Edition No. 39 · 3 Oct 2026
Twelve repositories for deploying, counting and checking what you ship
A deploy tool, two privacy counters, three money libraries and five tools that read what is really inside a file, a model or an image.
We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.
Three things worth knowing, separate from the recommendations
- A licence file can carry a sentence somebody typed by hand. Beancount ships the plain GNU General Public License version 2 (a licence that obliges anyone who distributes a changed copy to publish their changes), and then adds a line of its own: "This is a GNU GPL 'v2 only' license. This is not a GNU GPL 'v2 or any later version' license." signed by the author. Almost every copyleft project on GitHub says "version 2 or later". This one closed that door deliberately, and the effect is real: code under version 2 only cannot be combined with code under version 3. - Two of today's twelve have never published a release on GitHub, and that is a finding rather than a gap. Beancount and ta both say "There aren't any releases here." Both have shipped versions for years, through the Python package index instead. We looked, and the answer is none. - A download can be two years older than the code behind it. Offen's newest tagged version is 22 May 2024, and its code moved on 4 March 2026. The ready-made container image tagged latest still points at the 2024 build, so a reader who follows the instructions gets software from two years ago. That is printed in its entry rather than smoothed over.
If you only do three things
- anchore/grype (#11) — two minutes, one command, nothing to configure. Point it at a container image you already use and it prints every published security hole somebody has found in the software inside it. It only reads. It changes nothing.
- wader/fq (#10) — five minutes, one command. It opens a file that is not text — an MP3, a video, a captured network packet — and shows you what is actually inside it, field by field.
- basecamp/kamal (#1) — half an hour, and the gold of the edition. It takes a web application you have already packaged and puts it on a plain rented server over a normal remote login, then switches traffic from the old copy to the new one with no gap.
Every link in one place
| # | Repository | What it does | Stars | Licence | Newest version | Project site |
|---|---|---|---|---|---|---|
| 1 | basecamp/kamal | Puts a packaged app onto a rented server | 14,627 | MIT | v2.12.0 · 18 Jun 2026 | kamal-deploy.org |
| 2 | psviderski/uncloud | Joins a few servers into one place to run things | 5,419 | Apache-2.0 | v0.21.0 · 2 Oct 2026 | uncloud.run |
| 3 | milesmcc/shynet | Counts visitors without cookies | 3,151 | Apache-2.0 | v0.14.0 · 15 Mar 2026 | none |
| 4 | offen/offen 💎 | Visitor counting the visitor can read and delete | 979 | Apache-2.0 (logo: CC-BY-NC-ND-4.0) | v1.4.2 · 22 May 2024 | offen.dev |
| 5 | beancount/beancount | Double-entry accounting in a plain text file | 6,044 | GPL-2.0-only | 3.2.3 · 5 May 2026 (PyPI) | beancount.github.io |
| 6 | bukosabino/ta | 43 standard chart indicators for Python | 5,228 | MIT | 0.11.0 · 2 Nov 2023 (PyPI) | readthedocs |
| 7 | cvxgrp/cvxportfolio 💎 | Works out how much of each thing to hold | 1,247 | GPL-3.0 | 1.5.1 · 6 Jul 2025 | cvxportfolio.com |
| 8 | NVIDIA-NeMo/Guardrails | Rules around what an AI model may say | 7,189 | Apache-2.0 | v0.24.1 · 16 Sep 2026 | docs.nvidia.com |
| 9 | timescale/pgvectorscale | Makes similarity search in PostgreSQL fit on disk | 3,096 | PostgreSQL License | 0.9.1 · 4 Sep 2026 | timescale.com |
| 10 | wader/fq | Reads inside a file that is not text | 10,602 | MIT | v0.18.0 · 25 Aug 2026 | wader.github.io/fq |
| 11 | anchore/grype | Lists the known holes in a container image | 12,967 | Apache-2.0 | v0.120.0 · 2 Oct 2026 | none |
| 12 | quodlibet/mutagen 💎 | Reads and writes the labels on an audio file | 1,966 | GPL-2.0-or-later | release-1.48.1 · 25 Jun 2026 | mutagen.readthedocs.io |
No theme, on purpose. Twelve repositories across nine of the sixteen areas, three hidden gems, no repeats. Four new to the ledger, eight promoted from the queued backlog. All four areas that neither Edition 37 nor Edition 38 touched are covered: running-in-production, getting-found, markets-and-trading and ai-and-models, the first three with two entries each.
Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.
14,627 stars · MIT (read from /blob/main/MIT-LICENSE — plain /blob/main/LICENSE returns 404 because the file is named MIT-LICENSE; plain and unmodified, 'Copyright (c) 2023 David Heinemeier Hansson') · v2.12.0 (2026-06-18, year confirmed by rubygems.org/gems/kamal) · Track this in Scout
Copies a packaged application onto servers you own over SSH and switches the traffic over without a gap.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Kamal is a command-line program (a tool you type into a terminal window rather than click) written in Ruby. It takes a container — a sealed box holding your application and everything it needs to run — and sends it to one or more servers over SSH, which is the normal way of logging in to a remote machine.
What it is good for. Anyone who has a working application and a rented server, and who is paying a hosting company every month for the step in between. Kamal removes that step. It is also good for anyone who tried a cluster manager, found a hundred pages of documentation, and gave up. The thing it replaces is not a tool. It is a monthly bill.
- One file of settings and one command. There is no management panel to install on the server, and nothing is left running there except the application itself and a small traffic switch.
- It installs the container software on the target server for you during setup, so a blank rented machine is enough to start.
- It is the tool a real company built for its own products and still uses, so the awkward parts — rolling from the old version to the new one, running a one-off task, reading the logs — are all covered.
- You need Ruby on the machine you are typing on, because the install command is
gem install kamal. The project does say you can run it inside a container instead, and its own documentation calls that route limited. - Your application must already be packaged as a container, and you must write and keep a settings file by hand. There is no screen to click.
- The project publishes no memory, processor or disk figure anywhere, and names no minimum version of Ruby or of the container software. There are also 85 waiting changes against 73 waiting problems, which means the settings file can shift between small version numbers.
- dokku/dokku
The same job of running your own containers on your own machine, but it is a service installed on the server that you push code to, rather than a tool on the machine you type on; Ubuntu 22.04 and 24.04 or Debian 11 and later only.
Track this in Scout
coollabsio/coolifyThe same job of deploying to a server you own, but through a web page with a catalogue of ready-made services instead of a settings file and a command.
Track this in Scout- caprover/caprover
Also deploys containers to your own machine and adds a web screen with a web server and free certificates built in, but it runs on Docker Swarm, which is a cluster manager you then have to understand.
Track this in Scout
gem install kamal
5,419 stars · Apache-2.0 (read from /blob/main/LICENSE; stock unmodified text, and the boilerplate copyright line is left as the [yyyy] [name of copyright owner] template, so no holder is named) · v0.21.0 (2026-10-02, year confirmed by pkg.go.dev) · Track this in Scout
Links a few servers into one private network and runs containers across them, with no central controller.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Uncloud is a command-line tool written in Go. It builds an encrypted private network between your machines using WireGuard, which is a common way of making separate computers behave as if they were on the same local network, and then runs containers on them with names that resolve automatically and web traffic handled by Caddy.
What it is good for. Anyone whose single server has become the thing they are afraid of. One machine means one power cut, one disk, one reboot. Uncloud is for the step after that — two or three ordinary machines, possibly at different providers, treated as one place to put things — without the weight of Kubernetes, which is the industry standard cluster manager and takes weeks to learn properly.
- There is no controller to run and keep alive. The machines agree among themselves, so there is no single box whose failure stops everything.
- It reads the same
composefiles most people already have, so an application described for one machine can usually move across without being rewritten. - Machines at different hosting companies, or a machine at home and a machine in a data centre, can sit in the same private network.
- It is openly before version 1.0 and still changing in ways that break things. Version 0.21.0, released on 2 October 2026, moved the file the tool talks to from one path to another.
- The documented install pipes a script straight from the internet into a shell, which means running code you have not read. There is also no screen: it is a command line and YAML files only.
- No memory, processor or disk figure is published, and no minimum version of Go or of the container software is named. When something breaks you own four moving parts at once — the container software, WireGuard, Caddy and the agreement layer between machines — with 66 waiting problems and no company behind it.
- k3s-io/k3s
The same job of running containers across several machines, but it is real Kubernetes with the central controller and the standard client, which is precisely the weight uncloud avoids.
Track this in Scout - hashicorp/nomad
The same job of placing work on a pool of machines and it scales past ten thousand of them, but it is a server-and-client cluster with its own job format, and its Business Source License 1.1 is not open source.
Track this in Scout
coollabsio/coolifyAlso manages applications across several machines you can log in to, but through a web page and an application catalogue rather than a private network and compose files.
Track this in Scout
brew install psviderski/tap/uncloud
3,151 stars · Apache-2.0 (read from /blob/master/LICENSE; stock unmodified text with the copyright line left as the template) · v0.14.0 (2026-03-15; no package registry publishes this project, and the yearless release timestamp matches the ungh pushedAt to the second, 2026-03-15T23:00:29Z, which is what settles the year) · Track this in Scout
Self-hosted visitor counting that works from the server's own records, with no cookies.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Shynet is a web application written in Django, a long-established Python framework. It records page views, sessions, where people arrived from, their country and their kind of device, and shows them in a plain web screen for each site you add.
What it is good for. Anyone who wants to know whether their writing is read, and does not want to send every reader to an advertising company to find out. It also suits anyone in a place with strict rules about visitor consent: because it collects no cookies and stores no personal identifier, the usual consent banner question largely disappears.
- It can run with no script on the page at all, using a single invisible image instead, so it still counts people whose browser blocks scripts.
- It will run on SQLite, a database that is just a file, so you do not have to set up a separate database server to try it.
- The licence is plain Apache-2.0, read from the file. There is no paid edition, no feature held back and no limit on how many sites you add.
- Setting it up is several steps of hand work: copy a settings template, edit it, start the container, then run two more separate commands to create the administrator and set the name shown in the screen. There is no installer.
- The list of addresses the application will answer on defaults to
localhost, and the project's own guide warns against using the catch-all wildcard. Get that wrong and it silently refuses to work, or answers to the wrong name. - Its front page contains no install commands at all — they are in a separate guide file — and the code has not moved since 15 March 2026, about six and a half months. The last release did carry security fixes, so this is a slowing project rather than a stopped one.
- plausible/analytics
The same cookie-free counting with a much better screen, but it needs two separate databases running side by side and the self-hosted edition deliberately leaves out features the paid service has.
Track this in Scout
umami-software/umamiThe same job and far more widely used, but it does not work at all without a script on the page, and it wants Node.js 18.18 or later with PostgreSQL 12.14 or later.
Track this in Scout- usefathom/fathom
The same privacy-first counting in a single program and the easiest of the three to install, but it is the free remnant of a product that went paid and its own description promises maintenance and no new features.
Track this in Scout
docker pull milesmcc/shynet:latest
979 stars · Apache-2.0 for the code (read from /blob/development/LICENSE — the default branch is development, so main-based paths 404; stock text with the copyright line left as the template). SEPARATE RESTRICTION: the README states the Offen Fair Web Analytics icon and logo are CC-BY-NC-ND-4.0, which forbids commercial use and forbids derivatives. · v1.4.2 (2024-05-22, year confirmed by Docker Hub's tag API after pkg.go.dev proved unusable) against a code date of 2026-03-04 — two years and four months apart, and the container tag 'latest' still points at the 2024 build · Track this in Scout
Visitor counting where each visitor's own data is encrypted and they can read or delete it themselves.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Offen, which calls itself Fair Web Analytics, is a self-hosted server written in Go. Each visitor's events are encrypted with a key held in their own browser, so the operator can see totals but cannot read one person's history unless that person opens it.
What it is good for. Anyone who has to show, rather than claim, that they do not keep readable records about individual readers. The visitor-facing page is the whole point: you can link to it and a reader can check for themselves. It suits a small site where being able to prove the claim matters more than having the fullest possible numbers.
- The design is genuinely different, not a marketing line. The operator holds data they cannot read, and the visitor can delete their own part of it at any time.
- It is one program with first-party cookies only, so nothing is loaded from anybody else's domain and there is no third party in the path.
- The code licence is plain Apache-2.0, read from the file. The project has public funding from NLnet and NGI rather than a paid tier pulling features out of it.
- ⚠ The newest tagged version is v1.4.2 of 22 May 2024, and the code has moved since — last on 4 March 2026. The ready-made container image tagged
latestis still the 2024 build. So you either install software from two years ago or build an untagged version yourself. That is the single biggest cost here. - Its front page documents only a throwaway demo, which pipes a script from the internet into a shell, and a developer setup built on
make. There is no plain production install command anywhere in the repository. - Collection is opt-in with a consent banner, so your numbers are structurally incomplete by design. And although the code is Apache-2.0, ⚠ the icon and logo are licensed CC-BY-NC-ND-4.0, which forbids commercial use and forbids changing them — a restriction that sits outside the code licence entirely.
arp242/goatcounterCovered in Edition 30. The same small no-personal-data counting in one downloaded program and far more actively maintained, but with no consent banner and no per-visitor encryption; its EUPL-1.2 carries an author's edit to the compatible-licence appendix.
Track this in Scout- plausible/analytics
The same audience and the same cookie-free promise, far better maintained, but much heavier to run and the self-hosted edition has fewer features than the paid one.
Track this in Scout - usefathom/fathom
Also a single small program for privacy-first counting, and feature-frozen by its own maintainers.
Track this in Scout
curl https://demo.offen.dev | bash
6,044 stars · GPL-2.0-only (read from /blob/master/COPYING; stock GPLv2 text PLUS a hand-written line from the author narrowing it: 'This is a GNU GPL "v2 only" license. This is not a GNU GPL "v2 or any later version" license.' —Martin Blais) · no GitHub releases at all; PyPI 3.2.3 (2026-05-05) is the version to trust · Track this in Scout
Double-entry bookkeeping written as a plain text file, with a command-line program that checks it and reports on it.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Beancount defines a small written language for recording money moving between accounts, and ships a Python program that reads the file, refuses it if it does not balance, and produces balance sheets and income statements. Double-entry means every amount is recorded twice, once leaving one account and once arriving in another, which is what makes the arithmetic self-checking.
What it is good for. Anyone whose books matter in ten years. A text file can be read by anything, kept in version control so every change has a history, and checked by a program you write yourself. It suits a one-person business, a freelancer, or anyone who has lost data to an accounting product that shut down or raised its price.
- ⚠ Its licence file is the most interesting thing in this edition. It is the plain GNU General Public License version 2, and then it adds the author's own line: "This is a GNU GPL 'v2 only' license. This is not a GNU GPL 'v2 or any later version' license." — Martin Blais. That is a deliberate decision, stated by hand, where almost every other project says "or later".
- The file format has barely changed in twenty years, and plain text in version control means you can see exactly who changed which number and when.
- It refuses to load a file that does not balance. An accounting mistake stops the program rather than producing a quietly wrong report.
- Version 3 deliberately removed the parts people liked looking at. The web screen and many of the extra tools now live in separate projects, so a usable setup means installing more than one thing. Fava is the usual companion and it is not included.
- Everything is typed. There is no import wizard and no bank connection, so a month of card transactions is a month of typing or a script you write.
- ⚠ The "version 2 only" licence is a genuine trap if you plan to build something on top: code under version 2 only cannot legally be combined with code under version 3, and a great deal of modern open-source code is version 3.
- It publishes no GitHub releases at all — its releases page says "There aren't any releases here." That is a determination and not a gap: versions are published to the Python package index instead, where 3.2.3 is dated 5 May 2026. Code last moved on 23 August 2026, and there are 207 waiting problems.
- ledger/ledger
The same plain-text double-entry idea and the oldest of the three; written in C++ so it is faster, but it has no Python interface and needs compiling or a system package.
Track this in Scout - plaintextaccounting/hledger
The same model and a nearly compatible file format, and it ships a command line, a terminal screen and a web screen in the box rather than as separate projects, but extending it means Haskell.
Track this in Scout
firefly-iii/firefly-iiiCovered in Edition 28. The same double-entry bookkeeping but as a web application with a database and forms, which is easier to use every day and puts the data inside somebody's schema rather than a file you can read.
Track this in Scout
pip install beancount
5,228 stars · MIT (read from /blob/master/LICENSE; plain and unmodified, 'Darío López Padial (Bukosabino)', 2020) · no GitHub releases at all; PyPI 0.11.0 (2023-11-02) against a code date of 2026-03-18 — a release gap, NOT a dead project · Track this in Scout
Adds 43 standard technical-analysis indicators as new columns on a table of prices.
▶Repo detailsthe review · specs · pros & cons · install
What it is
ta is a small Python library that works on a pandas DataFrame, which is the standard way of holding a table of numbers in Python. You give it columns for the open, high, low and close prices plus the volume traded, and it returns the same table with the indicators attached.
What it is good for. Anyone preparing price data — for a chart, for a study, or as the input to something that learns from numbers. It is the easy answer in a field where the fast answer is painful to install, because it is pure Python and needs no compiler and no outside library.
- It installs anywhere in one command, with no compiler and no separate C library to fight. That is the whole reason it exists.
- 43 indicators grouped into volume, volatility, trend, momentum and other, with one function that adds all of them at once for a first look.
- Plain MIT, read from the licence file, with a named copyright holder and nothing added.
- You must supply the exact column names it expects, and fill in any gaps in the data yourself. Give it a table with holes and it returns numbers that look fine and are not.
- ⚠ No release since 2 November 2023, almost three years, while the code moved on 18 March 2026. It publishes no GitHub releases at all, so the Python package index is the only source, and 122 waiting problems and 34 waiting changes have built up behind that version. Fixes that exist in the code are not in the version you install.
- Adding every indicator at once over a long price history creates dozens of new columns of numbers, which can use a surprising amount of memory. The project publishes no figure for this at all. Its package listing also still advertises only Python 3.6 and 3.7, which cannot be right for code written in 2026.
TA-Lib/ta-lib-pythonCovered in Edition 35. The same job with more than 150 indicators and much faster, and the standard choice; the difference is the install, and from 0.6.5 it ships ready-built packages that include the C library.
Track this in Scout
jealous/stockstatsThe same approach of reaching indicators as columns on a table, with more than 50 of them, and actively maintained where ta has gone quiet; needs Python 3.9 or later.
Track this in Scout
nardew/talippThe same set of indicators but recomputed one new price at a time rather than over a whole table, which suits a live feed and is the wrong shape for bulk preparation.
Track this in Scout
pip install --upgrade ta
1,247 stars · GPL-3.0 (read from /blob/master/LICENSE; full unmodified GPLv3 text, FSF 29 June 2007, no added clause and no commercial carve-out) · 1.5.1 (2025-07-06, year confirmed by PyPI) against a code date of 2026-04-27 · Track this in Scout
Computes portfolio weights by solving an optimisation problem, and replays the resulting policy over historical prices.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Cvxportfolio is a Python library built on CVXPY, a tool for solving convex optimisation problems. Convex, here, means a shape of problem that a computer can solve reliably and provably, rather than by guessing. It takes forecasts of returns, a measure of how holdings move together, and a model of trading costs, and returns the holdings to aim for.
What it is good for. Anyone who has noticed that a simple allocation rule looks excellent on paper and loses money in practice, because the paper version does not pay the spread, the commission or the price impact of its own trades. This library's distinguishing feature is that the cost of trading is part of the problem rather than an afterthought.
- It comes from the group that wrote the standard textbook on convex optimisation, and it has a published paper behind it, so the method is written down and can be checked.
- Trading costs and holding costs are first-class parts of the model, so a strategy that only works when trading is free will show up as not working.
- It replays a whole policy over time, not just one allocation, which is a more honest test than optimising once on all of the history.
- ⚠ It is a research library, not a product. You must express what you want as a convex program. There is nothing to click and no list of ready-made strategies to pick from.
- ⚠ GPL-3.0, read from the licence file. Anything you build on it and then distribute must also be GPL-3.0, which rules out most closed commercial use. This is the opposite trap from Beancount's above, and in the same edition.
- The newest release, 1.5.1, is dated 6 July 2025, about fifteen months old, while the code moved on 27 April 2026. Note also that the development branch commits its example results into the repository every day, so the project looks busier than its code actually is. No memory or processor figure is published, and both time and memory grow with the number of holdings.
- PyPortfolio/PyPortfolioOpt
The same allocation job and much easier to pick up, with MIT instead of GPL-3.0, but it solves for one moment in time and has no built-in replay of a policy over history; renamed from robertmartin8/PyPortfolioOpt.
Track this in Scout
skfolio/skfolioCovered in Edition 33. The same optimisation, also through CVXPY, but presented in the shape of scikit-learn, which makes it familiar if you already work that way; needs Python 3.10 or later.
Track this in Scout
polakowo/vectorbtCovered in Edition 31. It tests thousands of rule combinations very fast, which is a different job: it is a tester, not an optimiser, and its Apache-2.0 plus Commons Clause is not open source.
Track this in Scout
pip install -U cvxportfolio
7,189 stars · Apache-2.0 (read from /blob/develop/LICENSE.md — the default branch is develop and /blob/develop/LICENSE returns 404; standard text, 'NVIDIA CORPORATION & AFFILIATES', no added clause and no commercial condition) · v0.24.1 (2026-09-16, year confirmed by PyPI's nemoguardrails project page) · Track this in Scout
Puts rules you write around a language model's input and output, and enforces them before the answer reaches anybody.
▶Repo detailsthe review · specs · pros & cons · install
What it is
This is a Python library from NVIDIA that wraps a model application in configurable rails. A rail is a rule applied at one point in the flow: the user's question, the documents retrieved to answer it, a tool the model wants to call, or the answer itself. Rules are written in a small language of its own called Colang, alongside YAML settings.
What it is good for. Anybody whose application answers in public. The failure that matters is not a wrong answer, it is a confident answer about something the application was never meant to discuss, or a model persuaded by a visitor to abandon its instructions. This library is the layer that refuses before the answer is sent.
- Checks happen at several separate points, not just on the final text, so a bad document retrieved from your own store can be caught before the model ever reads it.
- The licence is plain Apache-2.0, read from the file, with NVIDIA named as the copyright holder and no added commercial condition.
- It is one of the two serious projects in this field and it is actively worked on: version 0.24.1 landed on 16 September 2026 and code moved on 24 September 2026.
- ⚠ Colang is a language you have to learn. It is Python-like but it is not Python, and it sits on top of the Python and YAML you are already writing.
- ⚠ Every rail costs money and time. Checking a question and checking an answer are extra model requests on top of the one you wanted, and the project publishes no figure for either the added delay or the added cost.
- The jailbreak and content-safety checks download local models, so disk and memory use is substantial and undocumented. There are 153 waiting problems and 107 waiting changes, and development happens on a branch called
develop, which makes the state of the project hard to read at a glance.
guardrails-ai/guardrailsThe same job of checking what goes into and out of a model, at almost the same size and equally active; the difference is that the checks come from a hosted catalogue rather than rules written in a language of its own.
Track this in Scout- meta-llama/PurpleLlama
The same safety-filtering goal, but it ships trained models and benchmarks rather than a framework to organise them, and the models are under the Llama Community License, which is not an approved open-source licence.
Track this in Scout - protectai/llm-guard
The same input and output scanning, with 15 checks on the question and 20 on the answer, and archived by its owner on 9 July 2026.
Track this in Scout
pip install nemoguardrails
3,096 stars · PostgreSQL License (read from /blob/main/LICENSE, 17 lines, plain apart from the holder, which reads 'Tiger Data' — Timescale, Inc. d/b/a Tiger Data; a separate NOTICE file sits beside it pointing at the same licence. NOT Apache-2.0 and NOT Timescale's source-available TSL) · 0.9.1 (4 Sep; the year 2026 is INFERRED, not registry-confirmed — crates.io returns 404 for the name and no package registry publishes this project, so the year rests on the build targeting PostgreSQL 18, which did not exist before September 2025) · Track this in Scout
A PostgreSQL extension that makes similarity search work on more data than fits in memory.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Pgvectorscale is an extension for PostgreSQL, which means a piece of code you load into the database itself. It adds an index based on an approach called DiskANN that is designed to live on disk. It works beside pgvector, the base extension that gives PostgreSQL the ability to store those lists of numbers at all.
What it is good for. Anyone whose search-by-meaning feature has grown past what a reasonably priced server can hold in memory. The alternative is a second, separate database just for this, which is another thing to run, back up and keep in step. This keeps it in the database that already holds the rest of the data.
- ⚠ Its licence is the PostgreSQL License, read from the file: short, permissive and with no conditions worth worrying about. That matters because the company behind it also sells a source-available product, and this is not it.
- It keeps one database rather than two. Your text and your numbers stay in the same place, in the same backup, inside the same transaction.
- A small waiting list — 14 problems and 9 changes — which for a database extension is a good sign rather than a quiet one.
- It is not something you run. You must already have a working PostgreSQL server with pgvector installed, and building from source wants Rust, a build helper called
cargo-pgrxpinned to one exact version, and thejqtool. - ⚠ Index building needs the database's memory setting raised by hand. The project's own instruction is
maintenance_work_mem = '2GB', and without it a real dataset either crawls or fails. - Intel-based Mac computers are explicitly not supported, so some laptops can only use it through a container. The copyright holder in the licence file reads "Tiger Data", which is the company's new name for itself and does not match the repository owner.
pgvector/pgvectorThe same job of searching by meaning inside PostgreSQL, and in fact the thing pgvectorscale depends on; the difference is that its indexes are built to live in memory, which is the limit pgvectorscale exists to push past.
Track this in Scout- supervc-stack/VectorChord
Also a disk-friendly similarity index for PostgreSQL by a different method, and the successor to an earlier project by the same group, but dual-licensed AGPL-3.0 and Elastic License v2, so not permissive; renamed from tensorchord/VectorChord.
Track this in Scout - qdrant/qdrant
The same search job done quickly, but as a separate database you run alongside PostgreSQL rather than inside it.
Track this in Scout
CREATE EXTENSION IF NOT EXISTS vectorscale CASCADE;
10,602 stars · MIT (read from /blob/master/LICENSE; plain and unmodified, Mattias Wadman 2021, and the same file credits itchyny 2019-2021 for the forked colorjson and gojqextra code) · v0.18.0 (2026-08-25, year confirmed by pkg.go.dev) · Track this in Scout
Decodes a file that is not text into a structure you can query with a jq-style language.
▶Repo detailsthe review · specs · pros & cons · install
What it is
fq is a single command-line program written in Go. It understands more than a hundred file formats and turns each one into a tree of named fields, which you then query using the same language as jq, the standard tool for picking values out of JSON. It also has a hex view and an interactive prompt.
What it is good for. The moment when a file will not play, will not upload, or is the wrong size and nothing tells you why. A photograph with the wrong rotation, an audio file whose length is reported wrongly, a video a service refuses — all of these live in a few bytes somewhere inside, and this is the tool that shows you those bytes with their proper names. It also replaces a lot of guessing when you are writing code that handles media.
- More than a hundred formats in one downloaded program: audio, video, images, archives, network captures, certificates and more. There is nothing to install per format.
- It is read-only. Pointed at a file you care about, it cannot damage it.
- Plain MIT, read from the licence file, with the original author named and proper credit given in the same file to the author of the code it borrowed.
- It is only useful if you can write a
jqexpression, or are willing to learn one. There is no screen and no menu. - Installing from source needs Go on your machine first, unless your package manager happens to carry it. The project does list a wide set of package managers, so that is often avoidable.
- The output is a deep structure. It will tell you exactly what is in the file, and it will not tell you which of those fields is the one causing your problem.
- WerWolv/ImHex
The same job of making a non-text file readable, but as a graphical editor with its own pattern language, and it can write as well as read; GPL-2.0 with its library part under LGPL-2.1.
Track this in Scout - kaitai-io/kaitai_struct
The same idea of describing a binary format once, but it generates reading code in other programming languages instead of inspecting a file there and then.
Track this in Scout - ReFirmLabs/binwalk
Also finds structures inside a binary file, but aimed at pulling files out of device firmware rather than naming every field of a known format.
Track this in Scout
brew install wader/tap/fq
12,967 stars · Apache-2.0 (read from /blob/main/LICENSE; plain and unmodified, and the appendix is the unfilled [yyyy] [name of copyright owner] template, so no holder is named) · v0.120.0 (2026-10-02, year confirmed by pkg.go.dev; marked an immutable release) · Track this in Scout
Lists published security holes found in a container image, a folder, or a parts list of software.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Grype is a single command-line program written in Go. It identifies every piece of software inside whatever you point it at, then matches each piece against public vulnerability databases and prints what it finds, with a severity for each.
What it is good for. Anyone who built a container six months ago and has not thought about it since. The holes were not there when you built it. They were published afterwards, in libraries you never chose directly. This is how you find out, in one command, without signing up for anything.
- Two minutes from nothing to a useful answer, and it only reads. You can run it against an image you already use with no setup and no risk.
- It takes a container image, a plain folder of files, or a parts list produced by another tool, so it fits whether or not you already track what your software is made of.
- Plain Apache-2.0, read from the licence file. The company behind it sells other products, and this one carries no commercial condition at all. Released on 2 October 2026, with code moving the same day.
- It downloads a large vulnerability database and refreshes it, so it needs network access. Offline it either fails or quietly uses stale data, which is worse.
- ⚠ 329 waiting problems and a very fast release pace at version 0.120. Pin the version if you want the same output tomorrow as today.
- It prints a list of identifiers and severities. Knowing which ones genuinely reach your code, and which are in a part you never call, is security knowledge the tool does not supply. Nothing is fixed for you.
- aquasecurity/trivy
The same scanning of images and folders and by far the most widely used; the difference is scope, because it also checks configuration mistakes, leaked secrets and cloud settings.
Track this in Scout - quay/clair
The same static analysis of container images, but built to run as a service that indexes and matches continuously rather than a single command you type.
Track this in Scout - future-architect/vuls
The same reporting of known holes, but aimed at running Linux and FreeBSD machines and network devices rather than at images, and GPL-3.0 rather than permissive.
Track this in Scout
curl -sSfL https://get.anchore.io/grype | sudo sh -s -- -b /usr/local/bin
1,966 stars · GPL-2.0-or-later (read from /blob/main/COPYING — there is NO LICENSE, LICENSE.md or LICENSE.txt in the root at all; the file is the verbatim unmodified GNU GPL version 2, June 1991, with no project-specific holder) · release-1.48.1 (2026-06-25, year confirmed by PyPI) · Track this in Scout
A pure-Python library that reads and writes the metadata inside audio files, in about every format there is.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Mutagen handles the labels in ASF, FLAC, MP3 with ID3, MP4, Ogg in its Vorbis, Opus, FLAC, Speex and Theora forms, Musepack, Monkey's Audio, True Audio, WavPack, OptimFROG and AIFF files. It is written entirely in Python and depends on nothing outside the Python standard library.
What it is good for. Any pile of audio files with inconsistent labels, where fixing them by hand is a week of clicking. Thirty lines of Python using this library will rename, retag and tidy a thousand files. It is also the library other, friendlier tools are built on, so knowing it is here is useful even if you never write a line against it.
- No dependencies at all outside the standard library, which means it installs everywhere and keeps working for years. It runs on both the standard Python and PyPy, on Linux, Windows and macOS.
- It covers the awkward formats, not just MP3. Ogg Opus, Monkey's Audio and OptimFROG are in the list, and almost nothing else handles all of them.
- ⚠ It also installs six command-line programs that its own front page never mentions:
mid3v2,mid3cp,mid3iconv,moggsplit,mutagen-inspectandmutagen-pony.mid3iconvis the quietly useful one — it converts old-encoding labels to Unicode, which is what fixes a library full of unreadable characters.
- It is a library first. Most of what it can do needs you to write Python, and the command-line programs it ships are narrow, mostly ID3-focused utilities rather than a tag editor.
- ⚠ GPL-2.0-or-later, read from the
COPYINGfile. That is copyleft, so bundling it inside closed software is a real problem. Note that unlike Beancount above, this one does say "or later". - Its front page carries no install instructions at all and does not mention the command-line programs, so the project reads as less useful than it is. It needs Python 3.10 or later, and there are 105 waiting problems.
- taglib/taglib
The same job across many formats and the library most desktop music players actually use; it is C++ with bindings, so faster and harder to install than a pure-Python package, and dual-licensed LGPL-2.1 and MPL.
Track this in Scout - nicfit/eyeD3
The same Python tag editing with a better command-line tool, but it handles essentially only MP3 with ID3, which is the easy case.
Track this in Scout - tinytag/tinytag
The same reading of labels across MP3, FLAC, Ogg, WAV and more, with a far simpler interface and a permissive licence, but it only reads and cannot write a label back; renamed from devsnd/tinytag.
Track this in Scout
python3 -m pip install mutagen
Checked, and left out
These were opened for this edition and did not make it, with the reason.
protectai/llm-guard
protectai/llm-guard — already a not-qualified row from 30 September; archived 9 July 2026, confirmed again in entry 8's comparison list
usefathom/fathom
usefathom/fathom — alive at last code 18 March 2026, inside the bar, but feature-frozen by its own maintainers; stays queued and explicitly not called dead
twopirllc/pandas-ta
twopirllc/pandas-ta — could not be settled, HTTP 404 from ungh; left out of entry 6's comparison list rather than listed unopened
matomo-org/matomo
matomo-org/matomo — ungh returned HTTP 429; already published in Edition 36 in any case
Coming tomorrow




















