Edition No. 41 · 5 Oct 2026

Twelve repositories for building, publishing and reading what you keep

A licence file that gives you written permission to swap it for a different licence, and eleven more projects opened and checked this morning.

By Genn·12 repositories·14 min read

Twelve open-source projects, opened and checked this morning. No theme. The twelve are picked for how good they are, not for what they have in common, so a reader should not be able to guess what is in tomorrow's.

Today's title comes from the smallest-but-one project on the page. Entry #9 ships two licence files. The second one does something no licence in forty-one editions has done before: it gives you written permission to swap it for a different licence. Every other unusual licence this report has found took rights away. This one hands them out.

We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.

Three things worth knowing, separate from the recommendations

A licence can grant something instead of taking something away. Forty-one editions have turned up licences that add conditions: no production use without a paid key, no multi-tenant hosting, no removing the logo, no selling. Entry #9's second licence file is the first that widens the reader's choices rather than narrowing them, listing four other licences you may switch to. It sits beside a plain BSD file that says nothing of the sort, and GitHub cannot classify it, so the sidebar calls it "Unknown licenses found".

Six of today's twelve licence files name nobody as the copyright holder. That is the largest count this report has recorded, against three on each of the last two days. Four leave a template unfilled: nektos/act says only Copyright (c) 2019, and watchexec, qdrant and gftools all ship stock Apache 2.0 with [name of copyright owner] never replaced. Two — writefreely and siyuan — ship the Free Software Foundation's own licence text and never add their own copyright line to it, which is a milder version of the same gap. The licences work. They simply do not say who is granting them.

A date with no year was wrong by twelve months, and the mirror we check dates against was silently stale on half the page. Every one of today's twelve release pages printed a date with no year. Eleven were this year. wallabag's "07 Oct" is 7 October 2025, settled by two package sources, which means its newest download is a year old while its code moves daily. Separately, the public mirror this report uses for code dates returned a successful answer that was out of date for six of the twelve — including one case where its own release list contradicted its own code date. It did not fail; it answered wrongly, which is harder to notice.

If you only do three things

  1. yq (#8) — two minutes, one command, nothing to configure. It reads and edits YAML, JSON, XML and CSV files from the command line, the way jq does for JSON alone. One line in a script replaces a hand edit nobody remembers making.
  2. watchexec (#2) — five minutes, one command. It watches a folder and re-runs a command every time a file changes. Saving a file becomes the only thing you have to do.
  3. MediaInfo (#9) — ten minutes, read-only, on files that already exist. It tells you exactly what is inside a video or audio file: the codec, the bitrate, the real duration, every embedded tag. It never writes to the file.

No theme, on purpose. Twelve repositories across nine of the sixteen areas, three hidden gems, no repeats. Four of the twelve are new to the ledger; eight came out of the queued backlog. Both areas that neither Edition 39 nor Edition 40 touched — content-and-publishing and building-the-product — are covered, and content-and-publishing carries three entries, the ceiling. The request queue was read cleanly and is empty.

Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.

72,214 stars · MIT at master/LICENSE, stock text, AND THE HOLDER IS NOT NAMED — the line reads only 'Copyright (c) 2019' with no person or entity. · v0.2.89, '01 Jun' with no year, settled as 1 June 2026 by the ungh releases record (v0.2.88 1 May 2026, v0.2.87 1 Apr 2026 behind it). Code pushed 9 Aug 2026, two months after the release. · Track this in Scout

Runs your GitHub Actions workflows on your own machine inside Docker, so a broken workflow is fixed in seconds rather than in push-and-wait cycles.

▶Repo detailsthe review · specs · pros & cons · install

What it is

GitHub Actions is GitHub's own system for running automatic jobs — tests, builds, checks — whenever code changes. act reads the same workflow files and runs those jobs on your computer inside Docker, which is a way to run a program inside its own sealed box so it cannot break anything else on the machine.

What it is good for. Anyone who has sat waiting for a build to fail on a typo. The loop of push, wait, read the log, fix, push again is the slowest part of fixing a broken workflow, and this removes it. It is most useful to someone who maintains more than one small project and cannot keep a paid build service for each.

Stars72,214
LicenceMIT at master/LICENSE, stock text, AND THE HOLDER IS NOT NAMED — the line reads only 'Copyright (c) 2019' with no person or entity.
Latestv0.2.89, '01 Jun' with no year, settled as 1 June 2026 by the ungh releases record (v0.2.88 1 May 2026, v0.2.87 1 Apr 2026 behind it). Code pushed 9 Aug 2026, two months after the release.
Good
  • The same workflow file, no second copy to keep in step.
  • act -l lists every job it can see before anything runs.
  • Nine years old, 72,214 stars, and a release roughly every month.
Watch for
  • It needs Docker installed and running first, which is a real piece of software to learn.
  • It is not a real GitHub runner. The small default images leave out most of the tools GitHub preinstalls, so a job can pass here and fail there. The image that matches GitHub closely carries a warning in the project's own documentation: "this image is >18GB".
  • 266 open issues and 114 open pull requests, and no release since 1 June 2026 even though code landed on 9 August 2026. A fix you need may exist only in unreleased code.
  • Its MIT licence file reads only Copyright (c) 2019. No person and no company is named as the holder.
Similar repositories
Install
# Prerequisite: Docker installed and running.
# Linux or macOS, prebuilt:
curl --proto '=https' --tlsv1.2 -sSf https://raw.githubusercontent.com/nektos/act/master/install.sh | sudo bash
# Or, with the Go toolchain version 1.20 or newer:
go install github.com/nektos/act@latest
# Then, inside a project that already has a .github/workflows folder:
act -l
act
Screenshots
nektos/act: GitHub preview card

7,083 stars · Apache-2.0 at main/LICENSE, stock text including the standard appendix, AND THE HOLDER IS NOT NAMED — 'Copyright {yyyy} {name of copyright owner}' was never filled in. · v2.7.4, '02 Oct 15:27' with no year, settled as 2 October 2026 by crates.io to the minute (watchexec-cli 2.7.4 created_at 2026-10-02T15:27:34Z, library crate watchexec 8.4.3 at 15:26:28Z). · Track this in Scout

Watches files or folders and re-runs a command every time one changes, waiting out duplicate saves and stopping the previous run first.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A single downloaded program, written in Rust, that watches files or folders and runs a command you give it on every change. It handles the fiddly parts by itself: it waits a moment so one save does not trigger three runs, and it stops the previous run before starting the next.

What it is good for. Anyone writing code, a document or a stylesheet where the feedback loop is save-then-check. It is the smallest change in this edition that alters a daily habit, and it works the same way whatever language you write in, because it only knows about files and commands.

Stars7,083
LicenceApache-2.0 at main/LICENSE, stock text including the standard appendix, AND THE HOLDER IS NOT NAMED — 'Copyright {yyyy} {name of copyright owner}' was never filled in.
Latestv2.7.4, '02 Oct 15:27' with no year, settled as 2 October 2026 by crates.io to the minute (watchexec-cli 2.7.4 created_at 2026-10-02T15:27:34Z, library crate watchexec 8.4.3 at 15:26:28Z).
Good
  • One command, no configuration file, nothing running in the background afterwards.
  • 29 open issues and 6 open pull requests — by far the cleanest board in this edition.
  • Nine years old and released two days before this edition went out.
Watch for
  • The package to install is called watchexec-cli, not watchexec. watchexec is the library. Getting this wrong is a common first mistake.
  • The README gestures at package managers — "Arch, Debian, Homebrew, Nix, Scoop, Chocolatey" — without printing the command for any of them, so most people end up building from source and need the Rust toolchain installed first.
  • Its Apache-2.0 licence file still carries the unfilled template line Copyright {yyyy} {name of copyright owner}. The licence works. It names nobody as the party granting it.
Similar repositories
  • eradman/entr

    The same job in a much older and smaller C program, fed a list of files on standard input rather than watching a folder; its GitHub sidebar names no licence at all while the file in the repository is an ISC-style one.

    Track this in Scout
  • emcrisostomo/fswatch

    A file-change monitor that reports changes for other programs to act on, rather than running the command itself.

    Track this in Scout
  • cortesi/modd

    The same idea driven by a small configuration file instead of command-line arguments, which suits several watch rules at once.

    Track this in Scout
Install
# With Homebrew, on macOS or Linux:
brew install watchexec
# Or, with the Rust toolchain installed:
cargo install --locked watchexec-cli
# Run the tests every time a Python file changes:
watchexec -e py -- pytest
# Rebuild a site every time anything in the folder changes:
watchexec -- make build
Screenshots
watchexec/watchexec: GitHub preview card

50,024 stars · MIT at master/LICENSE — LICENSE.md, LICENSE.txt and MIT-LICENSE all 404 — stock text, holder named: 'Copyright (c) 2013, Andrew Cantino (Iteration Labs, LLC)'. · v2026.10.04, '04 Oct' with no year, and it SETTLED ITSELF: the tag encodes the date, and ungh's pushedAt of 2026-10-04T12:10:47Z matches the page's '04 Oct 12:10' to the minute. Released the day before the edition. · Track this in Scout

Runs small agents that watch pages, feeds and APIs and then act on what they find, with the data never leaving the machine it runs on.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A web application for assembling "agents". Each agent does one small job: fetch a page, read a feed, filter, wait, send an email, call another service. Agents feed into each other, so a chain of three simple ones does something a single complicated one would.

What it is good for. Anyone who has looked at a monthly automation bill and wondered what exactly they are paying for. Also anyone whose automations handle information they would rather not hand to a third party, because here the data never leaves the machine it runs on. It suits somebody comfortable running a web application and a database.

Stars50,024
LicenceMIT at master/LICENSE — LICENSE.md, LICENSE.txt and MIT-LICENSE all 404 — stock text, holder named: 'Copyright (c) 2013, Andrew Cantino (Iteration Labs, LLC)'.
Latestv2026.10.04, '04 Oct' with no year, and it SETTLED ITSELF: the tag encodes the date, and ungh's pushedAt of 2026-10-04T12:10:47Z matches the page's '04 Oct 12:10' to the minute. Released the day before the edition.
Good
  • Thirteen years old, started in March 2013, and it cut a release on 4 October 2026 — the day before this edition.
  • MIT licensed, with the holder plainly named in the file: Copyright (c) 2013, Andrew Cantino (Iteration Labs, LLC).
  • Releases are stamped with their own date, so the version number tells you how fresh it is without looking anything up.
Watch for
  • The real cost is the stack. The project asks for Ruby 3.4 or newer, Rails 8.1, and either MySQL or PostgreSQL — a database server you install and keep patched.
  • 613 open issues, the largest backlog in this edition. Many agents depend on other people's websites, and they go quiet when those sites change shape.
  • The setup instructions have you sign in as a user called admin, and every password for every service you connect ends up in your own database. Anything reachable from the internet needs hardening first.
Similar repositories
Install
# Prerequisites: Ruby 3.4 or newer, and MySQL or PostgreSQL installed.
git clone https://github.com/huginn/huginn.git
cd huginn
cp .env.example .env
# Edit .env and set APP_SECRET_TOKEN to a long random string.
bundle
bundle exec rake db:create
bundle exec rake db:migrate
bundle exec rake db:seed
bundle exec foreman start
# Then open http://localhost:3000 and sign in as admin.
Screenshots
huginn/huginn: GitHub preview cardhuginn/huginn: Screenshot 1huginn/huginn: Screenshot 2huginn/huginn: Screenshot 3huginn/huginn: Screenshot 4

12,994 stars · MIT, read from master/COPYING.md — LICENSE, LICENSE.md and COPYING all return 404. Stock text, holder named: 'Copyright (c) 2013-current Nicolas Lœuillet'. · 2.6.14, dated 7 OCTOBER 2025 — twelve months old. The /releases/latest page printed '07 Oct 08:06' with no year; settled twice, by Packagist (2025-10-07 08:05 UTC) and Docker Hub (last_updated 2025-10-07T08:21Z). · Track this in Scout

Saves the readable text of any web article on a machine you control, so the article survives the website.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A self-hosted read-later service. Self-hosted means it runs on a computer or rented server of your own rather than on somebody else's service. You send it a link; it strips the menus, adverts and pop-ups, keeps the article, and lets you tag, search, annotate and export it.

What it is good for. Anyone whose reading list is a hundred browser tabs. It is also the honest answer to link rot: a saved article survives the website. Thirteen years of use, mobile apps, browser extensions and an export to several formats make it the most finished product on this page.

Stars12,994
LicenceMIT, read from master/COPYING.md — LICENSE, LICENSE.md and COPYING all return 404. Stock text, holder named: 'Copyright (c) 2013-current Nicolas Lœuillet'.
Latest2.6.14, dated 7 OCTOBER 2025 — twelve months old. The /releases/latest page printed '07 Oct 08:06' with no year; settled twice, by Packagist (2025-10-07 08:05 UTC) and Docker Hub (last_updated 2025-10-07T08:21Z).
Good
  • Code was pushed on 5 October 2026, the morning this edition was written, and the project started in April 2013.
  • MIT licensed, with the holder named: Copyright (c) 2013-current Nicolas Lœuillet.
  • Everything you save can be exported — ePub, PDF, JSON, plain text — so nothing is trapped inside it.
Watch for
  • The newest download is twelve months old. Version 2.6.14 is dated 7 October 2025, confirmed by two separate package sources, while code lands almost daily. Anyone installing the released version is running year-old code on a web application that faces the internet.
  • 728 open issues and 32 open pull requests, the largest total in this edition.
  • The ready-made container starts with the user name wallabag and the password wallabag. Change it before the thing is reachable from anywhere. Installing from source instead asks for PHP 7.4 or newer with about seventeen extensions, Composer, and a database.
Similar repositories
Install
# Prerequisite: Docker installed and running.
docker run -v wallabag-data:/var/www/wallabag/data \
  -v wallabag-images:/var/www/wallabag/web/assets/images \
  -p 8080:80 \
  -e "SYMFONY__ENV__DOMAIN_NAME=http://localhost:8080" \
  wallabag/wallabag
# Then open http://localhost:8080 and sign in as wallabag / wallabag.
# Change that password immediately.
Screenshots
wallabag/wallabag: GitHub preview card

3,930 stars · MIT at main/LICENSE, stock text, holder named: 'Copyright 2025 Ronan Berder' (no '(c)', a slight deviation from the stock header). · 2.1.8, '08 Jun' with no year, settled as 2026-06-08 by the ungh releases record and consistent with package.json on main; corroborated only weakly by a relative 'three months ago' elsewhere, which pins the year but not the day. · Track this in Scout

An editing screen for a website whose content lives in a git repository, so the repository stays the only copy.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A small web application that signs in to your GitHub repository and shows the Markdown files and images in it as editable pages. Markdown is plain text with a few simple marks for headings and links. The files stay exactly where they were; this only edits them.

What it is good for. The situation where one person builds a site and a different person writes for it. The writer gets a form, not a code editor. It suits anyone whose site is already generated from files in a repository and who does not want to add a database and an admin system to make it editable.

Stars3,930
LicenceMIT at main/LICENSE, stock text, holder named: 'Copyright 2025 Ronan Berder' (no '(c)', a slight deviation from the stock header).
Latest2.1.8, '08 Jun' with no year, settled as 2026-06-08 by the ungh releases record and consistent with package.json on main; corroborated only weakly by a relative 'three months ago' elsewhere, which pins the year but not the day.
Good
  • Nothing new holds your content. The repository is still the only copy.
  • MIT licensed, with the holder named: Copyright 2025 Ronan Berder.
  • There is a hosted version run by the project, so you can see whether it suits you before installing anything.
Watch for
  • Self-hosting it is a real job, not a setting. It needs Node.js, PostgreSQL 16, Docker for the database, two secrets you generate by hand, and a GitHub App you register yourself before anything works at all.
  • No Node.js version is stated anywhere in the project, and there is no published package, so the only route is clone and build.
  • It has been renamed at least twice. pages-cms/pages-cms and pagescms/pagescms both lead here, and the project's own README still tells you to clone the old address. Code last landed on 23 June 2026, about three and a half months ago.
Similar repositories
Install
git clone https://github.com/hunvreus/pagescms.git
cd pagescms
docker run --name pagescms-db -e POSTGRES_USER=pagescms \
  -e POSTGRES_PASSWORD=pagescms -e POSTGRES_DB=pagescms \
  -p 5432:5432 -d postgres:16
npm install
# Create a file called .env.local containing:
#   DATABASE_URL=postgresql://pagescms:pagescms@localhost:5432/pagescms
#   BETTER_AUTH_SECRET=...
#   CRYPTO_KEY=...
# Generate each secret with: openssl rand -base64 32
npm run setup:github-app -- --base-url http://localhost:3000
npm run db:migrate
npm run dev
Screenshots
hunvreus/pagescms: GitHub preview cardhunvreus/pagescms: Screenshot 1

5,211 stars · AGPL-3.0 at develop/LICENSE — THE DEFAULT BRANCH IS 'develop', so every main-based path fails — verbatim unmodified GPL/AGPL v3 text of 19 November 2007 with no added clauses, AND NO PROJECT COPYRIGHT HOLDER: the only copyright line in the file is the Free Software Foundation's own. · v0.17.2, '10 Aug 07:27' with no year, settled as 10 August 2026 by pkg.go.dev. Release cadence is uneven: v0.16.0 29 Aug 2025, v0.17.0 17 Jul 2026, an eleven-month gap. · Track this in Scout

A small self-hosted blog in one downloaded program, with plain-text posts, no comments and optional federation.

▶Repo detailsthe review · specs · pros & cons · install

What it is

One compiled program written in Go, with either SQLite — a database that is just a file — or MySQL behind it. It publishes plain-text posts, supports several blogs per installation, and can federate, which means other independent social sites can follow and show its posts.

What it is good for. Someone who wants to write in public and is tired of everything else that comes attached. The deliberate absence of features is the feature: there is nothing to moderate and nothing to configure before the first post. It suits a personal site, a changelog, or a quiet company journal.

Stars5,211
LicenceAGPL-3.0 at develop/LICENSE — THE DEFAULT BRANCH IS 'develop', so every main-based path fails — verbatim unmodified GPL/AGPL v3 text of 19 November 2007 with no added clauses, AND NO PROJECT COPYRIGHT HOLDER: the only copyright line in the file is the Free Software Foundation's own.
Latestv0.17.2, '10 Aug 07:27' with no year, settled as 10 August 2026 by pkg.go.dev. Release cadence is uneven: v0.16.0 29 Aug 2025, v0.17.0 17 Jul 2026, an eleven-month gap.
Good
  • One program and one database file. Nothing else has to be installed.
  • Version 0.17.2, dated 10 August 2026 and confirmed through Go's own package index.
  • Nine years old, and the design has not sprawled in that time.
Watch for
  • AGPL-3.0, and the licence file names no copyright holder — the only copyright line in it is the Free Software Foundation's own. AGPL means that if you run a modified copy as a service for other people, you owe them your changes.
  • The install documentation publishes no download link and no download command, states no minimum version of Go or MySQL, and gives no memory or disk figure. The MySQL step asks for an old latin1 character set with no explanation.
  • The release pace is uneven: version 0.16.0 landed in August 2025 and 0.17.0 in July 2026, an eleven-month gap, with 77 open issues and 34 open pull requests behind it. Its default branch is called develop, which trips up anything expecting main.
Similar repositories
  • TryGhost/Ghost

    A full publishing platform with memberships, paid subscriptions and newsletters built in, so far more capable and far more to run.

    Track this in Scout
  • halo-dev/halo

    A self-hosted website and blog system with themes and plugins, closer to a traditional content system.

    Track this in Scout
  • Plume-org/Plume

    The other federated blogging project, and a warning rather than a recommendation: no code since 8 April 2025, which is nearly eighteen months, with no archived notice on the page.

    Track this in Scout
Install
# Download the archive for your operating system from
#   https://github.com/writefreely/writefreely/releases/latest
# then unpack it and change into the folder.
# SQLite needs no database server. For MySQL, create the database first:
#   CREATE DATABASE writefreely CHARACTER SET latin1 COLLATE latin1_swedish_ci;
./writefreely config start
./writefreely keys generate
./writefreely
Screenshots
writefreely/writefreely: Screenshot 1

46,600 stars · AGPL-3.0 at master/LICENSE, verbatim unmodified v3 text with no added clauses, AND NO PROJECT COPYRIGHT HOLDER: the only copyright line is the Free Software Foundation's own, and the 'Copyright (C) <year> <name of author>' template at the end is unfilled. · v3.8.6, '29 Sep 01:39' with no year, settled as 29 September 2026 TWICE — by the ungh releases/latest record and by Docker Hub (b3log/siyuan tag v3.8.6, last_updated 2026-09-29T02:52Z). Pre-release builds v3.8.7-alpha.2/3/4 on 1, 3 and 4 October 2026. · Track this in Scout

A block-based notebook that keeps every note as a file in a workspace folder you own, with links between blocks and search across all of them.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A block-based note application. Block-based means each paragraph is a thing you can link to, move or reuse on its own, not just text in a page. It stores a workspace folder you can back up, copy or read with any other program.

What it is good for. Anyone who has lost notes to a service closing, or who simply wants the file on their own disk. It is the self-hosted answer to the well-known paid notebooks, and the block linking makes it genuinely different from a folder of text files.

Stars46,600
LicenceAGPL-3.0 at master/LICENSE, verbatim unmodified v3 text with no added clauses, AND NO PROJECT COPYRIGHT HOLDER: the only copyright line is the Free Software Foundation's own, and the 'Copyright (C) <year> <name of author>' template at the end is unfilled.
Latestv3.8.6, '29 Sep 01:39' with no year, settled as 29 September 2026 TWICE — by the ungh releases/latest record and by Docker Hub (b3log/siyuan tag v3.8.6, last_updated 2026-09-29T02:52Z). Pre-release builds v3.8.7-alpha.2/3/4 on 1, 3 and 4 October 2026.
Good
  • 19 open issues and 3 open pull requests — an unusually small backlog for a project of this size.
  • Ready-made installers for Windows, macOS and Linux, so no building is involved.
  • Version 3.8.6 of 29 September 2026, with pre-release builds on 1, 3 and 4 October. It is moving fast.
Watch for
  • Keeping two devices in step is a paid feature. The project lists a one-time charge of 64 US dollars for syncing through storage you supply, and 148 US dollars for its own cloud service with 8 GB. The README's line that most features are free for commercial use does not mention that the one most people want is not.
  • AGPL-3.0, and the licence file names no copyright holder beyond the Free Software Foundation's own line. Running a modified copy as a service for others brings real obligations.
  • No memory, disk or processor figure is published anywhere. Building from source needs two separate toolchains and a manual step to fetch Electron 42.9.2 by hand, so for most people the installer or the container is the only sensible route.
Similar repositories
Install
# Easiest: download the installer for your system from
#   https://github.com/siyuan-note/siyuan/releases/latest
# Or run it as a server you reach in a browser:
docker run -d -v /siyuan/workspace:/siyuan/workspace -p 6806:6806 \
  -e PUID=1001 -e PGID=1002 \
  b3log/siyuan serve --workspace=/siyuan/workspace/ \
  --accessAuthCode=CHOOSE-A-LONG-PASSWORD
Screenshots
siyuan-note/siyuan: GitHub preview cardsiyuan-note/siyuan: Screenshot 1siyuan-note/siyuan: Screenshot 2

15,939 stars · MIT at master/LICENSE, stock text, holder named: 'Copyright (c) 2017 Mike Farah'. · v4.54.1, '29 Sep 04:22' with no year, settled as 29 September 2026 by pkg.go.dev. · Track this in Scout

Reads and edits YAML, JSON, XML and CSV files from the command line with jq-like expressions.

▶Repo detailsthe review · specs · pros & cons · install

What it is

One compiled program that queries and edits structured text files using expressions much like those of jq, the long-established tool for JSON. It handles YAML, JSON, XML, CSV, TOML, HCL, INI and properties files, and it can convert between them.

What it is good for. Anyone who edits configuration files and anyone who writes scripts that have to. Reading a value out of a settings file with grep and a text pattern works until the file is laid out slightly differently; this reads the actual structure, so it keeps working. It is the quickest useful thing on this page.

Stars15,939
LicenceMIT at master/LICENSE, stock text, holder named: 'Copyright (c) 2017 Mike Farah'.
Latestv4.54.1, '29 Sep 04:22' with no year, settled as 29 September 2026 by pkg.go.dev.
Good
  • Installed by almost every package manager there is, and also available as a single file you download.
  • MIT licensed, with the holder named: Copyright (c) 2017 Mike Farah.
  • Eleven years old, 15,939 stars, and version 4.54.1 landed on 29 September 2026.
Watch for
  • There is another program called yq. pip install yq installs a different tool by a different author, which behaves differently. Install this one through a package manager or by downloading the file.
  • The project's own README admits the limit that matters: it "attempts to preserve comment positions and whitespace as much as possible, but it does not handle all scenarios". Editing a hand-written configuration file can quietly reformat parts of it, so keep a copy.
  • 248 open issues and 51 open pull requests on what is effectively a one-maintainer project. The expressions are like jq's rather than the same, so knowledge does not transfer cleanly.
Similar repositories
Install
brew install yq                    # macOS or Linux with Homebrew
snap install yq                    # Ubuntu and other snap systems
winget install --id MikeFarah.yq   # Windows
# Or download the single file directly, on Linux:
wget https://github.com/mikefarah/yq/releases/latest/download/yq_linux_amd64 -O /usr/local/bin/yq
chmod +x /usr/local/bin/yq
# Read one value out of a file:
yq '.services.web.image' docker-compose.yml
# Change one value in place:
yq -i '.services.web.image = "nginx:1.29"' docker-compose.yml
Screenshots
mikefarah/yq: GitHub preview card
09

MediaArea/MediaInfoLib

💎 hidden gem

797 stars · TWO FILES WITH DIFFERENT TERMS. master/LICENSE is plain unmodified BSD-2-Clause, holder named: 'Copyright (c) 2002-2025, MediaArea.net SARL'. master/License.html, titled 'MediaInfo(Lib) License', same holder, is the same base PLUS two clauses the first file lacks: a relicensing GRANT to Apache-2.0 or later, LGPL-2.1 or later, GPL-2.0 or later and MPL-2.0 or later; and a mandatory binary-attribution sentence, 'This product uses MediaInfo library, Copyright (c) 2002-2025 MediaArea.net SARL', to be reproduced in the documentation of any product shipping it. GitHub's sidebar reads 'BSD-2-Clause, Unknown licenses found' and the unknown file is the one that matters. · v26.05, '12 May 09:33' with no year, settled as 2026-05-12 by the ungh releases record (exact time match). About five months old against code of 3 Oct 2026. · Track this in Scout

Reports exactly what is inside an audio or video file — codecs, bitrates, real duration and every embedded tag — and never writes to it.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A library — a piece of code other programs use rather than something you open — written in C++, that inspects media files and reports their technical details and tags in one consistent format. Most people want the ready-made program built on it, called MediaInfo, which has versions for every common system.

What it is good for. Anyone who handles video or audio and has to answer "what is this file". It settles arguments about codecs and bitrates in one command, and because it only reads, it is safe to point at a file that matters. Video editors, podcast producers and anyone converting a large archive use it constantly.

Stars797
LicenceTWO FILES WITH DIFFERENT TERMS. master/LICENSE is plain unmodified BSD-2-Clause, holder named: 'Copyright (c) 2002-2025, MediaArea.net SARL'. master/License.html, titled 'MediaInfo(Lib) License', same holder, is the same base PLUS two clauses the first file lacks: a relicensing GRANT to Apache-2.0 or later, LGPL-2.1 or later, GPL-2.0 or later and MPL-2.0 or later; and a mandatory binary-attribution sentence, 'This product uses MediaInfo library, Copyright (c) 2002-2025 MediaArea.net SARL', to be reproduced in the documentation of any product shipping it. GitHub's sidebar reads 'BSD-2-Clause, Unknown licenses found' and the unknown file is the one that matters.
Latestv26.05, '12 May 09:33' with no year, settled as 2026-05-12 by the ungh releases record (exact time match). About five months old against code of 3 Oct 2026.
Good
  • Read-only by design, so there is no way for it to damage what it looks at.
  • Code was pushed on 3 October 2026, and the project has been going since at least 2002 by its own copyright line.
  • Ready-made installers for Windows, macOS, iOS, Android, FreeBSD, Solaris, AppImage, Flatpak, Snap and most Linux distribution families.
Watch for
  • It ships two licence files with different terms, and this is the day's finding. LICENSE is the plain unmodified BSD-2-Clause, with the holder named as Copyright (c) 2002-2025, MediaArea.net SARL. Beside it sits License.html, titled "MediaInfo(Lib) License", which is the same base licence plus two clauses the first file does not have. The first grants something: "You can relicense (including source headers change) MediaInfoLib under Apache License 2.0 or later, and/or GNU Lesser General Public License 2.1 or later, and/or GNU General Public License 2.0 or later, and/or Mozilla Public License 2.0 or later." The second takes something: anyone shipping it inside a product must reproduce the sentence "This product uses MediaInfo library, Copyright (c) 2002-2025 MediaArea.net SARL" in their documentation. GitHub's own sidebar reads "BSD-2-Clause, Unknown licenses found" — the unknown file is the one that matters.
  • The newest tagged release is about five months old — version 26.05, dated 12 May 2026 — while code lands weekly. The in-repository change log stops at the 25.x series and never mentions 26.x at all, so the repository cannot tell you what is in a given build.
  • There are no build instructions in the README. A separate text file names two dependencies and lists supported compilers including Borland C++ Builder 6 and Visual Studio 2005, which is guidance nobody has revisited. 315 open issues and 35 open pull requests. Nobody who is not a programmer should attempt to build this; use an installer.
Similar repositories
  • FFmpeg/FFmpeg

    The program that converts almost any media file into almost any other, and its ffprobe tool reports much the same information; vastly larger in scope and harder to read the output of.

    Track this in Scout
  • exiftool/exiftool

    Reads and also writes metadata, and covers photographs and documents as well as video, so it is the one to reach for when you need to change a tag rather than read it.

    Track this in Scout
  • taglib/taglib

    The narrower library under most music players, covering audio tags rather than full technical detail; covered as entry #9 of Edition 40.

    Track this in Scout
Install
# Most people want the ready-made program, not the library.
# Installers for every common system are listed here:
#   https://mediaarea.net/en/MediaInfo/Download
# Once it is installed, one command reads a file:
mediainfo "holiday.mp4"
# Everything it knows, as machine-readable output:
mediainfo --Output=JSON "holiday.mp4"
Screenshots
MediaArea/MediaInfoLib: GitHub preview card
10

googlefonts/gftools

💎 hidden gem

287 stars · Apache-2.0 at main/LICENSE — LICENSE.txt and LICENSE.md both 404 — stock text, AND THE COPYRIGHT HOLDER IS LEFT AS THE TEMPLATE: 'Copyright {yyyy} {name of copyright owner}' is never filled in, so Google is not named anywhere in it. · v0.10.0, '07 Sep 18:27' with no year, settled as 7 September 2026 TWICE — by the PyPI project page and by the ungh releases record. · Track this in Scout

The command-line tools Google's font team uses to check, fix and package font families.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A collection of small Python programs for working on font families: checking them against a long list of rules, fixing common faults, building web versions, and packaging a family in the shape the Google Fonts library expects. It is a toolbox, not one tool.

What it is good for. Anyone making or publishing a typeface, and anyone who has inherited a font file and needs to know whether it is sound. The checks encode years of other people's mistakes, which is worth more than the code. At 287 stars it is the quietest project in this edition and the most specialised.

Stars287
LicenceApache-2.0 at main/LICENSE — LICENSE.txt and LICENSE.md both 404 — stock text, AND THE COPYRIGHT HOLDER IS LEFT AS THE TEMPLATE: 'Copyright {yyyy} {name of copyright owner}' is never filled in, so Google is not named anywhere in it.
Latestv0.10.0, '07 Sep 18:27' with no year, settled as 7 September 2026 TWICE — by the PyPI project page and by the ungh releases record.
Good
  • One pip command installs it, with no compiler and no system libraries for the basic tools.
  • Code was pushed on 29 September 2026, and version 0.10.0 landed on 7 September 2026, confirmed through Python's own package index.
  • Nine years old, and it is what actually runs against the fonts in a library almost every website uses.
Watch for
  • It is an internal toolbox rather than a product. Sub-commands are documented unevenly, and some of the rules it enforces — particular metadata files, particular naming — only mean anything inside the Google Fonts library.
  • Two of the tools need more than pip. The checking extras want pkg-config installed through Homebrew first, the packager needs Git 2.5 or newer, and two scripts will not run at all until you register a Google Fonts API key and put it in a configuration file by hand.
  • Still before version 1.0 after nine years, with odd historical version numbers, 131 open issues and 25 open pull requests. Its Apache-2.0 licence file leaves the copyright holder as the unfilled template, so Google is not named in it anywhere.
Similar repositories
Install
# Prerequisite: Python 3.10 or newer.
python3 -m venv venv
source venv/bin/activate
pip install gftools
gftools --help
# For the font-checking extras, install pkg-config first:
brew install pkg-config
pip install 'gftools[qa]'
Screenshots
googlefonts/gftools: GitHub preview card

34,935 stars · Apache-2.0 at master/LICENSE, read from the file and PLAIN AND UNMODIFIED with NO commercial carve-out — checked specifically because the company sells a hosted service. ungh's file listing for master shows ONE licence file and no ee/ or enterprise directory anywhere. The copyright holder is NOT named: the appendix template 'Copyright [yyyy] [name of copyright owner]' is unfilled. · v1.19.1, '04 Sep 07:59' with no year, settled as 4 September 2026 TWICE — by the ungh releases/latest record and by Docker Hub. COULD NOT SETTLE: Docker Hub also publishes v1.19.2, v1.19, v1 and latest all last_updated 2026-10-05, while /releases/tag/v1.19.2 returns 404 and both GitHub and ungh still name v1.19.1 as newest, so v1.19.1 is recorded as the newest RELEASED version. · Track this in Scout

Stores the number lists that stand for meaning and finds the closest matches among millions, with ordinary data attached so a search can be narrowed.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A vector database written in Rust. Vector is the name for that long list of numbers, usually called an embedding. It stores them with ordinary data attached, so a search can be narrowed — nearest matches, but only from this customer, only from this year.

What it is good for. Anyone building search over their own documents, or the memory behind an AI assistant that must answer from a particular set of material. The filtering is what sets it apart from a plain library: real questions almost always come with conditions attached.

Stars34,935
LicenceApache-2.0 at master/LICENSE, read from the file and PLAIN AND UNMODIFIED with NO commercial carve-out — checked specifically because the company sells a hosted service. ungh's file listing for master shows ONE licence file and no ee/ or enterprise directory anywhere. The copyright holder is NOT named: the appendix template 'Copyright [yyyy] [name of copyright owner]' is unfilled.
Latestv1.19.1, '04 Sep 07:59' with no year, settled as 4 September 2026 TWICE — by the ungh releases/latest record and by Docker Hub. COULD NOT SETTLE: Docker Hub also publishes v1.19.2, v1.19, v1 and latest all last_updated 2026-10-05, while /releases/tag/v1.19.2 returns 404 and both GitHub and ungh still name v1.19.1 as newest, so v1.19.1 is recorded as the newest RELEASED version.
Good
  • One command starts it, with a web screen at http://localhost:6333/dashboard.
  • Apache-2.0, read from the file and plain, with no commercial carve-out at all — checked on purpose, because the company sells a hosted service, and because this report has found eight licences that were narrower than their summary. There is no enterprise directory in the repository either.
  • Code was pushed on 5 October 2026, the morning this edition was written, and the project started in May 2020.
Watch for
  • The documented first command starts it with no password, in the project's own words an "insecure deployment without authentication". Anyone who opens port 6333 to the internet has published their data.
  • No minimum memory is published, only formulas for working it out. A million entries at 768 numbers each takes roughly 3 GB before the index and the attached data, and getting it wrong shows up as the program being killed rather than as slowness.
  • It is infrastructure, not an application. You still need a program to put things into it and a model to make the number lists in the first place. 488 open issues and 202 open pull requests.
  • Its Apache-2.0 file leaves the copyright holder as the unfilled template.
Similar repositories
Install
# Prerequisite: Docker installed and running.
docker run -p 6333:6333 \
  -v "$(pwd)/qdrant_storage:/qdrant/storage" \
  qdrant/qdrant
# The web screen is then at http://localhost:6333/dashboard
# This starts with NO password. Do not expose port 6333 to the internet.
Screenshots
qdrant/qdrant: GitHub preview cardqdrant/qdrant: Screenshot 1

1,918 stars · Apache-2.0 at main/LICENSE, stock text with the appendix PROPERLY FILLED IN — holder named: 'Copyright 2024 Heinrich Krupp' — and a NOTICE file beside it. One of only six of the twelve in Edition 41 that names a holder at all. · v11.15.0, '03 Oct 16:12' with no year, settled as 3 October 2026 by the PyPI project page (11.14.0 25 Sep, 11.13.0 19 Sep, 11.12.0 14 Sep, 11.11.0 5 Sep 2026 behind it). · Track this in Scout

A self-hosted memory store an AI assistant can read from and write to, searched by meaning rather than exact words.

▶Repo detailsthe review · specs · pros & cons · install

What it is

A service that stores notes and finds them again by meaning rather than by exact words. It speaks MCP, a standard way for assistants to connect to outside tools, and it also offers a plain web interface. It makes the number lists for the search itself, on your machine, so no search text is sent anywhere.

What it is good for. Anyone using a coding assistant on a long-running project who is tired of explaining the same decisions. It is also the narrower, smaller alternative to the big memory libraries: a thing you install and point an assistant at rather than a library you write code against.

Stars1,918
LicenceApache-2.0 at main/LICENSE, stock text with the appendix PROPERLY FILLED IN — holder named: 'Copyright 2024 Heinrich Krupp' — and a NOTICE file beside it. One of only six of the twelve in Edition 41 that names a holder at all.
Latestv11.15.0, '03 Oct 16:12' with no year, settled as 3 October 2026 by the PyPI project page (11.14.0 25 Sep, 11.13.0 19 Sep, 11.12.0 14 Sep, 11.11.0 5 Sep 2026 behind it).
Good
  • This project moved the opposite way from the usual. Its copy on Codeberg carries a notice that development moved to GitHub on 5 September 2026 and that the Codeberg copy is frozen. This report has recorded five projects leaving GitHub for Codeberg since September. This is the first it has found going the other way.
  • Apache-2.0 with the holder properly named — Copyright 2024 Heinrich Krupp — and a NOTICE file beside it. One of only six in this edition that names a holder at all.
  • 21 open issues and 7 open pull requests against 752 closed pull requests. Version 11.15.0 landed on 3 October 2026, confirmed through Python's package index.
Watch for
  • The project's own instructions clone the wrong place. Its advanced-install and developer steps still say git clone https://codeberg.org/doobidoo/mcp-memory-service.git, which is the copy Codeberg itself declares frozen with no further pushes. Clone from GitHub instead.
  • The release pace is extreme and includes security fixes. It went from version 10.66 to 11.15 in about four months, and its own change log records a fix for an authentication bypass rated 9.8 out of 10, where document routes were reachable without signing in. Falling behind on upgrades here is a real risk, and the project is less than a year old.
  • No memory, disk or processor figure is published anywhere, even though it runs a search model and a database on your machine. The README states Python 3.8 or newer while the published package requires 3.10 or newer — the package is right.
Similar repositories
  • mem0ai/mem0

    The best known of these, a library you write code against rather than a service you install, and it calls a paid model to decide what to remember; covered as entry #12 of Edition 28.

    Track this in Scout
  • basicmachines-co/basic-memory

    Keeps the memory as ordinary Markdown files you can read and edit yourself; AGPL-3.0 and a paid cloud tier alongside the free local install.

    Track this in Scout
  • getzep/zep

    Worth naming so it is not mistaken for the product: the repository states it is not Zep's own service, only examples and integrations for the hosted one, so there is nothing here to self-host.

    Track this in Scout
Install
# Prerequisite: Python 3.10 or newer.
python3 -m venv venv
source venv/bin/activate
pip install mcp-memory-service
memory launch
# For the other storage options, clone from GitHub — NOT from Codeberg,
# which the project itself has frozen:
git clone https://github.com/doobidoo/mcp-memory-service.git
Screenshots
doobidoo/mcp-memory-service: GitHub preview carddoobidoo/mcp-memory-service: Screenshot 1

Checked, and left out

These were opened for this edition and did not make it, with the reason.

Orange-OpenSource/hurl

Orange-OpenSource/hurl — already published, Edition 36, only five days ago. Caught by the id check against the final twelve before a single entry was written. Nothing released since earns a repeat.

biomejs/biome

biomejs/biome — already published, Edition 17. It was the replacement picked for hurl and the id check caught it on the second pass.

johnkerl/miller

johnkerl/miller (Edition 37), medialab/xan (Edition 36), ynqa/jnv (Edition 38), nocodb/nocodb (Edition 38) and discourse/discourse (Edition 37) — all already published, all five screened out in ONE pass before any research was spent on them, by writing 46 candidate ids as bare '### N. [owner/repo]' headings into a stub .md and letting check_public_text.py's repeat guard read them against the base ledger. Seven already-published catches in total, which equals the record of 27 September, and this time not one of them reached a draft.

earthly/earthly

earthly/earthly — 12,048 stars, MPL-2.0, last code 23 October 2025, about 11.5 months and inside the eighteen-month bar, no archived banner. Queued rather than left out, because its own README states that it is no longer actively maintained — the maintainers' own decision, not a dormancy reading.

Plume-org/Plume

Plume-org/Plume — 2,224 stars, AGPL-3.0, last code 8 April 2025, about two weeks short of the eighteen-month bar, no archived banner. Queued for a re-check rather than buried.

qdrant v1.19.2

qdrant v1.19.2 — COULD NOT SETTLE. Docker Hub publishes that tag last_updated 2026-10-05 while the GitHub release page for it returns 404 and both GitHub and ungh name v1.19.1 as newest. v1.19.1 of 4 September 2026 is recorded as the newest released version and the disagreement is printed in the edition.

Share this edition
← PreviousNo. 40Next →
Coming tomorrow

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.