Edition No. 43 · 7 Oct 2026

Twelve repositories for checking what you are actually running

A helpdesk asking for an eight-year-dead database, an invoicing app you may not host for other people, and ten more projects read line by line.

By Genn·12 repositories·16 min read

Wednesday 7 October 2026. Twelve open-source repositories, opened and read one by one. No theme, on purpose.

Today's edition is about what the install page does not say. One helpdesk with 3,906 stars still publishes a database requirement that stopped getting security fixes eight years ago. One invoicing application with 10,239 stars is on GitHub and is not open source. And eight of the twelve licence files read this morning name no copyright holder of their own.

We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.

Three things worth knowing, separate from the recommendations

- An install guide can be eight years out of date and still be the first thing a newcomer reads. osTicket's README and its official install page both give "MySQL database version 5.5 (or greater)" as the requirement. MySQL 5.5 stopped receiving security fixes in December 2018. The same documentation then links to MySQL 8.0 and MariaDB 10.11 downloads, so the project's own pages disagree, and the stale figure is the one printed as the requirement. - Being on GitHub does not make software open source. Invoice Ninja has 10,239 stars and ships the Elastic License 2.0, which says you "may not provide the software to third parties as a hosted or managed service" and "may not move, change, disable, or circumvent the license key functionality". Its own repository description is honest about it and says "source-available". Three of the four invoicing projects opened this morning carry a licence of this kind; only InvoicePlane, at 3,150 stars, is plainly open source. - Eight of the twelve licence files read this morning name no copyright holder of their own. Lighthouse and fontc leave the Apache appendix as the unfilled Copyright [yyyy] [name of copyright owner]. Aptabase, AdGuard Home, FreshRSS, osTicket and HandBrake ship only the Free Software Foundation's own line. Invoice Ninja's licence has no such field at all. Four named a real holder: detect-secrets, SQL Studio, delta and FastFlix. That is double the four-of-twelve recorded on 6 October, and it is worth saying because the GitHub badge looks identical either way.

If you only do three things

  1. dandavison/delta (#9) — two minutes. One install, two lines in a settings file, and every code difference Git prints becomes readable: colours, line numbers, and the file name on its own row. Nothing else changes.
  2. GoogleChrome/lighthouse (#1) — ten minutes, read-only, on a web page that already exists, and the gold of the edition. It loads the page in a real browser, runs about a hundred checks, and prints a scored list of what is slow, what is broken and what a search engine cannot read.
  3. Yelp/detect-secrets (#4) — twenty minutes, on a code folder that already exists. It finds passwords and keys that were typed into the code by mistake, and writes the list to a file so that only new ones are reported from then on.

A helpdesk still asks for a database that died in 2018

Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.

30,842 stars · Apache-2.0, read from /blob/main/LICENSE — plain and unmodified, but the appendix is left as the template 'Copyright [yyyy] [name of copyright owner]'; the real notice lives in source headers as 'Copyright 2016 Google LLC' · v13.5.0 (2026-09-18), read from /releases/latest as a yearless '18 Sep 16:18' and settled by the ungh releases record (2026-09-18T16:18:20Z); package.json agrees on 13.5.0 · Track this in Scout

Loads one web page in a real browser, runs about a hundred checks, and prints a scored report on speed, accessibility and search readiness.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Lighthouse is a program written by the team that makes the Chrome browser. It opens a page the way a visitor would, measures how long each part takes to appear, and then reports five scores: speed, accessibility, best practice, search readiness, and progressive web app.

What it is good for. Anyone who publishes a web page and has never been told what is wrong with it. It is the same measuring engine that sits behind the Chrome developer tools and behind Google's own PageSpeed Insights website, so the numbers agree with the numbers other people will quote back. It is most useful in two situations: a site that feels slow and nobody can say why, and a page that is not appearing in search results.

Stars30,842
LicenceApache-2.0, read from /blob/main/LICENSE — plain and unmodified, but the appendix is left as the template 'Copyright [yyyy] [name of copyright owner]'; the real notice lives in source headers as 'Copyright 2016 Google LLC'
Latestv13.5.0 (2026-09-18), read from /releases/latest as a yearless '18 Sep 16:18' and settled by the ungh releases record (2026-09-18T16:18:20Z); package.json agrees on 13.5.0
Good
  • It is free, and it is written by the people who make the browser that most visitors use.
  • It only reads. It visits the page, measures, prints, and stops. Nothing on the page is altered.
  • The report explains each failure in words, with a link to a page describing the fix.
Watch for
  • It needs Node.js (a way to run JavaScript programs outside a browser) version 22 or later, and a real Chrome or Chromium browser version 66 or later installed on the machine. Neither is heavy, but both have to be there.
  • The project publishes no memory, disk or processor figure anywhere. It drives a whole browser, so a small machine running other work will feel it.
  • The licence file leaves the copyright holder as the unfilled template, Copyright [yyyy] [name of copyright owner]. The real notice lives in the source files, which say "Copyright 2016 Google LLC". The terms themselves are plain Apache-2.0, which is permissive and carries no commercial restriction.
Similar repositories
Install
npm install -g lighthouse
lighthouse https://example.com --view
Screenshots
GoogleChrome/lighthouse: GitHub preview cardGoogleChrome/lighthouse: Screenshot 1GoogleChrome/lighthouse: Screenshot 2GoogleChrome/lighthouse: Screenshot 3GoogleChrome/lighthouse: Screenshot 4
02

aptabase/aptabase

💎 hidden gem

1,831 stars · AGPL-3.0-only, read from /blob/main/LICENSE — plain and unmodified, and the ONLY copyright line is the FSF's own 'Copyright (C) 2007 Free Software Foundation, Inc.'; no project line at all. The client SDKs are MIT per the README · NO RELEASES, EVER — /releases/latest says 'There aren't any releases here.' and the ungh releases array is empty. A determination, not a gap. The documented install pulls the container tag ':main' · Track this in Scout

Simple, privacy-first usage figures for phone, desktop and web apps, run on hardware you control.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Aptabase is a small analytics service with a web page showing charts and a set of small libraries you add to an app. The libraries report plain events — an app opened, a screen reached — and the service counts them.

What it is good for. Someone who ships an app and has no idea how it is used. Most analytics tools are built for websites; this one is built around phone and desktop apps, which is the gap. It is also the right shape for anyone who does not want to send customer behaviour to a third party, because every part of it runs where you put it.

Stars1,831
LicenceAGPL-3.0-only, read from /blob/main/LICENSE — plain and unmodified, and the ONLY copyright line is the FSF's own 'Copyright (C) 2007 Free Software Foundation, Inc.'; no project line at all. The client SDKs are MIT per the README
LatestNO RELEASES, EVER — /releases/latest says 'There aren't any releases here.' and the ungh releases array is empty. A determination, not a gap. The documented install pulls the container tag ':main'
Good
  • The pieces you embed in an app are MIT licensed, which means no conditions at all on the app itself. Only the server part carries the stricter licence.
  • It is deliberately small. There are no funnels, no session recordings and no experiments to configure.
  • Code landed on 1 October 2026, six days before this edition.
Watch for
  • It publishes no releases at all, and never has. The releases page says, in its own words, "There aren't any releases here." The install instructions pull a container image tagged main, which means whatever the development branch last built. There is no version to pin and no changelog to read before upgrading.
  • The official setup file contains published passwords. The docker-compose.yml in the project's own self-hosting repository ships POSTGRES_PASSWORD: sTr0NGp4ssw0rd, the same value for ClickHouse, and a fixed AUTH_SECRET. They are in a public repository, so they are no secret at all. Change all four before the thing is reachable from anywhere.
  • The server is AGPL-3.0. If you change the server code and then let other people use it over a network, that licence obliges you to offer them your changed source. The project says so plainly in its own README. Running it unchanged for yourself is fine. Also: the documented setup runs three containers, one of them a ClickHouse database, and the project publishes no memory or disk figure for any of them.
Similar repositories
Install
git clone https://github.com/aptabase/self-hosting
cd self-hosting
Screenshots
aptabase/aptabase: GitHub preview cardaptabase/aptabase: Screenshot 1

3,693 stars · MIT, read from /blob/main/LICENSE — plain and unmodified, holder named 'Copyright (c) 2024 frectonz'. Cargo.toml declares NO license field and no license-file, which is why the crate is not on crates.io · 0.1.53 (2026-08-26), read from /releases/latest as a yearless '26 Aug 15:03' and settled by the ungh releases/latest record (2026-08-26T15:03:19Z). crates.io 404s for this name · Track this in Scout

One command opens a browser page that explores any of nine kinds of database, including CSV and Parquet files.

▶Repo detailsthe review · specs · pros & cons · install

What it is

SQL Studio is a single program that reads a database and serves a small web page describing it. It covers SQLite, libSQL, PostgreSQL, MySQL and MariaDB, DuckDB, ClickHouse and Microsoft SQL Server, plus Parquet and CSV files; ClickHouse is marked as partly supported on its own page.

What it is good for. The moment when a database file lands on a machine and nobody can say what is in it. A full database tool is a large install and a long first hour; this is one file, one command, and a page that answers the obvious questions. It is also useful for a CSV file too large to open in a spreadsheet.

Stars3,693
LicenceMIT, read from /blob/main/LICENSE — plain and unmodified, holder named 'Copyright (c) 2024 frectonz'. Cargo.toml declares NO license field and no license-file, which is why the crate is not on crates.io
Latest0.1.53 (2026-08-26), read from /releases/latest as a yearless '26 Aug 15:03' and settled by the ungh releases/latest record (2026-08-26T15:03:19Z). crates.io 404s for this name
Good
  • Plain, unmodified MIT licence with a named holder, which is the simplest licence situation in this edition.
  • Nine database kinds through one program, so the same habit works whatever the project uses.
  • Two minutes to a working page. No configuration file exists.
Watch for
  • It has no login, and it can write. There is no password option of any kind on the web page. The query box hands whatever you type straight to the database, so DELETE and DROP will run. It opens your own database file for reading and writing; only the bundled demo file is read-only.
  • The documented container command binds to every network interface — --address=0.0.0.0:3030 is printed in the project's own instructions with no warning beside it. Anyone who can reach that port gets a database console with no password. On a laptop it defaults to 127.0.0.1:3030, which is the machine itself only, and that is the safe way to use it.
  • The headline install pipes a script from the internet straight into a shell, and the Windows version also tells you to switch off the execution policy first. The project's Cargo.toml declares no licence field, so the crate is not published to crates.io, and the README still installs version 0.1.52 while 0.1.53 is current. No memory, disk or processor figure is published anywhere.
Similar repositories
Install
docker run -p 3030:3030 frectonz/sql-studio /bin/sql-studio --no-browser --no-shutdown --address=127.0.0.1:3030 sqlite preview
Screenshots
frectonz/sql-studio: GitHub preview cardfrectonz/sql-studio: Screenshot 1frectonz/sql-studio: Screenshot 2frectonz/sql-studio: Screenshot 3frectonz/sql-studio: Screenshot 4

4,633 stars · Apache-2.0, read from /blob/master/LICENSE — plain, nothing appended, and the holder is FILLED IN: 'Copyright 2017-2018 Yelp Inc.' One of only four of the twelve that name a real holder · v1.5.0 (2024-05-06), read from /releases/latest as a yearless '06 May 18:05' and settled by the PyPI project page ('Released: May 6, 2024'). Twenty-nine months old, against code pushed 2026-04-02 — a release date is not a code date · Track this in Scout

Lists the passwords and keys that were typed into code by mistake, and records the known ones in a baseline so only new findings are reported.

▶Repo detailsthe review · specs · pros & cons · install

What it is

detect-secrets is a command-line program that scans files for text shaped like a credential, using both pattern rules and a measure of randomness. Its distinguishing idea is the baseline file: the known findings are recorded once, so the tool can be made part of everyday work without a wall of old warnings.

What it is good for. Anyone who writes code without a colleague to review it. The dangerous case is not the password you remember putting in; it is the one from eight months ago in a file you have not opened since. Because it can run automatically before each save to the project history, it also stops the next one.

Stars4,633
LicenceApache-2.0, read from /blob/master/LICENSE — plain, nothing appended, and the holder is FILLED IN: 'Copyright 2017-2018 Yelp Inc.' One of only four of the twelve that name a real holder
Latestv1.5.0 (2024-05-06), read from /releases/latest as a yearless '06 May 18:05' and settled by the PyPI project page ('Released: May 6, 2024'). Twenty-nine months old, against code pushed 2026-04-02 — a release date is not a code date
Good
  • The baseline file is the part that makes it usable. Without it, a scanner on an old project prints hundreds of findings nobody will read.
  • Plain, unmodified Apache-2.0 with a real named holder: "Copyright 2017-2018 Yelp Inc." Four of today's twelve licence files manage that.
  • It installs with one command, needs no server, and holds no data of its own.
Watch for
  • The newest release is v1.5.0 of 6 May 2024, nearly two and a half years old. The code itself is not stalled: the project pushed code on 2 April 2026. This is the pattern this report has learned to separate — a release date is not a code date, and an old release means the project has stopped publishing versions, not that it has stopped. It does mean a new rule added since May 2024 is not in the version you install.
  • It declares no minimum Python version anywhere. There is no python_requires in its setup file and none on its package page. Its own test settings exercise Python 3.9 to 3.13, which is the only evidence available.
  • It finds and does not fix. A found key still has to be replaced by hand at the service that issued it, and removing it from the project's history is a separate and riskier job. It also cannot tell a real key from a random-looking test string, so some findings will be wrong.
Similar repositories
Install
pip install detect-secrets
detect-secrets scan > .secrets.baseline
detect-secrets audit .secrets.baseline
Screenshots
Yelp/detect-secrets: GitHub preview card

36,367 stars · GPL-3.0-only, read from /blob/master/LICENSE.txt — plain and unmodified, and the only real copyright line is the FSF's own 'Copyright (C) 2007 Free Software Foundation, Inc.'; the appendix carries the unfilled 'Copyright (C) <year> <name of author>' template, so AdGuard asserts no copyright in the licence file at all · v0.107.79 (2026-08-18), read from /releases/latest as a yearless '18 Aug 15:45' and settled by the ungh releases record (2026-08-18T15:45:27Z). The 0.108 line has been in beta since 2026-07-30 (v0.108.0-b.90) while 0.107.x keeps taking stable patches · Track this in Scout

A home DNS server that refuses to answer for advertising and tracking addresses, with encrypted DNS built in.

▶Repo detailsthe review · specs · pros & cons · install

What it is

AdGuard Home is a DNS server — the service that turns a name like example.com into a numeric address — with blocklists, a web page of statistics and per-device rules. It also speaks the encrypted forms of DNS, so the questions the household asks are not readable by the network in between.

What it is good for. A household or a small office with devices that cannot run an ad blocker: a smart television, a games console, a phone with a locked-down browser. One always-on machine does the work for all of them. It is also the clearest way to see what a device is quietly talking to, which is often a surprise.

Stars36,367
LicenceGPL-3.0-only, read from /blob/master/LICENSE.txt — plain and unmodified, and the only real copyright line is the FSF's own 'Copyright (C) 2007 Free Software Foundation, Inc.'; the appendix carries the unfilled 'Copyright (C) <year> <name of author>' template, so AdGuard asserts no copyright in the licence file at all
Latestv0.107.79 (2026-08-18), read from /releases/latest as a yearless '18 Aug 15:45' and settled by the ungh releases record (2026-08-18T15:45:27Z). The 0.108 line has been in beta since 2026-07-30 (v0.108.0-b.90) while 0.107.x keeps taking stable patches
Good
  • Encrypted DNS is built in. Several alternatives need a second program bolted alongside for it.
  • Per-device rules, a readable statistics page and a query log, all in one program with no database to install.
  • Plain, unmodified GPL-3.0. That licence binds distribution, not use: running it at home for any number of people triggers nothing.
Watch for
  • The project's own documented install pipes a script from the internet straight into a shell, and it fetches that script from the development branch rather than a fixed release, so what runs is whatever that branch holds at that moment. All three variants in the README do this. The alternative is to download the release archive and run sudo ./AdGuardHome -s install by hand.
  • On first start it serves an unauthenticated setup page on every network interface, port 3000, and the administrator account is created on that page. Between the first start and finishing the form, anyone who can reach that port can claim the account. Finish the setup immediately, on a trusted network.
  • It is a single point of failure for the whole house. If the machine stops, nothing resolves names until somebody changes the setting back. Also worth knowing: the stable line is 0.107.x, and the 0.108 line has been in test builds since July 2026, so the version you install is not the newest number on the releases page. The project publishes no memory, disk or processor requirement anywhere, which is a real gap for software commonly run on a small single-board computer.
Similar repositories
Install
docker run --name adguardhome --restart unless-stopped \
  -v /my/own/workdir:/opt/adguardhome/work \
  -v /my/own/confdir:/opt/adguardhome/conf \
  -p 53:53/tcp -p 53:53/udp -p 80:80/tcp -p 443:443/tcp -p 3000:3000/tcp \
  -d adguard/adguardhome
Screenshots
AdguardTeam/AdGuardHome: GitHub preview card

16,249 stars · AGPL-3.0-only, read from /blob/edge/LICENSE.txt after COPYING and LICENSE both 404 — plain and unmodified, and the only copyright line is the FSF's own; the 'How to Apply' template is left unfilled · 1.30.1 (2026-10-05), read from /releases/latest as a yearless '05 Oct 19:40' and settled by the project's own CHANGELOG.md read raw AT THE TAG, whose top heading is '2026-10-05 FreshRSS 1.30.1'. ungh's releases endpoints returned 429 on every attempt · Track this in Scout

Gathers the feeds you follow into one page you control, with several accounts, labels, filters and the standard mobile-app interface.

▶Repo detailsthe review · specs · pros & cons · install

What it is

FreshRSS is a self-hosted feed reader: a PHP web application with a database behind it that fetches feeds on a schedule and stores the articles. It supports several accounts, labels, filters, extensions and the standard mobile-app interface, so phone readers can connect to it.

What it is good for. Anyone who wants to follow fifty sources without an algorithm deciding what they see. It is also the practical way to watch software projects: most GitHub repositories publish a release feed, so new versions arrive as items in a list instead of as a search you have to remember to run. Thirteen years old and released on 5 October 2026, two days before this edition.

Stars16,249
LicenceAGPL-3.0-only, read from /blob/edge/LICENSE.txt after COPYING and LICENSE both 404 — plain and unmodified, and the only copyright line is the FSF's own; the 'How to Apply' template is left unfilled
Latest1.30.1 (2026-10-05), read from /releases/latest as a yearless '05 Oct 19:40' and settled by the project's own CHANGELOG.md read raw AT THE TAG, whose top heading is '2026-10-05 FreshRSS 1.30.1'. ungh's releases endpoints returned 429 on every attempt
Good
  • It has been maintained since 2012 and still shipped a release this week. That is a long record for a project of this size.
  • It works on PostgreSQL, SQLite, MariaDB or MySQL, so it fits whatever database is already installed.
  • The container image and the hand install are both documented, and a user can be created from one command without touching the web form.
Watch for
  • It offers a mode with no authentication at all. The project's own documentation lists "No Authentication" among the options and warns, in its own words, that it is "dangerous" and to "never choose this option on a server that is able to be accessed outside of your home network". The warning is correct and the option exists; do not pick it.
  • It is AGPL-3.0. Modify it and let other people use it over a network, and that licence obliges you to offer them the changed source. Reading your own feeds triggers nothing. The licence file carries only the Free Software Foundation's own copyright line and no project line.
  • The project publishes no memory, disk or processor figure. Its requirements page says only that the needs are "really low", which is true and unhelpful. The example settings file in its container instructions uses the literal password freshrss three times, which is a placeholder and not a default, but it is a copy-and-paste trap.
Similar repositories
Install
docker run -d --restart unless-stopped \
  -p 8080:80 \
  -e TZ=Europe/Paris \
  -e CRON_MIN=1,31 \
  -v freshrss_data:/var/www/FreshRSS/data \
  -v freshrss_extensions:/var/www/FreshRSS/extensions \
  --name freshrss \
  freshrss/freshrss:edge
Screenshots
FreshRSS/FreshRSS: GitHub preview cardFreshRSS/FreshRSS: Screenshot 1

3,906 stars · GPL-2.0, read from /blob/develop/LICENSE.txt — plain and unmodified, and the only copyright line is the FSF's own 'Copyright (C) 1989, 1991 Free Software Foundation, Inc.'; no osTicket or Enhancesoft line exists in the file · v1.18.4 (2026-06-17), read from /releases/latest as a yearless '17 Jun 22:12' and settled by the ungh releases record (2026-06-17T22:12:12Z), corroborated independently by WHATSNEW.md whose newest entry reads 'Latest Patches 06/2026'. v1.17.8 shipped two minutes earlier the same day on the 1.17 line · Track this in Scout

Turns a shared email address into a numbered list of tickets with owners, departments and statuses.

▶Repo detailsthe review · specs · pros & cons · install

What it is

osTicket is a PHP help-desk application: incoming mail and a web form both become tickets, which are assigned to staff, grouped into departments, answered from canned replies and closed. It is one of the oldest projects of its kind still shipping.

What it is good for. A small team that has outgrown a shared mailbox but does not want a per-agent monthly bill. It is honest about its age: it is a form-and-queue help desk, not a chat widget, and it does its one job with twenty-three years of edge cases already handled.

Stars3,906
LicenceGPL-2.0, read from /blob/develop/LICENSE.txt — plain and unmodified, and the only copyright line is the FSF's own 'Copyright (C) 1989, 1991 Free Software Foundation, Inc.'; no osTicket or Enhancesoft line exists in the file
Latestv1.18.4 (2026-06-17), read from /releases/latest as a yearless '17 Jun 22:12' and settled by the ungh releases record (2026-06-17T22:12:12Z), corroborated independently by WHATSNEW.md whose newest entry reads 'Latest Patches 06/2026'. v1.17.8 shipped two minutes earlier the same day on the 1.17 line
Good
  • Plain, unmodified GPL-2.0. The company behind it sells hosting, not a crippled free edition, and there is no carved-out directory in the repository.
  • Very long record. A project running since 2003 has met most of the awkward email in the world already.
  • A real release went out on 17 June 2026, and its own notes record the security patches of that month.
Watch for
  • Its published database requirement is eight years out of date, and this is the edition's title. The README asks for "MySQL database version 5.5 (or greater)" and the official install page repeats it. MySQL 5.5 stopped receiving security fixes in December 2018. The documentation's own links then point at MySQL 8.0 and MariaDB 10.11, so the pages disagree with each other, and the published minimum is the one a newcomer will read. Install MySQL 8.0 or MariaDB 10.11, not what the requirement line says.
  • It is slow-moving, and the numbers say so. Code last landed on 17 June 2026, about three and a half months before this edition, on a branch named develop. There are 866 open issues and 329 open pull requests against a project of 3,906 stars. It is alive and it is not quick.
  • Its PHP support is narrow at both ends: "PHP version 8.2 - 8.4 (8.4 recommended)". PHP 8.5 is out and is not supported, and PHP 8.2 is already past active support. The licence file carries only the Free Software Foundation's own copyright line, so nobody is named as holding copyright in osTicket itself. The install also requires two clean-up steps that are easy to forget: remove write access from include/ost-config.php and delete the setup/ folder, or the installer stays reachable.
Similar repositories
Install
git clone https://github.com/osTicket/osTicket
cd osTicket
php manage.php deploy --setup /var/www/htdocs/osticket/
Screenshots
osTicket/osTicket: GitHub preview card

10,239 stars · ELASTIC LICENSE 2.0 (SPDX Elastic-2.0) — NOT an OSI open-source licence. Read from /blob/v5-stable/LICENSE; LICENSE.md and LICENSE.txt both 404, so there is exactly one licence file. The text is plain unmodified ELv2 and carries NO COPYRIGHT LINE AT ALL, naming only 'the licensor'. composer.json agrees with 'license': 'Elastic License' · v5.13.44 (2026-10-07), read from /releases/latest as a yearless '07 Oct 00:37' and settled by the ungh releases/latest record (2026-10-07T00:37:11Z) — the morning of the edition. VERSION.txt on v5-stable reads 5.13.43, one patch behind the tag · Track this in Scout

Quotes, invoices, payments, projects and time tracking in one self-hosted application, under a licence that forbids running it as a service for other people.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Invoice Ninja is a Laravel application — Laravel is a widely used PHP framework — covering the whole billing cycle from quote to paid invoice, with a customer-facing portal, recurring invoices and more than forty payment providers. It has been developed since 2013.

What it is good for. Someone invoicing a handful of clients every month who has reached the limits of a spreadsheet. The customer portal is the part that is hard to build and easy to underrate: a client can see the invoice, read the line items and pay, without an email thread. Code landed on 7 October 2026, the morning of this edition, and so did the newest release.

Stars10,239
LicenceELASTIC LICENSE 2.0 (SPDX Elastic-2.0) — NOT an OSI open-source licence. Read from /blob/v5-stable/LICENSE; LICENSE.md and LICENSE.txt both 404, so there is exactly one licence file. The text is plain unmodified ELv2 and carries NO COPYRIGHT LINE AT ALL, naming only 'the licensor'. composer.json agrees with 'license': 'Elastic License'
Latestv5.13.44 (2026-10-07), read from /releases/latest as a yearless '07 Oct 00:37' and settled by the ungh releases/latest record (2026-10-07T00:37:11Z) — the morning of the edition. VERSION.txt on v5-stable reads 5.13.43, one patch behind the tag
Good
  • Complete. Quotes, invoices, credits, recurring billing, projects, timers, expenses and a client portal, in one application.
  • Very active. The release v5.13.44 is dated 7 October 2026, the day of this edition.
  • Mature payment handling, with more than forty providers already written and tested.
Watch for
  • It is not open source, and the licence is the main fact about it. The LICENSE file is the Elastic License 2.0. Its own words: you "may not provide the software to third parties as a hosted or managed service", you "may not move, change, disable, or circumvent the license key functionality in the software", and you may not "alter, remove, or obscure any licensing, copyright, or other notices". Using it to bill your own customers is fine. Running it for other businesses as a service is not, and neither is working around the licence key that gates the paid features. The licence names no copyright holder at all, because the Elastic License has no such field, and the project's own repository description calls it "source-available".
  • The seeded install ships the password password. The README's demo accounts are small@example.com / password for the administrator and user@example.com / password for the client portal. An install left as seeded is open with a guessable password.
  • It publishes no memory, disk or processor figure anywhere. The real install asks for PHP 8.2 with sixteen extensions, MySQL 5.7 or MariaDB 10.3 or newer, a web server with HTTPS, a scheduled job every minute and a background worker — and its own documents pin php8.2 packages while the code declares support up to PHP 8.5, so the two disagree. The official advice is to install from the release archive; the Git route is marked as not recommended for real use.
Similar repositories
Install
sudo apt install php8.2-bcmath php8.2-gmp php8.2-gd php8.2-mbstring \
    php8.2-xml php8.2-curl php8.2-zip php8.2-mysql php8.2-fpm \
    php8.2-imagick php8.2-soap php8.2-common php8.2-intl
Screenshots
InvoiceNinja/invoiceninja: GitHub preview card

32,100 stars · MIT, read from /blob/main/LICENSE — standard wording, no added clauses, holder named 'Copyright 2020 Dan Davison'. Cargo.toml agrees with license = 'MIT' · 0.20.1 (2026-10-04), read from /releases/latest as a yearless '04 Oct 19:38' and settled by the crates.io API for the crate git-delta (version created_at 2026-10-04T19:32:21Z). The crates.io HTML page 404s to a fetcher and ungh /releases returned 429 twice · Track this in Scout

Makes the output of git diff readable, with syntax colouring, line numbers, word-level highlighting and an optional side-by-side view.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Delta is a pager — a program that formats text on its way to a terminal — written for Git's difference output. It also understands git log, git show, git blame, grep and rg --json output, and it can show two columns side by side.

What it is good for. Anyone who reads code changes in a terminal, which is to say anyone who uses Git without an editor doing it for them. It is the clearest example in this edition of a small change with a large daily return: the thing you were already doing becomes easy to read, and nothing has to be learned.

Stars32,100
LicenceMIT, read from /blob/main/LICENSE — standard wording, no added clauses, holder named 'Copyright 2020 Dan Davison'. Cargo.toml agrees with license = 'MIT'
Latest0.20.1 (2026-10-04), read from /releases/latest as a yearless '04 Oct 19:38' and settled by the crates.io API for the crate git-delta (version created_at 2026-10-04T19:32:21Z). The crates.io HTML page 404s to a fetcher and ungh /releases returned 429 twice
Good
  • Two minutes, and the reward arrives every time Git prints a difference from then on.
  • Plain, unmodified MIT with a named holder, "Copyright 2020 Dan Davison". No conditions worth worrying about.
  • Packaged almost everywhere. Homebrew, apt, dnf, pacman, Nix, FreeBSD, Chocolatey, Scoop and Winget all carry it, so no compiling is needed.
Watch for
  • The names do not match, and this catches people out. The repository is delta, the package in almost every package manager is git-delta, and the program you then run is delta. Installing delta by that name gets a different program on several systems.
  • It declares no minimum Rust version and no minimum Git version. Installing through cargo install means compiling a fairly large Rust project on the machine, which is the slow route; a packaged binary is the fast one.
  • Its settings surface is large and its real documentation is a separate manual rather than the README, so the first configuration takes longer than the install. It publishes no memory, disk or processor figure.
Similar repositories
Install
brew install git-delta
Screenshots
dandavison/delta: GitHub preview carddandavison/delta: Screenshot 1dandavison/delta: Screenshot 2dandavison/delta: Screenshot 3dandavison/delta: Screenshot 4

24,583 stars · GPL-2.0-only, read from /blob/master/COPYING — plain and unmodified, FSF copyright line only. The file named LICENSE is NOT licence text but a project notice explaining the mixture, and it carries no copyright line; graphics/LICENSE puts the artwork under Creative Commons Attribution-ShareAlike 4.0 with 'Copyright HandBrake Team' · 1.11.2 (2026-06-07), read from /releases/latest as a yearless '07 Jun 19:08' and settled by the ungh releases record (2026-06-07T19:08:25Z) to the minute; handbrake.fr/downloads2.php independently prints 'Current Version: 1.11.2' · Track this in Scout

A desktop program that shrinks and converts video files using presets, with its own encoding engine included.

▶Repo detailsthe review · specs · pros & cons · install

What it is

HandBrake is a cross-platform video transcoder with its own bundled encoding pipeline, a queue, a preset library and a chapter and subtitle editor. It has existed since 2003 and is the default answer to "how do I make this video smaller".

What it is good for. Anyone with a folder of video that is too large: recordings, camera footage, discs ripped years ago in a format nothing plays any more. The presets are the reason to choose it over a command line: "Fast 1080p30" is a sensible answer for most files and requires no understanding of what a codec is.

Stars24,583
LicenceGPL-2.0-only, read from /blob/master/COPYING — plain and unmodified, FSF copyright line only. The file named LICENSE is NOT licence text but a project notice explaining the mixture, and it carries no copyright line; graphics/LICENSE puts the artwork under Creative Commons Attribution-ShareAlike 4.0 with 'Copyright HandBrake Team'
Latest1.11.2 (2026-06-07), read from /releases/latest as a yearless '07 Jun 19:08' and settled by the ungh releases record (2026-06-07T19:08:25Z) to the minute; handbrake.fr/downloads2.php independently prints 'Current Version: 1.11.2'
Good
  • It publishes real hardware figures, which almost nothing else in this edition does. Its system-requirements page asks for 16 GB of memory for standard and high-definition video, 32 GB for 4K, and 150 MB of disk for the application itself. That honesty is worth more than a vague reassurance.
  • Official builds for Windows, macOS and Linux, with the encoding engine included, so nothing external is needed before it works.
  • Twenty-three years of presets, tested against a very large number of odd files.
Watch for
  • There is a licence trap, and it is in the project's own notice. The code is GPL-2.0, in the file named COPYING; the file named LICENSE is a notice explaining the mixture. That notice states that the Fraunhofer AAC audio library is "under a license incompatible with the GPLv2 license", so a build made with --enable-fdk-aac is "neither free nor redistributable". You may use such a build yourself and may not give it to anyone. Official builds leave that library out for exactly this reason. The artwork is under a different licence again, Creative Commons BY-SA 4.0.
  • The hardware figures are high, and they are real. 16 GB of memory for 1080p work is above what many laptops carry. Transcoding also keeps a processor fully busy for a long time; a feature-length film can take hours without a graphics card doing the encoding.
  • Hardware encoding needs specific equipment and sometimes extra downloads: Intel Quick Sync wants a 9th-generation Core processor or newer with current drivers, and on Linux the Flatpak build needs a separate add-on for it; Nvidia's encoder wants an RTX 2060 or better with driver 610 or newer. AV1 hardware encoding works only on the newest graphics cards. Linux gets a Flatpak and no official .deb or .rpm, the macOS build is Apple Silicon only, and the command-line version is a separate download on Windows and macOS. The two official pages also disagree about the minimum operating system: the download page says macOS 10.13 and Windows 10, the requirements page lists macOS 14 and calls Windows 10 deprecated.
Similar repositories
Install
flatpak install fr.handbrake.ghb
11

cdgriffith/FastFlix

💎 hidden gem

1,574 stars · MIT, read from /blob/master/LICENSE — plain and unmodified, holder named 'Copyright (c) 2019-2025 Chris Griffith', although the README and the website both say 2019-2026, so the file is a year stale. pyproject.toml declares NO license field and no classifiers, and there is no setup.py · 6.2.1 (2026-03-21), read from /releases/latest as a yearless '21 Mar 22:56' and settled by the ungh releases/latest record (2026-03-21T22:56:20Z). The repo's CHANGES file carries no dates at all and PyPI could not settle it, being stuck at 5.12.0 · Track this in Scout

A small window for HEVC and AV1 video encoding that drives an FFmpeg you install yourself, and carries HDR brightness data through instead of dropping it.

▶Repo detailsthe review · specs · pros & cons · install

What it is

FastFlix is a Python application with a graphical window that builds and runs FFmpeg commands. FFmpeg is the program almost every video tool uses underneath. Its focus is the modern codecs — HEVC, AV1, VP9 — and the careful handling of HDR10, HDR10+ and Dolby Vision brightness information.

What it is good for. Someone who wants AV1 or careful HDR output and finds a full transcoding suite more than they need. The brightness metadata is the real argument: a simple converter usually discards it, and the result looks washed out on a television that could have shown it properly. At 1,574 stars it is a genuine hidden gem, and it is the smallest project in this edition after fontc.

Stars1,574
LicenceMIT, read from /blob/master/LICENSE — plain and unmodified, holder named 'Copyright (c) 2019-2025 Chris Griffith', although the README and the website both say 2019-2026, so the file is a year stale. pyproject.toml declares NO license field and no classifiers, and there is no setup.py
Latest6.2.1 (2026-03-21), read from /releases/latest as a yearless '21 Mar 22:56' and settled by the ungh releases/latest record (2026-03-21T22:56:20Z). The repo's CHANGES file carries no dates at all and PyPI could not settle it, being stuck at 5.12.0
Good
  • Plain, unmodified MIT with a named holder, "Copyright (c) 2019-2025 Chris Griffith", and no conditions on what you make with it.
  • HDR10, HDR10+ and Dolby Vision metadata are carried through rather than dropped, which is unusual in a small tool.
  • Because it only writes FFmpeg commands, the output is reproducible outside the window, and the window is a thin layer over something standard.
Watch for
  • FFmpeg is not included and must be supplied separately. The README says you need ffmpeg and ffprobe on the system path, version 4.3 or later, and recommends the newest development build because some features need it. It also warns that an FFmpeg from a package manager may not support all the encoders. This is the hidden cost: the window is small and free, and finding a correctly built FFmpeg is the actual work.
  • Its package-index version is seventeen months and two major versions behind its own releases. pip install fastflix installs 5.12.0, dated 4 May 2025, while the current release is 6.2.1 of 21 March 2026. Download the build from the releases page instead. Prebuilt packages exist for Windows, for macOS 14 on Apple Silicon only, and for Ubuntu 22.04 and 24.04 on 64-bit Intel — there is no Intel Mac build and no ARM Linux build.
  • Hardware encoding needs more downloads again: the separate NVEncC, QSVEncC or VCEEncC programs, which it can fetch by itself on Windows only. It publishes no memory, disk or processor figure; the only resource note anywhere in the project is a troubleshooting line saying that burning in subtitles is probably what is using the memory. Its own third-party licence list is stale: it still names Python 3.7.2 and PyQt5, while the current code needs Python 3.13 and uses PySide6, and the licence file says 2019-2025 while the website says 2019-2026.
Similar repositories
Install
git clone https://github.com/cdgriffith/FastFlix.git
cd FastFlix
python3.13 -m venv venv
source venv/bin/activate
pip install setuptools
pip install .
venv/bin/python -m fastflix
Screenshots
cdgriffith/FastFlix: GitHub preview cardcdgriffith/FastFlix: Screenshot 1
12

googlefonts/fontc

💎 hidden gem

186 stars · Apache-2.0, read from /blob/main/LICENSE — plain and unmodified, and the appendix is LEFT AS THE UNFILLED TEMPLATE 'Copyright [yyyy] [name of copyright owner]', so Google is not named in it anywhere · fontc-v1.0.0 (2026-09-01), read from /releases/latest as a yearless '01 Sep 15:02' and settled by the crates.io API (version 1.0.0 created_at 2026-09-01T14:51:05Z, the same event minutes apart). Previous versions 0.6.0 of 2025-12-01 and 0.5.0 of 2025-11-21, consistent with a September 2026 1.0 milestone · Track this in Scout

Compiles font source drawings into finished OpenType and TrueType font files, written in Rust to be fast.

▶Repo detailsthe review · specs · pros & cons · install

What it is

fontc is a font compiler written in Rust by the Google Fonts team. It reads the two standard source formats — UFO and designspace files, and Glyphs files — and writes the binary font files a browser or a word processor loads.

What it is good for. Anyone who makes or maintains typefaces, or who builds them as part of a release process. The reason it exists is plainly stated by Google's own planning repository: fontc is "meant to replace fontmake", the Python compiler that has done this job for years, and fontc's own README says the team is "moving towards using fontc exclusively for all Google Fonts builds". A font build that took minutes is the problem it was written to solve. At 186 stars it is by far the smallest repository in this edition.

Stars186
LicenceApache-2.0, read from /blob/main/LICENSE — plain and unmodified, and the appendix is LEFT AS THE UNFILLED TEMPLATE 'Copyright [yyyy] [name of copyright owner]', so Google is not named in it anywhere
Latestfontc-v1.0.0 (2026-09-01), read from /releases/latest as a yearless '01 Sep 15:02' and settled by the crates.io API (version 1.0.0 created_at 2026-09-01T14:51:05Z, the same event minutes apart). Previous versions 0.6.0 of 2025-12-01 and 0.5.0 of 2025-11-21, consistent with a September 2026 1.0 milestone
Good
  • Version 1.0.0 arrived on 1 September 2026, after four years of work. A 1.0 from a team that builds thousands of fonts is a real signal.
  • It replaces a chain of Python tools with one program, so a failure has one place to look rather than four.
  • Plain, unmodified Apache-2.0, which is permissive and carries no commercial condition.
Watch for
  • Its own package description promises a licence it does not ship. The Cargo.toml declares license = "MIT/Apache-2.0", offering a choice of two, and there is no MIT licence file anywhere in the repository. Only the Apache one exists, and its appendix is left as the unfilled template, Copyright [yyyy] [name of copyright owner], so Google is not named in it at all.
  • The project it replaces is still the one in production, and is still moving. googlefonts/fontmake, the Python incumbent, pushed code on 14 September 2026 — more recently than the last code date readable for fontc. fontc's own README says it is still working toward matching fontmake's output exactly. For now, check the output before switching a real release over.
  • It publishes no install command of its own: the README shows only cargo run from inside a clone, so it has to be compiled first. No minimum Rust version is declared anywhere, and no memory, disk or processor figure is published. There are 179 open issues against 8 open pull requests.
Similar repositories
Install
git clone https://github.com/googlefonts/fontc
cd fontc
cargo run -p fontc -- resources/testdata/wght_var.designspace
Screenshots
googlefonts/fontc: GitHub preview cardgooglefonts/fontc: Screenshot 1

Checked, and left out

Nothing to show for this edition. Recording the repositories that were checked and rejected began with Edition No. 4, and every edition from there on has the list.

Share this edition
← PreviousNo. 42Next →
Coming tomorrow

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.