Edition No. 45 · 9 Oct 2026

Twelve repositories for watching, scheduling and measuring what you run

Grist's own README says that its default install downloads code that is not under a free or open-source licence, into a folder called ext.

By Genn·12 repositories·15 min read

Friday, 9 October 2026. Twelve open-source repositories, opened and checked this morning.

We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.

The title is about entry #8. Grist is a spreadsheet you can run yourself, and its code is under a normal open-source licence. But the standard install command quietly downloads a second piece of code that is not open source, into a folder called ext. The project says so in its own README. It is the default, and most people will never read that line.

Three things worth knowing, separate from the recommendations

- An open-source licence covers the code in the repository, not everything the install command fetches. Grist's own licence is plain Apache-2.0, and its own README says that yarn install downloads code that is "not under a free or open-source license" into an ext directory by default. The project is honest about it in writing. It is still the default, and the switch to avoid it — GRIST_SKIP_EXT_AUTOSETUP=1, or yarn run set-community-edition — is one line that almost nobody will type. - Four of today's twelve are open to anyone who can reach them, straight out of the box. Gatus binds to every network interface with an empty security block. Kestra's official compose file has its authentication block commented out, publishes a database password, and binds every interface. Cup's web page and JSON interface have no password at all. Cronicle ships admin / admin. All four are documented behaviours rather than bugs, and all four are the kind of default that ends up on a public address by accident. - A date with no year is not a date, and this morning it pointed the wrong way. Cup's newest release reads "21 Nov" with no year on its own page. Twenty-first of November has not happened yet in 2026, so the year was lost rather than known: the release is 21 November 2025, about ten and a half months old, not one day away. A second source settled it. The project is still comfortably alive — its code was last touched on 22 July 2026 — which is the other half of the same rule: a stale release is a fact about the release, never a verdict on the project.

If you only do three things

  1. charmbracelet/gum (#12) — two minutes, one install. It turns a shell script's questions into proper prompts: a menu you arrow through, a yes/no box, a spinner while something runs. Nothing else on your machine changes.
  2. anchore/syft (#11) — ten minutes, and it only reads. Point it at a container image or a folder and it lists every package inside, with versions. Most people have never seen that list for their own software.
  3. sergi0g/cup (#3) — twenty minutes, one container, and also one of today's three hidden gems. It tells you which of the containers you are running have a newer image waiting, on one page, and it changes nothing by itself.

An open-source spreadsheet installs code that is not open source

Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.

12.3k stars · Apache-2.0 · v5.37.0 (2026-09-23) · Track this in Scout

A status page with checks, history and alerts, all described in one YAML file.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Gatus is a single Go program that runs checks on a schedule and serves a web page showing the results. A check can be an HTTP request, a DNS lookup, a TCP or ICMP probe, a database query, or a certificate expiry test, and each one can carry its own conditions.

What it is good for. Anyone who runs more than two services and currently finds out they are broken from a customer. The useful part is that the whole thing is one settings file: the checks, the conditions, the alert channels and the public page are all described in text you can keep beside your code and copy to a new machine in a minute. If you have ever wanted the uptime page without signing up for a monitoring bill, this is it.

Stars12.3k
LicenceApache-2.0
Latestv5.37.0 (2026-09-23)
Good
  • One file describes everything, so the setup is reproducible and reviewable.
  • The conditions are expressive. You can require a status code, a response time under a limit, a value inside the JSON body, or a certificate with more than a set number of days left.
  • Alerting reaches a long list of destinations, and v5.37.0 added a configurable topic for Zulip, a client cookie-storage setting, and a TXT query type for DNS checks.
Watch for
  • ⚠ It binds to every network interface and has no password by default. The web.address setting defaults to 0.0.0.0 and web.port to 8080, and the security block defaults to empty, which means no login. Basic authentication and OIDC sign-in exist, but you have to switch them on. Do not put this on a public address before you do.
  • The licence file is plain Apache-2.0, but its copyright line was never filled in: it still reads Copyright [yyyy] [name of copyright owner], so the file names nobody.
  • No memory, disk or processor figure is published anywhere. The README says only that the footprint is "negligibly small", and 262 open issues against 139 open pull requests is a wide gap for a project this size.
Similar repositories
Install
# make a folder for the settings file
mkdir -p ~/gatus/config
# write the smallest useful config
cat > ~/gatus/config/config.yaml <<'YAML'
web:
  address: "127.0.0.1"      # localhost only, until you put a login in front
  port: 8080
endpoints:
  - name: my-website
    url: "https://example.com"
    interval: 60s
    conditions:
      - "[STATUS] == 200"
      - "[RESPONSE_TIME] < 500"
YAML
# run it
docker run -d --name gatus \
  -p 127.0.0.1:8080:8080 \
  -v ~/gatus/config:/config \
  ghcr.io/twin/gatus:stable
Screenshots
TwiN/gatus: GitHub preview card
02

pyrra-dev/pyrra

💎 hidden gem

1.6k stars · Apache-2.0 · v0.10.2 (2026-09-18) · Track this in Scout

Turns a short declaration about how reliable a service should be into the Prometheus rules that measure it, with the remaining error budget on a page.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Pyrra is a small Go service and a set of file formats for defining service level objectives — the formal name for "how good does this have to be". It generates the Prometheus recording and alerting rules that measure the objective, and serves a page showing the current error budget and burn rate.

What it is good for. Anyone already running Prometheus who has alerts that fire on every blip and never on the thing that matters. An error budget turns reliability from a feeling into a number with an allowance attached, and the point of this tool is that you do not have to hand-write the rule arithmetic, which is where almost everyone gets it wrong.

Stars1.6k
LicenceApache-2.0
Latestv0.10.2 (2026-09-18)
Good
  • You write the objective once, in a short declarative file, and the rules are generated from it.
  • Two ways to run it: as a Kubernetes controller that reconciles PrometheusRule objects, or in plain filesystem mode with no Kubernetes at all.
  • Its own web page shows the remaining budget and the burn rate, which is the part generator-only tools leave to you.
Watch for
  • ⚠ The documented install commands as written will fail. The README says to run kubectl apply -f ./example/kubernetes/manifests, and the folder in the repository is examples, with an s. The documented Docker tag is also stale: it says v0.7.0 while the current release is v0.10.2.
  • ⚠ It needs Prometheus already running, and that is not a small prerequisite. It is designed to sit beside Prometheus, not to replace it, and the Kubernetes route also wants the Prometheus Operator unless you pass --config-map-mode=true.
  • The README describes no authentication for Pyrra's own page or API, and publishes no memory, processor or disk figures at all. Its Apache-2.0 licence file also leaves the copyright holder as the unfilled template Copyright [yyyy] [name of copyright owner].
Similar repositories
  • slok/sloth

    Generates the same kind of Prometheus SLO rules from a declarative spec and stops there, with no web page of its own.

    Track this in Scout
  • google/slo-generator

    Computes the same budgets and burn rates in Python and reads from many monitoring backends rather than Prometheus alone, producing reports instead of a dashboard.

    Track this in Scout
  • OpenSLO/oslo

    A command-line tool for validating and converting the vendor-neutral OpenSLO specification, so it defines objectives without running anything.

    Track this in Scout
Install
git clone https://github.com/pyrra-dev/pyrra.git
cd pyrra
# note the folder name: examples, not example, which the README gets wrong
kubectl apply --server-side -f ./examples/kubernetes/manifests/setup
kubectl apply --server-side -f ./examples/kubernetes/manifests
kubectl apply --server-side -f ./examples/kubernetes/manifests/slos
Screenshots
pyrra-dev/pyrra: GitHub preview cardpyrra-dev/pyrra: Screenshot 1pyrra-dev/pyrra: Screenshot 2pyrra-dev/pyrra: Screenshot 3pyrra-dev/pyrra: Screenshot 4
03

sergi0g/cup

💎 hidden gem

1,350 stars · AGPL-3.0 · v3.5.1 (2025-11-21) · Track this in Scout

Shows which running containers have a newer image waiting, as a command or a small web page, and changes nothing by itself.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Cup is a Rust program that reads the containers on a machine and asks each image's registry whether a newer version of that tag exists. It runs as a one-off command, or as a server with a web page and a JSON interface at /api/v3/json.

What it is good for. Anyone running a handful of containers on one machine who currently finds out about an update by reading release notes they happened to see. The honest version of this job is "tell me, and let me decide" — the tools that update automatically are a different and riskier thing. On a Raspberry Pi 5 the author measured 3.7 seconds to check 58 images.

Stars1,350
LicenceAGPL-3.0
Latestv3.5.1 (2025-11-21)
Good
  • Very small and very fast. The README puts the binary at 5.4 MB.
  • It reports and never acts, so it cannot restart a service at three in the morning.
  • A JSON interface means you can feed the result into something else rather than reading a page.
Watch for
  • ⚠ Every documented command mounts the Docker socket, /var/run/docker.sock, into the container. That socket is equivalent to administrator access on the host machine, so anything that gets into this container gets the machine.
  • ⚠ The web page and its JSON interface have no password. The only page in the documentation headed "Authentication" is about giving Cup credentials for private image registries, not about protecting Cup itself. The default port is 8000 and no documentation page states which network interfaces it listens on.
  • Its newest release, v3.5.1, is dated 21 November 2025 — about ten and a half months ago — while its code was last touched on 22 July 2026. So there is unreleased work, and the released version is the old one. 38 open issues, 6 open pull requests. The licence is AGPL-3.0, which obliges anyone who offers it as a network service to publish their source; the file carries only the Free Software Foundation's own copyright line and names the author nowhere.
Similar repositories
  • containrrr/watchtower

    Did the same checking and then pulled and restarted containers itself, which is the part Cup deliberately refuses to do; archived by its owner on 17 December 2025.

    Track this in Scout
  • mag37/dockcheck

    Checks the same thing as a plain shell script and can also perform the update, with notifications and image backups, but has no web page.

    Track this in Scout
  • crazy-max/diun

    Watches registry references rather than running containers, is notification-first with many delivery backends, and never updates anything either.

    Track this in Scout
Install
# one-off check of everything on this machine
docker run --rm -t \
  -v /var/run/docker.sock:/var/run/docker.sock \
  ghcr.io/sergi0g/cup check
# or run the web page, bound to localhost only
docker run -d --name cup \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -p 127.0.0.1:8000:8000 \
  ghcr.io/sergi0g/cup serve -p 8000
Screenshots
sergi0g/cup: GitHub preview cardsergi0g/cup: Screenshot 1sergi0g/cup: Screenshot 2sergi0g/cup: Screenshot 3

29,443 stars · Apache-2.0 · v2.0.5 (2026-10-05) · Track this in Scout

Runs scheduled and event-driven workflows declared in YAML, with a web interface showing every run and every step.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Kestra is a Java orchestration server. Workflows are declared as YAML files rather than written in a programming language, and the individual steps are supplied by plugins, so a step can run a container, a query, a script in any language, or a call to a service.

What it is good for. Anyone whose important jobs currently live in cron lines on three different machines with no record of whether they ran. The thing an orchestrator gives you that cron cannot is the history: which run failed, at which step, with what output, and a retry that you did not have to write.

Stars29,443
LicenceApache-2.0
Latestv2.0.5 (2026-10-05)
Good
  • Workflows are plain YAML, so a person who does not write code can read and change one, and the whole thing lives in version control.
  • Any language runs as a step, through plugins fetched on demand, so you are not forced to rewrite existing scripts in the platform's language.
  • Actively developed: code landed on 9 October 2026, the morning this was checked, and v2.0.5 arrived on 5 October 2026.
Watch for
  • ⚠ The official docker-compose.yml has authentication commented out, so a default install is completely open. The whole kestra.server.basic-auth block is commented; the example credentials inside the comment are admin@kestra.io / Admin1234!. The same file also publishes a database password, POSTGRES_PASSWORD: k3str4, and declares ports as "8080:8080" with no host address, which means Docker binds them on every interface. An orchestrator that can run arbitrary commands, open to the network, with no login.
  • ⚠ The container runs as root and mounts the Docker socket, which the file's own comment admits is "intended for development purpose" — that is administrator-level control of the host.
  • No memory, processor or disk figure is published in the README, the compose file or the contributor notes, and there are 464 open issues against 168 open pull requests. The paid Enterprise Edition — multi-tenancy, single sign-on, role permissions, audit logs — is a separate product whose terms are not in this repository, so what you can and cannot do with the free version has to be read off a marketing page rather than a licence.
Similar repositories
Install
docker run --rm -it \
  --name kestra \
  -p 127.0.0.1:8080:8080 \
  --user=root \
  -v kestra_data:/app/storage \
  -v kestra_db:/app/data \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v /tmp:/tmp \
  -e KESTRA_PLUGINS_AUTO_INSTALL_ENABLED=true \
  kestra/kestra:latest-slim server local
Screenshots
kestra-io/kestra: Screenshot 1kestra-io/kestra: Screenshot 2

5,854 stars · MIT · v0.9.135 (2026-10-01) · Track this in Scout

A scheduled job runner with a web interface, keeping the output and timing of every past run across one or several servers.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Cronicle is a Node.js application that schedules and runs commands, with a master server and optional additional servers. It keeps the output and timing of every run, supports catch-up for missed jobs, and has a user and permission system of its own.

What it is good for. Anyone with a handful of nightly scripts and no record of whether last Tuesday's actually ran. It is the thing cron never gave you: the output, the history, and a message when the exit code was not zero. Ten years of release notes behind it, which for software you leave running unattended is worth more than it sounds.

Stars5,854
LicenceMIT
Latestv0.9.135 (2026-10-01)
Good
  • Alive and shipping. Version 0.9.135 was released on 1 October 2026 and the code was last touched the same day, with releases roughly weekly through August, September and October 2026.
  • It has a login system by default, and self-registration by guests is off.
  • It runs jobs across several servers from one screen, with per-job memory and processor limits — the memory limit defaults to one gigabyte per job.
Watch for
  • ⚠ The ships-with password is admin / admin. The documentation says to change it "as soon as possible", which is to say that until you do, anyone who reaches port 3012 is an administrator.
  • ⚠ The documented quick install pipes a script from the internet straight into Node, as root: curl -s https://raw.githubusercontent.com/jhuckaby/Cronicle/master/bin/install.js | node. The manual route is in the documentation and is the safer one.
  • It needs Node.js 22.12.0 or later, runs on Unix-like systems only, and there are 318 open issues against 15 open pull requests. No memory, processor or disk figure is published for the server itself. One oddity, reported rather than explained: package.json on the default branch reads version 0.9.134 while the newest tag is v0.9.135, and the changelog read at that tag has no 0.9.135 entry.
Similar repositories
  • rundeck/rundeck

    The same idea of a web interface over jobs and access control, built on the Java virtual machine and aimed at larger operations runbooks.

    Track this in Scout
  • distribworks/dkron

    The closest direct match, a distributed scheduler with a web page shipped as a single Go binary with built-in clustering.

    Track this in Scout
  • pixlcore/xyops

    The same author's newer and broader workflow-automation and server-monitoring system, BSD-3-Clause; its star count could not be settled and its relationship to Cronicle is not stated in the repository.

    Track this in Scout
Install
# Node.js 22.12.0 or later is required
node --version
sudo mkdir -p /opt/cronicle
cd /opt/cronicle
sudo curl -L https://github.com/jhuckaby/Cronicle/archive/v0.9.135.tar.gz \
  | sudo tar zxvf - --strip-components 1
sudo npm install
sudo node bin/build.js dist
sudo /opt/cronicle/bin/control.sh setup
sudo /opt/cronicle/bin/control.sh start
Screenshots
jhuckaby/Cronicle: GitHub preview cardjhuckaby/Cronicle: Screenshot 1jhuckaby/Cronicle: Screenshot 2

44,287 stars · MIT · v4.5.85 (2026-10-01) · Track this in Scout

One programming interface in front of 103 cryptocurrency exchanges, published for eight languages from a single codebase.

▶Repo detailsthe review · specs · pros & cons · install

What it is

CCXT normalises the market data and trading interfaces of a long list of exchanges behind one set of function names. It is published for JavaScript, TypeScript, Python, C#, PHP, Go, Java and Rust from the same source.

What it is good for. Anyone writing anything that touches more than one exchange — a price tracker, a research notebook, a bot — who would otherwise write and maintain a separate adapter per venue. The README's own count is 103 exchanges. Eight languages from one codebase is unusual and is the reason it has lasted.

Stars44,287
LicenceMIT
Latestv4.5.85 (2026-10-01)
Good
  • Plain MIT licence, read from LICENSE.txt, with a real copyright line: "Copyright © 2024 Igor Kroitor".
  • Version 4.5.85 is dated 1 October 2026, and the package registries agree with the repository: both the npm package and the Python package sit on 4.5.85.
  • Very actively developed, with code landing on 8 October 2026.
Watch for
  • ⚠ The Rust build has an enormous memory requirement, published by the project itself: about 19 GB of memory to build every exchange in debug mode and about 50 GB in release mode. Limiting it to three exchanges brings that down to roughly 2.5 GB. This applies to the Rust crate only; the Python, JavaScript and PHP packages are ordinary installs.
  • ⚠ The documentation advertises piping a script from the internet into a shell: curl -fsSL https://raw.githubusercontent.com/ccxt/ccxt/master/install-skills.sh | bash. You do not need it to use the library.
  • 594 open pull requests against 236 open issues is a very large queue, and the install documentation contradicts itself on the minimum Node.js version, saying both "Node v15+" and "Node 18+" on one page — the package's own metadata requires 18 or later. And the real risk is not the code: this library holds exchange keys and can move money.
Similar repositories
Install
python3 -m venv venv
source venv/bin/activate        # on Windows: venv\Scripts\activate
pip install ccxt
Screenshots
ccxt/ccxt: GitHub preview cardccxt/ccxt: Screenshot 1
07

dgunning/edgartools

💎 hidden gem

2,780 stars · MIT · v5.61.1 (2026-10-06) · Track this in Scout

Reads United States company filings and their financial tables in Python, returning typed objects rather than raw documents.

▶Repo detailsthe review · specs · pros & cons · install

What it is

EdgarTools is a Python library over the Securities and Exchange Commission's EDGAR system. It covers annual and quarterly reports, current reports, insider-trading forms, institutional holdings disclosures and adviser registrations, and parses the structured financial data inside them rather than only downloading the files.

What it is good for. Anyone doing research on listed companies who is currently copying numbers out of a web page by hand, or paying for a data feed that repackages this same free source. The parsing is the whole value: downloading a filing is easy and turning its financial statements into a table is not.

Stars2,780
LicenceMIT
Latestv5.61.1 (2026-10-06)
Good
  • MIT, read from LICENSE.txt, with a real copyright line: "Copyright (c) 2022-present Dwight Gunning".
  • A fast release cadence with real activity behind it: v5.61.1 on 6 October 2026, two releases that same day, and code on 8 October 2026.
  • It understands the document types rather than treating every filing as a blob, so financial statements, Form 4 insider trades and 13F holdings all come back as structured objects.
Watch for
  • ⚠ The current release is a security release, so anything older should be updated. Version 5.61.1's own notes say it "raises dependency minimums past known vulnerabilities", and that the optional MCP server's HTTP mode now listens only on the local machine by default — which means earlier versions did not.
  • ⚠ You must set an identity before anything works. EDGAR requires an email address with every request, so the first line of any script is set_identity("your.name@example.com"). Leave it out and the requests are refused.
  • United States filings only, the published Python minimum (3.10) lives on the package page rather than in the README, and the optional artificial-intelligence extras bring a much larger dependency set with them. No memory or disk figures are published.
Similar repositories
Install
python3 -m venv venv
source venv/bin/activate        # on Windows: venv\Scripts\activate
pip install edgartools
Screenshots
dgunning/edgartools: Screenshot 1dgunning/edgartools: Screenshot 2

11,917 stars · Apache-2.0 (the repository) plus a proprietary licence on the optional ext/ extensions · v1.7.20 (2026-09-28) · Track this in Scout

A self-hosted spreadsheet with real column types, references between tables and Python formulas, stored as portable per-document files.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Grist is a document-based spreadsheet and database hybrid. Each document is a portable file with its own schema, formulas and access rules, and the server is a Node.js application with a Python formula engine beside it.

What it is good for. Anyone whose important spreadsheet has grown to the point where a wrong type in one cell breaks a report. Typed columns, references between tables and real formulas fix that without moving to a database nobody on the team can read. If you want that and you also want the file to live on a machine you control, this is the main open-source answer.

Stars11,917
LicenceApache-2.0 (the repository) plus a proprietary licence on the optional ext/ extensions
Latestv1.7.20 (2026-09-28)
Good
  • The repository's own licence is plain Apache-2.0, read from LICENSE.txt, with a real copyright line: "Copyright 2014-2022 Grist Labs Inc." — no network clause, no field-of-use restriction, nothing added.
  • It publishes real hardware figures, which almost nothing else today does: 8 GB of memory, 2 processors and 20 GB of disk for "a variety of moderate workloads", and a measured 100 MB of memory on one sample document without sandboxing, 200 MB with it, and 1 processor.
  • The default listening address is localhost only. GRIST_HOST has to be set to 0.0.0.0 deliberately before it answers on other interfaces, which is the opposite of several other entries today.
Watch for
  • ⚠ yarn install downloads code that is not open source, by default. The README's own words: "By default, the build is the full edition: yarn install downloads optional extensions (into an ext directory)", and "Note that this will add non-OSS code to your build", and "This extra code is not under a free or open-source license, though by default is completely inert". The mechanism is a postinstall hook that clones gristlabs/grist-ee. Grist's own documentation describes that code as available "under a proprietary license that does not grant any automatic rights to use or redistribute the software", starting a thirty-day trial, after which "Activation keys are required to run the full edition". To avoid it entirely: yarn run set-community-edition, or set GRIST_EDITION=community, or set GRIST_SKIP_EXT_AUTOSETUP=1.
  • ⚠ Sign-in is effectively absent until you configure it. Grist runs in a limited anonymous mode until it knows who is editing, and a single default identity can be set with GRIST_DEFAULT_EMAIL, which skips sign-in altogether. Locking it down needs GRIST_ANON_PLAYGROUND=false or GRIST_FORCE_LOGIN.
  • 637 open issues against 101 open pull requests, formulas are Python so there is a language to learn, and the Node.js version is pinned in a dotfile (.nvmrc, v22.12.0) rather than stated in the README.
Similar repositories
  • nocodb/nocodb

    The same spreadsheet-database idea, but an interface over an existing SQL database, where Grist carries its own document engine.

    Track this in Scout
  • baserow/baserow

    The same no-code database in a grid, built on PostgreSQL and positioned as an application builder, with GitHub acting as a mirror of a GitLab-primary project.

    Track this in Scout
  • teableio/teable

    Also a self-hostable spreadsheet-database, backed by PostgreSQL with database-scale as its pitch, against Grist's portable per-document files.

    Track this in Scout
Install
mkdir -p ~/grist
docker run -d --name grist \
  -p 127.0.0.1:8484:8484 \
  -v ~/grist:/persist \
  -e GRIST_SESSION_SECRET=replace-this-with-a-long-random-string \
  -e GRIST_DEFAULT_EMAIL=your-email@example.com \
  gristlabs/grist
Screenshots
gristlabs/grist-core: GitHub preview cardgristlabs/grist-core: Screenshot 1

11,620 stars · Apache-2.0 · v0.40.0 (2026-10-07) · Track this in Scout

An embedded retrieval library for embeddings, imported into a program and pointed at a folder, with no server to run.

▶Repo detailsthe review · specs · pros & cons · install

What it is

LanceDB is a retrieval library built on its own columnar file format. It stores vectors, text and other columns together, and supports vector search, full-text search and filtering from Python, TypeScript and Rust, against a local folder or object storage.

What it is good for. Anyone adding search-by-meaning to one application who does not want a second service to run, back up and patch. The embedded shape is the whole argument: pip install, point it at a directory, and the database is a set of files you can copy. It also reads from S3-style object storage, so the same code works when the data outgrows one machine.

Stars11,620
LicenceApache-2.0
Latestv0.40.0 (2026-10-07)
Good
  • Nothing to deploy. No port, no process, no password, because there is no server.
  • Three first-class languages from one engine — Python, TypeScript and Rust — and the data on disk is one columnar format rather than an opaque store.
  • Apache-2.0, read from the licence file, with no added clauses and no commercially carved-out directory. A paid LanceDB Enterprise exists, but only as documentation; the code here is uniformly Apache-2.0.
Watch for
  • ⚠ On an older processor it will not start at all. The default Python package is built for x86-64-haswell and requires the AVX2 instruction set. On a processor without it, import lancedb fails with "Illegal instruction", and the documented fix is to install a different package, lancedb-compat.
  • ⚠ It is still before version 1.0 and the version numbers move fast — 0.26.0 in December 2025 to 0.40.0 on 7 October 2026. The release notes for 0.40.0 list breaking changes.
  • The Apache-2.0 file leaves the copyright holder as the unfilled template Copyright [yyyy] [name of copyright owner]; there are 466 open issues against 142 open pull requests; and because it is embedded, access control is whatever the filesystem or object store gives you, not something the library provides.
Similar repositories
Install
python3 -m venv venv
source venv/bin/activate        # on Windows: venv\Scripts\activate
pip install lancedb             # needs Python 3.10 or later
# on a processor without AVX2, use this instead:
# pip install lancedb-compat
Screenshots
lancedb/lancedb: GitHub preview cardlancedb/lancedb: Screenshot 1lancedb/lancedb: Screenshot 2lancedb/lancedb: Screenshot 3

18,722 stars · Apache-2.0 · python-v4.2.4 (2026-09-22); PyPI is ahead at 4.2.8 (2026-10-02) · Track this in Scout

Tests for the output of language models, written and run like ordinary unit tests and able to score with a local model.

▶Repo detailsthe review · specs · pros & cons · install

What it is

DeepEval is a Python evaluation framework. It provides metrics for things like faithfulness to a source document, relevance of an answer, and the correctness of a retrieval step, and runs them as test cases you can keep in a repository and run in automation.

What it is good for. Anyone shipping a feature built on a language model who currently decides whether a prompt change helped by reading a few answers. The useful shape here is that it looks like a test suite, so it fits where your existing tests already run instead of becoming a separate ritual.

Stars18,722
LicenceApache-2.0
Latestpython-v4.2.4 (2026-09-22); PyPI is ahead at 4.2.8 (2026-10-02)
Good
  • It works like ordinary tests, so it lands in the pipeline that already exists.
  • It can run entirely on a local model, with deepeval set-ollama --model=<name>, or through environment variables pointing at a local server, or with your own model class — so the running cost can be zero.
  • Some metrics are small language models that run locally rather than calls to a provider, and the licence is Apache-2.0 with no ee/ directory and no added conditions.
Watch for
  • ⚠ By default it costs money on every run. The README's own first step is export OPENAI_API_KEY="...", and the model-judged metrics call a paid model for each test case. A large test suite run on every commit is a bill.
  • ⚠ deepeval login sends your results off the machine. Once linked to the company's hosted platform, the README says "All test cases will automatically be logged" and traces "stream to it with no code changes". That is a reasonable feature and it is also data leaving, so decide before you type it.
  • 322 open issues against 387 open pull requests, and the published version numbers do not line up: the newest release object on GitHub is 4.2.4 of 22 September 2026 while the Python package is already at 4.2.8 of 2 October 2026. The licence file's copyright line reads Copyright [2024] [Confident AI Inc.], with the template's square brackets left in place around a real name.
Similar repositories
Install
python3 -m venv venv
source venv/bin/activate        # on Windows: venv\Scripts\activate
pip install -U deepeval         # needs Python 3.9 or later
# either pay a provider:
export OPENAI_API_KEY="sk-..."
# or score with a model on your own machine, and pay nothing:
deepeval set-ollama --model=deepseek-r1:1.5b
# deepeval unset-ollama   # to undo
Screenshots
confident-ai/deepeval: GitHub preview cardconfident-ai/deepeval: Screenshot 1

9,658 stars · Apache-2.0 · v1.54.1 (2026-10-06) · Track this in Scout

Lists every package inside a container image or a folder as a standard bill of materials, in SPDX or CycloneDX, and changes nothing.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Syft is a Go command-line tool and library that scans container images and filesystems and produces a software bill of materials. It recognises packages from a long list of ecosystems and can emit the result in the two standard formats, SPDX and CycloneDX, as well as its own.

What it is good for. Anyone who ships a container and would struggle to answer "does this contain the library that was in the news yesterday". It is the half of the job that is purely factual: the inventory, with no judgement attached. Its sibling tool takes that inventory and reports known vulnerabilities, which is why the two are usually used together.

Stars9,658
LicenceApache-2.0
Latestv1.54.1 (2026-10-06)
Good
  • It reads and never writes, so there is nothing to undo and nothing to break.
  • It covers a wide range of ecosystems in one pass and emits both standard formats, so the output goes into other people's tools without conversion.
  • Very actively developed: v1.54.1 on 6 October 2026 and code on 9 October 2026, the morning this was checked.
Watch for
  • ⚠ The only install command in the README pipes a script from the internet into a root shell: curl -sSfL https://get.anchore.io/syft | sudo sh -s -- -b /usr/local/bin. Other channels exist — Homebrew, Docker, Scoop, Chocolatey, Nix — but the README names them without giving the commands.
  • ⚠ It tells you what is there and nothing about whether it is safe. The list on its own is not a finding; you need a second tool to turn it into one.
  • 504 open issues against 126 open pull requests, no memory or disk figures published anywhere, no website set in the repository sidebar, and the Apache-2.0 licence file leaves the copyright holder as the unfilled template Copyright [yyyy] [name of copyright owner] — Anchore's name appears in it nowhere. Building from source needs Go 1.26.8, read from the module file at the release tag.
Similar repositories
Install
# list everything inside a public image
docker run --rm anchore/syft:latest alpine:latest
# or scan a folder on this machine
docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src
# write a standard SPDX file instead of a table
docker run --rm -v "$PWD":/src anchore/syft:latest dir:/src \
  -o spdx-json > sbom.spdx.json
Screenshots
anchore/syft: GitHub preview cardanchore/syft: Screenshot 1

24,479 stars · MIT · v2.0.2 (2026-09-24) · Track this in Scout

One command that gives a shell script menus, confirmations, text fields, spinners and styled output, leaving the script a plain script.

▶Repo detailsthe review · specs · pros & cons · install

What it is

Gum is a Go program offering a set of subcommands — choose, confirm, input, write, filter, spin, table, style, pager — each of which draws an interactive control in the terminal and returns the answer on standard output. It is built on the same library as its author's terminal applications.

What it is good for. Anyone with a setup script, a deploy script or a release script that other people have to run. The thing it fixes is not looks; it is that a menu cannot be mistyped. Because each control is just a command that prints its answer, it drops into a script that already exists, one line at a time, with no framework to adopt.

Stars24,479
LicenceMIT
Latestv2.0.2 (2026-09-24)
Good
  • The licence is plain MIT, read from the file, with a real holder: "Copyright (c) 2022-2024 Charmbracelet, Inc." No added conditions.
  • The Debian and Red Hat install routes never pipe anything into a shell — the curl goes into gpg --dearmor and tee to add a signing key and a repository, which is materially safer than the alternatives several other entries today ship.
  • Packaged almost everywhere: Homebrew, pacman, dnf, Nix, Flox, winget, Scoop, FreeBSD ports, plus prebuilt .deb, .rpm and .apk files and binaries for Linux, macOS, Windows, FreeBSD, OpenBSD and NetBSD.
Watch for
  • ⚠ The Go install line is unpinned: go install charm.land/gum/v2@latest fetches whatever is newest at the time, so the command is not repeatable. Prefer the package manager, or pin a version.
  • ⚠ Version 2's module path changed to charm.land/gum/v2, not github.com/charmbracelet/gum, so an older install command or a script that references the old path will not resolve.
  • 143 open issues against 65 open pull requests, no memory or processor figures published, no website set in the repository sidebar, and the copyright line's year range still ends at 2024. Also worth knowing before you assume the whole publisher is permissive: Charm's licensing is not uniform. This project and its underlying library are plain MIT, but charmbracelet/crush, which Edition 44 covered, ships the Functional Source License, which restricts competing use.
Similar repositories
Install
# macOS or Linux with Homebrew
brew install gum
# Debian or Ubuntu — nothing is piped into a shell here
sudo mkdir -p /etc/apt/keyrings
curl -fsSL https://repo.charm.sh/apt/gpg.key \
  | sudo gpg --dearmor -o /etc/apt/keyrings/charm.gpg
echo "deb [signed-by=/etc/apt/keyrings/charm.gpg] https://repo.charm.sh/apt/ * *" \
  | sudo tee /etc/apt/sources.list.d/charm.list
sudo apt update && sudo apt install gum
Screenshots
charmbracelet/gum: GitHub preview cardcharmbracelet/gum: Screenshot 1charmbracelet/gum: Screenshot 2charmbracelet/gum: Screenshot 3charmbracelet/gum: Screenshot 4

Checked, and left out

Nothing to show for this edition. Recording the repositories that were checked and rejected began with Edition No. 4, and every edition from there on has the list.

Share this edition
← PreviousNo. 44Next →
Coming tomorrow

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.