Edition No. 42 · 6 Oct 2026

Twelve repositories for watching a machine, keeping things out, and money

Netdata's own release notes tell you not to install the version GitHub serves as its latest, and a trading library with 2,501 stars ships no licence file at all.

By Genn·12 repositories·14 min read

6 October 2026. Twelve open-source projects, each one opened and checked this morning. Ten of the sixteen areas this report covers. Three hidden gems under 3,000 stars. No repeats.

Today's reach went into the five areas that neither of the last two editions touched, and four of the five carry an entry: watching a running machine, keeping unwanted things out, models you run yourself, and trading tools.

We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.

Three things worth knowing, separate from the recommendations

- A project's newest release is not always the one it wants you to have. Netdata's v2.12.0 of 30 September 2026 is what GitHub serves as the latest release, and the release notes for that very version say it "has been discovered to have serious stability issues that cause it to crash randomly on startup" and point to v2.11.1 instead. The warning is inside the thing it warns about. - A licence badge is not a licence file, and sometimes there is no file. Ta4j has 2,501 stars, nine years of history and a release cut yesterday, and we could not find a licence file at any of the eight paths we tried. The "MIT" on its page appears to come from a link in the readme to someone else's website, and no copyright holder is named anywhere in the repository. Seven of today's twelve licence files were read in full; four of them name nobody at all. - Documentation can lose a fact that people relied on. Ollama used to publish how much memory each model size needs. That table is gone — we checked the readme, the documentation site, the graphics-card page, the questions page and the download page. What remains relates a graphics card's own memory to how much text a model can hold, which answers a different question. There is now no published way to know whether a model will run before trying it.

If you only do three things

  1. aquasecurity/trivy (#3) — ten minutes, one command, and it changes nothing on the machine. It reads a project folder or a packaged program and lists the known security holes inside it, with the severity of each. Today's gold.
  2. AnalogJ/scrutiny (#2) — half an hour, one container. It reads the health figures that hard drives already keep about themselves and draws them as a web page, so a disk that is quietly dying shows up before it takes the files with it.
  3. pi-hole/pi-hole (#4) — one evening, one small always-on computer. Ads and tracking are blocked for every device in the house at once, including phones and televisions, with nothing installed on any of them. ---

Netdata's newest release is one it tells you not to install

Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.

80,789 stars · GPL-3.0-or-later · v2.12.0 (2026-09-30) · Track this in Scout

Draws hundreds of live charts about a single computer with almost no setting up.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Netdata is a program you install on a machine; it finds what is running by itself and starts charting it. The charts appear on a web page served by that same machine, at port 19999.

What it is good for. Anyone who runs a server and only finds out something is wrong when a person complains. Also useful on a home machine that stores family photographs or backups, because the charts make a filling disk or a failing network obvious at a glance.

Stars80,789
LicenceGPL-3.0-or-later
Latestv2.12.0 (2026-09-30)
Good
  • One command installs it, and it discovers what to measure without being told.
  • The charts update every second, which is far finer than most monitoring tools and makes short spikes visible.
  • The project publishes honest sizing figures: "1%-5% of a single core with default settings", "100-200 MB on an empty system" and "250-350 MB in typical production", and about 4 GiB of disk by default.
Watch for
  • The newest release is one the project tells you not to run. The release notes for v2.12.0 of 30 September 2026 say it "has been discovered to have serious stability issues that cause it to crash randomly on startup" and advise using "the latest known working version (v2.11.1)". GitHub still shows v2.12.0 as the latest release, so copying the obvious thing installs the broken one.
  • The one-line installer's defaults sign you up for nightly builds, automatic updates and anonymous usage reporting. You have to know to add --stable-channel --disable-telemetry to avoid all three.
  • Only the part that runs on the machine is open source. The repository's own notes say the hosted service is proprietary and the web interface itself is closed source, free to use. The licence file is GNU GPL version 3 (a licence that requires anyone distributing a changed copy to publish their changes), and it names no Netdata copyright holder at all — the only copyright line in it belongs to the Free Software Foundation.
Similar repositories
Install
# Needs: a Linux machine with systemd, root access, and outgoing internet.
wget -O /tmp/netdata-kickstart.sh https://get.netdata.cloud/kickstart.sh
sh /tmp/netdata-kickstart.sh --stable-channel --disable-telemetry
Screenshots
netdata/netdata: GitHub preview cardnetdata/netdata: Screenshot 1netdata/netdata: Screenshot 2

8,300 stars · MIT · v0.9.5 (2026-09-30) · Track this in Scout

Shows whether the drives in a machine are healthy, failing, or already in trouble.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Scrutiny runs the standard drive-health tool smartctl on a schedule and stores what it reads in a time-series database, so you see trends and not just today's number. It ships as a Docker image (Docker is a way to run a program inside its own sealed box, so it cannot disturb anything else on the machine).

What it is good for. Anyone whose photographs, recordings or backups sit on drives nobody is watching. The useful part is not the raw numbers, which are hard to read, but the verdict Scrutiny puts on top of them and the history behind it.

Stars8,300
LicenceMIT
Latestv0.9.5 (2026-09-30)
Good
  • It turns an obscure, hard-to-read set of drive figures into a page anyone can understand.
  • It keeps the history, so a slow decline over months is visible rather than a single reading today.
  • MIT licence (a very short, very permissive licence with no conditions beyond keeping the notice), read from the file, plain and unmodified, with the holder named: "Copyright (c) 2020 Jason Kulatunga".
Watch for
  • The setup is hand-written. There is no installer. You must list every drive in the command by its system name, such as /dev/sda, and getting one wrong leaves an empty page with no explanation of why.
  • It needs deep access to the hardware to work, which the command grants with --cap-add SYS_RAWIO and one --device flag per drive; solid-state NVMe drives also need --cap-add SYS_ADMIN. And the web page has no password at all in the documented setup, so anyone on the same network can read it.
  • It runs a full time-series database whose data grows for as long as it is installed, and the project publishes no memory or disk figure anywhere, so there is nothing to plan storage against.
Similar repositories
Install
# Needs: Docker installed, and the names of your drives (/dev/sda, /dev/sdb, ...).
docker run -p 8080:8080 -p 8086:8086 --restart unless-stopped \
  -v `pwd`/scrutiny:/opt/scrutiny/config \
  -v `pwd`/influxdb2:/opt/scrutiny/influxdb \
  -v /run/udev:/run/udev:ro \
  --cap-add SYS_RAWIO \
  --device=/dev/sda \
  --device=/dev/sdb \
  --name scrutiny \
  ghcr.io/analogj/scrutiny:latest-omnibus
Screenshots
AnalogJ/scrutiny: GitHub preview cardAnalogJ/scrutiny: Screenshot 1

38,100 stars · Apache-2.0 · v0.75.0 (2026-10-01) · Track this in Scout

Lists the known security holes in a project's parts and in packaged programs.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Trivy is a single command-line program that scans container images, ordinary folders, code repositories and infrastructure settings files. It compares what it finds against public databases of reported security problems.

What it is good for. Anyone who ships software without a security team to check it, and anyone running programs somebody else packaged. Running it on a folder that already exists, before touching anything, is a ten-minute answer to "is there anything badly wrong in here".

Stars38,100
LicenceApache-2.0
Latestv0.75.0 (2026-10-01)
Good
  • It is read-only, so there is no risk in trying it, and the first useful answer arrives in one command.
  • It covers more than one kind of problem: known holes in code libraries, mistakes in settings files, and passwords left in the files by accident.
  • Apache licence 2.0 (a permissive licence that also grants patent rights), read from the file at main/LICENSE and plain and unmodified, with no commercial carve-out.
Watch for
  • The copyright holder in the licence file was never filled in. The line reads exactly Copyright [yyyy] [name of copyright owner] — the template Apache ships, left as it came. The licence terms themselves are standard; nobody is named as owning the work.
  • Output is a long wall of terminal text, with no interface. It tells you a problem exists and leaves the judgement about what matters to you.
  • The documented way to scan container images mounts /var/run/docker.sock into the scanner, which gives that container root-level control over the whole machine. It is one copied line and it is easy to run without understanding what was granted.
Similar repositories
Install
# Debian or Ubuntu. Needs: sudo, and an internet connection for the first scan.
sudo apt-get install -y wget gnupg
wget -qO - https://aquasecurity.github.io/trivy-repo/deb/public.key \
  | gpg --dearmor | sudo tee /usr/share/keyrings/trivy.gpg > /dev/null
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" \
  | sudo tee -a /etc/apt/sources.list.d/trivy.list
sudo apt-get update
sudo apt-get install -y trivy
# Scan a folder that already exists:
trivy fs .
Screenshots
aquasecurity/trivy: GitHub preview cardaquasecurity/trivy: Screenshot 1

60,800 stars · EUPL-1.2 · v6.4.3 (2026-07-06) · Track this in Scout

Blocks advertising and tracking for every device on a network by refusing to look up those addresses.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Pi-hole is a name-lookup server with blocklists in front of it. Devices ask it for addresses, and for anything on a list it answers that there is nothing there, so the advertisement never loads.

What it is good for. Any household or small office with devices that cannot run an ad blocker of their own — smart televisions, games consoles, phones with locked-down browsers. It also gives a plain log of which device asked for what, which is often the first time anyone sees how much background traffic a television produces.

Stars60,800
LicenceEUPL-1.2
Latestv6.4.3 (2026-07-06)
Good
  • One blocking setup covers every device on the network, including ones that can never install software.
  • The published requirements are small: "512MB RAM", "Min. 2GB free space, 4GB recommended", and the documentation says "Pi-hole is very lightweight and does not require much processing power."
  • Thirteen years old, actively maintained, with 26 open issues against 17 open requests to change the code — an unusually tidy state for a project this size.
Watch for
  • It becomes a single point of failure for the whole network. If that machine is off, rebooting, or its memory card has died, nothing on the network can look up anything until the router change is undone.
  • The documented install pipes a script from the internet straight into a command shell running as the administrator, and the step people actually get stuck on is not the install but changing the router.
  • The licence is the European Union Public Licence version 1.2, read from the file — a copyleft licence that also applies when software is offered over a network, and far less familiar than MIT or GPL. The file also adds a scope note before the licence text: "This license applies to the whole project EXCEPT: any commits made to the master branch prior to the release of version 3.0". Anyone redistributing it should take advice rather than assume it behaves like MIT.
Similar repositories
Install
# Needs: an actively maintained Linux machine that stays on, sudo, port 53 free,
# and a fixed network address for that machine.
curl -sSL https://install.pi-hole.net | bash

182,121 stars · MIT · v0.35.1 (2026-09-29) · Track this in Scout

Downloads and runs AI language models on the computer in front of you.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Ollama is a background program with a small command-line front end and a catalogue of ready-packaged models. It also offers an interface other programs can call, so applications can talk to a local model the way they would talk to a hosted one.

What it is good for. Anyone who wants to use a language model on text that must not leave the building — contracts, medical notes, customer records — and anyone who wants to try models without an account or a card. It is also the simplest way to put a local model behind an existing application.

Stars182,121
LicenceMIT
Latestv0.35.1 (2026-09-29)
Good
  • One command installs it and one more command gets a working model; nothing else to configure.
  • MIT licence, read from the file at main/LICENSE, plain and unmodified, with the holder given as "Copyright (c) Ollama".
  • Very actively developed: 182,121 stars, code pushed on 4 October 2026, and release v0.35.1 dated 29 September 2026.
Watch for
  • The memory guidance has been removed from the documentation. The project used to state how much memory each model size needs. Today no model-size-to-memory table exists anywhere in its documentation — we checked the readme file, the documentation site, the graphics-card page, the questions page and the download page. The only published memory figures relate a graphics card's own memory to how much text the model can hold at once: "< 24 GiB VRAM: 4k context", "24-48 GiB VRAM: 32k context", ">= 48 GiB VRAM: 256k context". So there is no published way to know in advance whether a model will run; you find out by watching it fail or crawl.
  • Models are multi-gigabyte downloads that are kept for ever and never cleaned up, under ~/.ollama/models on Linux and macOS. Nothing warns before the disk fills.
  • The background program listens for requests with no password by default. One wrong setting of OLLAMA_HOST opens the model to the network. And the MIT licence covers Ollama's own code only — each model you download carries its own separate licence, which MIT says nothing about.
Similar repositories
Install
# macOS and Linux:
curl -fsSL https://ollama.com/install.sh | sh
# Then run a model (this downloads it the first time):
ollama run gemma3
Screenshots
ollama/ollama: GitHub preview cardollama/ollama: Screenshot 1
06

ta4j/ta4j

💎 hidden gem

2,501 stars · MIT (claimed; NO LICENCE FILE IN THE REPOSITORY) · 0.26.0 (2026-10-05) · Track this in Scout

A Java toolbox of chart indicators and a tester for trading rules.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Ta4j provides the common indicators — moving averages, momentum measures, volatility bands — and a framework for stating a rule, running it over historical prices and reporting what it would have done. It is published as a Java library, fetched through the standard Java package tool.

What it is good for. Someone who already writes Java and wants to test a trading idea without building the indicator mathematics themselves. It is the most complete answer in Java; almost everything comparable is written in Python.

Stars2,501
LicenceMIT (claimed; NO LICENCE FILE IN THE REPOSITORY)
Latest0.26.0 (2026-10-05)
Good
  • Nine years old, 2,501 stars, with code pushed on the morning of this edition and release 0.26.0 dated 5 October 2026.
  • It covers both halves of the job — the indicators and the strategy testing — where most libraries do only one.
  • This is one of the few release pages we read today that printed its own year. Every other project in this edition showed a date with no year, which had to be settled against a second source. Ta4j's 2026-10-05 was readable as it stood and matched the Java package registry exactly.
Watch for
  • The repository contains no licence file. We tried LICENSE, LICENSE.md, LICENSE.txt, MIT-LICENSE, COPYING, COPYING.md, License.html and a LICENSES folder, on the default branch and the other usual branch names; every one returned "not found". GitHub shows "MIT" in the sidebar, and that appears to come from a link in the readme file to the MIT licence text on another website. The only statement inside the repository is in the build file: <name>MIT License</name> with the comment "All source code is under the MIT license." and no web address. No copyright holder is named anywhere we could read. That is a real gap if the work is ever redistributed or put through a legal review.
  • The readme file states "ta4j requires Java 25+", and the build file enforces it. Java 25 is very new; a typical or company-managed computer will have Java 17 or Java 21, so a new Java installation comes first.
  • It is a library with nothing to run. There is no window, no command, no example you can click. And a subtle mistake in an indicator does not break a build — it produces a plausible, wrong number about money. The build file on the main branch also still says 0.23.1-SNAPSHOT, three minor versions behind the 0.26.0 that is actually published.
Similar repositories
Install
# Needs: Java 25 or newer, plus Maven or Gradle. Check what you have:
java -version
Screenshots
ta4j/ta4j: Screenshot 1ta4j/ta4j: Screenshot 2ta4j/ta4j: Screenshot 3ta4j/ta4j: Screenshot 4

49,178 stars · MIT · v0.9.7 (2025-08-15) · Track this in Scout

A Python research workbench for machine-learning experiments on market data.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Qlib is a set of Python components that cover the whole path from stored price history to a scored prediction, with a collection of ready-made models to compare. Microsoft publishes it, under a plain MIT licence.

What it is good for. Someone with Python experience who wants to test a prediction idea properly rather than by eye — with separate training and testing periods and a fair comparison against other models. The value is the discipline it imposes, not the models themselves.

Stars49,178
LicenceMIT
Latestv0.9.7 (2025-08-15)
Good
  • 49,178 stars, created in August 2020, with code pushed on 5 October 2026 — the day before this edition.
  • MIT licence, read from the file at main/LICENSE, plain and unmodified, holder named as "Copyright (c) Microsoft Corporation."
  • It supplies the scaffolding that most people building this themselves get wrong: proper separation of training and testing periods, and a comparable scoring of several models at once.
Watch for
  • The newest release is about fourteen months old. Version 0.9.7 is dated 15 August 2025 — the release page prints only "15 Aug", with no year, and we settled it against both the project's own release records and the Python package index, which gives 0.9.7 as 15 August 2025. Code is pushed almost daily, so installing the published package gives something materially older than the repository.
  • The readme file states the official datasets are temporarily unavailable and points to community-provided alternatives instead. So the first tutorial can stop dead, and the fallback is market data of uncertain origin.
  • There is nothing to open. Setting it up means creating a Python environment, compiling parts of it, fetching data separately and writing scripts. The project publishes no memory, disk or processor figure anywhere. Nothing here is advice about money, and a model that scores well on past prices is not evidence about future ones.
Similar repositories
Install
# Needs: Python 3.8 to 3.12. The project recommends the conda environment tool.
conda create -n qlib python=3.11 -y
conda activate qlib
# On an Apple-silicon Mac only, first:  brew install libomp
pip install pyqlib
# Market data has to be fetched separately:
python -m qlib.cli.data qlib_data --target_dir ~/.qlib/qlib_data/cn_data --region cn
Screenshots
microsoft/qlib: Screenshot 1microsoft/qlib: Screenshot 2microsoft/qlib: Screenshot 3microsoft/qlib: Screenshot 4

3,217 stars · AGPL-3.0 · v0.7.6 (2026-09-06) · Track this in Scout

Charts and reports over a plain-text money ledger you already keep.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Paisa reads a plain-text accounting file and serves a web page of charts, budgets, retirement projections and investment summaries. It ships as a desktop application, a single command-line file, and a container image.

What it is good for. Anyone already keeping accounts in ledger, hledger or beancount format who is tired of reading numbers in a terminal. Also for anyone considering plain-text accounting who wants to see what the reports look like before committing.

Stars3,217
LicenceAGPL-3.0
Latestv0.7.6 (2026-09-06)
Good
  • A desktop application for Linux, macOS and Windows, so there is a route that needs no terminal at all.
  • It reads all three common plain-text formats — ledger, hledger and beancount — chosen with one line in its settings file.
  • The ledger program is included, so that route works with nothing else installed. The documentation is explicit about the other two: "Paisa ships with ledger binary. If you use hledger or beancount, make sure that the binaries are installed."
Watch for
  • You still have to understand double-entry bookkeeping and write the transactions by hand or import them. Its own questions page sends newcomers off to learn the underlying tool first.
  • The licence is AGPL-3.0, read from the file — but not at LICENSE or LICENSE.md, which both return "not found". It is at master/COPYING. The text is the standard Affero licence, unmodified, and it names no project copyright holder: the only copyright line in the file is the Free Software Foundation's own. Personal use is unaffected; offering a changed copy to other people over a network means publishing your changes.
  • The command-line and container routes serve a web page on port 7500 with no password unless you switch sign-in on, so it should not be exposed beyond the machine itself. On macOS you also have to strip the download warning flag by hand. One maintainer, 82 open issues, and no published memory, disk or processor figure.
Similar repositories
Install
# Easiest: download the desktop app for your system from the releases page.
# On Debian or Ubuntu:
sudo dpkg -i paisa-app-linux-amd64.deb
# Command line instead:
chmod u+x paisa && sudo mv paisa /usr/local/bin
paisa serve        # then open http://localhost:7500
# Or with Docker:
docker run -p 7500:7500 -v /path/to/paisa:/root/Documents/paisa/ ananthakumaran/paisa:latest
Screenshots
ananthakumaran/paisa: GitHub preview card

5,895 stars · AGPL-3.0 · no GitHub releases at all · Track this in Scout

Turns a shared email address into a list of support tickets with owners and history.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Zammad is a help-desk application with email, web forms, telephone notes and chat in one place, searchable, with rules that assign and escalate tickets. It is fourteen years old and maintained by a foundation.

What it is good for. A small team that has outgrown a shared mailbox and needs to know who is answering what, which questions keep coming back, and what has been waiting too long. It is the right size when "who replied to this?" has become a daily question.

Stars5,895
LicenceAGPL-3.0
Latestno GitHub releases at all
Good
  • AGPL-3.0, read from the file at develop/LICENSE, the standard text completely unmodified. We also checked specifically for a paid-features carve-out: the two other licence files at the top of the repository are third-party credits only, with no Zammad terms in them. The commercial offering is support and services, not held-back code.
  • The project publishes its hardware needs plainly, which most self-hosted applications do not: minimum "2 CPU cores" and "6 GB of RAM (+4 GB if you want to run Elasticsearch on the same server)".
  • Real ticket discipline out of the box — ownership, escalation rules, full history, and search across everything.
Watch for
  • The install is system administration. The documented order has you fix the machine's language settings by hand, install the Elasticsearch search engine first, and only then install Zammad, plus a database and a web server with certificates.
  • The memory floor is a real floor: 6 GB before the search engine and 10 GB with it on the same machine, so a cheap small server will not run it. And no disk figure is published at all — the documentation says "We can't make any disk space recommendations, as this highly depends on how you work." — so storage for mail attachments is a guess.
  • It publishes no releases on GitHub at all. The releases page says "There aren't any releases here", and the project's own release records are empty too. Version numbers come from its package repository instead, so there is no page on GitHub to read before upgrading. Self-hosting is free, but vendor support for it starts at €2,999 a year, and the optional AI features are billed at "€0.03 per AI call". The licence is also the usual Affero obligation: customise it for people who use it over a network and you must offer them your changes. 430 open issues against 25 open change requests.
Similar repositories
Install
# Ubuntu 22.04. Needs: sudo, a UTF-8 language setting, and Elasticsearch first.
sudo apt install curl apt-transport-https gnupg
sudo locale-gen en_US.UTF-8
echo "LANG=en_US.UTF-8" | sudo tee /etc/default/locale
sudo curl -fsSL "https://go.packager.io/srv/deb/zammad/zammad/gpg-key.gpg" \
  -o /usr/share/keyrings/zammad.gpg && sudo chmod 644 /usr/share/keyrings/zammad.gpg
sudo curl -fsSL "https://go.packager.io/srv/zammad/zammad/stable/installer/ubuntu/22.04.list" \
  -o /etc/apt/sources.list.d/zammad.list
sudo apt update
sudo apt install zammad
sudo systemctl start zammad
Screenshots
zammad/zammad: GitHub preview card

4,105 stars · MIT · 4.76.0 (2026-09-30) · Track this in Scout

Runs a GitLab build-and-test pipeline on the machine in front of you.

▶Repo detailsthe review · specs · pros & cons · install

What it is

The program reads a project's .gitlab-ci.yml file and carries out the jobs in it, either directly in a shell or inside containers, the way GitLab's own runners would.

What it is good for. Anyone who has pushed the same commit eleven times to fix a typo in a build file. It removes the wait entirely, and it keeps the failed attempts out of the project's shared history.

Stars4,105
LicenceMIT
Latest4.76.0 (2026-09-30)
Good
  • MIT licence, read from the file at master/LICENSE, plain and unmodified, with the holder named: "Copyright (c) 2025 Mads Jon Nielsen".
  • Packaged for many systems — a package repository for Debian and Ubuntu, Homebrew for macOS, Arch, npm and Bun — so there is a route that fits most machines.
  • Busy and current: 4,105 stars, release 4.76.0 of 30 September 2026, code pushed on 5 October 2026.
Watch for
  • It is only useful where a .gitlab-ci.yml file already exists, and the output is raw build logs in a terminal. There is nothing to click.
  • Running jobs in containers pulls real build images, which are commonly several gigabytes. No memory, disk or processor requirement is published anywhere, so there is no figure to plan against. The readme file does state that the bash shell "must be above or equal 4.x.x", and the version macOS ships is older than that, so macOS users need a newer bash first.
  • It reads real build secrets from a plain, unencrypted file in your home folder, and the shell mode runs the job scripts directly on the machine with your own permissions. Running a pipeline from a repository you do not trust runs its commands with your access.
Similar repositories
Install
# Debian or Ubuntu, the route the project prefers:
sudo wget -O /etc/apt/sources.list.d/gitlab-ci-local.sources \
  https://gitlab-ci-local-ppa.firecow.dk/gitlab-ci-local.sources
sudo apt-get update
sudo apt-get install gitlab-ci-local
# Or, if Node.js and npm are already installed:
npm install -g gitlab-ci-local
# macOS, which also needs a newer bash:
brew install bash gitlab-ci-local
Screenshots
firecow/gitlab-ci-local: GitHub preview cardfirecow/gitlab-ci-local: Screenshot 1
11

googlefonts/fontmake

💎 hidden gem

889 stars · Apache-2.0 · v3.12.1 (2026-06-02) · Track this in Scout

Turns font source files into finished, installable font files.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Fontmake is a Python command-line program that compiles .glyphs or UFO source files into TrueType and OpenType fonts, and into the single-file variable fonts that cover a whole family. It is the tool Google Fonts uses to build its own library.

What it is good for. Anyone with a typeface in a design tool who needs installable files, and anyone maintaining a font project who wants its builds to run the same way every time instead of being exported by hand.

Stars889
LicenceApache-2.0
Latestv3.12.1 (2026-06-02)
Good
  • It is the tool the Google Fonts library itself is built with, which is a strong statement about whether it works on real font projects.
  • Apache licence 2.0, read from the file at main/LICENSE, plain and unmodified, with no conditions beyond attribution — a genuinely safe licence here.
  • Small, old and current: 889 stars, created in December 2015, release 3.12.1 of 2 June 2026 and code pushed on 14 September 2026.
Watch for
  • The licence file's copyright holder was never filled in. The line reads exactly Copyright [yyyy] [name of copyright owner], so Google is not named in it anywhere. The terms are standard; nobody is named as owning the work.
  • It is one link in a chain, not a solution. It expects valid source files, and when something fails the message comes from fontTools, glyphsLib or ufo2ft rather than from fontmake, so understanding it needs real font-engineering knowledge.
  • 263 open issues against 7 open change requests, and Google is openly building a replacement in another language — googlefonts/fontc, whose stated aim is "Wherein we pursue oxidizing fontmake". Command line only; no window, no buttons, and you need the flag vocabulary before anything comes out.
Similar repositories
Install
# Needs: Python 3.10 or later. The project recommends a separate environment.
python3 -m venv ~/venvs/fontmake
source ~/venvs/fontmake/bin/activate
pip3 install fontmake
# Build TrueType and OpenType files from a Glyphs source:
fontmake -g MyFont.glyphs -o ttf otf
Screenshots
googlefonts/fontmake: GitHub preview card
12

tinytag/tinytag

💎 hidden gem

842 stars · MIT · 2.3.2 (2026-09-07) · Track this in Scout

Reads the hidden information inside audio files from Python, with no other software needed.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Tinytag is a pure-Python library — no compiled parts, no other packages — that reads tags and technical details from MP3, FLAC, MP4, Ogg, Wave and other formats through one small interface.

What it is good for. Anyone with a large folder of audio who needs to make a list of it, find duplicates, check which files are missing their album name, or sort a backlog of recordings. The attraction is that it installs anywhere Python runs and brings nothing with it.

Stars842
LicenceMIT
Latest2.3.2 (2026-09-07)
Good
  • No other software required at all. The readme file states it is "Pure Python, no dependencies." — so it installs on a server, inside a container, or on a locked-down machine with nothing extra.
  • One interface covers every common audio format, so code written for MP3 works unchanged on FLAC.
  • MIT licence, read from the file at master/LICENSE, plain and unmodified, with the holders properly named: "Copyright (c) 2014-2026 Tom Wallroth, Mat (mathiascode), et al." — and an unusually tidy project, 3 open issues against 2 open change requests, twelve years old.
Watch for
  • It is a library, not a program. Using it means writing Python; from tinytag import TinyTag is the starting point and there is nothing to click.
  • It reads and does not write. To correct or add tags you need a different library, mutagen or eyeD3.
  • A small project with essentially one active maintainer and no organisation behind it. It has already changed owner once, from devsnd to tinytag, and the only support channel is its issue list. Low activity is normal for a stable library, but there is nobody to call.
Similar repositories
Install
# Needs: Python 3.7 or later, and pip.
python3 -m pip install tinytag
Screenshots
tinytag/tinytag: GitHub preview card

Checked, and left out

Nothing to show for this edition. Recording the repositories that were checked and rejected began with Edition No. 4, and every edition from there on has the list.

Share this edition
← PreviousNo. 41Next →
Coming tomorrow

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.