Edition No. 45 · 9 Oct 2026
Twelve repositories for watching, scheduling and measuring what you run
Grist's own README says that its default install downloads code that is not under a free or open-source licence, into a folder called ext.
Friday, 9 October 2026. Twelve open-source repositories, opened and checked this morning.
We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.
The title is about entry #8. Grist is a spreadsheet you can run yourself, and its code is under a normal open-source licence. But the standard install command quietly downloads a second piece of code that is not open source, into a folder called ext. The project says so in its own README. It is the default, and most people will never read that line.
Three things worth knowing, separate from the recommendations
- An open-source licence covers the code in the repository, not everything the install command fetches. Grist's own licence is plain Apache-2.0, and its own README says that yarn install downloads code that is "not under a free or open-source license" into an ext directory by default. The project is honest about it in writing. It is still the default, and the switch to avoid it — GRIST_SKIP_EXT_AUTOSETUP=1, or yarn run set-community-edition — is one line that almost nobody will type. - Four of today's twelve are open to anyone who can reach them, straight out of the box. Gatus binds to every network interface with an empty security block. Kestra's official compose file has its authentication block commented out, publishes a database password, and binds every interface. Cup's web page and JSON interface have no password at all. Cronicle ships admin / admin. All four are documented behaviours rather than bugs, and all four are the kind of default that ends up on a public address by accident. - A date with no year is not a date, and this morning it pointed the wrong way. Cup's newest release reads "21 Nov" with no year on its own page. Twenty-first of November has not happened yet in 2026, so the year was lost rather than known: the release is 21 November 2025, about ten and a half months old, not one day away. A second source settled it. The project is still comfortably alive — its code was last touched on 22 July 2026 — which is the other half of the same rule: a stale release is a fact about the release, never a verdict on the project.
If you only do three things
- charmbracelet/gum (#12) — two minutes, one install. It turns a shell script's questions into proper prompts: a menu you arrow through, a yes/no box, a spinner while something runs. Nothing else on your machine changes.
- anchore/syft (#11) — ten minutes, and it only reads. Point it at a container image or a folder and it lists every package inside, with versions. Most people have never seen that list for their own software.
- sergi0g/cup (#3) — twenty minutes, one container, and also one of today's three hidden gems. It tells you which of the containers you are running have a newer image waiting, on one page, and it changes nothing by itself.
Every link in one place
| # | Repository | Website | Stars | Licence |
|---|---|---|---|---|
| 1 | TwiN/gatus | gatus.io | 12,300 | Apache-2.0 |
| 2 | pyrra-dev/pyrra 💎 | demo.pyrra.dev | 1,533 | Apache-2.0 |
| 3 | sergi0g/cup 💎 | cup.sergi0g.dev | 1,350 | AGPL-3.0 |
| 4 | kestra-io/kestra | kestra.io | 29,443 | Apache-2.0 |
| 5 | jhuckaby/Cronicle | cronicle.net | 5,854 | MIT |
| 6 | ccxt/ccxt | ccxt.com | 44,287 | MIT |
| 7 | dgunning/edgartools 💎 | edgartools.readthedocs.io | 2,780 | MIT |
| 8 | gristlabs/grist-core | getgrist.com | 11,917 | Apache-2.0 plus non-open-source extras |
| 9 | lancedb/lancedb | lancedb.com/docs | 11,620 | Apache-2.0 |
| 10 | confident-ai/deepeval | deepeval.com | 18,722 | Apache-2.0 |
| 11 | anchore/syft | none in the sidebar | 9,658 | Apache-2.0 |
| 12 | charmbracelet/gum | none in the sidebar | 24,479 | MIT |
An open-source spreadsheet installs code that is not open source
Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.
12.3k stars · Apache-2.0 · v5.37.0 (2026-09-23) · Track this in Scout
A status page with checks, history and alerts, all described in one YAML file.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Gatus is a single Go program that runs checks on a schedule and serves a web page showing the results. A check can be an HTTP request, a DNS lookup, a TCP or ICMP probe, a database query, or a certificate expiry test, and each one can carry its own conditions.
What it is good for. Anyone who runs more than two services and currently finds out they are broken from a customer. The useful part is that the whole thing is one settings file: the checks, the conditions, the alert channels and the public page are all described in text you can keep beside your code and copy to a new machine in a minute. If you have ever wanted the uptime page without signing up for a monitoring bill, this is it.
- One file describes everything, so the setup is reproducible and reviewable.
- The conditions are expressive. You can require a status code, a response time under a limit, a value inside the JSON body, or a certificate with more than a set number of days left.
- Alerting reaches a long list of destinations, and v5.37.0 added a configurable topic for Zulip, a client cookie-storage setting, and a TXT query type for DNS checks.
- ⚠ It binds to every network interface and has no password by default. The
web.addresssetting defaults to0.0.0.0andweb.portto8080, and thesecurityblock defaults to empty, which means no login. Basic authentication and OIDC sign-in exist, but you have to switch them on. Do not put this on a public address before you do. - The licence file is plain Apache-2.0, but its copyright line was never filled in: it still reads
Copyright [yyyy] [name of copyright owner], so the file names nobody. - No memory, disk or processor figure is published anywhere. The README says only that the footprint is "negligibly small", and 262 open issues against 139 open pull requests is a wide gap for a project this size.
louislam/uptime-kumaThe same uptime monitoring with a point-and-click web interface instead of a settings file, which is easier to start and harder to copy to a second machine.
Track this in Scout- bluewave-labs/Checkmate
Also monitors uptime and response times, adds server hardware metrics, and has a product-style interface rather than configuration as code.
Track this in Scout - upptime/upptime
Produces the same public status page but runs as scheduled GitHub Actions committing results into a repository, so there is no server to host.
Track this in Scout
# make a folder for the settings file
mkdir -p ~/gatus/config
# write the smallest useful config
cat > ~/gatus/config/config.yaml <<'YAML'
web:
address: "127.0.0.1" # localhost only, until you put a login in front
port: 8080
endpoints:
- name: my-website
url: "https://example.com"
interval: 60s
conditions:
- "[STATUS] == 200"
- "[RESPONSE_TIME] < 500"
YAML
# run it
docker run -d --name gatus \
-p 127.0.0.1:8080:8080 \
-v ~/gatus/config:/config \
ghcr.io/twin/gatus:stable1.6k stars · Apache-2.0 · v0.10.2 (2026-09-18) · Track this in Scout
Turns a short declaration about how reliable a service should be into the Prometheus rules that measure it, with the remaining error budget on a page.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Pyrra is a small Go service and a set of file formats for defining service level objectives — the formal name for "how good does this have to be". It generates the Prometheus recording and alerting rules that measure the objective, and serves a page showing the current error budget and burn rate.
What it is good for. Anyone already running Prometheus who has alerts that fire on every blip and never on the thing that matters. An error budget turns reliability from a feeling into a number with an allowance attached, and the point of this tool is that you do not have to hand-write the rule arithmetic, which is where almost everyone gets it wrong.
- You write the objective once, in a short declarative file, and the rules are generated from it.
- Two ways to run it: as a Kubernetes controller that reconciles
PrometheusRuleobjects, or in plain filesystem mode with no Kubernetes at all. - Its own web page shows the remaining budget and the burn rate, which is the part generator-only tools leave to you.
- ⚠ The documented install commands as written will fail. The README says to run
kubectl apply -f ./example/kubernetes/manifests, and the folder in the repository isexamples, with an s. The documented Docker tag is also stale: it saysv0.7.0while the current release is v0.10.2. - ⚠ It needs Prometheus already running, and that is not a small prerequisite. It is designed to sit beside Prometheus, not to replace it, and the Kubernetes route also wants the Prometheus Operator unless you pass
--config-map-mode=true. - The README describes no authentication for Pyrra's own page or API, and publishes no memory, processor or disk figures at all. Its Apache-2.0 licence file also leaves the copyright holder as the unfilled template
Copyright [yyyy] [name of copyright owner].
- slok/sloth
Generates the same kind of Prometheus SLO rules from a declarative spec and stops there, with no web page of its own.
Track this in Scout - google/slo-generator
Computes the same budgets and burn rates in Python and reads from many monitoring backends rather than Prometheus alone, producing reports instead of a dashboard.
Track this in Scout - OpenSLO/oslo
A command-line tool for validating and converting the vendor-neutral OpenSLO specification, so it defines objectives without running anything.
Track this in Scout
git clone https://github.com/pyrra-dev/pyrra.git cd pyrra # note the folder name: examples, not example, which the README gets wrong kubectl apply --server-side -f ./examples/kubernetes/manifests/setup kubectl apply --server-side -f ./examples/kubernetes/manifests kubectl apply --server-side -f ./examples/kubernetes/manifests/slos
1,350 stars · AGPL-3.0 · v3.5.1 (2025-11-21) · Track this in Scout
Shows which running containers have a newer image waiting, as a command or a small web page, and changes nothing by itself.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Cup is a Rust program that reads the containers on a machine and asks each image's registry whether a newer version of that tag exists. It runs as a one-off command, or as a server with a web page and a JSON interface at /api/v3/json.
What it is good for. Anyone running a handful of containers on one machine who currently finds out about an update by reading release notes they happened to see. The honest version of this job is "tell me, and let me decide" — the tools that update automatically are a different and riskier thing. On a Raspberry Pi 5 the author measured 3.7 seconds to check 58 images.
- Very small and very fast. The README puts the binary at 5.4 MB.
- It reports and never acts, so it cannot restart a service at three in the morning.
- A JSON interface means you can feed the result into something else rather than reading a page.
- ⚠ Every documented command mounts the Docker socket,
/var/run/docker.sock, into the container. That socket is equivalent to administrator access on the host machine, so anything that gets into this container gets the machine. - ⚠ The web page and its JSON interface have no password. The only page in the documentation headed "Authentication" is about giving Cup credentials for private image registries, not about protecting Cup itself. The default port is 8000 and no documentation page states which network interfaces it listens on.
- Its newest release, v3.5.1, is dated 21 November 2025 — about ten and a half months ago — while its code was last touched on 22 July 2026. So there is unreleased work, and the released version is the old one. 38 open issues, 6 open pull requests. The licence is AGPL-3.0, which obliges anyone who offers it as a network service to publish their source; the file carries only the Free Software Foundation's own copyright line and names the author nowhere.
- containrrr/watchtower
Did the same checking and then pulled and restarted containers itself, which is the part Cup deliberately refuses to do; archived by its owner on 17 December 2025.
Track this in Scout
mag37/dockcheckChecks the same thing as a plain shell script and can also perform the update, with notifications and image backups, but has no web page.
Track this in Scout
crazy-max/diunWatches registry references rather than running containers, is notification-first with many delivery backends, and never updates anything either.
Track this in Scout
# one-off check of everything on this machine docker run --rm -t \ -v /var/run/docker.sock:/var/run/docker.sock \ ghcr.io/sergi0g/cup check # or run the web page, bound to localhost only docker run -d --name cup \ -v /var/run/docker.sock:/var/run/docker.sock \ -p 127.0.0.1:8000:8000 \ ghcr.io/sergi0g/cup serve -p 8000
29,443 stars · Apache-2.0 · v2.0.5 (2026-10-05) · Track this in Scout
Runs scheduled and event-driven workflows declared in YAML, with a web interface showing every run and every step.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Kestra is a Java orchestration server. Workflows are declared as YAML files rather than written in a programming language, and the individual steps are supplied by plugins, so a step can run a container, a query, a script in any language, or a call to a service.
What it is good for. Anyone whose important jobs currently live in cron lines on three different machines with no record of whether they ran. The thing an orchestrator gives you that cron cannot is the history: which run failed, at which step, with what output, and a retry that you did not have to write.
- Workflows are plain YAML, so a person who does not write code can read and change one, and the whole thing lives in version control.
- Any language runs as a step, through plugins fetched on demand, so you are not forced to rewrite existing scripts in the platform's language.
- Actively developed: code landed on 9 October 2026, the morning this was checked, and v2.0.5 arrived on 5 October 2026.
- ⚠ The official
docker-compose.ymlhas authentication commented out, so a default install is completely open. The wholekestra.server.basic-authblock is commented; the example credentials inside the comment areadmin@kestra.io/Admin1234!. The same file also publishes a database password,POSTGRES_PASSWORD: k3str4, and declares ports as"8080:8080"with no host address, which means Docker binds them on every interface. An orchestrator that can run arbitrary commands, open to the network, with no login. - ⚠ The container runs as root and mounts the Docker socket, which the file's own comment admits is "intended for development purpose" — that is administrator-level control of the host.
- No memory, processor or disk figure is published in the README, the compose file or the contributor notes, and there are 464 open issues against 168 open pull requests. The paid Enterprise Edition — multi-tenancy, single sign-on, role permissions, audit logs — is a separate product whose terms are not in this repository, so what you can and cannot do with the free version has to be read off a marketing page rather than a licence.
- apache/airflow
Schedules the same kind of pipeline, but each one is written as Python code, and it is scheduler-centred rather than event-driven.
Track this in Scout - PrefectHQ/prefect
Adds orchestration to existing Python functions by decorating them, which is lighter to adopt and Python-only.
Track this in Scout - dagster-io/dagster
Organised around data assets and their lineage rather than around tasks and events, which suits analytics work and fits awkwardly around general automation.
Track this in Scout
docker run --rm -it \ --name kestra \ -p 127.0.0.1:8080:8080 \ --user=root \ -v kestra_data:/app/storage \ -v kestra_db:/app/data \ -v /var/run/docker.sock:/var/run/docker.sock \ -v /tmp:/tmp \ -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true \ kestra/kestra:latest-slim server local
5,854 stars · MIT · v0.9.135 (2026-10-01) · Track this in Scout
A scheduled job runner with a web interface, keeping the output and timing of every past run across one or several servers.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Cronicle is a Node.js application that schedules and runs commands, with a master server and optional additional servers. It keeps the output and timing of every run, supports catch-up for missed jobs, and has a user and permission system of its own.
What it is good for. Anyone with a handful of nightly scripts and no record of whether last Tuesday's actually ran. It is the thing cron never gave you: the output, the history, and a message when the exit code was not zero. Ten years of release notes behind it, which for software you leave running unattended is worth more than it sounds.
- Alive and shipping. Version 0.9.135 was released on 1 October 2026 and the code was last touched the same day, with releases roughly weekly through August, September and October 2026.
- It has a login system by default, and self-registration by guests is off.
- It runs jobs across several servers from one screen, with per-job memory and processor limits — the memory limit defaults to one gigabyte per job.
- ⚠ The ships-with password is
admin/admin. The documentation says to change it "as soon as possible", which is to say that until you do, anyone who reaches port 3012 is an administrator. - ⚠ The documented quick install pipes a script from the internet straight into Node, as root:
curl -s https://raw.githubusercontent.com/jhuckaby/Cronicle/master/bin/install.js | node. The manual route is in the documentation and is the safer one. - It needs Node.js 22.12.0 or later, runs on Unix-like systems only, and there are 318 open issues against 15 open pull requests. No memory, processor or disk figure is published for the server itself. One oddity, reported rather than explained:
package.jsonon the default branch reads version 0.9.134 while the newest tag is v0.9.135, and the changelog read at that tag has no 0.9.135 entry.
- rundeck/rundeck
The same idea of a web interface over jobs and access control, built on the Java virtual machine and aimed at larger operations runbooks.
Track this in Scout - distribworks/dkron
The closest direct match, a distributed scheduler with a web page shipped as a single Go binary with built-in clustering.
Track this in Scout - pixlcore/xyops
The same author's newer and broader workflow-automation and server-monitoring system, BSD-3-Clause; its star count could not be settled and its relationship to Cronicle is not stated in the repository.
Track this in Scout
# Node.js 22.12.0 or later is required node --version sudo mkdir -p /opt/cronicle cd /opt/cronicle sudo curl -L https://github.com/jhuckaby/Cronicle/archive/v0.9.135.tar.gz \ | sudo tar zxvf - --strip-components 1 sudo npm install sudo node bin/build.js dist sudo /opt/cronicle/bin/control.sh setup sudo /opt/cronicle/bin/control.sh start
44,287 stars · MIT · v4.5.85 (2026-10-01) · Track this in Scout
One programming interface in front of 103 cryptocurrency exchanges, published for eight languages from a single codebase.
▶Repo detailsthe review · specs · pros & cons · install
What it is
CCXT normalises the market data and trading interfaces of a long list of exchanges behind one set of function names. It is published for JavaScript, TypeScript, Python, C#, PHP, Go, Java and Rust from the same source.
What it is good for. Anyone writing anything that touches more than one exchange — a price tracker, a research notebook, a bot — who would otherwise write and maintain a separate adapter per venue. The README's own count is 103 exchanges. Eight languages from one codebase is unusual and is the reason it has lasted.
- Plain MIT licence, read from
LICENSE.txt, with a real copyright line: "Copyright © 2024 Igor Kroitor". - Version 4.5.85 is dated 1 October 2026, and the package registries agree with the repository: both the npm package and the Python package sit on 4.5.85.
- Very actively developed, with code landing on 8 October 2026.
- ⚠ The Rust build has an enormous memory requirement, published by the project itself: about 19 GB of memory to build every exchange in debug mode and about 50 GB in release mode. Limiting it to three exchanges brings that down to roughly 2.5 GB. This applies to the Rust crate only; the Python, JavaScript and PHP packages are ordinary installs.
- ⚠ The documentation advertises piping a script from the internet into a shell:
curl -fsSL https://raw.githubusercontent.com/ccxt/ccxt/master/install-skills.sh | bash. You do not need it to use the library. - 594 open pull requests against 236 open issues is a very large queue, and the install documentation contradicts itself on the minimum Node.js version, saying both "Node v15+" and "Node 18+" on one page — the package's own metadata requires 18 or later. And the real risk is not the code: this library holds exchange keys and can move money.
nautechsystems/nautilus_traderAlso reaches many venues, but it is a whole event-driven trading engine with backtesting rather than a thin layer that normalises interfaces.
Track this in Scout- hummingbot/hummingbot
Connects to many exchanges through its own connectors and ships a finished market-making and arbitrage bot with a command-line interface.
Track this in Scout - bmoscon/cryptofeed
Normalises many exchanges behind one Python interface for market data only, with no order placement, pushing the stream into backends such as Redis or Kafka.
Track this in Scout
python3 -m venv venv source venv/bin/activate # on Windows: venv\Scripts\activate pip install ccxt
2,780 stars · MIT · v5.61.1 (2026-10-06) · Track this in Scout
Reads United States company filings and their financial tables in Python, returning typed objects rather than raw documents.
▶Repo detailsthe review · specs · pros & cons · install
What it is
EdgarTools is a Python library over the Securities and Exchange Commission's EDGAR system. It covers annual and quarterly reports, current reports, insider-trading forms, institutional holdings disclosures and adviser registrations, and parses the structured financial data inside them rather than only downloading the files.
What it is good for. Anyone doing research on listed companies who is currently copying numbers out of a web page by hand, or paying for a data feed that repackages this same free source. The parsing is the whole value: downloading a filing is easy and turning its financial statements into a table is not.
- MIT, read from
LICENSE.txt, with a real copyright line: "Copyright (c) 2022-present Dwight Gunning". - A fast release cadence with real activity behind it: v5.61.1 on 6 October 2026, two releases that same day, and code on 8 October 2026.
- It understands the document types rather than treating every filing as a blob, so financial statements, Form 4 insider trades and 13F holdings all come back as structured objects.
- ⚠ The current release is a security release, so anything older should be updated. Version 5.61.1's own notes say it "raises dependency minimums past known vulnerabilities", and that the optional MCP server's HTTP mode now listens only on the local machine by default — which means earlier versions did not.
- ⚠ You must set an identity before anything works. EDGAR requires an email address with every request, so the first line of any script is
set_identity("your.name@example.com"). Leave it out and the requests are refused. - United States filings only, the published Python minimum (3.10) lives on the package page rather than in the README, and the optional artificial-intelligence extras bring a much larger dependency set with them. No memory or disk figures are published.
- sec-edgar/sec-edgar
Bulk-downloads the same filings and leaves all parsing to the caller, so there is no financial-statement layer.
Track this in Scout - jadchaar/sec-edgar-downloader
Deliberately narrow: saves filings to disk by ticker, company number or form type, with no extraction of the data inside them.
Track this in Scout - lefterisloukas/edgar-crawler
Research-oriented, pulling named sections such as the risk-factors item into JSON for text analysis rather than offering a filings interface.
Track this in Scout
python3 -m venv venv source venv/bin/activate # on Windows: venv\Scripts\activate pip install edgartools
11,917 stars · Apache-2.0 (the repository) plus a proprietary licence on the optional ext/ extensions · v1.7.20 (2026-09-28) · Track this in Scout
A self-hosted spreadsheet with real column types, references between tables and Python formulas, stored as portable per-document files.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Grist is a document-based spreadsheet and database hybrid. Each document is a portable file with its own schema, formulas and access rules, and the server is a Node.js application with a Python formula engine beside it.
What it is good for. Anyone whose important spreadsheet has grown to the point where a wrong type in one cell breaks a report. Typed columns, references between tables and real formulas fix that without moving to a database nobody on the team can read. If you want that and you also want the file to live on a machine you control, this is the main open-source answer.
- The repository's own licence is plain Apache-2.0, read from
LICENSE.txt, with a real copyright line: "Copyright 2014-2022 Grist Labs Inc." — no network clause, no field-of-use restriction, nothing added. - It publishes real hardware figures, which almost nothing else today does: 8 GB of memory, 2 processors and 20 GB of disk for "a variety of moderate workloads", and a measured 100 MB of memory on one sample document without sandboxing, 200 MB with it, and 1 processor.
- The default listening address is localhost only.
GRIST_HOSThas to be set to0.0.0.0deliberately before it answers on other interfaces, which is the opposite of several other entries today.
- ⚠
yarn installdownloads code that is not open source, by default. The README's own words: "By default, the build is the full edition:yarn installdownloads optional extensions (into anextdirectory)", and "Note that this will add non-OSS code to your build", and "This extra code is not under a free or open-source license, though by default is completely inert". The mechanism is apostinstallhook that clonesgristlabs/grist-ee. Grist's own documentation describes that code as available "under a proprietary license that does not grant any automatic rights to use or redistribute the software", starting a thirty-day trial, after which "Activation keys are required to run the full edition". To avoid it entirely:yarn run set-community-edition, or setGRIST_EDITION=community, or setGRIST_SKIP_EXT_AUTOSETUP=1. - ⚠ Sign-in is effectively absent until you configure it. Grist runs in a limited anonymous mode until it knows who is editing, and a single default identity can be set with
GRIST_DEFAULT_EMAIL, which skips sign-in altogether. Locking it down needsGRIST_ANON_PLAYGROUND=falseorGRIST_FORCE_LOGIN. - 637 open issues against 101 open pull requests, formulas are Python so there is a language to learn, and the Node.js version is pinned in a dotfile (
.nvmrc, v22.12.0) rather than stated in the README.
nocodb/nocodbThe same spreadsheet-database idea, but an interface over an existing SQL database, where Grist carries its own document engine.
Track this in Scout- baserow/baserow
The same no-code database in a grid, built on PostgreSQL and positioned as an application builder, with GitHub acting as a mirror of a GitLab-primary project.
Track this in Scout - teableio/teable
Also a self-hostable spreadsheet-database, backed by PostgreSQL with database-scale as its pitch, against Grist's portable per-document files.
Track this in Scout
mkdir -p ~/grist docker run -d --name grist \ -p 127.0.0.1:8484:8484 \ -v ~/grist:/persist \ -e GRIST_SESSION_SECRET=replace-this-with-a-long-random-string \ -e GRIST_DEFAULT_EMAIL=your-email@example.com \ gristlabs/grist
11,620 stars · Apache-2.0 · v0.40.0 (2026-10-07) · Track this in Scout
An embedded retrieval library for embeddings, imported into a program and pointed at a folder, with no server to run.
▶Repo detailsthe review · specs · pros & cons · install
What it is
LanceDB is a retrieval library built on its own columnar file format. It stores vectors, text and other columns together, and supports vector search, full-text search and filtering from Python, TypeScript and Rust, against a local folder or object storage.
What it is good for. Anyone adding search-by-meaning to one application who does not want a second service to run, back up and patch. The embedded shape is the whole argument: pip install, point it at a directory, and the database is a set of files you can copy. It also reads from S3-style object storage, so the same code works when the data outgrows one machine.
- Nothing to deploy. No port, no process, no password, because there is no server.
- Three first-class languages from one engine — Python, TypeScript and Rust — and the data on disk is one columnar format rather than an opaque store.
- Apache-2.0, read from the licence file, with no added clauses and no commercially carved-out directory. A paid LanceDB Enterprise exists, but only as documentation; the code here is uniformly Apache-2.0.
- ⚠ On an older processor it will not start at all. The default Python package is built for
x86-64-haswelland requires the AVX2 instruction set. On a processor without it,import lancedbfails with "Illegal instruction", and the documented fix is to install a different package,lancedb-compat. - ⚠ It is still before version 1.0 and the version numbers move fast — 0.26.0 in December 2025 to 0.40.0 on 7 October 2026. The release notes for 0.40.0 list breaking changes.
- The Apache-2.0 file leaves the copyright holder as the unfilled template
Copyright [yyyy] [name of copyright owner]; there are 466 open issues against 142 open pull requests; and because it is embedded, access control is whatever the filesystem or object store gives you, not something the library provides.
qdrant/qdrantDoes the same vector search as a standalone Rust server deployed separately and reached over the network.
Track this in Scout- chroma-core/chroma
Also an embeddings store usable either in-process or as a server, Python-first, without a columnar on-disk format of its own.
Track this in Scout - asg017/sqlite-vec
The closest match on the no-server axis, a small SQLite extension adding vector search to an existing database, with none of the multimodal or full-text retrieval around it.
Track this in Scout
python3 -m venv venv source venv/bin/activate # on Windows: venv\Scripts\activate pip install lancedb # needs Python 3.10 or later # on a processor without AVX2, use this instead: # pip install lancedb-compat
18,722 stars · Apache-2.0 · python-v4.2.4 (2026-09-22); PyPI is ahead at 4.2.8 (2026-10-02) · Track this in Scout
Tests for the output of language models, written and run like ordinary unit tests and able to score with a local model.
▶Repo detailsthe review · specs · pros & cons · install
What it is
DeepEval is a Python evaluation framework. It provides metrics for things like faithfulness to a source document, relevance of an answer, and the correctness of a retrieval step, and runs them as test cases you can keep in a repository and run in automation.
What it is good for. Anyone shipping a feature built on a language model who currently decides whether a prompt change helped by reading a few answers. The useful shape here is that it looks like a test suite, so it fits where your existing tests already run instead of becoming a separate ritual.
- It works like ordinary tests, so it lands in the pipeline that already exists.
- It can run entirely on a local model, with
deepeval set-ollama --model=<name>, or through environment variables pointing at a local server, or with your own model class — so the running cost can be zero. - Some metrics are small language models that run locally rather than calls to a provider, and the licence is Apache-2.0 with no
ee/directory and no added conditions.
- ⚠ By default it costs money on every run. The README's own first step is
export OPENAI_API_KEY="...", and the model-judged metrics call a paid model for each test case. A large test suite run on every commit is a bill. - ⚠
deepeval loginsends your results off the machine. Once linked to the company's hosted platform, the README says "All test cases will automatically be logged" and traces "stream to it with no code changes". That is a reasonable feature and it is also data leaving, so decide before you type it. - 322 open issues against 387 open pull requests, and the published version numbers do not line up: the newest release object on GitHub is 4.2.4 of 22 September 2026 while the Python package is already at 4.2.8 of 2 October 2026. The licence file's copyright line reads
Copyright [2024] [Confident AI Inc.], with the template's square brackets left in place around a real name.
- Arize-ai/phoenix
Scores the same things, but it is an observability platform first, with tracing and a self-hosted interface around the evaluations rather than a test library.
Track this in Scout
vibrantlabsai/ragasMetric-library-centred with synthetic test-set generation, and not a test runner.
Track this in Scout
promptfoo/promptfooDeclarative evaluation and red-teaming from YAML in a Node command-line tool, with side-by-side model comparison, where this is a Python library.
Track this in Scout
python3 -m venv venv source venv/bin/activate # on Windows: venv\Scripts\activate pip install -U deepeval # needs Python 3.9 or later # either pay a provider: export OPENAI_API_KEY="sk-..." # or score with a model on your own machine, and pay nothing: deepeval set-ollama --model=deepseek-r1:1.5b # deepeval unset-ollama # to undo
9,658 stars · Apache-2.0 · v1.54.1 (2026-10-06) · Track this in Scout
Lists every package inside a container image or a folder as a standard bill of materials, in SPDX or CycloneDX, and changes nothing.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Syft is a Go command-line tool and library that scans container images and filesystems and produces a software bill of materials. It recognises packages from a long list of ecosystems and can emit the result in the two standard formats, SPDX and CycloneDX, as well as its own.
What it is good for. Anyone who ships a container and would struggle to answer "does this contain the library that was in the news yesterday". It is the half of the job that is purely factual: the inventory, with no judgement attached. Its sibling tool takes that inventory and reports known vulnerabilities, which is why the two are usually used together.
- It reads and never writes, so there is nothing to undo and nothing to break.
- It covers a wide range of ecosystems in one pass and emits both standard formats, so the output goes into other people's tools without conversion.
- Very actively developed: v1.54.1 on 6 October 2026 and code on 9 October 2026, the morning this was checked.
- ⚠ The only install command in the README pipes a script from the internet into a root shell:
curl -sSfL https://get.anchore.io/syft | sudo sh -s -- -b /usr/local/bin. Other channels exist — Homebrew, Docker, Scoop, Chocolatey, Nix — but the README names them without giving the commands. - ⚠ It tells you what is there and nothing about whether it is safe. The list on its own is not a finding; you need a second tool to turn it into one.
- 504 open issues against 126 open pull requests, no memory or disk figures published anywhere, no website set in the repository sidebar, and the Apache-2.0 licence file leaves the copyright holder as the unfilled template
Copyright [yyyy] [name of copyright owner]— Anchore's name appears in it nowhere. Building from source needs Go 1.26.8, read from the module file at the release tag.
anchore/grypeThis tool's sibling: it consumes the inventory and reports known vulnerabilities instead of producing one.
Track this in Scout
aquasecurity/trivyAlso generates bills of materials, as one feature of a much broader scanner covering misconfiguration, secrets, clusters and cloud accounts.
Track this in Scout- CycloneDX/cdxgen
Generates the same kind of inventory from source code and build manifests across many languages, CycloneDX-first and written in Node.js.
Track this in Scout
# list everything inside a public image docker run --rm anchore/syft:latest alpine:latest # or scan a folder on this machine docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src # write a standard SPDX file instead of a table docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src \ -o spdx-json > sbom.spdx.json
24,479 stars · MIT · v2.0.2 (2026-09-24) · Track this in Scout
One command that gives a shell script menus, confirmations, text fields, spinners and styled output, leaving the script a plain script.
▶Repo detailsthe review · specs · pros & cons · install
What it is
Gum is a Go program offering a set of subcommands — choose, confirm, input, write, filter, spin, table, style, pager — each of which draws an interactive control in the terminal and returns the answer on standard output. It is built on the same library as its author's terminal applications.
What it is good for. Anyone with a setup script, a deploy script or a release script that other people have to run. The thing it fixes is not looks; it is that a menu cannot be mistyped. Because each control is just a command that prints its answer, it drops into a script that already exists, one line at a time, with no framework to adopt.
- The licence is plain MIT, read from the file, with a real holder: "Copyright (c) 2022-2024 Charmbracelet, Inc." No added conditions.
- The Debian and Red Hat install routes never pipe anything into a shell — the
curlgoes intogpg --dearmorandteeto add a signing key and a repository, which is materially safer than the alternatives several other entries today ship. - Packaged almost everywhere: Homebrew, pacman, dnf, Nix, Flox, winget, Scoop, FreeBSD ports, plus prebuilt
.deb,.rpmand.apkfiles and binaries for Linux, macOS, Windows, FreeBSD, OpenBSD and NetBSD.
- ⚠ The Go install line is unpinned:
go install charm.land/gum/v2@latestfetches whatever is newest at the time, so the command is not repeatable. Prefer the package manager, or pin a version. - ⚠ Version 2's module path changed to
charm.land/gum/v2, notgithub.com/charmbracelet/gum, so an older install command or a script that references the old path will not resolve. - 143 open issues against 65 open pull requests, no memory or processor figures published, no website set in the repository sidebar, and the copyright line's year range still ends at 2024. Also worth knowing before you assume the whole publisher is permissive: Charm's licensing is not uniform. This project and its underlying library are plain MIT, but
charmbracelet/crush, which Edition 44 covered, ships the Functional Source License, which restricts competing use.
- charmbracelet/bubbletea
The framework this is built on, where the difference is that a Go program is written against it rather than a command called from a shell script.
Track this in Scout - junegunn/fzf
Also a standalone binary a script shells out to for interactive choosing, and it does that one job better while offering none of the other controls.
Track this in Scout - charmbracelet/huh
Offers the same prompts as a Go library for building multi-field forms inside a program rather than as a command a script can call.
Track this in Scout
# macOS or Linux with Homebrew brew install gum # Debian or Ubuntu — nothing is piped into a shell here sudo mkdir -p /etc/apt/keyrings curl -fsSL https://repo.charm.sh/apt/gpg.key \ | sudo gpg --dearmor -o /etc/apt/keyrings/charm.gpg echo "deb [signed-by=/etc/apt/keyrings/charm.gpg] https://repo.charm.sh/apt/ * *" \ | sudo tee /etc/apt/sources.list.d/charm.list sudo apt update && sudo apt install gum
Checked, and left out
Nothing to show for this edition. Recording the repositories that were checked and rejected began with Edition No. 4, and every edition from there on has the list.
Coming tomorrow

































