Edition No. 46 · 10 Oct 2026

Twelve repositories for publishing, billing and listening to customers

Five hidden gems, eleven of the sixteen areas, and a Photoshop clone that is ten days old.

By Genn·12 repositories·16 min read

10 October 2026. Twelve open-source repositories, opened and checked this morning. No theme, on purpose.

We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.

Three things worth knowing, separate from the recommendations

- An open-source licence covers the repository, not the thing the install command fetches. Two near-identical social schedulers were examined this morning and the difference is entirely in what the licence does not reach. TryPost (#7) is AGPL-3.0 with no paid tier: the programmable interface, the assistant interface and all thirteen networks are in the public code. Mixpost, covered in Edition 4, is plain MIT with the copyright properly filled in — and its own README calls that public code "the Lite version of Mixpost Pro, a commercial product", while its official install command, composer create-project inovector/MixpostApp, fetches an application skeleton carrying no licence file and no licence field at all, which by default means all rights reserved. An MIT package inside an unlicensed application. Nobody is hiding it; it was simply never filled in. Three entries today install software that is not under their own licence. - A rename can break every obvious way of checking what version you have. cdxgen moved owner and changed its package name. The old package name is frozen at 12.8.5, Homebrew still installs 12.8.5, and the project's own releases list page says 13.1.0 is newest when the real answer is 13.3.0. Three of four checks give the wrong answer, and the only one that works is the single-release page. A user filing an issue on 28 September 2026 asked why version 13 was missing; the answer was that the name had changed. - The authors of a database are now building the feature their most popular extension does not have. sqlite-vec is explicitly brute-force by design: it compares a query against every stored row. On 30 March 2026 a core SQLite developer announced on the project's own forum that SQLite is building its own vector extension with approximate indexing, now at version 0.7 with no further features planned before 1.0. Neither page mentions sqlite-vec. That is the most consequential thing in this edition for anyone choosing a vector store today.

If you only do three things

  1. py-pdf/pypdf (#2) — five minutes, one pip install, on PDF files that already exist, and the standout of this edition. Split, merge, rotate, encrypt and pull the text out of a PDF from a few lines of Python, with no paid service and nothing uploaded anywhere. A new version shipped yesterday.
  2. cdxgen/cdxgen (#10) — twenty minutes, inside a container. Point it at a project folder and it writes a full list of every package inside, in a standard format that auditors and scanners both read. Run it in a container, not on a laptop: it starts the project's own build tools, and its authors say so plainly.
  3. getfider/fider (#6) — one evening, one container and an email provider. A public page where the people who use a piece of software post what they want next, vote on each other's ideas, and get an answer. This one is a REPEAT: Edition 3 covered it, and it is raised again because of a security release on 5 October 2026. ---

A Photoshop clone reached 39,000 stars in ten days

Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.

what it doesstorytold/photocraft

39,525 stars · MIT OR Apache-2.0, both read from the files. LICENSE-MIT names 'ArtCraft Team and the PhotoCraft contributors' (2026); LICENSE-APACHE omits the appendix entirely, so that half of the dual licence carries no copyright line at all. · v0.6.0 (2026-10-10), read from /releases/latest; the repository was created 2026-09-30, which bounds the year. Note Cargo.toml declares version 0.2.0 against a v0.6.0 tag. · Track this in Scout

A free picture editor that opens Photoshop files and copies Photoshop's layout, ten days old and self-described as an early test version.

▶Repo detailsthe review · specs · pros & cons · install

What it does

PhotoCraft opens a picture, shows it in layers, and lets you paint, mask, cut, type and draw shapes on those layers. It reads and writes real .psd and .psb files through a separate piece of code built from Adobe's published file description, so a file can go out to someone using Photoshop and come back. It also handles PNG, JPEG, TIFF, WebP, OpenEXR and AVIF, plus its own .pcraft format. Drawing happens on the graphics card, through the same drawing system used by modern browsers, with a slower fallback that uses the main processor instead. Every single action is also a named command, so the same edits can be run from the command line or from a script instead of by hand — the project counts more than 500 such commands. The project reports that 134 of its 135 test files save back to .psd byte for byte; that is its own measurement, not an outside one. It does not have Photoshop's full feature set, and the project tracks the gap publicly rather than claiming otherwise. It has no plug-in system, so Photoshop plug-ins will not run in it.

Why it matters

Who it suits. Anyone who opens a .psd file a few times a month and resents paying a subscription for the privilege. It also suits anyone who wants to apply the same edit to four hundred images from a script, because the command line and the graphical program share one list of commands. Skip it if the pictures are paid work with a deadline: at ten days old it is a test version, and a tool that produces slightly different output from the one your client uses is a problem you do not need.

What people say. Two named outlets have written about it and they disagree in a useful way. Michael Larabel at Phoronix, 7 October 2026, puts both "open-source" and "clean room" in quotation marks, writes that the project "appears to be rely predominantly on AI", and says the effort raises "potentially pressing legal challenges" without naming them; Phoronix sells advertisement-free subscriptions and its own benchmarking software, but nothing that competes with a picture editor. Joey Sneddon at OMG Ubuntu, 8 October 2026 actually installed it and tested it on Ubuntu: he found it quick to start but "some way off feeling like it's Photoshop", called it "A superficial facsimile with pronounced flaws", and made the point that matters most — "Having similar features in similar locations with similar names/icons is not the same as features behaving or outputting that is the same." He also measured memory use reaching about 5 GB after opening one .psd file. Set that hands-on account against the project's own 134-of-135 figure before believing either on its own.

Verdict. Worth twenty minutes of curiosity and nothing more yet. Download it, open a .psd you have a backup of, and see whether the layers land where you expect. Do not move real work onto it this month, and do not treat the file-fidelity numbers as independent. If you want a mature free picture editor today, GNOME/gimp is thirty years old and still shipping, though its menus are nothing like Photoshop's. If you want a Rust editor with a different idea of how editing should work, GraphiteEditor/Graphite was Edition 25's entry on diagrams' near neighbour and runs in a browser. The honest summary is that PhotoCraft is the most interesting new repository of the week and the least safe one to rely on.

Stars39,525
LicenceMIT OR Apache-2.0, both read from the files. LICENSE-MIT names 'ArtCraft Team and the PhotoCraft contributors' (2026); LICENSE-APACHE omits the appendix entirely, so that half of the dual licence carries no copyright line at all.
Latestv0.6.0 (2026-10-10), read from /releases/latest; the repository was created 2026-09-30, which bounds the year. Note Cargo.toml declares version 0.2.0 against a v0.6.0 tag.
Good
  • It opens and saves real Photoshop files, which is the one thing most free picture editors get wrong.
  • Every action is also a command, so the same edit runs by hand, from a script, or against four hundred files in a batch.
  • Dual MIT or Apache-2.0 licence read from the files, with no extra conditions, no paid key and no watermark.
Watch for
  • It is ten days old and self-described as "early alpha". There are already 540 open issues and 222 open pull requests.
  • One named reviewer who installed it calls it "a superficial facsimile with pronounced flaws" and measured about 5 GB of memory after opening a single file. The project publishes no memory requirement at all.
  • The Apache-2.0 file has no copyright line in it, so who owns that half of the dual licence is unclear. Two named outlets report the code as largely written by AI tools, and one says the "clean room" claim raises legal questions nobody has answered.
Similar repositories
Install
git clone https://github.com/storytold/photocraft
cd photocraft
cargo run --release -p photocraft -- image.psd
Screenshots
storytold/photocraft: GitHub preview cardstorytold/photocraft: Screenshot 1storytold/photocraft: Screenshot 2storytold/photocraft: Screenshot 3storytold/photocraft: Screenshot 4
what it doespy-pdf/pypdf

10,250 stars · BSD-3-Clause read from /blob/main/LICENSE, holders FILLED IN (Mathieu Fenniak 2006-2008, with contributions by Ashish Kulkarni and Steve Witham), no added conditions; confirmed by pyproject.toml at the tag and by the package page. · 6.20.0 (2026-10-09), settled three ways: the release title itself carries the year, the package page says 'Released: Oct 9, 2026', and CHANGELOG.md read AT THE TAG says 2026-10-09. · Track this in Scout

Joins, splits, locks and reads PDF files from a few lines of Python, with no service involved and nothing uploaded anywhere.

▶Repo detailsthe review · specs · pros & cons · install

What it does

pypdf reads a PDF file, gives you its pages as objects, and writes a new file out. It merges several documents into one, pulls a page range into its own file, rotates and crops pages, and copies bookmarks, named destinations, annotations and viewer settings across. It extracts text, with an optional "layout mode" that tries to keep columns in the order a person would read them. It opens password-protected files and can encrypt the ones it writes — the basic install handles the older RC4 scheme, and the stronger AES needs the extra pypdf[crypto] install. It decodes the compression formats PDFs use, including Brotli, which arrived in version 6.20.0 on 9 October 2026. It is written in pure Python, so a plain install pulls in almost nothing else. It does not draw pages as images, so it is not a viewer and cannot make thumbnails. It does not do character recognition on scans, and it does not find tables or work out page layout — that is a different tool's job.

Why it matters

Who it suits. Anyone who handles PDFs in bulk: merging statements, splitting a scanned batch into one file per invoice, stripping passwords off files a supplier insists on protecting, or pulling text out of a hundred reports so something else can search them. It is also the right choice when the documents must not leave the building, because there is no service involved. Skip it if you want to see the pages — it has no interface — and skip it if the PDFs are photographs of paper, because it reads text that is already text.

What people say. Two independent distributions carry it and both name a maintainer and a date, which is the most useful outside signal a library like this gets. The Arch Linux package page, read 10 October 2026, lists python-pypdf 6.20.0-1 packaged by Caleb Maclennan and last updated 9 October 2026 — the same day as the upstream release. The Debian package tracker, also read 10 October 2026, records 6.19.0-1 accepted into unstable on 30 September 2026 by Pieter Lenaerts and migrated to testing on 5 October 2026. Neither sells anything. The one security write-up found, Wiz on CVE-2026-33123 published 20 March 2026, describes a crafted PDF driving excessive processor and memory use in versions before 6.9.1 — and Wiz sells a commercial cloud-security product, so its vulnerability database is marketing as well as information, although the facts check out against the project's own advisory list. No authored, dated, non-vendor technical review of pypdf exists that we could find, and that is the honest finding.

Verdict. The best five minutes in this edition. Install it, point it at a folder of PDFs, and it will do in one afternoon what a paid tool charges monthly for. The one thing to know is the security pattern: the project published ten advisories between 26 May and 23 June 2026, all of the same kind — a malformed PDF making it loop forever or eat memory — and it keeps shipping limits to stop them. So wrap it in a time limit and a memory cap before feeding it files from strangers, and stay on the current version. If you need to turn pages into pictures, pymupdf/PyMuPDF does that and was Edition 37's entry, but it is AGPL-3.0 with a paid commercial option rather than BSD. If you want tables out of a PDF, jsvine/pdfplumber is the tool for that job.

Stars10,250
LicenceBSD-3-Clause read from /blob/main/LICENSE, holders FILLED IN (Mathieu Fenniak 2006-2008, with contributions by Ashish Kulkarni and Steve Witham), no added conditions; confirmed by pyproject.toml at the tag and by the package page.
Latest6.20.0 (2026-10-09), settled three ways: the release title itself carries the year, the package page says 'Released: Oct 9, 2026', and CHANGELOG.md read AT THE TAG says 2026-10-09.
Good
  • BSD-3-Clause read from the file with the real copyright holders named, no added conditions, and a plain install that pulls in essentially nothing else.
  • Genuinely current: version 6.20.0 released 9 October 2026, confirmed by the project's own changelog, its package page and two independent Linux distributions.
  • It publishes actual hardening limits with numbers — 10,000 objects before it gives up recovering a damaged file, 500,000 objects while copying, a maximum object number of 1,000,000 — all of which can be turned off if you need to.
Watch for
  • Ten published advisories in four weeks of mid-2026, every one of them a malformed file causing an endless loop or runaway memory use. Current versions are patched, but the pattern says: do not hand it untrusted files without a timeout.
  • The stronger AES encryption, image extraction and right-to-left text all need extra installs, and the [full] option pulls in a component under the LGPL, which is a stricter licence than the library's own BSD. The documented route for one image format tells you to install jbig2dec, which is GPL3.
  • It is a library. There is nothing to open, nothing to click, and no command-line tool as the main way in.
Similar repositories
Install
pip install pypdf
pip install pypdf[crypto]
pip install pypdf[image]
Screenshots
py-pdf/pypdf: GitHub preview card
03

fontra/fontra

💎 hidden gem
what it doesfontra/fontra

844 stars · GPL-3.0 read from /blob/main/LICENSE.txt, verbatim and unmodified, no added conditions. HOLDER NOT FILLED IN: the only copyright line is the Free Software Foundation's own on the licence text, and the appendix is left as the template; attribution lives in separate AUTHORS.txt and CONTRIBUTORS.txt. · Fontra Pak 2026.10.0 (2026-10-05). The repository itself publishes NO releases; desktop builds ship from the sibling fontra-pak. Settled three ways: fontra.xyz asset timestamps, CHANGELOG.md on main, and the snap listing. · Track this in Scout

A typeface editor that runs in a browser against a folder on your own machine, built variable-font-first.

▶Repo detailsthe review · specs · pros & cons · install

What it does

Fontra has two halves: a program written in Python that runs on your machine and reads the files, and a drawing interface written in JavaScript that opens in a browser at http://localhost:8000/. You start it by pointing it at a folder — fontra --launch filesystem /path/to/a/folder — and it lists the fonts it finds there. It opens .designspace, .ufo, .ttf and .otf sources, and it is built around variable fonts first rather than treating them as an afterthought. Beyond drawing outlines it edits font information, spacing between letter pairs, typographic features and the variation axes themselves, with an overview screen for the whole character set. Storage backends and interface panels are plug-ins registered through a standard mechanism, which is how a separate package adds support for a Chinese-Japanese-Korean format and a remote server. The project calls itself "in-development" and publishes a roadmap listing what is missing. It does not edit .ttf or .otf binaries directly for a quick fix — that is marked "currently not planned", so you export instead. It has no scripting interface and no plug-in interface for ordinary users yet, both planned and neither started, and none of the collaborative features — seeing someone else's selection, comments, suggested edits — exist.

Why it matters

Who it suits. Anyone drawing a typeface who wants to work in a browser without installing a large desktop application, and anyone whose fonts are variable fonts, since that is what the whole design is arranged around. It also suits a small team that wants the files to stay in a folder they control rather than inside an application's own format. Skip it if you need hinting, proofing, or any of the long list of features the roadmap marks as not started — and skip it if you need a finished tool this quarter.

What people say. Fontra's standing is institutional rather than editorial, and the distinction matters. It was presented at ATypI Paris in 2023 by Jérémie Hornus of Black[Foundry] and by Just van Rossum, the author of FontTools — the library almost every font pipeline in the world depends on — and again at the Libre Graphics Meeting on 30 May 2025, hosted by Lasse Fister. Both of those are the project's own talks, so they establish who is behind it and nothing more. Steve Emms wrote it up at LinuxLinks on 27 March 2026, and that piece is accurate on the licence and the architecture but is a catalogue entry rather than a test: no screenshots of his own, no criticisms, no requirements. Beyond that there is nothing. There is no substantial independent hands-on review of Fontra anywhere we could reach, and that is the honest finding.

Verdict. Worth an evening if you draw type, and worth nothing if you do not — this is a specialist tool and it does not pretend otherwise. What makes it interesting is the provenance: when the author of FontTools builds a new editor, the file handling is likely to be right even while the interface is not. Two practical warnings. The core program has no password and no login of any kind; it binds to localhost by default, which is correct, but if you expose it beyond that you have published an editor with access to the folder you launched it against. And pip install fontra installs an unrelated package of the same name, not this editor — use the desktop build or install from the repository. For a mature alternative today, fontforge/fontforge is the long-standing free option; for something smaller and browser-only, glyphr-studio/Glyphr-Studio-2 is aimed at beginners by its own description.

Stars844
LicenceGPL-3.0 read from /blob/main/LICENSE.txt, verbatim and unmodified, no added conditions. HOLDER NOT FILLED IN: the only copyright line is the Free Software Foundation's own on the licence text, and the appendix is left as the template; attribution lives in separate AUTHORS.txt and CONTRIBUTORS.txt.
LatestFontra Pak 2026.10.0 (2026-10-05). The repository itself publishes NO releases; desktop builds ship from the sibling fontra-pak. Settled three ways: fontra.xyz asset timestamps, CHANGELOG.md on main, and the snap listing.
Good
  • Plain GPL-3.0 read from the file, no added conditions, no paid tier and no licence key anywhere.
  • Properly current: code on the main branch four days before this edition, 33 dated releases in 2026 alone, and desktop builds for macOS, Windows and Linux dated 5 October 2026.
  • It binds to localhost by default rather than to every network interface, which is the right choice for a single-person tool and the opposite of several other entries in this edition.
Watch for
  • The roadmap's "not yet" list is long and includes things a working type designer needs: vertical text, interactive spacing, font-level guides, advanced segment editing, scripting. None of the collaborative features exist.
  • No independent review of it exists at all, so there is nobody outside the project to tell you where it breaks.
  • Two traps for the unwary: the GPL file never had its copyright holder filled in, and the fontra name on Python's package index belongs to an entirely different project. The Linux snap package is published by a third party, not by the Fontra organisation.
Similar repositories
Install
python3.10 -m venv venv --prompt=fontra
source venv/bin/activate
pip install --upgrade pip
pip install -r requirements.txt
pip install -e .
fontra --launch filesystem /path/to/a/folder
Screenshots
fontra/fontra: GitHub preview card
04

tsduck/tsduck

💎 hidden gem
what it doestsduck/tsduck

1,089 stars · BSD-2-Clause read from master/LICENSE.txt, holder FILLED IN and current: 'Copyright (c) 2005-2026, Thierry Lelegard'. No added conditions beyond the two standard clauses. The most permissive licence in the edition. · v3.45-4798 (2026-09-12), settled against freshports.org, which records the FreeBSD port moving 3.44 to 3.45 with Last Update 2026-09-13, and corroborated by Homebrew, whose stable version is exactly 3.45-4798. · Track this in Scout

Reads, measures and rewrites the video streams used by digital television, as a set of small command-line tools and a pipeline.

▶Repo detailsthe review · specs · pros & cons · install

What it does

TSDuck is a set of command-line programs plus one pipeline tool, tsp, that chains an input, any number of processing steps, and an output. Inputs and outputs include plain files, network streams over UDP, HTTP, SRT and RIST, real television tuner cards, and professional capture and modulator hardware. On the reading side it takes a stream apart and explains its signalling tables for the European, American, Japanese and ARIB standards, measures the bitrate of the whole stream and of each component, scans networks and extracts or inserts tables. It can convert a stream between delivery systems, filter and renumber components, rewrite service descriptions, and scramble or unscramble, including standing in for the key servers a television head-end needs so that the rest can be tested. Recent work pushes stream measurements into a time-series database so they can be drawn on a dashboard. It ships as a C++ library as well, with Python and Java bindings, and the documentation runs to separate user, builder, developer and contributor guides. It explicitly has no graphical interface — its own README says so — and every tool does one small job on purpose. It is not an encoder or a transcoder: it works at the stream and signalling level and lists no video or audio compression features at all.

Why it matters

Who it suits. Anyone who handles digital television or professional video contribution feeds: an engineer checking why a channel drops, a small broadcaster building a test setup, a developer writing software that has to read those streams. Skip it entirely if your video is files and web players — this is about the signalling layer underneath broadcast, and nothing in it will help with an MP4 on a website.

What people say. This is the rare specialist tool with real third-party standing, and all of it is checkable. Cisco's own technical note Document ID 214208, updated 13 December 2018, contributed by Cisco engineers Tristan Van Egroo and Francesco Di Ciccio, uses TSDuck's key-server simulator in place of a commercial product to build a cable television test environment; Cisco sells the hardware in that document, but TSDuck is the free test instrument in it rather than a competitor. The HbbTV Association's developer portal lists it under development and testing tools. The European Broadcasting Union's own awesome-broadcasting list includes it. And the RIST Forum's certified-products page corrects an easy overclaim: TSDuck is not in the tested-and-certified list, it appears only under "Open source RIST implementations". What does not exist is a dated editorial review of it that we could read end to end, and the project's own references page is a collection of company testimonials that the companies posted themselves.

Verdict. If broadcast streams are part of the job, install it today; it is the tool the industry quietly already uses, and the dormant state of its nearest small competitor says why. If they are not, read this entry for the finding rather than the software. The one real risk is written on the README in the author's own words: "TSDuck is maintained by one single developer on spare time and on personal expenses." Nine years and 4,800 commits is a strong record, but it is one person's record. Note also that the project publishes no running memory figures — only build-time ones, and those are sobering: an unparallelised build on a 2020 machine "takes several hours", against two minutes on a recent Apple machine with ten parallel jobs. For wider multimedia work rather than broadcast signalling, gpac/gpac covers more ground; for packaging streams for web delivery with encryption, shaka-project/shaka-packager is the industrial choice.

Stars1,089
LicenceBSD-2-Clause read from master/LICENSE.txt, holder FILLED IN and current: 'Copyright (c) 2005-2026, Thierry Lelegard'. No added conditions beyond the two standard clauses. The most permissive licence in the edition.
Latestv3.45-4798 (2026-09-12), settled against freshports.org, which records the FreeBSD port moving 3.44 to 3.45 with Last Update 2026-09-13, and corroborated by Homebrew, whose stable version is exactly 3.45-4798.
Good
  • BSD-2-Clause read from the file with the copyright line filled in and running to 2026 — the most permissive licence in this edition, with no conditions beyond keeping the notice.
  • Code pushed the same morning it was checked, 4,801 commits since 2017, and zero open pull requests against 257 closed — one of the cleanest review records this report has seen.
  • Nothing listens on a network port unless you ask for it, there is no account, no password and no telemetry, and it costs nothing to run beyond the hardware it runs on.
Watch for
  • One unpaid maintainer. The README says so plainly, and that is the whole risk in a sentence.
  • No graphical interface at all, by design, and no runtime memory or processor figures published anywhere. Building from source needs GNU Make 4 or newer and a C++20 compiler — specifically GCC 13, Clang 17 or Visual Studio 2022, because older ones are rejected over compiler bugs.
  • The .deb and .rpm files on the releases page are not signed by a distribution, so installing them bypasses the signature checking your package manager would otherwise do. Prefer the Homebrew, winget, FreeBSD or community distribution packages where they exist.
Similar repositories
Install
brew install tsduck
winget install tsduck
pkg install tsduck
Screenshots
tsduck/tsduck: GitHub preview card
05

FOSSBilling/FOSSBilling

💎 hidden gem

1,710 stars · Apache-2.0 read from main/LICENSE, holders FILLED IN for both 'Copyright 2022 FOSSBilling' and 'Copyright 2011-2021 Boxbilling, Inc'. One non-standard appendix line noting inherited BoxBilling code, which is attribution rather than a restriction. No field-of-use, competing-use, branding, licence-key or network clause. · 0.8.8 (2026-10-03), settled three ways: the release notes heading carries the year in full, Docker Hub's tag record gives last_updated 2026-10-03T07:06:56Z three minutes after the publish, and the mirror's release record matches to the minute. · Track this in Scout

Self-hosted recurring billing, invoicing and customer accounts for a small service business, and the only maintained open-source option of its kind.

▶Repo detailsthe review · specs · pros & cons · install

What it does

FOSSBilling runs the whole commercial loop for a business that charges people every month. It holds a product catalogue, a shopping basket and a checkout, turns a paid order into a provisioned service, generates recurring invoices, and captures payment through add-on modules for individual payment providers. Customers get their own login with invoices, services and support tickets; staff get accounts with fine-grained permissions. A single scheduled job every few minutes drives invoice generation and the suspension of unpaid services. The interface is themed with templates, and an extension system lets other people add payment providers and hosting-panel integrations. It was forked in May 2022 from BoxBilling, an older project of the same kind, and exists to be its maintained continuation. It is at version 0.8.8, and its own frequently-asked-questions page says the team "doesn't generally recommend production use just yet" unless you have relevant experience, with no date given for a 1.0. It does not aim to match the commercial product it is compared with feature for feature, does not support one popular game-hosting panel and says it never will, and does not promise that BoxBilling extensions, themes or data will carry over. It is not a double-entry accounting package — there is no ledger and no bank reconciliation — and not a payment processor; you bring your own.

Why it matters

Who it suits. Anyone selling a recurring service to more than a handful of customers who has outgrown spreadsheets and invoices typed by hand, and who is willing to patch software regularly. It fits best where the alternative on the table is a commercial licence costing money every month. Skip it if nobody will be watching the advisory feed, and skip it if you want to install something and forget it — this is not that.

What people say. The outside record on FOSSBilling is almost entirely about security, and it reads two ways at once. VulnCheck published a technical analysis on 23 June 2026 by Valentin Lobstein, describing how a single missing keyword in an authorisation check let anonymous callers reach administrative endpoints, and how chaining that with an unsandboxed template renderer produced database access and then remote code execution — fixed in 0.8.0 on 28 May 2026; VulnCheck sells vulnerability-intelligence services and therefore profits from finding and publicising bugs, though the write-up is root-cause analysis with code rather than a sales pitch. Spain's national cybersecurity institute, INCIBE-CERT, published an early-warning entry on 6 July 2026 for a low-severity information-disclosure issue, also fixed in 0.8.0; a government body with nothing to sell. And the project's own advisory list runs to four pages, with four High-severity authorisation and payment-forgery problems published between 20 July and 11 September 2026 — including one where a password reset did not end existing sessions, and one where a payment notification was accepted without verifying who it was for. The second reading of the same facts is that this is a project that finds, documents and fixes these things in the open every month. Both readings are true. On the editorial side there is nothing: every general-interest article about it is an undated listicle published by a hosting company, and we excluded all of them.

Verdict. Recommend it, with conditions, because it is effectively the only live option in its category — and that fact is the finding. Its own ancestor, boxbilling/boxbilling, was archived by its owner on 14 February 2026 and is now read-only, with a README that has said it is unmaintained since October 2022. So anyone still running BoxBilling is running unmaintained payment code. FOSSBilling is the maintained continuation, it ships roughly monthly, and its licence is plain Apache-2.0 with the copyright filled in. Install it if, and only if, you will keep it patched, put it behind TLS, and protect the install/ directory afterwards — the documentation never tells you to, and its sample web-server configuration still routes that directory to the application. The nearest live alternative is paymenter/paymenter, which is MIT and was pushed the same day this edition was written; it is younger and narrower but worth comparing. invoiceninja/invoiceninja is bigger and better known but is not open source — its own README calls it "source-available" and removing its branding costs a yearly fee.

Stars1,710
LicenceApache-2.0 read from main/LICENSE, holders FILLED IN for both 'Copyright 2022 FOSSBilling' and 'Copyright 2011-2021 Boxbilling, Inc'. One non-standard appendix line noting inherited BoxBilling code, which is attribution rather than a restriction. No field-of-use, competing-use, branding, licence-key or network clause.
Latest0.8.8 (2026-10-03), settled three ways: the release notes heading carries the year in full, Docker Hub's tag record gives last_updated 2026-10-03T07:06:56Z three minutes after the publish, and the mirror's release record matches to the minute.
Good
  • Plain unmodified Apache-2.0 read from the file, with the copyright filled in for both FOSSBilling and the original BoxBilling authors, and a stated promise that the core will never cost money.
  • A sensible configuration template out of the box: debugging off, a per-install random secret generated rather than shipped, HTTPS forced, error reporting off, request-forgery protection on, rate limiting on, and the administrator account created interactively rather than shipped with a password.
  • A real coordinated-disclosure process with dated public advisories, roughly monthly releases through 2026, and code pushed the day before this edition.
Watch for
  • It is version 0.8.8 and the project itself says it is not ready for production unless you know what you are doing. There is no 1.0 date.
  • Four High-severity authorisation and payment-forgery advisories between July and September 2026. The fixes landed quickly; the pattern says this is money-handling code that still needs watching.
  • Two sharp edges in the documented installs. The installation guide never tells you to remove or protect the install/ directory afterwards. And the official container maps port 80 on every interface with no TLS and no warning, while the application's own configuration default is to force HTTPS.
Similar repositories
Install
export MARIADB_PASSWORD="$(openssl rand -base64 32)"
docker compose up -d
Screenshots
FOSSBilling/FOSSBilling: GitHub preview card

4.5k stars · AGPL-3.0 · v0.36.1 (2026-07-03) · Track this in Scout

Self-hosted public feedback board — a roadmap that builds trust, and user language that doubles as keyword research.

▶Repo detailsthe review · specs · pros & cons · install

What it does

Fider puts up a public board at an address you choose. Anyone who signs in can post an idea, vote on anybody else's, and reply in a threaded comment. The person running the board gives each post a status and writes an official response, which sends an email to everyone who voted and can also send a message to another system through a webhook. Each board gets its own title, welcome message, branding and shareable link, and search across posts. Posts can be tagged and grouped. Signing in is by a link emailed to you, with optional sign-in through Google, GitHub or Facebook; voting requires being signed in, which is deliberate — it is what stops one person voting fifty times — and it is also the main thing people grumble about. It is translated into several languages, and a multi-board mode serves separate boards on separate subdomains. It ships as a single program written in Go serving a browser interface, backed by PostgreSQL 12 or newer, distributed as a container. It will not run usefully without an outbound email provider — one of SMTP, Mailgun or Amazon SES is mandatory and the no-reply address has no default. It is not a help desk: there are no agents, queues, assignment, service-level targets, canned replies or private one-to-one conversations, because everything on it is public. It is not a live chat widget and not a customer-records system. There is no built-in roadmap board, no mobile app and no in-application widget — you send people a link.

Why it matters

Who it suits. Anyone shipping software to more than a few dozen people who is currently guessing what to build next, and who would rather have the argument in public than in a support inbox. It suits open-source maintainers particularly well, because the board doubles as a filter: an idea nobody votes for is an answer in itself. Skip it if what you actually need is a ticket queue with assignment and private threads — that is a different product — and skip it if you have no way to send email.

What people say. Independent editorial coverage of Fider is genuinely thin for a nine-year-old project, and we would rather say so than pad it. The one real hands-on account is by Isaac Johnson, a named cloud architect, at freshbrewed.science on 3 June 2025, and it is useful precisely because it is critical: his container kept crashing until he filled in the mail settings, he found the email verification for the first administrator "seems silly", the verification message never arrived and he had to dig the link out of his mail provider's logs, and he noted that the sign-in-by-email model "might be a challenge". His conclusion after moving it to Kubernetes with a mail provider and TLS was "Once in Kubernetes, it worked like a charm". He sells nothing and has no connection to the project. The second useful source is the project's own security record: advisory GHSA-wjrq-7x2x-9p48, published 5 October 2026, was reported by an outside researcher and describes unescaped user names and post titles landing misleading links in other people's notifications; it was patched the same day in version 0.38.2, with an honest note that notifications created before the upgrade are not rewritten. Fider also appears as a one-click template on several hosting platforms — Railway, Hostinger, Dokploy — which is evidence of distribution rather than quality, and every one of those companies makes money when you deploy through them.

Verdict. The most complete product in this edition, and the reason it earns a second outing: nine years old, code pushed the day before this was written, a release five days before that whose headline content is two externally reported security fixes plus a hardening pass, and 31 open issues against 4,572 stars — a tracker somebody is grooming rather than abandoning. Run it for an evening and the hard part is the mail provider, not the software. Four practical warnings. Encryption is off by default and the program binds every network interface on port 3000, with the documented container mapping that to port 80, so put a proxy in front. Signups are open by default. The docker-compose.yml in the repository is a development file full of hardcoded passwords — do not deploy it. And there is no latest tag on its container registry, so pin a version. The closest alternatives are logchimp/logchimp and clearflask/clearflask; the second is Apache-2.0 rather than AGPL, which matters if the network clause is a problem.

Stars4.5k
LicenceAGPL-3.0
Latestv0.36.1 (2026-07-03)checked 7 Sep 2026
Written inGo
RunsSelf-hosted on your own server
Setup effort
2 / 5
Payoff
3 / 5
Good
  • Plain unmodified AGPL-3.0 read from the file, with no added conditions. The 250-item limit and the paid tier belong to the company's hosted service, not to the licence or the self-hosted version.
  • Hardening defaults that are right rather than convenient: no shipped credential, a signing secret that is mandatory with no default so it cannot start with a baked-in key, outbound webhooks blocked from reaching private networks, the measurements endpoint off, and a 25 MB request limit and iframe restrictions added in the newest release.
  • A tidy project: 31 open issues on a nine-year-old repository with 4,572 stars, an outside security report patched the same day it was published, and no curl … | bash anywhere in the install.
Watch for
  • It does nothing without an email provider. One of SMTP, Mailgun or Amazon SES is mandatory, the no-reply address has no default, and the first administrator is created by a code sent in an email — which one named reviewer never received.
  • Encryption is off by default, it binds every network interface, and new signups are open by default. The repository's own compose file is for development and ships a database password of fider_pw.
  • Voting requires signing in, which keeps the numbers honest and loses you the casual vote. And there is no latest container tag, so an unpinned pull does not resolve the way most people assume.
Replaces

That is the exact vocabulary you should be feeding into OpenSEO (Edition 2) as keyword seeds, and the exact phrasing your landing page should be using instead of yours.

Similar repositories
  • logchimp/logchimp

    The same public voting board in Node and Vue rather than Go, current but with 144 open issues on a quarter of the stars and no versioned releases at all.

    Track this in Scout
  • clearflask/clearflask

    The same feedback-and-roadmap idea under Apache-2.0 rather than AGPL, which matters if the network clause is a problem; heavier stack and no versioned releases.

    Track this in Scout
  • astuto/astuto

    The obvious smaller competitor, archived by its owner on 8 February 2026 with a README saying it is no longer maintained.

    Track this in Scout
Install
docker compose pull
docker compose up -d
docker compose logs app
Screenshots
getfider/fider: GitHub preview cardgetfider/fider: Screenshot 1
07

trypostit/trypost

💎 hidden gem

692 stars · AGPL-3.0 read from main/LICENSE.md, verbatim and unmodified, NO added conditions and NO paid split. HOLDER NOT FILLED IN: only the Free Software Foundation's own line. No licence-key variable exists anywhere in .env.example. · v1.1.0 (2026-09-21), settled three ways: the mirror's releases/latest record gives publishedAt 2026-09-21T17:45:12Z matching the page to the minute, the repository's own createdAt of 2026-01-17 is a hard lower bound, and the tag page confirms the Latest label. · Track this in Scout

Schedules and publishes social posts to thirteen networks from a machine of your own, with the programmable interface in the free code.

▶Repo detailsthe review · specs · pros & cons · install

What it does

TryPost is a web application written in PHP on the Laravel framework with a browser front end, a database, a queue for the actual publishing and a websocket service for live updates. The centre of it is a calendar with month, week and day views and drag-and-drop rescheduling, plus a composer where you write a post once and then adjust the preview for each network before it goes. It publishes to thirteen distinct networks through each one's official interface, every one with its own code and its own rules for media sizes, text length, hashtags and alternative text. It exposes a proper programmable interface of about fifty endpoints, and a machine-readable interface for assistants at a fixed address, both protected by a token scoped to one workspace — and both are in the free code rather than held back. Workspaces separate brands or clients, with owner, administrator and member roles, comments and mentions on drafts, reusable signature and label blocks, an asset library with stock image and animation search, and a browser interface translated into sixteen languages. Measurements are per-account reach and engagement shown on the post screen, with two more networks' post figures added in the newest release. The machine-learning features are present but need keys you supply yourself, so they cost nothing unless you turn them on. It does not have an inbox for replies, no social listening, no link shortener and no approval workflow. Its automation module was removed in the newest release and replaced with something narrower, although the old code is still sitting in the tree.

Why it matters

Who it suits. One person or a small team posting to several networks who wants the scheduling to run on hardware they control, with no monthly fee, no per-post cap and no account limit. It suits anyone who wants to drive publishing from a script or an assistant particularly well, because the programmable interface is in the free code rather than behind a paywall. Skip it if you need an approval workflow or an inbox for replies, and skip it if you are not willing to change several default passwords before it goes anywhere near a public address.

What people say. Nothing credible exists outside the repository, and that is the honest finding. Three searches turned up only mirror copies of the repository itself, the project's own marketing and pricing pages, and undated directory listings — one of which is published by a company selling managed hosting for exactly these tools. We used none of them. For a repository created on 17 January 2026 that absence is what you would expect, and it is the main reason to be careful: there is nobody outside the project who has run it in anger and written down what broke. A discussion thread about it does exist on one large forum, but that forum's pages cannot be read from where this report is built, so we are not characterising it. What can be checked is the code itself, and we did: the networks, the programmable interface and the assistant interface were all read from the source files rather than from the marketing copy.

Verdict. The best thing about it is what is not there. The licence is plain AGPL-3.0 with no added conditions, and there is no paid edition holding features back — the pricing page says in its own words "No feature gating", the two hosted plans differ only in how many workspaces they allow, there is no licence-key setting anywhere in the configuration, and the organisation has no private paid repository. That is worth saying because the closest comparable, inovector/mixpost from Edition 4, is the exact counter-example: its own README calls the public repository "the Lite version of Mixpost Pro, a commercial product", its shipped configuration supports four account types against twelve advertised on its website, and its paid edition is a private package on a separate major version. So if the choice is between the two, this is the one without the catch. Two things to fix before it is reachable from the internet, though, because the shipped defaults are genuinely bad: the install seeds an administrator account of admin@trypost.it with the password password and prints it to the console, and the production container file ships a database password of trypost-password and binds plain unencrypted ports on every network interface. Change both, and turn on the optional encryption profile. If you want something older and far larger, gitroomhq/postiz-app was Edition 1's entry.

Stars692
LicenceAGPL-3.0 read from main/LICENSE.md, verbatim and unmodified, NO added conditions and NO paid split. HOLDER NOT FILLED IN: only the Free Software Foundation's own line. No licence-key variable exists anywhere in .env.example.
Latestv1.1.0 (2026-09-21), settled three ways: the mirror's releases/latest record gives publishedAt 2026-09-21T17:45:12Z matching the page to the minute, the repository's own createdAt of 2026-01-17 is a hard lower bound, and the tag page confirms the Latest label.
Good
  • Plain unmodified AGPL-3.0 read from the file, with no paid tier at all: the programmable interface, the assistant interface and all thirteen networks are in the free code, verified from the source rather than from the marketing copy.
  • Thirteen networks with real code behind each one — not a list of intentions. Every network has its own publishing class, its own status handling and its own connect steps, plus a switch to turn it off.
  • It publishes actual requirements, which most entries in this edition do not: one processor core and 1 GB of memory as a minimum, two cores and 2 GB recommended, 10 GB of disk minimum and 20 GB or more recommended depending on stored media.
Watch for
  • The shipped defaults are unsafe as published. The install seeds an administrator account of admin@trypost.it with the password password and prints it to the console; the production container file carries a database password of trypost-password and a websocket secret of change-me-reverb-secret; the application and websocket ports are published on every network interface over plain unencrypted traffic unless you switch on the optional encryption profile; and the example settings file ships with debugging and verbose logging turned on.
  • It is nine months old and the documentation is already out of step with the code in three places: the README still says twelve networks when thirteen are implemented, the upgrade guide documents a version 2.0 with its own one-off data migration while no 2.0 release is tagged, and the removed automation module's code is still in the tree.
  • No outside source has written about it at all, so there is nobody independent to tell you where it breaks. Fifteen open pull requests sit against a nine-month-old project with 182 copies.
Similar repositories
Install
git clone https://github.com/trypostit/trypost.git
cd trypost
docker compose -f compose.prod.yaml run --rm --no-deps app php artisan key:generate --show
docker compose -f compose.prod.yaml up -d
docker compose -f compose.prod.yaml exec app php artisan db:seed --force
docker compose -f compose.prod.yaml exec app php artisan db:seed --class=UserSeeder --force
docker compose -f compose.prod.yaml --profile proxy up -d
Screenshots
trypostit/trypost: GitHub preview cardtrypostit/trypost: Screenshot 1

19,423 stars · MIT read from raw main/LICENSE after the blob URL returned a server error. HOLDER FILLED IN BUT STALE AND INTERESTING: 'Copyright (c) 2016 Netlify <decap@p-m.si>' — the original owner's name with the new maintainer's contact address. Ownership moved in February 2023; the copyright line did not. No added conditions. · decap-cms@3.16.3 (2026-09-22), settled against the mirror's releases/latest record (publishedAt 2026-09-22T12:51:56Z) and corroborated by packages/decap-cms-core/CHANGELOG.md on main and by the npm registry's own latest for decap-cms-core (3.19.1, same date). THE RELEASES LIST PAGE WAS STALE, showing 3.16.1. · Track this in Scout

An editing screen for a website whose pages live as files in a repository, where every save becomes an ordinary commit.

▶Repo detailsthe review · specs · pros & cons · install

What it does

Decap CMS is a single-page application written in React that you mount at an /admin address on a site you already publish. Someone visits that address, signs in, and gets a clean screen for editing the content; every change becomes a commit in the repository, so the files themselves are the content store and there is no separate database. What the screen offers is declared in one config.yml file: collections, fields and widgets, with widgets shipped for boolean, date, file, image, list, markdown, number, object, relation, select, string and text, plus components that embed inside the text. It works against several repository hosts — Bitbucket, a hosted gateway, GitHub, GitLab and a test backend — and recent work adds another. It does not implement passwords at all: its own security document states the project "does not store passwords, delegating authentication to providers". An optional editorial workflow adds draft, review and ready states, backed by branches and pull requests. It supports several languages, media folders and pluggable media libraries. It does not have a content interface of its own, no database and no server-side part in the default install — it is a browser program talking to a repository host. It does not host or build the website. The editorial workflow does not work against a local repository through the development proxy, which its own documentation states. And centralised user management, advanced roles, a database proxy and paid support are all routed to a commercial offering, so they are outside the open-source part.

Why it matters

Who it suits. Anyone running a site built from files — a documentation site, a company blog, a marketing site — who needs a non-technical colleague to change the text without learning git or opening an editor. It suits that job better than a database-backed system because there is nothing extra to run, back up or patch, and the content history is the repository history. Skip it if you want live collaborative editing, several people typing in one document at once, which it does not do. Skip it too if you want a content interface other programs can read from, because there isn't one.

What people say. The most authoritative outside account is three and a half years old and is about ownership rather than quality. Netlify's own engineering blog, in a post by Min Kim on 23 February 2023, announced that it was handing the project — then called Netlify CMS — to an agency partner, which renamed it Decap CMS and took over the packages, the accounts, the repositories and the website; Netlify is the party giving the project away and it sells the hosting and identity services the default configuration leans on, so that is a first-party announcement with a commercial interest, not analysis. Joost van der Schee at the web agency Usecue corroborated the handover independently in a post dated 24 February 2023; a practitioner's note, and his firm builds the kind of sites this software serves. Beyond 2023 there is no credible dated review of it that we could find — the searches returned only auto-generated directory pages, and we used none of them. One more thing belongs here because it is a competitor's claim and must carry its own label: the README of sveltia/sveltia-cms describes itself as a "complete modern rewrite", says Decap "has been neglected for years", and claims to have solved 365 reported issues from Decap's tracker. That is a rival project stating its case, none of it independently verified, and the checkable part cuts against the strong version: Decap released version 3.16.3 on 22 September 2026 and merged work in early October 2026.

Verdict. Still the sensible default for this job, with one caveat about resourcing and one about development safety. It is not abandoned — code landed on 8 October 2026, five pull requests were opened on 2 October, and the newest release is three weeks old — but 565 open issues on a project whose own security document says it is "a community-maintained open-source project without dedicated security staff" is a real signal about how much attention it can give. The thing to be careful about is the local development proxy, npx decap-server: it listens on port 8081, has no authentication of any kind, writes to your repository on behalf of whoever reaches it, and does not bind to the local machine only unless you tell it to. Before version 3.8.0 it accepted requests from anywhere. If you want a drop-in replacement whose compatibility is the whole pitch, look at sveltia/sveltia-cms; if you want visual editing on the page itself, tinacms/tinacms does that and was Edition 35's late substitution.

Stars19,423
LicenceMIT read from raw main/LICENSE after the blob URL returned a server error. HOLDER FILLED IN BUT STALE AND INTERESTING: 'Copyright (c) 2016 Netlify <decap@p-m.si>' — the original owner's name with the new maintainer's contact address. Ownership moved in February 2023; the copyright line did not. No added conditions.
Latestdecap-cms@3.16.3 (2026-09-22), settled against the mirror's releases/latest record (publishedAt 2026-09-22T12:51:56Z) and corroborated by packages/decap-cms-core/CHANGELOG.md on main and by the npm registry's own latest for decap-cms-core (3.19.1, same date). THE RELEASES LIST PAGE WAS STALE, showing 3.16.1.
Good
  • Plain MIT read from the file with no added conditions, and no database, no server process and nothing extra to patch in the default install. The content is the repository.
  • Genuinely alive: release 3.16.3 on 22 September 2026, code on 8 October 2026, and pull requests opened eight days before this edition.
  • It stores no passwords at all and says so in writing, delegating sign-in to a provider — which means there is no credential store of yours for anyone to steal.
Watch for
  • 565 open issues, and the project's own security document says it has no dedicated security staff and that some dependency problems "may not be patchable without breaking backward compatibility" because the legacy dependencies are hard to update.
  • The local development proxy listens with no authentication, writes to your repository, and does not bind to the local machine by default — only a cross-origin check stands in the way, and that check only arrived in decap-server 3.8.0.
  • The no-build-tooling install route loads the application from a third-party content network at a floating version range, so what the editing screen runs is whatever that network serves at page load. And centralised user management, roles and support are a paid offering, not part of this.
Similar repositories
Install
npm install decap-cms-app --save
Screenshots
decaporg/decap-cms: Screenshot 1
what it doessamuelclay/NewsBlur

7,649 stars · MIT read from main/LICENSE.md — NOT at /LICENSE, which 404s; the real filename was found by enumerating the repository's files through the mirror. Holder FILLED IN: 'Copyright (c) 2009 Samuel Clay, NewsBlur'. No added conditions. · v0.2.2 (2026-08-11), and it covers only the CLI, not the server, which publishes no tags. Settled against the package page for newsblur-cli, which prints 'Released: Aug 11, 2026'. · Track this in Scout

A feed reader that learns which stories are wanted and hides the rest, running since 2009 and self-hostable.

▶Repo detailsthe review · specs · pros & cons · install

What it does

NewsBlur collects articles from feeds and shows each one beside the publisher's original page rather than only as stripped text, expanding feeds that only publish a summary into the full article. Its distinguishing feature is training: thumb an author, a tag or a word in a headline up or down, and a classifier then highlights or hides matching stories, with a slider running from heavily filtered to completely unfiltered. Stories arrive as they are published rather than on a slow timer, and it notices when an article is quietly edited after publication, which is a genuinely rare feature. It searches the full text, supports custom tags and saved searches, reads email newsletters and follows video channels as though they were feeds, and shares stories to a per-person public page. There are four reading layouts, a dark mode, and native applications for phones and desktops, plus support in several third-party readers. Underneath it is a Python web application with a browser front end, backed by PostgreSQL for accounts and subscriptions, MongoDB for stories and read state, Redis for assembly and caching, optional Elasticsearch for search, a task queue for fetching, and two small services for text extraction and image proxying. The hosted free tier is capped at 64 feeds. Its agent interface requires a paid subscription, and the artificial-intelligence features and related-story discovery do nothing without a paid model key. Search is absent unless you also run Elasticsearch.

Why it matters

Who it suits. Anyone who follows more feeds than they can read and wants software to do the first pass of sorting — that is what the training is for, and nothing else in this category does it as seriously. It also suits anyone who wants their reading history to stay on hardware they control. Skip it if you want something small: this is the heaviest install in this edition by a wide margin, and the project's own README says the hosted service is the right choice for most people.

What people say. The oldest source is also the best and it is fifteen years out of date, which is itself worth knowing. Nathan Willis reviewed it at Linux.com on 23 November 2011 and was both admiring and sharp: he praised the rating and statistics engines as a level of machine learning other free readers did not attempt, and called the install instructions "on the sparse side", the database setup "non-trivial", and the whole thing "probably overkill" for one person. Several of his specific complaints no longer apply, because the stack has been rebuilt around containers since. The useful current source is a distribution rather than a review: the F-Droid package record for com.newsblur shows a reproducible build of version 15.0.5 "Added on Oct 05, 2026", confirming both the licence and that the mobile application is still being built; F-Droid is independently operated and sells nothing. One current article exists, feeder.co's comparison updated 27 September 2026, and it is published by a company selling a directly competing reader — it says so itself in the page — so we list it only as a price reference and not as an assessment. No current, credible, authored review of NewsBlur exists that we could find.

Verdict. Pay for the hosted version unless self-hosting is the point. That is the project's own advice and it is correct: running this yourself means PostgreSQL, MongoDB, Redis, Elasticsearch, a load balancer, a web server and two Node services, and the project publishes no memory or disk figure for any of it. If you do self-host, read this next. The shipped development compose file has a PostgreSQL password of newsblur, a hardcoded agent-interface secret, Elasticsearch security switched off and no Redis password — and every single port, databases included, is published on every network interface rather than only through the proxy. On top of that the documented self-hosting defaults turn on automatic premium for new accounts, enable new users automatically, and switch the signup challenge off. In other words, an install left as documented is an open-signup service with your databases exposed. Fix those four things before it touches a public address. If you want something light instead, miniflux/v2 is one Go binary, and FreshRSS/FreshRSS is a PHP application that several people can share.

Stars7,649
LicenceMIT read from main/LICENSE.md — NOT at /LICENSE, which 404s; the real filename was found by enumerating the repository's files through the mirror. Holder FILLED IN: 'Copyright (c) 2009 Samuel Clay, NewsBlur'. No added conditions.
Latestv0.2.2 (2026-08-11), and it covers only the CLI, not the server, which publishes no tags. Settled against the package page for newsblur-cli, which prints 'Released: Aug 11, 2026'.
Good
  • The training actually works and nothing else in this category attempts it seriously: highlight and hide rules per feed, with a slider from filtered to raw.
  • Real features other readers lack — original-page view, full-text expansion of truncated feeds, detection of stories silently edited after publication, saved searches, and newsletters and video channels treated as feeds.
  • MIT read from the file (at LICENSE.md, not LICENSE) with the copyright holder named, no added conditions, and code pushed the day before this edition, corroborated by an independent reproducible build five days earlier.
Watch for
  • The documented self-hosted defaults are unsafe as published: a PostgreSQL password of newsblur, a shipped agent-interface secret, Elasticsearch authentication off, no Redis password, and every port — PostgreSQL, MongoDB, Redis, Elasticsearch included — published on every interface. Plus automatic premium, automatic account enabling and no signup challenge.
  • Seven services to run and no memory, processor or disk figure published anywhere for any of them. The first visit requires typing a phrase into the browser to get past a self-signed certificate.
  • The agent interface needs a paid subscription, the machine-learning extras need a paid model key, and search needs Elasticsearch running. The hosted free tier stops at 64 feeds.
Similar repositories
Install
git clone https://github.com/samuelclay/NewsBlur.git
cd NewsBlur
make
Screenshots
samuelclay/NewsBlur: GitHub preview cardsamuelclay/NewsBlur: Screenshot 1samuelclay/NewsBlur: Screenshot 2samuelclay/NewsBlur: Screenshot 3
10

cdxgen/cdxgen

💎 hidden gem
what it doescdxgen/cdxgen

1,084 stars · Apache-2.0 read from the file at both master and the v13.3.0 tag, only licence file at root, no added conditions. HOLDER NOT FILLED IN: the appendix reads 'Copyright {yyyy} {name of copyright owner}' verbatim, and neither CycloneDX, OWASP nor AppThreat appears anywhere in the file — worth noting for a tool whose output is used as a compliance artefact. · v13.3.0 (2026-10-02), settled against the npm registry's own publish timestamp for @cdxgen/cdxgen, which decodes to 2026-10-02 ~20:09 UTC against the page's 20:03. THE RELEASES LIST PAGE IS STALE and claims v13.1.0 is Latest. · Track this in Scout

Writes a standard list of every package inside a project or a container image, in both of the common formats.

▶Repo detailsthe review · specs · pros & cons · install

What it does

cdxgen reads a project folder or a container image and produces a bill of materials — a machine-readable list of every component inside it — in the CycloneDX format, and it can also write the competing SPDX 3.0.1 format. It covers a wide range of languages and package managers, reading manifests and lock files rather than only what is installed. Beyond plain dependency lists it writes specialised kinds: one for cryptography, one for a hosted service's dependencies, one for the operating system and machine it runs on, one for hardware, and one for machine-learning models, where model identifiers can be fed in directly. For a limited set of manifest formats it resolves the dependency tree rather than a flat list, and with its bundled analysis tool it can add evidence about which parts are actually reached by the code. It signs and verifies the lists it writes, submits them to a tracking server as an optional step, and also runs as a library, an interactive shell and an HTTP service. It does not read one older binary lock file format and says so. It does not generate the older CycloneDX versions 1.4 or 1.5 — those are available only as a downgrade of its output. Licence resolution is off by default and must be switched on, and its own documentation warns that repository addresses resolved from registries "may be inaccurate or malicious".

Why it matters

Who it suits. Anyone who has been asked, by a customer or a regulator or a nervous colleague, to produce a list of what is inside a piece of software. It is also the right tool when a flat list is not enough — when you need to know which package pulled in which, because that is where the answer to "can we remove it" lives. Skip it if all you need is a quick inventory of a container image, because a simpler tool does that without running anything, and skip it if you cannot give it a container to run in.

What people say. We looked hard and the honest answer is that no independent, dated, authored technical evaluation of cdxgen exists that we could verify. The search results are dominated by comparison pages published by companies selling bill-of-materials products, and we excluded all of them. The two least bad, with their interests attached: a comparison on sbomify published 26 January 2026, which says cdxgen "focuses on deep analysis of language-specific dependency trees" and "Generates evidence-based SBOMs with call graph analysis" — but sbomify sells a commercial platform whose own action is built on top of cdxgen, so it is both a customer and a competitor, it is bylined to a well-known pseudonym rather than a person, and its stated limitation of "CycloneDX output only" is now out of date; and a piece by James Walker at Earthly on 29 December 2023, which is properly authored and dated but is almost three years old and predates two major versions. Against that absence, the project's own documents are unusually good: it ships a threat model, a permissions document and a supply-chain transparency document in the repository, which very few projects of this size do.

Verdict. Install it, in a container, and it answers the question in twenty minutes. Two findings matter more than the usual caveats. The first is a rename that quietly breaks the three most obvious ways to check what version you have: the project moved from CycloneDX/cdxgen to cdxgen/cdxgen, the package name changed from @cyclonedx/cdxgen to @cdxgen/cdxgen with the old name frozen at 12.8.5, brew install cdxgen still installs 12.8.5, and the releases list page itself claims 13.1.0 is newest while the actual latest is 13.3.0. The second is written in the project's own threat model: "Accurate dependency resolution often requires invoking build tools that may execute untrusted code", rated High risk, with the advice to "Scan untrusted code in containers or ephemeral CI environments, not on developer machines". Take that seriously. If you want the safer, shallower answer, anchore/syft from Edition 45 catalogues what is present in an image without running anything; if you only need the other standard format, microsoft/sbom-tool writes SPDX and nothing else.

Stars1,084
LicenceApache-2.0 read from the file at both master and the v13.3.0 tag, only licence file at root, no added conditions. HOLDER NOT FILLED IN: the appendix reads 'Copyright {yyyy} {name of copyright owner}' verbatim, and neither CycloneDX, OWASP nor AppThreat appears anywhere in the file — worth noting for a tool whose output is used as a compliance artefact.
Latestv13.3.0 (2026-10-02), settled against the npm registry's own publish timestamp for @cdxgen/cdxgen, which decodes to 2026-10-02 ~20:09 UTC against the page's 20:03. THE RELEASES LIST PAGE IS STALE and claims v13.1.0 is Latest.
Good
  • Plain Apache-2.0 read from the file with no added conditions, and genuinely active: code pushed the same morning it was checked.
  • Unusually honest documentation. It ships a threat model that rates its own highest risk as High and tells you where not to run it, plus permissions and supply-chain documents, and its own install instructions recommend skipping install scripts and waiting two days before taking a new package version.
  • Good supply-chain practice all round: no curl … | bash anywhere, the standalone binary route verifies a checksum before running anything, and releases are published automatically with provenance attached.
Watch for
  • It starts the build tools of whatever it scans. Its own threat model rates that High risk and says to confine it to containers or short-lived build machines. Three published advisories, two of them from 2026, are about exactly this class of problem.
  • The rename is a trap. The old package name stops at 12.8.5, Homebrew still installs 12.8.5, and the project's own releases list page is stale — so three of the four obvious ways to check the version give the wrong answer.
  • 413 open issues against one open pull request, and the server mode has no authentication at all: its documentation says to put it behind a proxy and warns against exposing it to untrusted networks, and the default bind address is not published anywhere.
Similar repositories
Install
npm install -g @cdxgen/cdxgen --omit=optional --ignore-scripts --min-release-age=2
Screenshots
cdxgen/cdxgen: GitHub preview cardcdxgen/cdxgen: Screenshot 1
what it doesasg017/sqlite-vec

8,175 stars · Dual MIT OR Apache-2.0, read from both LICENSE-MIT and LICENSE-APACHE; there is no plain LICENSE file. HOLDER FILLED IN properly in both: 'Alex Garcia', 2024. No added conditions. Two metadata defects: npm declares the malformed expression 'MIT OR Apache', which breaks automated licence tooling, and the package page's only project link is the placeholder https://TODO.com. · v0.1.9 (2026-03-31), settled three ways: the package page states 'Released: Mar 31, 2026', and the npm publish timestamp decodes to 2026-03-31 ~08:02 UTC against the page's 08:00. A pre-release 0.1.10a4 is dated 18 May 2026. · Track this in Scout

Adds find-the-closest-match to SQLite as one small portable file, with no server and nothing to compile.

▶Repo detailsthe review · specs · pros & cons · install

What it does

sqlite-vec is an extension you load into SQLite, written as a single portable C file, designed to run "anywhere SQLite runs" — Linux, macOS, Windows, inside a browser, and on small single-board computers. You create a vec0 table, put number lists in it, and query for nearest neighbours; you can keep ordinary columns alongside them for filtering and partitioning. It handles three storage sizes: full precision, eight-bit, and a one-bit form whose speed difference the author published himself — on one million long number lists, full precision took 8.52 seconds and the one-bit form returned in 124 milliseconds. It ships as a ready-made package for Python, Node, Ruby, Go and two data tools, so there is normally nothing to compile. It does not build an approximate index, which is the central thing to understand: the author states the project "is currently focused on really fast brute-force vector search", so search time grows with the number of rows rather than staying flat. Static read-only blobs do not support inserting, updating or deleting. And it does not let you add a column to a table that already exists — the numbers live in their own table, which makes queries more involved. Its own README says plainly: "sqlite-vec is a pre-v1, so expect breaking changes!"

Why it matters

Who it suits. Anyone building search-by-meaning into a program that already uses SQLite, where the collection is tens or hundreds of thousands of items rather than tens of millions, and where running a separate database server would be absurd. It suits a desktop application, a phone application, or a small service particularly well, because there is no server at all. Skip it if the collection is large and growing: with no approximate index, the cost of a query rises with the row count, and the author's own figures show a million long number lists needing about 6 GB of memory to hold.

What people say. This is the entry with genuinely strong outside sources, and the most important one is bad news. Dan Kennedy, one of SQLite's own core developers, posted on the SQLite user forum on 30 March 2026 that SQLite upstream is building its own vector extension: "There is still no vec1 release, but we are getting closer", with work remaining on processor-specific optimisation and testing he calls "woefully inadequate". The documentation for that extension says it "provides approximate nearest-neighbor (ANN) vector search", is "implemented in portable C and has no external dependencies", uses a named indexing method, and that "The current release is version 0.7" with "No further features are required before a 1.0 release." Neither page mentions sqlite-vec — and what SQLite is building is exactly the approximate indexing sqlite-vec does not have. The other substantial source is Marco Bambini's piece of 1 September 2025, which calls sqlite-vec "A clean re-implementation in C, easier to maintain, exposing a brute-force search strategy" and notes its table design "means vectors must live in separate tables and queries become more complex" — and he discloses in the article, as we do here, that he founded a company selling a competing extension and that his team first sponsored sqlite-vec. Simon Willison wrote two useful how-to pieces in August and October 2024, but he authors the two data tools sqlite-vec ships plugins for, so he is an interested neighbour, and both pieces are two years old.

Verdict. Use it today if the collection is small and the simplicity is the point — one file, no server, and it works in a browser. But go in knowing three things, and the third is the one nobody tells you. It is still before version 1.0 two and a half years in, with 52 unmerged pull requests and the last code landing on 18 May 2026 — about five months ago, well inside the line this report draws, and we are explicitly not calling it dormant. A third party has forked it, stating in the fork's README that it exists "to merge pending upstream PRs and provide community support while the original author is unavailable" — that is the fork's claim and not a verified fact, but it points the same way. And SQLite's own authors are now shipping a competing extension at version 0.7 that does the approximate indexing this one lacks, which will reshape the whole category when it lands. Its own predecessor, asg017/sqlite-vss, is the cautionary note: 2,004 stars, not archived, and no code since 5 May 2024, with a README that tells readers to come here instead.

Stars8,175
LicenceDual MIT OR Apache-2.0, read from both LICENSE-MIT and LICENSE-APACHE; there is no plain LICENSE file. HOLDER FILLED IN properly in both: 'Alex Garcia', 2024. No added conditions. Two metadata defects: npm declares the malformed expression 'MIT OR Apache', which breaks automated licence tooling, and the package page's only project link is the placeholder https://TODO.com.
Latestv0.1.9 (2026-03-31), settled three ways: the package page states 'Released: Mar 31, 2026', and the npm publish timestamp decodes to 2026-03-31 ~08:02 UTC against the page's 08:00. A pre-release 0.1.10a4 is dated 18 May 2026.
Good
  • Dual MIT or Apache-2.0 read from both files with the copyright holder properly filled in, no added conditions, no hosted dependency and nothing to pay for.
  • One portable C file with no server, installing as an ordinary package for Python, Node, Ruby and Go, and running in a browser and on small boards as well as on servers.
  • The one-bit storage option is a real, published speed difference: 8.52 seconds against 124 milliseconds on the author's own million-row benchmark.
Watch for
  • No approximate index, so a query's cost rises with the row count. The author's own numbers put one million long number lists at about 6 GB, and his benchmark machine ran out of memory on a larger set — so that figure is a practical ceiling, not just a disk size.
  • Still before version 1.0 two and a half years in, with 52 open pull requests, the last code in May 2026, and a third-party fork whose stated reason for existing is to merge what upstream has not.
  • SQLite's own core team is building a competing extension with the approximate indexing this one lacks, already at version 0.7 with no further features planned before 1.0. Two metadata defects are worth knowing too: its package metadata declares a malformed licence expression that will confuse automated tooling, and its published home page address is still the placeholder https://TODO.com.
Similar repositories
  • asg017/sqlite-vss

    The same author's earlier attempt at the same job on a heavier library; its README says it is not in active development and sends readers to sqlite-vec.

    Track this in Scout
  • sqliteai/sqlite-vector

    The same job with extra compression and no separate table, but free only inside open-source projects and non-production otherwise, where sqlite-vec is permissive.

    Track this in Scout
  • vlasky/sqlite-vec

    A fork rather than an alternative, adding distance limits and paged results, created to merge pending upstream changes by its own account.

    Track this in Scout
Install
pip install sqlite-vec
npm install sqlite-vec
gem install sqlite-vec
go get -u github.com/asg017/sqlite-vec/bindings/go
Screenshots
asg017/sqlite-vec: GitHub preview card
what it doesNousResearch/hermes-agent

252,450 stars · MIT read from main/LICENSE, holder FILLED IN: 'Copyright (c) 2025 Nous Research'. No added conditions and no non-commercial model-weights term; the repository bundles no weights. BUT the documented install fetches a script from the company's own domain, not from this repository, which then installs uv, Python 3.11, Node.js, ripgrep, ffmpeg and a portable MinGit — none of it under this licence. · v0.21.6 (2026-10-08), settled against the package page's version ladder (0.19.0 on 20 Jul 2026, 0.18.2 and 0.18.1 on 8 Jul, 0.17.0 on 19 Jun, 0.16.0 on 6 Jun), which makes an October 2025 date impossible. Note the package index LAGS BADLY: its latest is 0.19.0 against GitHub's v0.21.6. · Track this in Scout

A self-hosted assistant that runs commands, remembers past work and answers through six chat platforms and a terminal at once.

▶Repo detailsthe review · specs · pros & cons · install

What it does

Hermes Agent is a terminal program plus one gateway process that puts the same assistant behind Telegram, Discord, Slack, WhatsApp, Signal and the command line at once, including turning voice messages into text. The terminal side has multi-line editing, command completion, history, the ability to interrupt and redirect it mid-answer, and streaming output from the tools it runs. Its central claim is a learning loop: it curates its own memory, writes itself new skills after finishing a complicated task, searches past sessions by full text, and builds a model of the person using it. A built-in scheduler runs jobs on a timer and delivers the results to whichever chat app you prefer. Work can be handed to separate isolated sub-assistants, and ordinary scripts can call its tools over a local interface. Where it runs commands is pluggable across the local machine, a container, another machine over SSH, and several hosted sandbox services. It is not tied to one model provider — one command switches between its own service, an aggregator, a commercial provider or an address you supply. It also imports an existing setup from a predecessor project with one command. It publishes no hardware requirement, no model-size requirement and, in its own security document, no default ports or bind addresses for the gateway. Its own security document is explicit that the local command backend "is outside the supported posture when untrusted input sources are present", that prompt manipulation is not treated as a vulnerability, and that exposing the gateway to the public internet without a password or a firewall is out of scope.

Why it matters

Who it suits. Anyone who wants one assistant reachable from a phone and a terminal at the same time, running on hardware they control, with memory that survives between conversations. The scheduler plus the chat gateways is the combination nothing else in this edition offers: a job that runs at seven in the morning and sends you the answer on Telegram. Skip it if you want a coding assistant specifically — several narrower tools do that better — and skip it if you cannot afford to run every request through a paid model, because that bill is unavoidable.

What people say. For a project of this size, the absence of criticism is itself the finding. The only substantive outside write-up we could verify is by Ryan Merket at RuntimeWire on 3 August 2026, covering an earlier release: clause-by-clause voice streaming, speak-to-interrupt, an on-device wake word, signed outbound webhooks, a citations skill, and the default tool-iteration ceiling raised from 90 to 500. It is useful on facts and weak as assessment: it relies almost entirely on the project's own materials, offers no criticism, and discloses no relationship; it does at least note that the project's own published commit and pull-request counts disagree with the company's own graphic, and calls both approximate. That publication sells comparison tools but no competing assistant. Everything else we found was an unauthored or auto-generated review page and we used none of it. So: no critical, independent, expert assessment of this project exists outside the repository, and for something claiming a quarter of a million stars that absence is worth printing.

Verdict. Worth a weekend if the combination of chat gateways, a scheduler and persistent memory is what you actually want; not worth it as a coding assistant, where narrower tools are better. Three warnings, in order of how much they matter. First, the install is a script fetched from the company's own address and piped into a shell — not from this repository — and it then installs a package manager, a language runtime, a search tool, a media tool and a portable git, none of which is covered by the repository's MIT licence. Second, the default place it runs commands is directly on the machine, and its own document calls the approval prompt "a heuristic, not a security boundary"; skills "execute arbitrary Python at import time", so reading a skill's description is not enough, and plugins "run with full agent privileges". Third, treat the numbers as attributed rather than established: the star count reads between 250,000 and 252,450 depending on which source answers, the issue and pull-request counts are capped by the interface at "5k+" with a third-party mirror reporting about 48,000 combined, and no reading from the main programmatic source could be obtained at all this morning. The nearest alternatives are openclaw/openclaw, the predecessor it imports from, and openai/codex if the job is really code.

Stars252,450
LicenceMIT read from main/LICENSE, holder FILLED IN: 'Copyright (c) 2025 Nous Research'. No added conditions and no non-commercial model-weights term; the repository bundles no weights. BUT the documented install fetches a script from the company's own domain, not from this repository, which then installs uv, Python 3.11, Node.js, ripgrep, ffmpeg and a portable MinGit — none of it under this licence.
Latestv0.21.6 (2026-10-08), settled against the package page's version ladder (0.19.0 on 20 Jul 2026, 0.18.2 and 0.18.1 on 8 Jul, 0.17.0 on 19 Jun, 0.16.0 on 6 Jun), which makes an October 2025 date impossible. Note the package index LAGS BADLY: its latest is 0.19.0 against GitHub's v0.21.6.
Good
  • Plain MIT read from the file with the copyright holder filled in, no added conditions, and no requirement to use the authors' own model service — one command points it at an aggregator, another provider, or an address of your choosing.
  • One assistant reachable from six chat platforms and a terminal at once, with a scheduler that can deliver a job's result to any of them. Nothing else here does that.
  • The security document is unusually candid. It names what is out of scope, says the approval prompt is a heuristic rather than a boundary, warns that skills run code when imported, and notes that provider keys are stripped from the environment handed to subprocesses while stating plainly that this "reduces casual exfiltration but is not containment".
Watch for
  • The documented install pipes a remote script from the company's own address into a shell, and what lands on disk is substantially not under this repository's licence. The contributor route pipes a second remote script into a shell as well.
  • By default it runs commands directly on the machine, not in a container. Skills execute code at import time and plugins run with the assistant's full privileges. Container, remote-host and hosted-sandbox backends all exist, and none of them is the default.
  • Every request costs money at a model provider, and no hardware, memory or model-size figure is published anywhere — the only number offered is the marketing range "on a $5 VPS or a GPU cluster". The published scale figures do not reconcile between sources.
Similar repositories
  • openclaw/openclaw

    The same self-hosted personal assistant fronted by chat apps, in TypeScript rather than Python and without the self-improvement loop; the direct predecessor it imports from.

    Track this in Scout
  • openai/codex

    A terminal assistant that runs tools on the machine but scoped to a code repository, with no chat gateways, scheduler, memory loop or provider switching.

    Track this in Scout
  • anthropics/claude-code

    A terminal assistant that reads a codebase and runs git work; single-provider and coding-focused rather than a self-hosted general assistant.

    Track this in Scout
Install
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash
source ~/.bashrc
hermes
Screenshots
NousResearch/hermes-agent: GitHub preview card

Checked, and left out

Nothing to show for this edition. Recording the repositories that were checked and rejected began with Edition No. 4, and every edition from there on has the list.

Share this edition
← PreviousNo. 45Next →
Coming tomorrow

Get the next edition in your inbox

A dozen repositories, opened and checked. The licence read, the last release dated, and the ones that did not make it named with the reason. It is the half most lists leave out.

No tracking pixels. One click to leave. The archive stays free either way.

We use your address to send the edition and nothing else. Confirm by email, leave in one click. How we handle it.