures are published anywhere. Rendering video through a headless browser is memory-hungry, and the parallel rendering feature multiplies that, so anyone sizing a machine for it is guessing.
remotion-dev/remotion60,366 stars, code on 25 September 2026; the same idea using React components, far larger and far busier, and its licence is not free for companies.
Track this in Scout- motion-canvas/motion-canvas
19,182 stars, last code 2 July 2026; the project Revideo was forked from, built around an interactive editor for hand-tuning rather than server-side batch rendering.
Track this in Scout - tnfe/FFCreator
3,159 stars, and its last code landed on 19 December 2024, about twenty-one months ago; a Node.js video generator driven by ffmpeg rather than a browser.
Track this in Scout
# needs Node.js and a terminal npm init @revideo@latest
~4,700 stars · Apache-2.0, read from /blob/main/LICENSE on 2026-09-28; standard unmodified text, copyright "2026 Magnitude AI Inc.", and the sidebar agrees · @magnitudedev/cli@0.1.5 (2026-09-23), read from /releases/latest and confirmed by ungh; npm's latest dist-tag still serves the DEPRECATED 0.0.15 · Track this in Scout
It measures the machine it is installed on, recommends a local AI model that will run well there, then downloads, tunes and serves it.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A local inference server plus a desktop application. The unusual part is the profiling step: rather than asking which model you want, it measures the hardware first and recommends from there. It runs on Apple Silicon, NVIDIA, AMD or a plain processor, and other programs talk to it over a local connection.
What it is good for. Anyone who has tried to run an AI model locally and given up because the choice of model, size and settings is a maze. It also suits anyone whose per-request bill at a cloud provider has grown uncomfortable, and anyone who cannot send text to a third party at all.
- No API key (a password that lets one program use another over the internet), no rate limit and no per-request cost.
- The hardware-profiling step is genuinely useful and nothing else in this category does it.
- Apache-2.0, read from the LICENSE file and completely plain, with no branding clause and no paid tier.
- The same repository has been three different products, and the install command in its README currently fetches the wrong one. The npm package
magnitude-testdescribes a browser-testing client. The package@magnitudedev/cliat version 0.0.15 describes an AI coding agent and is marked deprecated, with a notice saying the project has moved to a desktop application. The current README describes neither. Anyone running the README'snpm i -g @magnitudedev/clitoday installs the deprecated 0.0.15, not the 0.1.5 that GitHub lists as newest. - It is very new. The whole 0.1.x line began on 17 September 2026, eleven days before this was written, and the first release that day was an alpha.
- No hardware requirements are published at all. The project says plainly that there is no fixed minimum because it profiles the machine. That is a reasonable design choice, but it means there is no number to check before starting, and the models themselves are multi-gigabyte downloads with their own separate licences.
- ollama/ollama
181,752 stars, code on 25 September 2026; overwhelmingly the standard way to run local models, and it does not profile the machine or recommend a model, so you choose the size yourself.
Track this in Scout - janhq/jan
44,308 stars, code on 3 September 2026; a fully offline desktop application that leads with a chat window rather than a server for other programs to use.
Track this in Scout
mozilla-ai/llamafile25,611 stars, code on 16 August 2026, covered in Edition 26; it ships the model and the runtime as one downloadable file, with no catalogue and no tuning step.
Track this in Scout
npm i -g @magnitudedev/cli magnitude setup # then confirm you did not get 0.0.15
35,388 stars · MIT, read from /blob/main/LICENSE on 2026-09-28; standard unmodified text, copyright "2025 Vectorize AI, Inc.". THE PROJECT'S OWN CHANNELS DISAGREE: the repository and the npm package say MIT, the PyPI page for hindsight-api says Apache 2.0 · v0.10.1 (2026-09-21), read from /releases/latest and confirmed by both ungh and PyPI; only two releases exist in total · Track this in Scout
A memory store for AI agents that keeps what mattered from past sessions and hands the useful parts back, rather than replaying a whole conversation history.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A server plus client libraries for Python and JavaScript that give an agent long-term memory. It stores memories in PostgreSQL with the pgvector extension and uses a language model to decide what is worth keeping and what to hand back.
What it is good for. Anyone building an assistant that people use more than once. A support assistant that remembers a customer's setup, a coding assistant that remembers the house rules, a personal agent that stops asking the same three questions. It is developer infrastructure, so it is for people writing the application rather than using one.
- MIT, read from the LICENSE file, with no restrictions at all — unusual in a category where most projects are commercially backed.
- It works with more than twenty-five model providers, so nothing is locked to one vendor.
- PostgreSQL rather than a special database, which means backups and monitoring you may already know how to do.
- It has an unavoidable running bill. Every memory written and every recall calls a language model and an embedding model, so the cost grows with how much the agents remember and re-read. No pricing guidance is published for people running it themselves.
- Only two releases exist — v0.10.0 on 14 September 2026 and v0.10.1 on 21 September 2026 — and the newest tag is already 140 commits behind the main branch. Pinning a release means running well behind the code the maintainers are testing. The JavaScript client is at 0.8.4, two minor versions behind the server.
- Its own publishing channels disagree about the licence: the repository and the npm package say MIT while the PyPI page says Apache 2.0. Both are permissive, so the practical risk is small, but it is a contradiction in the project's own metadata.
mem0ai/mem065,967 stars, code on 25 September 2026, covered in Edition 28; the leader in this category, with a paid hosted service alongside it, and a more general store rather than one built around learning from experience.
Track this in Scout- getzep/graphiti
31,139 stars, code on 24 September 2026; stores memory as a knowledge graph in a graph database rather than in PostgreSQL, which suits questions about how things relate.
Track this in Scout - letta-ai/letta
24,870 stars, code on 10 September 2026; a whole platform for building agents inside, rather than a memory component added to an agent that already exists.
Track this in Scout
# Python pip install hindsight-all -U # JavaScript npm install @vectorize-io/hindsight-client
2,454 stars · MIT, read from /blob/master/LICENSE on 2026-09-28 after /blob/main/LICENSE returned 404; plain, copyright "(c) Danny Ben Shitrit" · v2.0.0 (2026-09-27), read from /releases/latest, confirmed by ungh and by the rubygems API, which records the gem as created 2026-09-27T09:37:33 UTC, seven minutes before the GitHub release · Track this in Scout
Describe a command-line tool's commands, arguments and flags in one YAML file and it generates a standalone shell script with the parsing, validation and help text written.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A generator. You write a YAML file naming the commands, arguments and flags, run one command, and it emits a standalone shell script with the parsing, validation and help text already written. Your own logic lives in separate per-command files that the generator leaves alone.
What it is good for. Anyone whose useful scripts have become embarrassing. The moment a script needs two subcommands and a --dry-run flag, hand-written argument parsing turns into a wall of case statements nobody wants to touch. This removes that wall and keeps the result a plain shell script, so it still runs anywhere with no runtime to install.
- The output is one ordinary shell script. There is nothing to install on the machine that runs it, which is the whole reason for choosing shell in the first place.
- It ships a standard library: coloured output, settings files, YAML reading and shell completions, so those are not written by hand either.
- It is tightly kept. One open issue, and version 2.0.0 landed on 27 September 2026, the day before this edition.
- Version 2.0.0 is one day old. It is the least-tested release in the project's history, and it is a major version, so anyone on the 1.x line faces a migration. Its notes include swapping out a dependency and reworking completions.
- It needs Ruby 3.3 or newer to run the generator, which is an odd dependency for a shell tool and a real obstacle on older systems. The Docker route avoids that.
- The generated scripts need bash 4.2 or newer. That excludes the bash that ships with macOS by default, so macOS users install a newer bash first.
- matejak/argbash
1,487 stars, last code 17 July 2025; generates only the argument-parsing block, with no subcommand framework, no standard library and no completions.
Track this in Scout - ko1nksm/getoptions
522 stars, and its last code landed on 18 November 2024, about twenty-two months ago; a runtime library rather than a generator, and it works on shells other than bash.
Track this in Scout - docopt/docopts
523 stars, and its last code landed on 2 July 2024, about twenty-six months ago; it derives the parsing from the help text you write, which is the opposite direction, and does nothing else.
Track this in Scout
# as a Ruby gem gem install bashly # or with Homebrew brew install bashly # or with Docker, which avoids installing Ruby alias bashly='docker run --rm -it --user $(id -u):$(id -g) \ --volume "$PWD:/app" dannyben/bashly'
1,862 stars · MIT, read from /blob/main/LICENSE.md on 2026-09-28 after /blob/main/LICENSE returned 404; plain, copyright "(c) 2024 jer3m01" · @kobalte/core@0.13.14 (2026-09-07), read from /releases/latest and confirmed by ungh and the npm registry; the npm alpha dist-tag serves 2.0.0-alpha.2 of the same day · Track this in Scout
Unstyled, accessible component primitives for SolidJS, with keyboard handling, focus management and ARIA wiring done and no visual styling at all.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A set of component primitives for SolidJS. Keyboard handling, focus management and the accessibility attributes screen readers depend on are all done. The visual styling is deliberately absent, so nothing appears until you write the CSS.
What it is good for. Anyone building a design system on SolidJS. The accessibility work in a dialog or a combo box takes days to get right and is easy to get subtly wrong, and this is the part it hands over. SolidJS has few credible options here, so the choice is narrow and this is the largest of them.
- It is officially sponsored by SolidJS, which for a framework with a small ecosystem is a meaningful signal about where it sits.
- Unstyled by design, so it imposes no look and fits into an existing design system rather than fighting it.
- MIT, read from the LICENSE.md file, plain, with no paid tier.
- A version 2.0 rewrite is already publishing alpha builds, and there is no migration guide. The stable line is 0.13.14; the alpha is 2.0.0-alpha.2, released the same day. The 2.0 line tracks SolidJS 2, which is itself an alpha, so adopting it means depending on two unfinished things at once. Staying on 0.13 means a migration later.
- It is still before version 1.0 after nearly four years, and stable releases are lumpy. Between July 2025 and August 2026 there was nothing at all.
- 110 open issues and 16 open pull requests for a project of this size is a wide queue, so expect slow review. And unstyled means nothing is visible until you have written the entire CSS layer yourself, which is real work.
- corvudev/corvu
721 stars, code on 24 August 2026; the same idea for SolidJS, much smaller, and pitched at lower-level building blocks rather than a full component set.
Track this in Scout - chakra-ui/ark
5,312 stars, code on 1 August 2026; unstyled accessible components for React, Vue, Solid and Svelte at once, so SolidJS is one target among four rather than the only one.
Track this in Scout - radix-ui/primitives
19,198 stars, code on 8 August 2026; the reference library in this category and Kobalte's stated inspiration, but React only, so it is not a substitute in a SolidJS project.
Track this in Scout
npm i @kobalte/core
8,933 stars · MIT, read from /blob/master/LICENSE.txt on 2026-09-28 after both /blob/main/LICENSE and /blob/master/LICENSE failed; plain, copyright "(c) 2014-2026 Andrew Kane, 2008-2014 Heroku (initial queries)" · no GitHub releases at all - a determination, not a gap, confirmed on /releases/latest and by ungh; the gem pghero 4.0.1 (2026-08-15) is the version to trust, matching CHANGELOG.md and rubygems exactly · Track this in Scout
A web dashboard for PostgreSQL that names the slow queries, the missing indexes, the unused ones, table sizes, connections and locks.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A performance dashboard for PostgreSQL. It reads the database's own statistics and presents slow queries, index suggestions, table sizes, connections, locks and unused indexes on one page. It runs either as a standalone container or mounted inside a Ruby on Rails application.
What it is good for. Anyone running PostgreSQL without a monitoring bill. The usual alternative is paying a hosted service or reading log files by hand. This sits between those: one container, a read-only database user, and a page that answers "why is it slow" in about a minute. It has been in production at Instacart for years, so it is not a weekend project.
- One command and a database address gives a working dashboard on port 8080. Nothing to build, nothing to compile.
- Suggested indexes, not just slow queries. It names the index to create, which is the part that usually takes expertise.
- Mature and well tended. Version 4.0.1, released 15 August 2026, nearly twenty million downloads of the package, and only three open issues.
- It has no password by default. The project's own guide says to secure the dashboard in production. Anyone who opens port 8080 on a public machine has published the shape of their database and its slowest queries. Set
PGHERO_USERNAMEandPGHERO_PASSWORD, or put something in front of it. - The most useful part needs a database restart. Query statistics come from the
pg_stat_statementsextension, which means editingpostgresql.conf, restarting PostgreSQL, and runningCREATE EXTENSIONas a superuser. On a managed database you do not control, that may not be possible at all. - Version 4.0 dropped several things: PostgreSQL below 14, and also the Linux distribution packages, so that installation route no longer exists. It is Docker or the Ruby package now. There are also no GitHub releases at all, so there is no release feed to follow — the changelog file and the package registry are where the news is.
darold/pgbadger4,065 stars, code on 15 September 2026, covered in Edition 18; it reads PostgreSQL log files and writes one static report, so it needs no connection and no extension, but it is not a live dashboard.
Track this in Scout
cybertec-postgresql/pgwatch866 stars, code on 27 August 2026, covered in Edition 26; a full monitoring stack with a collector, a time-series store and Grafana, built for many servers, so far more moving parts.
Track this in Scout- powa-team/powa-web
84 stars, code on 26 September 2026; only the web half of the PoWA project, so it also requires installing the powa extension in the database itself.
Track this in Scout
docker run -ti \ -e DATABASE_URL=postgres://user:password@hostname:5432/dbname \ -e PGHERO_USERNAME=admin -e PGHERO_PASSWORD=choose-something-long \ -p 8080:8080 ankane/pghero
6,528 stars · GPL-3.0, read from /blob/main/LICENSE on 2026-09-28; the complete unmodified GPLv3 text, no added restriction and no enterprise carve-out · v0.6.3 (2026-04-30), read from /releases/latest and confirmed by ungh; the release's own changelog heading says 2026-05-01, one day ahead of the tag · Track this in Scout
A deliberately simplified LDAP authentication server with a web page for users and groups, so several self-hosted programs can share one account list.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A deliberately simplified authentication server that speaks LDAP, the old protocol most self-hosted software understands for external logins. It stores users and groups in SQLite by default, and it ships a web page for managing them so there is no configuration file to hand-edit.
What it is good for. Anyone running several self-hosted services who has one password list per service. The usual answer is OpenLDAP, which is powerful and famously unpleasant to configure. This covers the narrow job — be the list of people that other programs check — and does nothing else. Its repository ships example settings for a range of programs, which is the part that usually costs an afternoon.
- Genuinely tiny. The project's own documentation quotes both "under 10 MB of memory including the database" and "about 15 MiB on startup", against a full OpenLDAP install.
- A web page for users and groups, so no LDIF files and no
slapdconfiguration. - GPL-3.0, read from the LICENSE file and completely unmodified. No paid edition, no feature held back.
- It is not a full LDAP server, and the project says so first. Browsing tools are generally unsupported, some programs need attributes it does not implement, and it will never hand out password hashes, because its password scheme is built not to have them. The project names one program as definitely incompatible: Synology.
- Releases are rare. Roughly one every eight to twelve months, and v0.6.3 from 30 April 2026 contained a fix for a crash that a specially crafted query could trigger. Anyone running it exposed waits a long time between tagged builds, even though the code itself is active.
- Still before 1.0 after five and a half years, with 97 open issues and 33 open pull requests. And the real ongoing work is not this program — it is writing LDAP settings into each program that uses it, one at a time.
- glauth/glauth
2,852 stars, code on 27 September 2026; a small LDAP server in Go that its own README scopes at development, home use and CI, and it has no first-class web page for managing users.
Track this in Scout - goauthentik/authentik
25,733 stars, code on 26 September 2026; a complete identity provider with SAML, OIDC, login flows and multi-factor, which can also serve LDAP, so far more capable and far heavier.
Track this in Scout - osixia/container-openldap
4,230 stars, code on 31 July 2026, renamed from osixia/docker-openldap; real OpenLDAP packaged as an image, so the full feature set and the full configuration burden, with no user-management page included.
Track this in Scout
It ships as a container image for Docker or Podman, and also as packages for Arch, Debian, CentOS, Fedora, openSUSE, Ubuntu and FreeBSD, plus a Kubernetes chart and a TrueNAS SCALE app.
8,746 stars · Apache-2.0, read from /blob/master/LICENSE.txt on 2026-09-28 after both /blob/main/LICENSE and /blob/master/LICENSE returned 404; the standard text, but the copyright line is the unfilled appendix template, "Copyright [yyyy] [name of copyright owner]" · v0.15.0 (2026-08-11), read from /releases/latest and confirmed by ungh to the second; v0.16.0-rc.1 of 2026-09-20 is newer but is a release candidate, which is why /releases/latest correctly serves the stable · Track this in Scout
One downloaded program that validates, merges, splits, shrinks, encrypts, signs, stamps and extracts text and images from PDFs, up to PDF 2.0.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A PDF toolkit, available both as a command-line program and as a Go library. It validates, optimises, encrypts, signs, merges, splits, extracts images and text, adds watermarks and stamps, rearranges pages and fills forms, up to PDF 2.0.
What it is good for. Anyone who handles PDFs regularly and has been uploading them to a website to do it. Contracts, scans, invoices and reports are exactly the documents nobody should be uploading to a free converter. It is also the right answer for doing the same job to two hundred files, because a command in a loop costs nothing and a web form costs an afternoon.
- One static file with no dependencies, installable through Homebrew, MacPorts or Fedora's package manager, or just downloaded. Upgrading means replacing the file.
- Apache-2.0, read from the licence file, with no restriction on commercial or hosted use.
- Nine years old and still shipping. Version 0.15.0 came eight days after 0.14.0 to fix what that release turned up, which is the behaviour of a maintainer who is paying attention.
- Everything is flags on a command line and there is no visual interface. The README is a signpost, so the real instructions live on the project's website, and nobody will be productive from the repository alone.
- It has been on version 0.x for nine years, and the Go library interface is still being reshaped — the current release candidate describes an updated API with a new configuration design. The command line is far more stable than the library.
- No memory or disk figures are published. Whole-file processing in memory is normal for this kind of tool, so very large scanned PDFs are the risk. The project added a progress flag for long batch runs, which suggests big collections take real time.
- qpdf/qpdf
5,346 stars, code on 22 August 2026; structural PDF surgery from a command line, deliberately content-preserving, so it does not stamp text or lay out new content, and it is the engine underneath several other tools.
Track this in Scout - py-pdf/pypdf
10,168 stars, code on 21 August 2026; the same page-level work as a pure Python library, so it is for embedding in Python code and has no command-line tool, and it is slower on large files.
Track this in Scout - Hopding/pdf-lib
8,605 stars, and its last code landed on 17 July 2024, about twenty-six months ago, despite still being the usual recommendation for PDF work in JavaScript.
Track this in Scout
# macOS brew install pdfcpu # Fedora sudo dnf install golang-github-pdfcpu # or with a Go toolchain go install github.com/pdfcpu/pdfcpu/cmd/pdfcpu@latest # then check it pdfcpu version pdfcpu merge merged.pdf in1.pdf in2.pdf
37,943 stars · Monospace Sustainable Core License 1.0 (SPDX MSCL-1.0-GPL), derived from the Fair Core License - NOT open source. Read from /blob/main/license on 2026-09-28; the path is LOWER CASE and all five conventional upper-case paths returned 404 · v12.4.1 (2026-09-23), read from /releases/latest; ungh was behind with v12.3.0 of 2026-08-18 · Track this in Scout
Wraps an existing SQL database with generated REST and GraphQL interfaces and an editing application, with permissions down to the individual field.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A backend layer over a database that already exists. It generates REST and GraphQL interfaces from the existing tables and provides an editing application, with field-level permissions, extensions and support for PostgreSQL, MySQL, MariaDB, SQL Server and SQLite. It has existed since 2012 and is at major version 12.
What it is good for. Anyone with a database and no admin screen. Building that screen by hand is weeks of work that produces nothing a customer ever sees. It also suits a team where a non-programmer needs to edit content that a website reads, without being given database access.
- It wraps the database you have rather than owning its own schema, which means it can be added to an existing system instead of replacing it.
- Field-level permissions, so an editor can be given one column and not the table.
- Very actively developed. Version 12.4.1 on 23 September 2026, with code the day before.
- It is not open source, the licence file is not where you would look for it, and the rule that makes it free is not in the licence at all. The licence lives at the lower-case path
/blob/main/license; every conventional upper-case path returns "not found". It is the Monospace Sustainable Core License 1.0, derived from the Fair Core License. Its Competing Use clause forbids making the software available to anyone who competes with the licensor's paid offering of it, and its Limitations clause says you "must not move, change, disable or circumvent the license key functionality". But the widely repeated thresholds — free under five million dollars of annual revenue and fifty employees — appear only in the README and on the project's website, as an "Open Innovation Grant", not in the licence text. A promise in a README is a weaker instrument than a clause in a licence. - The one genuine comfort is also in the licence: each release converts to GPL-3.0 four years after it first became available, irrevocably. Old versions do eventually become free software. Current ones are not.
- No install commands and no requirements at all appear in the README. It offers a one-click deploy to a paid third-party host and otherwise points at its documentation site. No memory, disk, database version or Node version figures are published in the repository, so anyone sizing a machine is guessing. The 12.x line also ships breaking changes between minor versions.
- strapi/strapi
72,825 stars, code on 7 August 2026; the same headless content platform idea, but it creates and owns its own database structure rather than wrapping an existing one.
Track this in Scout - nocodb/nocodb
65,101 stars, code on 28 September 2026; also turns an existing SQL database into something usable, but presents it as a spreadsheet grid and aims at internal tools rather than powering websites.
Track this in Scout - hasura/graphql-engine
32,110 stars, code on 19 August 2026; points at an existing database and generates an interface with fine-grained permissions, but it is interface-only with no editing screen for non-technical people.
Track this in Scout
The repository documents only a one-click deploy to a hosted platform.
15.7k stars · Apache-2.0 · v2.0.2 (2026-07-21) · Track this in Scout
Apache's Q&A platform — user questions become indexable pages, which is user-generated SEO.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A question-and-answer platform with voting and accepted answers, written in Go with a React interface. It is a project of the Apache Software Foundation, and it is aimed equally at a public community forum, a product help centre and internal knowledge management.
What it is good for. Anyone answering the same questions repeatedly in private. A support inbox loses every answer the moment the thread closes; a question-and-answer site keeps them and lets search find them. It also suits a team whose knowledge lives in chat history, which is the worst possible place to keep it.
- Apache-2.0, read from the LICENSE file and completely plain, with no paid edition and no feature held back.
- Under the Apache Software Foundation, which means governance that does not depend on one company's plans.
- One command gets a working instance on port 9080, with the data in a named volume so it survives a restart.
- An empty question-and-answer site is worse than none, because the emptiness is the first thing a visitor sees. This is premature until there are enough people asking to keep it looking alive, and that is an editorial judgement rather than a fault in the software.
- The README on the main branch tells you to pull image tag 2.0.3, and there is no stable 2.0.3 release — the newest stable is v2.0.2 from 21 July 2026, with a 2.0.3 release candidate on 23 September. Use the 2.0.2 tag until a stable 2.0.3 exists.
- No memory, processor or disk figures appear anywhere in the repository, so sizing a machine is guesswork. And a public site means moderation, which is ongoing human work that no software removes. Building from source needs Go 1.25, Node.js 20 and pnpm 9.
- discourse/discourse
47,918 stars, code on 28 September 2026; the best-known self-hosted community platform, but a threaded forum first, without accepted answers and voting as the main structure, and much heavier to run.
Track this in Scout - NodeBB/NodeBB
15,161 stars, code on 25 July 2026; a real-time forum in Node.js with a large plugin collection, again thread-shaped rather than question-shaped.
Track this in Scout - q2a/question2answer
1,672 stars, the closest match in shape, and its last code landed on 20 August 2024, over two years ago.
Track this in Scout
docker run -d -p 9080:80 -v answer-data:/data \ --name answer apache/answer:2.0.2
972 stars · MIT, read from /blob/master/LICENSE on 2026-09-28 after /blob/main/LICENSE returned 404; plain, copyright "(c) 2014 Pierre du Plessis", with no branding requirement and no paid-module carve-out · 3.0.1 (2026-06-23), read from /releases/latest and confirmed by ungh; Packagist is TWO MAJOR VERSIONS BEHIND at 2.2.6, last updated 2024-05-06 · Track this in Scout
Self-hosted quoting and invoicing with recurring billing, multiple currencies and taxes, PDF templates, overdue detection and card payment through Stripe and PayPal.
▶Repo detailsthe review · specs · pros & cons · install
What it is
An invoicing application built on Symfony and PHP. It covers clients, quotes, invoices, recurring billing on a schedule, multiple currencies and taxes, eight PDF templates, automatic overdue detection, two-factor login, and online payment through Stripe and PayPal. It also exposes an interface for other programs to use.
What it is good for. A freelancer or a small team currently invoicing from a spreadsheet and a word processor. The value is not the PDF — it is that quotes become invoices without retyping, recurring clients bill themselves, and overdue ones are flagged without anyone remembering to look. Hosted services do this for a monthly fee and hold the client list.
- MIT, read from the LICENSE file, with no conditions at all. That is the exception in this category: the two best-known alternatives are either source-available or keep useful features behind paid modules.
- Quotes convert to invoices, and recurring billing runs on a schedule, which is the part that actually saves time.
- A modern stack for a fourteen-year-old codebase — Symfony 7.1 and PHP 8.4 — and card payment through Stripe and PayPal is built in rather than bolted on.
- The obvious installation route gives an outdated version. The PHP package registry still lists 2.2.6 from 6 May 2024, two major versions behind the 3.0.1 released on 23 June 2026. Installing with Composer lands you on a two-year-old release. Use the container image, the Homebrew tap, or a tagged release.
- The 3.0 line is new and it rebuilt the tax system. Version 3.0.0 arrived in June 2026 with a tax overhaul covering multiple taxes, invoice-level tax and frozen snapshots. On software that produces the documents you bill clients with, test the tax figures and the PDF output against invoices you have already sent before trusting it.
- 129 open issues and 52 open pull requests against about 970 stars is a very wide queue, and releases come from one author, so expect slow review. A real installation also needs an external database, a certificate, a mail service for sending invoices, and PHP kept patched. From source it needs PHP 8.4 with seven extensions.
- invoiceninja/invoiceninja
10,106 stars, code on 22 September 2026; far more complete, including time tracking and a client portal, but its own description calls it source-available rather than open source, which restricts redistribution.
Track this in Scout - akaunting/akaunting
10,125 stars, code on 17 September 2026; a full double-entry accounting suite rather than an invoicing tool, and much of the useful functionality sits behind paid modules in its own store.
Track this in Scout - InvoicePlane/InvoicePlane
3,142 stars, code on 21 September 2026; the same self-hosted invoicing job on an older PHP base, which makes it easier to put on cheap shared hosting and harder to extend.
Track this in Scout
# the quickest look docker run -p 8080:80 solidinvoice/solidinvoice # or with Homebrew brew install solidworx/tap/solidinvoice solidinvoice run
Checked, and left out
These were opened for this edition and did not make it, with the reason.
apify/crawlee - already-published, Edition 25 number 3, on 19 September, nine days before this edition. This was request id 31. Nothing has happened since that edition that earns a repeat, so it is reported as used rather than repeated.
apify/crawlee - already-published, Edition 25 number 3, on 19 September, nine days before this edition. This was request id 31. Nothing has happened since that edition that earns a repeat, so it is reported as used rather than repeated.
coqui-ai/TTS - not-qualified. 45,998 stars, last code 16 August 2024, twenty-five months, and no archived banner, so the page reads as alive. The best-known open-source voice-cloning toolkit there is, found in the comparison list under entry 1, and it is the Edition 34 title. The largest finished project this archive has ever added.
coqui-ai/TTS - not-qualified. 45,998 stars, last code 16 August 2024, twenty-five months, and no archived banner, so the page reads as alive. The best-known open-source voice-cloning toolkit there is, found in the comparison list under entry 1, and it is the Edition 34 title. The largest finished project this archive has ever added.
Hopding/pdf-lib - not-qualified. 8,605 stars, last code 17 July 2024, twenty-six months, no archived banner, and still the default recommendation for PDF work in JavaScript. Found in the comparison list under entry 9.
Hopding/pdf-lib - not-qualified. 8,605 stars, last code 17 July 2024, twenty-six months, no archived banner, and still the default recommendation for PDF work in JavaScript. Found in the comparison list under entry 9.
crater-invoice-inc/crater - not-qualified. 8,349 stars, last code 10 August 2024, twenty-five months, no archived banner. Also a rename, from bytefury/crater. The most-starred project in the invoicing niche and effectively abandoned; InvoiceShelf is the community fork that took it over.
crater-invoice-inc/crater - not-qualified. 8,349 stars, last code 10 August 2024, twenty-five months, no archived banner. Also a rename, from bytefury/crater. The most-starred project in the invoicing niche and effectively abandoned; InvoiceShelf is the community fork that took it over.
tnfe/FFCreator - not-qualified. 3,159 stars, last code 19 December 2024, twenty-one months. Found in the comparison list under entry 2.
tnfe/FFCreator - not-qualified. 3,159 stars, last code 19 December 2024, twenty-one months. Found in the comparison list under entry 2.
q2a/question2answer - not-qualified. 1,672 stars, last code 20 August 2024, twenty-five months. The closest direct match in shape to entry 11.
q2a/question2answer - not-qualified. 1,672 stars, last code 20 August 2024, twenty-five months. The closest direct match in shape to entry 11.
docopt/docopts - not-qualified. 523 stars, last code 2 July 2024, twenty-six months. Found in the comparison list under entry 5.
docopt/docopts - not-qualified. 523 stars, last code 2 July 2024, twenty-six months. Found in the comparison list under entry 5.
ko1nksm/getoptions - not-qualified. 522 stars, last code 18 November 2024, twenty-two months. Found in the comparison list under entry 5; with docopts, two of bashly's three named alternatives are finished.
ko1nksm/getoptions - not-qualified. 522 stars, last code 18 November 2024, twenty-two months. Found in the comparison list under entry 5; with docopts, two of bashly's three named alternatives are finished.
dathere/qsv - queued. 3,798 stars, code 28 September 2026, the day of the run. Passed over for the-workshop only because it is above the 3,000-star gem line and bashly took the slot.
dathere/qsv - queued. 3,798 stars, code 28 September 2026, the day of the run. Passed over for the-workshop only because it is above the 3,000-star gem line and bashly took the slot.
ananthakumaran/paisa - queued. 3,217 stars, code 6 September 2026. Note that paisa-money/paisa returns 404 and ananthakumaran/paisa is the correct owner.
ananthakumaran/paisa - queued. 3,217 stars, code 6 September 2026. Note that paisa-money/paisa returns 404 and ananthakumaran/paisa is the correct owner.
veeso/termscp - queued. 3,105 stars, code 16 September 2026. Just above the gem line.
veeso/termscp - queued. 3,105 stars, code 16 September 2026. Just above the gem line.
ellite/Wallos - queued. 8,545 stars, code 18 September 2026. Held back from the money slot because it tracks personal subscriptions rather than running billing.
ellite/Wallos - queued. 8,545 stars, code 18 September 2026. Held back from the money slot because it tracks personal subscriptions rather than running billing.
pikepdf/pikepdf - queued. 2,774 stars, code 31 July 2026. A genuine gem candidate held back because it is a Python binding over QPDF with nothing a reader can run on its own.
pikepdf/pikepdf - queued. 2,774 stars, code 31 July 2026. A genuine gem candidate held back because it is a Python binding over QPDF with nothing a reader can run on its own.
moneymanagerex/moneymanagerex - queued. 2,236 stars, code 25 July 2026. Household budgeting rather than the money work a small team runs a business on.
moneymanagerex/moneymanagerex - queued. 2,236 stars, code 25 July 2026. Household budgeting rather than the money work a small team runs a business on.
coder/agentapi - queued, unchanged from 27 September. 1,500 stars, code 13 September 2026, and its newest release v0.12.2 of 27 May 2026 is still four months behind the code.
coder/agentapi - queued, unchanged from 27 September. 1,500 stars, code 13 September 2026, and its newest release v0.12.2 of 27 May 2026 is still four months behind the code.
awesome-selfhosted/awesome-selfhosted - request id 35, left pending. It was fourth in a queue of five and three requests per edition is the maximum, so it returns tomorrow.
awesome-selfhosted/awesome-selfhosted - request id 35, left pending. It was fourth in a queue of five and three requests per edition is the maximum, so it returns tomorrow.
Coming tomorrow































