Edition No. 36 · 30 Sep 2026

Twelve repositories for moving files, checking code and watching your own machines

A tool with 38,600 stars has taken no new code for twenty-one months, and nothing on its page says so.

By Genn·12 repositories·15 min read

Wednesday 30 September 2026 · GitHub Radar · a daily review of the best open-source software on GitHub

Twelve repositories, opened and checked this morning. There is no theme. The spread is deliberate, the quality bar is not.

The title came out of a comparison list, not out of a search. While checking the alternatives to entry 3 we opened httpie/cli, the friendly replacement for curl that a great many people have installed. It has 38,600 stars. Its newest release is 3.2.4, dated 1 November 2024. Its own changelog stops on that same day. GitHub's release page states that master has received two commits in the twenty-three months since. There is no archived banner and no notice in the README saying the project has stopped, and 150 pull requests are waiting. Anyone installing it today gets a tool nobody is working on, and nothing on the page says so.

We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.

If you only do three things

  1. dua-cli (entry 5) — two minutes, one command, and in its plain form it changes nothing. It tells you what actually filled a disk, in a few seconds instead of a few minutes.
  2. xan (entry 4) — twenty minutes, on CSV files that already exist. One downloaded program that filters, sorts, joins and summarises a table far too large for a spreadsheet.
  3. rclone (entry 1) — half an hour, and the strongest thing on this page. One command that copies files to and from more than seventy kinds of cloud storage, checking every file after it arrives. Read the warning about sync before you run it.

No theme, on purpose. Twelve repositories across ten of the sixteen areas, three hidden gems, no repeats. Four new to the ledger, seven promoted from the queued backlog, one settled out of unverified.

Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.

60025 stars · MIT — read from /blob/master/COPYING, plain unmodified text, 'Copyright (C) 2012 by Nick Craig-Wood'; all four conventional LICENSE paths 404 · v1.75.1 of 2026-09-04, the yearless GitHub date confirmed by pkg.go.dev; ungh's releases endpoint was a full patch behind at v1.75.0 of 2026-07-31 · Track this in Scout

A command-line program that copies, syncs and verifies files across more than seventy kinds of cloud storage.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A single downloaded program, first published in March 2014 and at 60,025 stars, that presents every storage service through the same set of commands. It checks copied files by comparing a fingerprint of the contents, keeps the original modification times, and can also mount remote storage so it looks like an ordinary folder.

What it is good for. Anyone whose files are spread across several storage services and who wants one repeatable command instead of several web pages. It is also the usual answer when a backup has to land somewhere off the machine that made it, and when the same copy has to be verified rather than assumed.

Stars60025
LicenceMIT — read from /blob/master/COPYING, plain unmodified text, 'Copyright (C) 2012 by Nick Craig-Wood'; all four conventional LICENSE paths 404
Latestv1.75.1 of 2026-09-04, the yearless GitHub date confirmed by pkg.go.dev; ungh's releases endpoint was a full patch behind at v1.75.0 of 2026-07-31
Good
  • Its own website states that over seventy cloud storage products are supported, including the big object stores and ordinary transfer protocols such as SFTP and WebDAV.
  • Every transfer is verified with a content fingerprint, so a file that arrived damaged is reported rather than trusted.
  • It is genuinely active: version 1.75.1 was published on 4 September 2026, and new code landed on the morning this edition was written.
Watch for
  • The sync command is destructive on purpose. Its documented job is to make the destination identical to the source, which means files that exist only at the destination are deleted. The documentation recommends running with --dry-run first and with --interactive while learning, and that advice is not optional.
  • Its optional encryption hides less than people assume. The file length is not hidden and can be worked out to within sixteen bytes, modification times are not hidden because they are needed for syncing, and the folder structure stays visible under the standard setting. The password cannot be changed afterwards: the project states plainly that the key of already encrypted content cannot be changed, so a leaked password means uploading everything again.
  • It is a large project with a large backlog: 980 open issues and 260 open pull requests. Building from source needs Go version 1.26 or newer, and the published documentation carries several security advisories, so staying on a current version matters.
Similar repositories
  • peak/s5cmd

    Moves files to and from object storage very quickly with many parallel connections, but it speaks to one kind of object store and local disks only, with no other services, no encryption and no folder mounting.

    Track this in Scout
  • s3fs-fuse/s3fs-fuse

    Makes one object-storage bucket look like an ordinary folder on Linux, macOS and FreeBSD, which is only the mounting part, with no copy engine and no verified transfers.

    Track this in Scout
  • kahing/goofys

    Mounts object storage as a folder faster than s3fs-fuse but does only that, and it has taken no new code since 18 July 2024.

    Track this in Scout
Install
sudo -v ; curl https://rclone.org/install.sh | sudo bash
Screenshots
rclone/rclone: GitHub preview card

5707 stars · MIT — read from /blob/master/LICENSE, plain unmodified text, 'Copyright (c) 2024-2025 Chetan Jain' · no GitHub releases at all, ever — a determination, not a gap; PyPI botasaurus 4.0.97 published 2026-01-06, so the package is about eight months behind the code · Track this in Scout

A Python framework for collecting data from web pages that are trying to block automated visitors.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A Python framework at 5,707 stars, created in May 2023, that wraps browser control and plain web requests behind short decorators. It names several commercial blocking products it aims to get past, and it can package a finished collector as a desktop application for Windows, macOS and Linux.

What it is good for. Someone who already writes collectors in Python and keeps getting refused by the site they need. The framework part is the real value: caching between runs, running many pages at once, and human-looking mouse movement are all supplied rather than written by hand.

Stars5707
LicenceMIT — read from /blob/master/LICENSE, plain unmodified text, 'Copyright (c) 2024-2025 Chetan Jain'
Latestno GitHub releases at all, ever — a determination, not a gap; PyPI botasaurus 4.0.97 published 2026-01-06, so the package is about eight months behind the code
Good
  • MIT licensed, read from the licence file itself and completely plain, so there is no paid key and no restriction on commercial use.
  • Caching, parallel collection and browser control come as one piece, which is a large amount of fiddly work you do not have to write.
  • It is alive. Code landed on 26 July 2026, which took some proving — see the appendix.
Watch for
  • It publishes no releases on GitHub at all. That is a decision, not an oversight, so there is no tag to pin and no changelog there; the version to follow is the published Python package, and that has not moved since 6 January 2026. The code is therefore about eight months ahead of what an ordinary install gives you.
  • Nothing here is usable without writing Python. There is no window and no wizard, and the "desktop application" is a thing to be assembled rather than a thing to be downloaded.
  • One maintainer is named in the licence file, and there are 52 open issues against 5 open pull requests. The documentation lives on a separate commercial website rather than in the repository, so it can move or change terms independently of the code.
  • Its selling point is getting past named commercial blocking products, which usually means going against the terms of the site being read. That is a decision to make deliberately.
Similar repositories
Install
python3 -m venv venv && source venv/bin/activate
python -m pip install --upgrade botasaurus
Screenshots
omkarcloud/botasaurus: Screenshot 1omkarcloud/botasaurus: Screenshot 2omkarcloud/botasaurus: Screenshot 3omkarcloud/botasaurus: Screenshot 4

19228 stars · Apache-2.0 — read from /blob/master/LICENSE, plain body, appendix filled in as 'Copyright 2023 Hurl' rather than Orange · 8.0.1 published 2026-04-29, confirmed by crates.io; the release TITLE embeds 2026-04-28, a one-day self-contradiction · Track this in Scout

Runs and tests HTTP requests written in a plain text file, with captures and assertions.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A command-line program at 19,228 stars, published by Orange, that reads a file of requests, carries values from one answer into the next request, and asserts things about headers and content. It works as a way to fetch data and as a test runner for an API — an API being the machine-readable doorway a service offers to other programs.

What it is good for. Anyone testing a web service who wants those tests stored as readable text files in the same repository as the code. It suits a small team with no dedicated tester: the file is short enough to write in an afternoon and plain enough that the next person can read it.

Stars19228
LicenceApache-2.0 — read from /blob/master/LICENSE, plain body, appendix filled in as 'Copyright 2023 Hurl' rather than Orange
Latest8.0.1 published 2026-04-29, confirmed by crates.io; the release TITLE embeds 2026-04-28, a one-day self-contradiction
Good
  • Apache-2.0, read from the licence file and completely plain.
  • The tests are one text file. They can be compared between versions, reviewed, and copied between projects, which is not true of tests kept inside an application's own database.
  • Packaging is unusually careful for a project this size: releases are cut automatically with a verified signature and nineteen ready-made downloads for different systems.
Watch for
  • The file format is a small language of its own, with its own way of writing checks and carrying values forward. There is no window to click in, so somebody has to learn it.
  • The newest release, 8.0.1, is dated 29 April 2026 — five months before this edition — while code is still going in, most recently on 26 September 2026. Anyone following releases only is five months behind.
  • Building from source is the awkward route: it needs the Rust toolchain plus the development files for libssl, libcurl and libxml2. The ready-made downloads avoid all of that.
  • Because the format captures values out of answers, passwords and access tokens tend to end up written into files that are then committed alongside the code. The tool does not solve that.
Similar repositories
  • usebruno/bruno

    The closest match in spirit, storing requests as plain files in your own repository, but it is a desktop application first and its README points at paid versions.

    Track this in Scout
  • grafana/k6

    Also scripts and checks web traffic from a command line, but built for load testing with JavaScript test files, and AGPL-3.0 is a much heavier licence.

    Track this in Scout
  • httpie/cli

    Sends single web requests from a terminal in a friendly readable form, but with no test file format, no chaining and no checks — and it has taken no code since December 2024.

    Track this in Scout
Install
brew install hurl
choco install hurl
Screenshots
Orange-OpenSource/hurl: Screenshot 1Orange-OpenSource/hurl: Screenshot 2Orange-OpenSource/hurl: Screenshot 3

4531 stars · Unlicense OR MIT — read from /blob/master/UNLICENSE and /blob/master/LICENSE-MIT, both plain and unmodified; nothing at LICENSE, so automatic licence checkers find nothing · 0.61.0 of 2026-09-11, the yearless GitHub date settled to the minute by crates.io's API · Track this in Scout

A command-line tool for processing, exploring and drawing CSV data in the terminal.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A program written in Rust, at 4,531 stars, maintained by a social-science research lab in Paris. It began as a fork of BurntSushi/xsv, the original fast CSV toolkit, and its README says it has been nearly entirely rewritten since. Its newest release, 0.61.0, is dated 11 September 2026, and code landed on 29 September 2026.

What it is good for. Anyone who receives a table too large for a spreadsheet and needs to answer one question about it: how many rows, which values appear, what the totals are per group. It is also useful as the first step before a table goes into a database, because it can describe and check a file before anything loads it.

Stars4531
LicenceUnlicense OR MIT — read from /blob/master/UNLICENSE and /blob/master/LICENSE-MIT, both plain and unmodified; nothing at LICENSE, so automatic licence checkers find nothing
Latest0.61.0 of 2026-09-11, the yearless GitHub date settled to the minute by crates.io's API
Good
  • The lineage is credited honestly, which is rarer than it should be. The README says it began as a fork of xsv, and the licence file still names xsv's original author beside the current maintainer.
  • Both licences are as permissive as they come: the project is offered as public domain or MIT, at your choice.
  • Real speed. It parses using processor instructions designed for this kind of work and spreads the job across processor cores, so a large file is a wait of seconds rather than minutes.
Watch for
  • It has no version 1.0. At 0.61.0, command names and options can still move between versions, so a script written today is not guaranteed to run next year.
  • There are 120 open issues against a single open pull request, from a small academic lab. That is a real risk if the lab's attention moves elsewhere.
  • Operations such as sorting, joining and removing duplicates have to hold data in memory. "Handles gigabyte files" is not the same as "never runs out of memory", and no figures are published either way.
  • There is no file at the usual LICENSE path: the two licences sit in UNLICENSE and LICENSE-MIT. Automatic licence checkers report nothing at all, which causes arguments in companies that run them.
Similar repositories
  • dathere/qsv

    The other successor named in xsv's own farewell note, doing the same job with a much larger command set, but its README does not credit xsv or its author where xan credits both openly.

    Track this in Scout
  • johnkerl/miller

    The same work on CSV, tab-separated files and line-by-line JSON with genuine streaming for files larger than memory, but written in Go and with a query language of its own to learn.

    Track this in Scout
  • BurntSushi/xsv

    The original both successors descend from, with the same commands and the same job, archived by its owner on 24 April 2025 and now pointing readers at the two projects that replaced it.

    Track this in Scout
Install
brew install xan
sudo pacman -S xan
scoop install xan
Screenshots
medialab/xan: GitHub preview cardmedialab/xan: Screenshot 1medialab/xan: Screenshot 2medialab/xan: Screenshot 3medialab/xan: Screenshot 4

6315 stars · MIT — read from /blob/main/LICENSE, plain unmodified text, 'Copyright (c) 2019 Sebastian Thiel' · v2.45.1 of 2026-09-30, the morning of the run, ONE SECOND after the code that produced it; crates.io's HTML pages returned 404 all morning so docs.rs and ungh settled it · Track this in Scout

Reports what is taking up disk space, much faster than the standard tool, with an interactive mode that can delete.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A small program written in Rust, at 6,315 stars, created in May 2019. It walks a folder tree using several processor cores at once, which is why it finishes in seconds where the standard du command takes minutes. Version 2.45.1 was published on 30 September 2026, the morning this edition was written, one second after the code that made it.

What it is good for. The moment a disk is full and nobody knows why. It answers that question faster than anything else here, and its interactive mode then lets you remove the thing you found without opening a file manager or typing paths.

Stars6315
LicenceMIT — read from /blob/main/LICENSE, plain unmodified text, 'Copyright (c) 2019 Sebastian Thiel'
Latestv2.45.1 of 2026-09-30, the morning of the run, ONE SECOND after the code that produced it; crates.io's HTML pages returned 404 all morning so docs.rs and ungh settled it
Good
  • MIT, read from the licence file and completely plain.
  • It is fast in the way that changes behaviour: quick enough that you check a disk out of curiosity rather than only in an emergency.
  • The plain command only reports. Nothing is changed unless you deliberately enter the interactive mode, which makes it safe to try.
Watch for
  • The interactive mode deletes files, and there is no recycle bin and no undo. The project says care has been taken to prevent accidents through a multi-stage process, which is a confirmation step and not a way back.
  • Memory grows with the size of the tree: the project states roughly 60 MB of memory per million files in interactive mode, and a hard limit of about 4.29 billion entries. Scanning a very large file server is not free.
  • The Windows install route needs the nightly Rust toolchain, which is a heavier thing to ask than an ordinary install.
  • Releases arrive very fast — this one was cut seconds after a code change — so a version installed today has had almost no time in anyone else's hands. The documented Linux install also pipes a script from a raw address into a shell, and that script sits on a branch the repository no longer uses by default.
Similar repositories
  • bootandy/dust

    The same fast replacement for du, showing which folders dominate a tree as a bar chart, but it only reports: no interactive mode and no delete, so it cannot destroy anything.

    Track this in Scout
  • dundee/gdu

    The closest like-for-like competitor, with the same parallel scanning, interactive screen and ability to delete, written in Go and tuned for solid-state disks.

    Track this in Scout
  • imsnif/diskonaut

    Draws the tree as blocks sized by space used and can also delete, but it has had no new code since 7 March 2024.

    Track this in Scout
Install
brew install dua-cli
cargo install dua-cli
Screenshots
Byron/dua-cli: GitHub preview card

15560 stars · MIT — read from /blob/master/LICENSE, plain unmodified text, 'Copyright (c) 2010-2016 Adrian Sampson' · v2.14.1 of 2026-09-17, the yearless GitHub date confirmed by PyPI · Track this in Scout

Catalogues a music collection and corrects its tags against a public music database.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A Python program at 15,560 stars, created in August 2010, that keeps a searchable catalogue of a music library and matches each album against the MusicBrainz database. Almost everything beyond the core is a plug-in: artwork fetching, loudness levelling, acoustic fingerprinting, lyrics and genres.

What it is good for. Anyone with a large local music collection assembled over years from different sources, where half the albums have wrong track numbers and no artwork. It is also the right tool when files need to end up in a predictable folder shape for a media server to read.

Stars15560
LicenceMIT — read from /blob/master/LICENSE, plain unmodified text, 'Copyright (c) 2010-2016 Adrian Sampson'
Latestv2.14.1 of 2026-09-17, the yearless GitHub date confirmed by PyPI
Good
  • MIT, read from the licence file and plain.
  • The matching is genuinely good, because it identifies the album rather than trusting whatever text the files arrived with.
  • Actively released: version 2.14.1 is dated 17 September 2026.
Watch for
  • A plain install gets the cataloguing but not the features most people came for. Acoustic fingerprinting needs a separate program called Chromaprint plus an audio decoder chain, and the loudness plug-in needs an outside program for every one of its five methods — the names differ on Ubuntu, Arch, macOS and Windows, and this is where most people give up.
  • It rewrites tags and moves files by design. Importing is a change to your collection, so a backup before the first large import is the honest precaution, not an optional one.
  • The Python version window is narrow at both ends: 3.10 or later is required and the package refuses to install above 3.14, so a very new Python will not work.
  • 636 open issues against 78 open pull requests, and the loudness plug-in alone offers five different back ends with different format coverage and two that cannot work in parallel. That is configuration effort, not a single blessed path.
Similar repositories
  • metabrainz/picard

    Tags files against the same public music database and can also use acoustic fingerprinting, but it is a desktop window you drag files into rather than a catalogue you can query.

    Track this in Scout
  • Lidarr/Lidarr

    Also renames and sorts a music collection, but its purpose is watching feeds and acquiring new releases rather than fixing files that are already on the disk.

    Track this in Scout
  • puddletag/puddletag

    A spreadsheet-style tag editor for Linux where many files are edited by hand, the opposite approach to automatic matching.

    Track this in Scout
Install
uv tool install beets
Screenshots
beetbox/beets: GitHub preview card

32055 stars · MIT with an ADDED PREAMBLE plus the SigNoz Enterprise License — see notes; NOT plain MIT · v0.144.0 of 2026-09-29; pkg.go.dev dates the same tag 2026-09-28, a one-day module-proxy disagreement, both 2026 · Track this in Scout

An OpenTelemetry-native platform for logs, metrics and traces, built on ClickHouse, with application performance monitoring built in.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A monitoring platform at 32,055 stars that stores everything in ClickHouse, a database built for very large numbers of records, and presents application performance, request tracing, log searching and alerting in one place. It is designed around OpenTelemetry, the common standard programs use to report what they are doing.

What it is good for. Anyone paying by the gigabyte to a monitoring service and wondering what it would take to hold the same data themselves. It is also the right shape when a slow request has to be followed across several services, because the log lines and the timings are joined rather than searched separately.

Stars32055
LicenceMIT with an ADDED PREAMBLE plus the SigNoz Enterprise License — see notes; NOT plain MIT
Latestv0.144.0 of 2026-09-29; pkg.go.dev dates the same tag 2026-09-28, a one-day module-proxy disagreement, both 2026
Good
  • One tool instead of three. Logs, numbers and request traces normally mean three separate systems to install and keep patched.
  • It takes data in the common standard form, so a program already reporting to a paid service usually needs only a new address.
  • Very active: version 0.144.0 was published on 29 September 2026, one day before this edition.
Watch for
  • The licence needs reading, and the phrase "open source" needs a qualifier. The licence file in the root is MIT, but it is not the plain MIT text: a paragraph has been added above it stating that everything under the ee/ and cmd/enterprise/ folders is covered by a different licence instead. That second file is the SigNoz Enterprise License, and its own words are that the software "may only be used in production, if you have agreed to, and are in compliance with, the SigNoz Subscription Terms of Service", with a licence for the right number of user seats. Copying and testing are allowed; production use of those folders is not. Go's own package index independently marks the whole project's licence as unknown and not redistributable because of it.
  • Four gigabytes of memory allocated to the container system is stated as the minimum, and that is a floor rather than a working figure. No processor or disk figure is published at all, which matters, because the database underneath is the part that fills a disk as data is kept.
  • The documented install now downloads a script from the vendor's website and runs it in a shell. The older route of fetching the repository and starting it with a compose file is no longer what the documentation hands you.
  • 1,200 open issues and 366 open pull requests. Single sign-on, fine-grained permissions, custom retention and the compliance features are in the paid tiers, not in the MIT part.
Similar repositories
Install
curl -fsSL https://signoz.io/foundry.sh | bash
foundryctl cast -f casting.yaml
Screenshots
SigNoz/signoz: GitHub preview cardSigNoz/signoz: Screenshot 1SigNoz/signoz: Screenshot 2SigNoz/signoz: Screenshot 3SigNoz/signoz: Screenshot 4
08

GitGuardian/ggshield

💎 hidden gem

1999 stars · MIT — read from /blob/main/LICENSE, plain unmodified text, 'Copyright (c) 2019 GitGuardian' · v1.55.0 of 2026-09-24, the yearless GitHub date settled by PyPI · Track this in Scout

Detects more than 500 kinds of hardcoded secret, as a pre-commit hook, a CI action or a command.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A small Python command-line program at 1,999 stars that checks files, code history, container images and packages for more than five hundred kinds of secret. It runs as a plain command, as a check before every save, or inside an automated build. New code landed on the morning this edition was written.

What it is good for. A small team that wants strong detection wired into the moment code is saved, without writing and maintaining its own list of patterns. It is also the easiest of these tools to put in front of an AI coding assistant: the newest version withholds the whole output when an assistant's tool call exposes a secret, rather than passing it along with a warning.

Stars1999
LicenceMIT — read from /blob/main/LICENSE, plain unmodified text, 'Copyright (c) 2019 GitGuardian'
Latestv1.55.0 of 2026-09-24, the yearless GitHub date settled by PyPI
Good
  • MIT, read from the licence file and completely plain.
  • The detection list is maintained by a company that does this for a living, so it covers far more kinds of key than a list you would write yourself.
  • It fits into the places that matter: a check before saving, an automated build, and now three different AI coding assistants by name.
Watch for
  • The detection is a hosted service, not a local program, so your code leaves your machine. The README says plainly that it uses the company's public service to scan content. The company's stated position is that only information such as the time of the call, the size of the request and the mode is kept, and that files and secrets are not stored or shown on the dashboard. That is a promise about retention, not a design that makes sending unnecessary.
  • An account is required. Nothing works without signing in first, so there is no offline or disconnected use.
  • The free level is metered and the command-line tool is deliberately limited on it. The published lowest tier lists up to 25 developers, up to 500 historical detections and 10,000 service calls a month, and marks the command-line tool and the save-time check as "Limited", with the full version in the paid tiers.
  • It puts somebody else's service on the path of your saves. A check that calls a service can hold up a save or a build when that service is slow. The newest version added a configurable timeout for exactly that reason.
  • Keeping content in-house is possible, but only by buying the company's on-premises product — not by running this tool by itself.
Similar repositories
  • gitleaks/gitleaks

    The same job entirely on your own machine with no account and nothing sent anywhere, at the cost of never saying whether a found key still works; its maintainer states it is feature complete.

    Track this in Scout
  • trufflesecurity/trufflehog

    Also reaches the network, but to the key's own provider to test whether each credential is still live, and it needs no scanning account; AGPL-3.0 matters if it is redistributed.

    Track this in Scout
  • Yelp/detect-secrets

    Fully local and account-free, built around a saved list of already-known secrets so an old repository can be brought under control without every run failing; the weakest detection of the three.

    Track this in Scout
Install
python3 -m venv venv && source venv/bin/activate
pip install ggshield
ggshield auth login
Screenshots
GitGuardian/ggshield: GitHub preview card

7456 stars · Apache-2.0 — read from /blob/main/LICENSE, plain unmodified text, appendix left as the stock '[yyyy] [name of copyright owner]' template so no copyright holder is asserted · v0.11.0 of 2026-08-14, the yearless GitHub date settled by PyPI · Track this in Scout

Adds checks around a language model's output, covering content as well as shape.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A Python framework at 7,456 stars, created in January 2023, that puts an input guard and an output guard around a model call. Each guard runs small components called validators, and the answer can be forced into a defined shape. Version 0.11.0 is dated 14 August 2026 and code landed on 25 September 2026.

What it is good for. Anyone putting a language model in front of other people who needs the answer checked before it is shown, and needs the answer as structured data rather than a paragraph to be picked apart. It is worth the effort at the point where "usually correct" stops being acceptable.

Stars7456
LicenceApache-2.0 — read from /blob/main/LICENSE, plain unmodified text, appendix left as the stock '[yyyy] [name of copyright owner]' template so no copyright holder is asserted
Latestv0.11.0 of 2026-08-14, the yearless GitHub date settled by PyPI
Good
  • Apache-2.0, read from the licence file and entirely plain.
  • The checks are separate, small and composable, so you add the two you need instead of adopting a whole opinionated system.
  • The vendor account requirement has gone. Version 0.11.0 removed the private component registry and the tool that talked to it, and every check is now an ordinary Python package. Setting up now only asks whether you want to send anonymous usage figures.
Watch for
  • That change is a migration in progress, not a finished one. Anyone on an older version using the old install command has to move, and the page that documented the old hosted checking is already missing.
  • The checks are now your problem to run. Many of them are machine-learning models that download their own files and run on your machine, and no memory, disk or processor figures are published anywhere for a project that until recently offered to do that work on its own servers.
  • Still before version 1.0 after three and a half years, and the last two versions removed features that had shipped. The set of commands you write against is not settled.
  • 54 open pull requests against 38 open issues, which suggests contributions arrive faster than they are reviewed. The Python window is fixed at 3.10 or later and below 3.14.
Similar repositories
  • NVIDIA/NeMo-Guardrails

    The same job of putting rules around a model, at almost the same size and equally active, but organised around the shape of a conversation in a small modelling language of its own.

    Track this in Scout
  • 567-labs/instructor

    Overlaps only the structured-answer half — defined shapes and automatic retries — and is the leaner choice when a safety layer is not wanted.

    Track this in Scout
  • protectai/llm-guard

    Was the closest local equivalent with fifteen input and twenty output checks, archived by its owner on 9 July 2026, with its published models abandoned too.

    Track this in Scout
Install
python3 -m venv venv && source venv/bin/activate
pip install guardrails-ai
guardrails configure

2269 stars · GPL-2.0 — read from /blob/master/LICENSE, plain unmodified FSF text; there is no COPYING file and no main branch · v1.9.4 of 2026-08-31, the yearless GitHub date settled by ungh's releases endpoint · Track this in Scout

A mature desktop personal-finance manager for tracking accounts, budgets and spending, built on wxWidgets.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A desktop application at 2,269 stars, written in C++ and first published in May 2014, that stores everything in a single SQLite file with optional encryption. It covers current accounts, credit cards, savings, shares and assets, with nested categories, tags, reminders, budgets and charts. Version 1.9.4 is dated 31 August 2026 and code landed on 27 September 2026.

What it is good for. Someone who wants to see where household money goes without handing a bank feed to a company. Its own README states the aim plainly: the basic features that ninety per cent of people would want. It is also the easiest thing here to carry about, because a version runs from a memory stick with nothing installed.

Stars2269
LicenceGPL-2.0 — read from /blob/master/LICENSE, plain unmodified FSF text; there is no COPYING file and no main branch
Latestv1.9.4 of 2026-08-31, the yearless GitHub date settled by ungh's releases endpoint
Good
  • GPL-2.0, read from the licence file and the plain unmodified text.
  • One local file, optionally encrypted, with no account and no subscription. Nothing is uploaded anywhere by design.
  • Ready-made downloads for Windows, macOS, Linux through Flathub, and phone versions, so nothing has to be built.
Watch for
  • The release notes for the current version state a known problem with balance calculations when date-range filters are used. In a program whose whole job is arithmetic about money, that is worth knowing before you trust a figure it shows.
  • 456 open issues against a single open pull request. Reports arrive far faster than they are worked through, so expect long-lived bugs.
  • Everything lives in one file on one disk. Backing it up, keeping it in step across two computers, and recovering it if it is damaged are entirely your job.
  • No minimum operating system version, memory or disk figure is published anywhere. Building it yourself is a real commitment: Visual Studio on Windows, or a hand-built interface library on macOS.
Similar repositories
  • gnucash/gnucash

    The same job with full double-entry accounting and small-business features such as invoicing, more capable and considerably harder to learn; its licence is compound, GPL-2 or 3 plus an OpenSSL exception.

    Track this in Scout
  • actualbudget/actual

    Also personal finance kept on your own machine, but built as a self-hosted web application around envelope budgeting rather than a native program with one file.

    Track this in Scout
  • KDE/kmymoney

    The same kind of desktop finance manager with strong investment and bank-connection support, but this address is only a mirror and the real development lives on KDE's own servers.

    Track this in Scout
Install
https://github.com/moneymanagerex/moneymanagerex/releases/
Screenshots
moneymanagerex/moneymanagerex: GitHub preview cardmoneymanagerex/moneymanagerex: Screenshot 1moneymanagerex/moneymanagerex: Screenshot 2moneymanagerex/moneymanagerex: Screenshot 3moneymanagerex/moneymanagerex: Screenshot 4

21855 stars · GPL-3.0 — read from /blob/master/LICENSE, plain unmodified FSF text; the only project words are inside the standard fill-in-the-blank appendix · 5.14.0 — GitHub dates it 2026-09-21, Packagist dates the same version 2026-09-16, a five-day disagreement with both in 2026; version 6 is in beta, 6.0.0-b4 published 2026-09-30, the morning of the run · Track this in Scout

Website visitor reporting that runs on your own hosting, with the data in your own database.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A large PHP application at 21,855 stars, created in March 2011, that collects and reports on website and application traffic. Version 5.14.0 is the current stable release, dated 21 September 2026, and version 6 is in testing right now: a test build was published on the morning this edition was written.

What it is good for. Anyone who must keep visitor data on their own machines, which is usually a legal or a client-confidentiality requirement rather than a preference. It is also the right choice when reports have to be as detailed as the well-known free service, because the simpler counters cover far less ground.

Stars21855
LicenceGPL-3.0 — read from /blob/master/LICENSE, plain unmodified FSF text; the only project words are inside the standard fill-in-the-blank appendix
Latest5.14.0 — GitHub dates it 2026-09-21, Packagist dates the same version 2026-09-16, a five-day disagreement with both in 2026; version 6 is in beta, 6.0.0-b4 published 2026-09-30, the morning of the run
Good
  • GPL-3.0, read from the licence file and the plain unmodified text. The only project-specific words in it are inside the standard fill-in-the-blank example at the end.
  • It publishes honest sizing figures, which almost nothing else here does. Up to 100,000 page views a month wants 2 processor cores, 2 GB of memory and a 50 GB disk; up to 1 million wants 4 cores, 8 GB and 250 GB; up to 10 million wants 8 cores, 16 GB and 100 to 400 GB; up to 100 million wants 16 or more cores, 32 GB or more and a 1 TB disk.
  • Very active. Five versions, including test builds of the next major version, were published in the fortnight before this edition.
Watch for
  • The honest cost is the paid add-ons, not the licence. There are twenty of them, and they cover features many people assume are included: A/B testing, funnels, heat maps and session recording, user flows, custom reports, form reporting, media reporting, crash reporting, multi-channel attribution, roll-up reporting, search-engine keyword performance, activity logs, single sign-on and white labelling. The price is a subscription counted by user seats with a thirty-day trial, and no figure is shown without going through the trial or contacting sales, so we are not quoting one.
  • Installing it is real system administration: a web server, PHP, a MySQL or MariaDB database, and a database user granted a long list of permissions including file access.
  • Do not install it by copying the repository. The release page states that the source download is meant for developers and will need extra work; the archive attached to the release, or the download on the project's own site, is the way in.
  • 2,500 open issues, the largest backlog on this page. Version 6 raises the floor to PHP 8.1 and MySQL 8.0 or MariaDB 10.6, which will leave older hosting behind.
Similar repositories
Install
sudo apt-get install php php-curl php-gd php-cli mysql-server php-mysql php-xml php-mbstring
Screenshots
matomo-org/matomo: GitHub preview card
12

nardew/talipp

💎 hidden gem

538 stars · MIT — read from /blob/main/LICENSE, plain unmodified text, 'Copyright (c) 2020 nardew' · 2.7.0 of 2025-09-09 — THE YEAR TRAP: the GitHub page shows a bare '09 Sep', which the old past-date heuristic would have read as 2026; PyPI settled it as 2025 · Track this in Scout

Financial indicators for Python that recompute incrementally as each new value arrives.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A Python library at 538 stars with no outside dependencies, offering the usual technical indicators in a form where adding, changing or removing a single value costs the same no matter how long the history is. Indicators can also feed each other, so one can be built on the output of another.

What it is good for. Anyone feeding live or streaming prices into indicators, where recalculating the whole series on every new value is what makes the program too slow. It is the wrong shape for working through a large stored history in one go, and the library's own design says so.

Stars538
LicenceMIT — read from /blob/main/LICENSE, plain unmodified text, 'Copyright (c) 2020 nardew'
Latest2.7.0 of 2025-09-09 — THE YEAR TRAP: the GitHub page shows a bare '09 Sep', which the old past-date heuristic would have read as 2026; PyPI settled it as 2025
Good
  • MIT, read from the licence file and plain.
  • The updating design is genuinely unusual. Nearly every other Python library of this kind works through a whole table at once, so there is no like-for-like alternative with this property.
  • No outside library, no compiler and no separate C library to install first, which is exactly the problem the best-known alternative has.
Watch for
  • No new code for about twelve months. Version 2.7.0 and the last code change both date from 9 September 2025, and this needed proving: the release page shows the date without a year, and read carelessly it would have looked three weeks old. This is not a stale release date over live code — the code stopped too. It is well inside the eighteen-month line this report uses, and it is explicitly not being called dead, but it is the quietest project on this page.
  • One maintainer is named as the sole copyright holder. There are 23 open issues and 8 open pull requests, and with no pushes in a year those contributions are simply waiting.
  • The stated Python range runs from 3.8 to 3.11. There is no published statement about 3.12 or later, and nobody has pushed code to add one.
  • Far fewer indicators than the mainstream libraries. You would adopt this for the updating behaviour and accept a smaller catalogue for it.
Similar repositories
  • TA-Lib/ta-lib-python

    The same job at much larger scale with more than 150 indicators and candlestick patterns, but it works through whole arrays at once and wraps a C library that has to be present.

    Track this in Scout
  • bukosabino/ta

    Pure Python and installable in one command, with 43 indicators, but it works over whole table columns for preparing data rather than accepting one new value at a time.

    Track this in Scout
Install
python3 -m venv venv && source venv/bin/activate
pip install talipp
Screenshots
nardew/talipp: GitHub preview card

Checked, and left out

These were opened for this edition and did not make it, with the reason.

ananthakumaran/paisa

ananthakumaran/paisa — researched in full and passed over at the last step; stays queued

httpie/cli

httpie/cli — not-qualified, no code in 21 months, the edition title

httpie/desktop

httpie/desktop — not-qualified, code-quiet since Mar 2025 and not open source

kahing/goofys

kahing/goofys — not-qualified, no code in 26 months

imsnif/diskonaut

imsnif/diskonaut — not-qualified, no code in 30 months

protectai/llm-guard

protectai/llm-guard — not-qualified, archived 9 Jul 2026

twopirllc/pandas-ta

twopirllc/pandas-ta — unverified, ungh 404 twice and page metadata unreadable

Share this edition
← PreviousNo. 35Next →
Coming tomorrow

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.