Edition No. 47 · 11 Oct 2026
Twelve repositories for building code and keeping the rest running
Five hidden gems, three basic tools rewritten in Rust, and a release date that was wrong by exactly one year.
Sunday, 11 October 2026. A mixed edition, on purpose. Twelve repositories, chosen for how good they are and not for whether they fit together.
We aim for twelve every day. Some candidates fall out while we check them — those are listed at the end, with the reason.
Three things worth knowing
- A coding assistant with 24,284 stars was archived by its owner on 15 May 2026, and its own front page now sends readers to a project with 1,973 stars. This report had the larger project recorded on 8 October as alive and slowing. It is not slowing. It is read-only, and the correction is entry #5 and the left-out list. - A release date read "11 Oct" and was one year old. GitHub often prints a release date without the year. The usual mistake makes a project look one or two years older than it is. This morning the date on the page was today's own day and month, which is the most convincing possible wrong answer, and the real date is 11 October 2025. A package registry settled it. - GitHub could not name one of today's licences at all. Entry #7's sidebar showed the word "License" and no licence name, because the licence is not one GitHub recognises. The file forbids any commercial product that "offers the same or substantially similar functionality", and turns into the MIT licence two years after each release.
If you only do three things
- oxc-project/oxc (#2) — two minutes. One command, nothing installed for good, and it tells you what is wrong with your JavaScript in a fraction of the time the usual checker takes.
- facebook/pyrefly (#1) — ten minutes, on Python code that already exists. It reads the settings file your current checker already uses, so starting is one command rather than an afternoon.
- jsvine/pdfplumber (#9) — twenty minutes, on PDF files you already have. It pulls tables out of them as rows and columns, and it shows you a picture of what it thinks the table is when it gets that wrong.
Every link in one place
| # | Repository | Project site | Stars | Licence |
|---|---|---|---|---|
| 1 | facebook/pyrefly | pyrefly.org | 6,900 | MIT |
| 2 | oxc-project/oxc | oxc.rs | 22,805 | MIT |
| 3 | GitoxideLabs/gitoxide | none published | 12,009 | Apache-2.0 and MIT |
| 4 | openai/codex | none in the sidebar | 128,633 | Apache-2.0 |
| 5 | Zoo-Code-Org/Zoo-Code | zoocode.dev | 1,973 | Apache-2.0 |
| 6 | Panniantong/Agent-Reach | none published | 95,708 | MIT |
| 7 | gitbutlerapp/gitbutler | gitbutler.com | 21,795 | FSL-1.1-MIT, not open source |
| 8 | holmgr/cargo-sweep | none published | 995 | MIT |
| 9 | jsvine/pdfplumber | none published | 10,700 | MIT |
| 10 | paymenter/paymenter | paymenter.org | 2,280 | MIT |
| 11 | logchimp/logchimp | logchimp.app | 1,111 | AGPL-3.0, with part of the code under a separate licence |
| 12 | nicfit/eyeD3 | eyed3.nicfit.net | 640 | GPL-3.0 |
A coding assistant with 24,000 stars was switched off in May
Twelve repositories, checked and reviewed. Every version verified against the GitHub API and dated.
6,900 stars · MIT, read from /blob/main/LICENSE, plain and unmodified, 'Copyright (c) Meta Platforms, Inc. and affiliates.' · 1.3.2 (2026-09-28), read from /releases/latest, whose body states the year, and confirmed on pypi.org/project/pyrefly/ · Track this in Scout · Share this tool
A fast type checker for Python that reads the settings your current checker already uses.
▶Repo detailsthe review · specs · pros & cons · install
What it does
It reads your Python source files. It prints a list of places where the types you declared do not agree with the code, with the file and line for each. It also runs as a language server, which is the background program your editor talks to for jump-to-definition, autocomplete, hover text and inline hints. It is a CLI, meaning you run it by typing a command rather than clicking, and pyrefly init reads an existing Mypy or Pyright settings file and converts it, so moving across is one command. The project publishes two figures: it checks "over 1.85 million lines of code per second", and in an editor a re-check after saving a file "typically complete in under 10 milliseconds". It is the default checker for a 20-million-line Python codebase at Instagram. What it does not do is check everything by default: with no settings file it runs a basic preset that shows only high-confidence problems such as syntax errors and missing imports, and hides the rest until you configure it.
Why it matters
Who it suits. Anyone with a Python codebase big enough that a checker takes a coffee break to finish, and anyone whose editor feels slow when the project grows. It also suits a team already using another checker, because the migration command means you do not start from a blank settings file. Skip it if your Python has no type annotations at all, because there is nothing for it to check yet, and skip it if you need a stable tool that never changes under you.
Verdict. Worth ten minutes today. pip install pyrefly and pyrefly init is the whole trial, and if you dislike it you uninstall it and your old settings file is untouched. Two honest warnings. The project says plainly that it does not follow the usual version rules, and that "any version may introduce new type errors and other breaking changes", so pinning a version in a shared project is sensible. And at 6,900 stars it is much smaller than astral-sh/ty, which Edition 44 covered and which is at 19,842 — two Rust type checkers for Python, from two different companies, both released this year. If you want the one with more users today, that is ty. If you want the one with a 20-million-line codebase behind it, this is it.
- The migration command reads your existing Mypy or Pyright settings, so there is no configuration to write on day one.
- It is both a command-line checker and a language server, so one install covers the terminal and the editor.
- MIT licence, read from the file, plain and with nothing added.
- It does not follow the usual version rules, and says so: any release may add new errors and break things.
- Without a settings file it deliberately hides most problems, so a first run can look misleadingly clean.
- Upgrading it, or any library you depend on, can reveal new errors in code you did not touch.
astral-sh/tyThe same job, also written in Rust, also released this year, and at 19,842 stars it has roughly three times the following; Edition 44 covered it.
Track this in Scout- microsoft/pyright
The checker behind the Python extension in VS Code, written in TypeScript, older and slower but the one most editors already use.
Track this in Scout - python/mypy
The original, written in Python, the reference for what the rules even are, and the slowest of the four.
Track this in Scout
python3 -m venv venv source venv/bin/activate pip install pyrefly pyrefly init pyrefly check --summarize-errors
22,805 stars · MIT, read from /blob/main/LICENSE, plain, with TWO copyright holders: '(c) 2024-present VoidZero Inc. & Contributors' and '(c) 2023 Boshen' · oxlint_v1.87.0 (2026-10-05), read from /releases/latest; the year was absent and was settled against the npm registry, whose dist-tag matches 1.87.0 and whose staging timestamp resolves to 2026-10-05 — a staging timestamp, not a stated publish date, and recorded as such · Track this in Scout · Share this tool
Fast replacements for the usual JavaScript checker, formatter, parser and minifier, usable one piece at a time.
▶Repo detailsthe review · specs · pros & cons · install
What it does
It takes JavaScript and TypeScript source files. The checker, called oxlint, reads them and prints the problems it finds, and will fix the fixable ones with --fix. The formatter, oxfmt, rewrites the spacing and line breaks. There is also a parser, a transformer that turns newer syntax into older syntax, a minifier that shrinks code for the web, and a module resolver that works out which file an import refers to. The project publishes a rule count and a speed claim: oxlint has "871 built-in rules" and its own benchmarks put it "50 to 100 times faster than ESLint depending on the number of CPU cores". The transformer is stated as four times faster than its nearest rival, using 20 per cent less memory. What it does not do is cover the plugin ecosystem: support for existing checker plugins is marked alpha, and in framework files such as Vue or Svelte it lints "only their <script> blocks", so the markup part of those files is not checked at all.
Why it matters
Who it suits. Anyone whose JavaScript checker takes minutes rather than seconds, which usually means a codebase of a few hundred files or more. It also suits a project where the check runs on every save, because the difference between two seconds and two hundred milliseconds changes how often people run it. Skip it if your rules depend on a plugin outside the built-in 871, and skip it if most of your logic lives inside Vue or Svelte markup rather than in script blocks.
Verdict. The easiest two minutes in this edition. npx oxlint@latest downloads it, runs it, and leaves nothing behind, so there is no decision to make before trying it. Keep your existing checker in place while you compare the two lists of problems, because the rule sets are not identical and a shorter list is not automatically a better one. The pieces to be careful about are the newer ones: the formatter and the plugin layer are much younger than the checker, and the project routes anyone wanting a complete toolchain towards a commercial product rather than to oxc itself. Worth knowing that biomejs/biome does the same job in the same language and is a direct competitor at 25,747 stars; Edition 17 covered it.
- One command through
npxtries the checker with nothing installed permanently. - The pieces are separate, so you can adopt the checker and ignore the formatter, parser and minifier.
- MIT licence, read from the file, with two copyright holders named and no added conditions.
- Support for existing checker plugins is marked alpha, so a rule you depend on may simply not exist.
- In Vue and Svelte files it checks only the script blocks, and the markup is left unchecked.
- Every speed figure the project publishes is a multiple of a rival, never an absolute time, and no benchmark machine is named.
biomejs/biomeThe closest match, also Rust, also one tool for checking and formatting, and further along on formatting; it does not try to replace the parser and minifier as well.
Track this in Scout- swc-project/swc
The established Rust replacement for the transformer and minifier only, with no checker; oxc's own figures are measured against it.
Track this in Scout - eslint/eslint
The original checker, written in JavaScript, with the plugin ecosystem that is the real reason to stay.
Track this in Scout
# Try it with nothing installed npx oxlint@latest # Or add it to a project pnpm add -D oxlint pnpm oxlint # check pnpm oxlint --fix # check and fix what it can
12,009 stars · Dual Apache-2.0 and MIT, both read from the files at /blob/main/LICENSE-APACHE and /blob/main/LICENSE-MIT; both plain, and the MIT file carries NO copyright line at all while its own text requires the notice be retained · gix-utils-v0.5.1 (2026-10-11), read from /releases/latest and matched to the second by crates.io, which dates the same version 2026-10-11T08:14:26Z; the project releases its gix-* crates individually, so the newest tag is one workspace crate and not a whole-project version · Track this in Scout · Share this tool
Git written again from scratch as a library other programs can build on, with its own gaps written down.
▶Repo detailsthe review · specs · pros & cons · install
What it does
The main piece is a library, meaning code you call from your own program rather than something you open. It reads and writes a real git folder on disk: the stored objects, the branch names, the index of staged files, the settings, the ignore rules and the commit history. It also speaks the protocols git uses to talk to a server, so it can clone and fetch. Two command-line programs come with it: one for everyday use and one of low-level plumbing commands. Today it covers cloning, fetching, status, blame, comparing files and folders, merging file contents and folder trees, committing, and checking out a working copy. What it does not do is listed plainly in its own files: push, merging whole commits, rebase and reset are not implemented, commit hooks are not done, and the README warns that the command-line tools are development aids and that you should "not rely on them in scripts".
Why it matters
Who it suits. People writing software that handles git repositories and who do not want to shell out to the git command or link a C library. The published limits are unusually specific, so you can tell in ten minutes whether your use is covered. Skip it if you need push, rebase or reset, and skip it if you were hoping for a faster drop-in replacement for the git command you type every day, because that is not what this is.
Verdict. This is the most honest README in today's twelve, and that is the reason to take it seriously. A separate file lists its own shortcomings, including that fetches over the older protocol with a stateful connection "may hang", that pack files are read through memory maps which "squelch IO errors", and that files above two or four gigabytes cannot be loaded on a 32-bit machine. Two of its crates are declared stable and the rest are not. That combination — pre-1.0, with the gaps written down rather than discovered — is far safer to build on than a project that promises everything. If you want a finished tool today rather than a foundation, libgit2/libgit2 is the C library everything else already uses, and rust-lang/git2-rs wraps it for Rust.
- A separate file in the repository lists its own weaknesses, with specifics rather than apologies.
- Dual Apache-2.0 and MIT licences, both read from the files, with nothing added to either.
- Code landed on the morning of this edition, and the project has been going since June 2018.
- Push, rebase, reset and merging whole commits are not implemented, and commit hooks are not done.
- Pre-1.0 and expected to stay there for a while: only two of its many crates are declared stable.
- The MIT licence file carries no copyright line at all, while its own text requires that the copyright notice be kept.
- libgit2/libgit2
The long-established C library that most git integrations already use; complete where this is not, and C rather than Rust.
Track this in Scout - rust-lang/git2-rs
The Rust wrapper around libgit2, which is the practical alternative today if you need push and rebase.
Track this in Scout - go-git/go-git
The same idea in Go: git implemented from scratch as a library rather than wrapping the original.
Track this in Scout
# Prebuilt binaries, the easy route cargo binstall gitoxide # Or from source, which needs cmake cargo install gitoxide # Or a build that needs only Rust and a C compiler cargo install gitoxide --locked --no-default-features --features max-pure
128,633 stars · Apache-2.0, read from /blob/main/LICENSE, plain and unmodified, 'Copyright 2025 OpenAI' · rust-v0.162.1 (2026-10-09), read from /releases/latest; the year was absent and was settled against registry.npmjs.org/@openai/codex/latest, whose version matches and whose staging timestamp is consistent · Track this in Scout · Share this tool
A terminal coding assistant that reads a project, writes the changes and runs the commands to check them.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You install it, run codex in a project folder, and describe a change. It reads the files in the folder, proposes edits, applies them, and runs the commands needed to check its work, such as the test suite or a package install. It has three levels of access to your machine, named in its own documentation: read-only, workspace-write and danger-full-access. Separately from that, it has two settings for when it must stop and ask you: ask on request, or never ask. The two controls are independent, which the documentation states explicitly: one sets the technical boundary and the other decides when you are consulted. It sandboxes the commands it spawns, using the operating system's own facilities on each platform. What it does not do is work without a paid service behind it, and on Linux it does not sandbox at all without the right system support: it needs bwrap or a bundled helper that requires unprivileged user namespaces, and it prints a warning at startup when that is missing.
Why it matters
Who it suits. Anyone who already works mostly in a terminal and would rather describe a change than make it by hand, and anyone on a paid plan from this provider that already includes the tool. The sandbox levels mean it can be used cautiously: read-only is a real mode, and it is a reasonable way to start. Skip it if you are not willing to pay a model provider, and skip it if your work is on a machine where you cannot install the sandbox support it needs.
Verdict. At 128,633 stars this is the largest repository in today's twelve by a wide margin, and code landed on it on the morning of this edition. Worth half an hour if you already pay for the plan, because the setup is a single command. Two things to get right before you let it loose. First, the combination of full access and never asking removes the file and network boundaries completely, and the documentation says so in those words; that combination should be a deliberate decision and not a default you inherited. Second, on some Ubuntu systems the sandbox is blocked by a security policy, and the documentation's fallback suggestion is to turn that policy off, which is a worse trade than it sounds. Alternatives worth comparing: sst/opencode at 212,625 stars is larger still and provider-neutral, and cline/cline lives inside an editor rather than a terminal.
- Three named access levels, with read-only as a genuine option, so a cautious first run is possible.
- Apache-2.0 licence, read from the file, plain and unmodified, copyright 2025 OpenAI.
- Installs as a single command on macOS, Linux and Windows, and code landed today.
- It costs money to run. The tool is free; the thinking behind it is a paid plan or a metered key.
- Full access plus never asking removes the file and network boundaries altogether.
- Over 5,000 open issues, and the version is 0.162.1, which is still before 1.0.
- sst/opencode
The same job in a terminal, larger at 212,625 stars, and not tied to one model provider.
Track this in Scout - google-gemini/gemini-cli
The same shape from a different provider, at 107,274 stars, with the same cost structure.
Track this in Scout
Aider-AI/aiderThe older terminal assistant, which commits each change to git as it goes; Edition 25 covered it, and its last code landed 22 May 2026.
Track this in Scout
# macOS and Linux curl -fsSL https://chatgpt.com/codex/install.sh | sh # With Node.js npm install -g @openai/codex # macOS, with Homebrew brew install --cask codex
1,973 stars · Apache-2.0, read from /blob/main/LICENSE, plain, 'Copyright 2026 Zoo Code.' in the appendix slot · v3.88.0 (2026-10-10), read from /releases/latest and settled against ungh's releases endpoint, which dates it 2026-10-10T00:52:52Z; releases are cut by a GitHub Actions bot · Track this in Scout · Share this tool
An editor assistant with several agent modes, continuing a much larger project that was shut down in May 2026.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You install it as an extension in VS Code. It reads the files in the folder you have open, and can search the codebase by meaning rather than by exact text. It writes edits into your files, runs terminal commands, drives a browser and talks to MCP servers, which are small helper programs that give an assistant extra abilities. It supports 25 model providers, listed by name in its own documentation, so you can point it at a paid service or at a model running on your own machine. It has several named modes for different jobs, such as asking questions, planning and debugging. What it does not do is think for itself: its own documentation says "Zoo isn't an LLM model, it needs an LLM provider to work", and the same documentation states that it "costs more to run than the alternatives", which the project presents as a deliberate trade.
Why it matters
Who it suits. Anyone who was using the project that shut down in May and wants their settings and habits to carry over, since the file layout and settings structure are deliberately the same. It also suits anyone who wants an editor assistant that can be pointed at a local model instead of a paid one. Skip it if you want the biggest community behind your tools, because at 1,973 stars this is a fraction of the size of its alternatives, and skip it if you are not comfortable with telemetry being on until you turn it off.
Verdict. Worth an evening if you were a user of the shut-down project, and worth knowing about either way, because the story is the useful part. The repository is under six months old, created on 23 April 2026, but it carries 7,436 commits — nearly all of them inherited from the codebase it continues, not six months of new work. That is both the reassurance and the warning: it is mature code with a small new team around it, 391 issues open and no company named as a backer. Two specifics to weigh. Telemetry is on by default, which the project states in its own privacy file, along with what it collects and that it does not include your code or prompts. And a paid credit service runs under the project's name, so "community-maintained" and "nobody is taking money" are not the same claim. If you want the larger live alternatives, cline/cline is at 70,074 stars and Kilo-Org/kilocode at 27,497.
- It asks before acting: the documentation says that out of the box it "will ask for your permission to everything", and automatic approval is opt-in.
- 25 named model providers, including models you run on your own machine, so it need not cost anything at a provider.
- Apache-2.0 licence, read from the file, plain, copyright 2026 Zoo Code, and a release cut yesterday.
- Telemetry is on by default, collecting a machine identifier, feature usage and error reports, kept for twelve months.
- Very small and very young for the size of the codebase it carries: 1,973 stars, 391 open issues, no company named.
- Its own documentation says it costs more to run than the alternatives, and VS Code is the only editor its documentation covers.
cline/clineThe same job in the same editor, at 70,074 stars and named by the shut-down project's own front page as an alternative.
Track this in Scout- Kilo-Org/kilocode
Another editor assistant in the same family, at 27,497 stars, positioned as a whole platform rather than one extension.
Track this in Scout - RooCodeInc/Roo-Code
The project this one continues, archived by its owner on 15 May 2026 and read-only; the archiving is the useful fact about it.
Track this in Scout
1. Open the Extensions view: Ctrl+Shift+X, or Cmd+Shift+X on a Mac. 2. Search for "Zoo Code" and install the one published by ZooCodeOrg. 3. Reload VS Code if it asks you to. 4. Open the extension's settings and connect a model provider.
95,708 stars · MIT, read from /blob/main/LICENSE, plain, 'Copyright (c) 2025 Agent Eyes' — a holder name that is neither the repository nor the command · v1.5.0 (2026-06-11), read from /releases/latest; the year was absent and NO package registry applies, because the project installs from a GitHub archive zip and its README states the same-named PyPI package is a different project. Settled against the repository's own createdAt of 2026-02-24: a June release cannot predate it. Code was pushed 2026-10-08, four months after the release · Track this in Scout · Share this tool
Installs and looks after one reader per website so an assistant can read public web content.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You install it, then tell your assistant to set up a site. It picks a reader for that site, installs it, checks it works and routes to it; if one reader stops working it falls back to another. agent-reach doctor prints the state of every channel and which reader is active. The reading itself is done by the upstream reader, called directly by the assistant, with no wrapper in between. Its support table lists 15 sources, including web pages, a video platform, feeds, a general web search, a code host, several discussion sites and a podcast service, with three readers each for some of them. What it does not do is log in for you: for one site it states plainly that it does not perform the login and does not read your browser's stored session, and for a discussion site it says there is no zero-setup route at all because the anonymous interface is blocked. For another video site it has retired a reader entirely after the site's defences started refusing it.
Why it matters
Who it suits. Anyone running an assistant that keeps needing public web content and who is tired of each site breaking in a different way. Keeping fifteen readers working is genuinely tedious, and that tedium is the whole product. Skip it if the accounts involved matter to you, because the project itself warns about bans, and skip it if you are not comfortable with a tool that installs other tools and drives a browser session.
Verdict. The most interesting number in today's edition: this repository was created on 24 February 2026 and has 95,708 stars seven and a half months later. Worth an hour if the problem is yours, with three cautions. The project's own text warns that cookie-based scripted access "risks platform detection and account bans" and recommends burner accounts rather than your main one; take that at face value. One setup flow opens a browser debugging port on the local machine, and the install guide warns that any local process that can reach it can fully control that browser. And the zero-fee claim rests on several upstream services staying free, which the project does not promise and cannot control. The README is mostly in Chinese. Note also that a package of the same name on PyPI is explicitly not this project, which the README says outright.
- It warns you about account bans itself, rather than leaving you to find out, and recommends spare accounts.
- The default install changes nothing on the system: system changes need an explicit
--systemflag, and--dry-runpreviews them. - MIT licence, read from the file, plain, and code landed on 8 October 2026.
- Scripted logged-in access can get an account banned, which the project states plainly.
- It installs other tools, drives a browser session, and one flow exposes a controllable browser debugging port on the machine.
- No GitHub release since 11 June 2026, and the whole design depends on third-party services staying free and unchanged.
firecrawl/firecrawlTurns web pages into clean text for a model, at 189,778 stars, as a hosted or self-run service rather than a set of per-site readers.
Track this in Scout
unclecode/crawl4aiThe same page-to-text job as a Python library, at 85,207 stars; Edition 25 covered it.
Track this in Scout- microsoft/playwright-mcp
Gives an assistant a real browser to drive, at 38,001 stars, which is the general answer where this is the per-site one.
Track this in Scout
pipx install https://github.com/Panniantong/agent-reach/archive/main.zip agent-reach install --env=auto # checks only, changes nothing agent-reach install --env=auto --dry-run --system # shows what --system would do agent-reach doctor # reports every channel's state
21,795 stars · NOT OPEN SOURCE. Functional Source License 1.1 with an MIT Future License (FSL-1.1-MIT), read from /blob/master/LICENSE.md. GitHub's sidebar shows only the word 'License' and NAMES NO LICENCE AT ALL, because this is not one GitHub recognises · release/0.22.3 (2026-08-29), read from /releases/latest; the year was absent and was settled against ungh's releases endpoint, which dates it 2026-08-29T07:58:12Z. No package registry applies · Track this in Scout · Share this tool
A desktop git client that keeps several unrelated changes on separate branches without switching.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You point it at a git folder you already have. It shows the changes in your working copy and lets you assign each file, or each part of a file, to one of several branches that are all active at once. It commits, amends, rewords, splits, squashes and moves commits by dragging, and restacks the dependent branches automatically when you amend something underneath them. It keeps a timeline you can undo from. Conflicts work differently here: a rebase "always succeeds", and you resolve the conflicts afterwards, in any order you like. It opens and updates pull requests on three hosting services, and it has built-in helpers that write commit messages and branch descriptions. What it does not do is come with any stated limits in its README — the limits are in the licence and in the developer notes, where one dependency "doesn't currently compile on ARM" for Windows and the development server can fail to start on a case-sensitive macOS disk.
Why it matters
Who it suits. People who regularly have two or three unrelated changes in flight and lose time to stashing and switching. It also suits anyone who finds rebasing stressful, because the always-succeeds model moves the hard part to a moment of your choosing. Skip it if you work on one thing at a time, because the whole benefit disappears. And skip it if your organisation requires OSI-approved open-source licences for its tooling, because this is not one.
Verdict. Worth an evening on a real project, because the idea only makes sense once you have felt it. The licence is the thing to read first, and the entry ranks it above the features for that reason. It is the Functional Source License, version 1.1 with an MIT future grant, and GitHub's sidebar cannot even name it — the page shows the word "License" and no licence name, because this is not a licence GitHub recognises. The terms forbid making the software available in a commercial product or service that "substitutes for the Software" or "offers the same or substantially similar functionality as the Software", and grant you the MIT licence on each version two years after it ships. For an individual or a team using it internally, that restriction costs nothing. For anyone building a product, it is the whole question. Two smaller notes: it is version 0.22.3, still before 1.0, and the development setup collects build-tool telemetry by default, which you turn off with pnpm exec turbo telemetry disable. If the licence is a problem, jj-vcs/jj and jesseduffield/lazygit are the two live alternatives.
- It works on any existing git folder with no conversion and no change to the repository format.
- Several unrelated changes stay separate without stashing or switching, and dependent branches restack themselves.
- Code landed on the morning of this edition, and it has been going since January 2023.
- Not open source. The licence forbids a competing commercial product and only becomes MIT two years after each release.
- Version 0.22.3, before 1.0, and the README states no limitations at all, so the only written boundaries are in the licence and the developer notes.
- Build-tool telemetry is collected by default in the development setup, and a company with a hosted service stands behind the project.
- jesseduffield/lazygit
A terminal git interface at 83,102 stars, MIT, which makes ordinary git faster to drive rather than changing how branches work.
Track this in Scout - jj-vcs/jj
A different version-control model that still stores everything in a git repository, at 31,295 stars, and the closest match for the always-succeeds idea.
Track this in Scout - arxanas/git-branchless
A set of commands for working on many small branches at once, at 4,119 stars, as plain git commands rather than a window.
Track this in Scout
# Debian or Ubuntu, the system packages first sudo apt install libwebkit2gtk-4.1-dev build-essential curl wget file \ libxdo-dev libssl-dev libayatana-appindicator3-dev librsvg2-dev cmake # Then the project pnpm install cargo build pnpm dev:desktop # Command-line tool only cargo build -p but
995 stars · MIT, read from /blob/master/LICENSE, plain and unmodified, 'Copyright (c) 2018 Viktor Holmgren' · v0.8.0 (2025-10-11) — THE YEAR TRAP, and a new shape of it. /releases/latest read '11 Oct', which is the day and month of this run, so the past-or-future heuristic would have given 2026-10-11 and been wrong by exactly one year. crates.io dates the same version 2025-10-11T05:31:31Z and settled it · Track this in Scout · Share this tool
Deletes old build files from one project folder or a whole disk, by age, toolchain or size.
▶Repo detailsthe review · specs · pros & cons · install
What it does
It reads a project's target folder, which is where the Rust build tool keeps its intermediate files, and the list of toolchains you currently have installed. It then deletes build files by one of three rules: older than a number of days, not built by a currently installed toolchain, or whatever is needed to bring the folder under a size you name. With --recursive it walks a whole directory tree and does the same to every project it finds. --stamp writes a marker file so a later run can use that moment as the cut-off. It has ten documented options, and --dry-run prints what it would delete without deleting it. What it does not do is state any limits at all: there is no section in the README saying what it will not handle, and no size or speed figures. The example values in the documentation, 30 days and 10 gigabytes, are examples rather than measurements.
Why it matters
Who it suits. Anyone with more than two or three Rust projects on a machine that keeps running out of disk. It is read-only until you choose a rule, so the trial costs nothing. Skip it if you write no Rust, because it does nothing for any other language, and think twice if you want a tool somebody is maintaining.
Verdict. Worth two minutes today, and the gem of the three in this part, but read the front page first. The README says plainly: "cargo-sweep is currently unmaintained" and "The project has issues and is lacking a dedicated maintainer". It is not archived and it is not dead by any measure this report uses — code landed on 26 May 2026, well inside the eighteen-month line — but the author points readers to dnlmlr/cargo-clean-all as the alternative, and that project took code on 30 August 2026. A tool this small and this frozen still works, and for a job as simple as deleting old files that is often fine. Always run --dry-run first: every real mode deletes without confirming, and there is no undo. One more thing, recorded because it nearly caught this report out: the release page showed "11 Oct" with no year, which is today's own day and month, and the real date is 11 October 2025. The registry settled it.
- One command, seconds to run, and
--dry-runshows the whole list before anything is deleted. - Three different rules, including a size ceiling, so a disk can be brought under a number rather than emptied.
- MIT licence, read from the file, plain and unmodified, and the crate has over a million downloads.
- Its own README says it is unmaintained and names a replacement. Code last landed on 26 May 2026.
- Every mode deletes files with no confirmation and no undo, and the README carries no warning about that.
- The release is from 11 October 2025, a year old, and the version is 0.8.0, still before 1.0.
- dnlmlr/cargo-clean-all
The replacement this project's own README names, at 308 stars, with code on 30 August 2026.
Track this in Scout
tbillington/kondoThe same job across many languages rather than Rust only, at 2,351 stars, with a terminal interface.
Track this in Scout- matthiaskrgr/cargo-cache
Cleans the shared package cache rather than a project's own build folder, at 995 stars, and its last code landed 4 June 2023.
Track this in Scout
cargo install cargo-sweep # See what would go, change nothing cargo sweep --dry-run --time 30 # Then, for real cargo sweep --time 30 # delete anything older than 30 days cargo sweep --installed # delete anything not built by a current toolchain cargo sweep --maxsize 10GiB # trim the folder down to 10 GiB cargo sweep --recursive --all ~/code --time 30 # every project under one folder
10,700 stars · MIT, read from /blob/stable/LICENSE.txt, plain and unmodified, 'Copyright (c) 2015, Jeremy Singer-Vine' · v0.11.10 (2026-06-15), read from /releases/latest; the year was absent and was settled against pypi.org/project/pdfplumber/, which dates 0.11.10 to 15 June 2026 · Track this in Scout · Share this tool
Pulls text, tables and the exact position of every object out of a PDF, and draws the table it detected so a bad result can be fixed.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You give it a file path, or bytes, or a file object, and a password if the file has one. It exposes every object on each page as a list you can read: characters, lines, rectangles, curves, images, annotations and links, each with its coordinates. On top of that it extracts text, words and tables. Table finding has four strategies in each direction — ruled lines, strict lines, text alignment, or boundaries you give it yourself — and twenty settings to tune them. There is also a command-line mode that writes CSV, JSON or plain text. The debugging view renders a page as an image at 72 dots per inch and draws the lines, intersections and table boundaries it detected on top, which is how you work out why a table came out wrong. What it does not do is stated plainly in the README: it "works best on machine-generated, rather than scanned, PDFs", it has no text recognition for scans, it does not create or modify PDFs at all, it does not rebuild the content of images, and it has no interface for form fields.
Why it matters
Who it suits. Anyone who regularly gets data as a PDF and types it out again. Bank statements, invoices, government reports and published tables are the usual cases, and this is the tool that gets them into rows and columns. It also suits anyone debugging a table extraction that another library got wrong, because the picture it draws shows you what the computer actually saw. Skip it if your documents are scans or photographs, because there is no text recognition here at all, and skip it if you need to write PDFs rather than read them.
Verdict. Worth twenty minutes today on a document you have already given up on once. pip install pdfplumber and four lines of Python gets you the first table, and the debugging image is what makes the second one work. Three honest limits. It is slower than the alternatives, and the README says so itself, naming pymupdf/PyMuPDF as substantially faster. On a large document its per-page caching "can use a lot of memory", released by closing each page. And several features, including layout-preserving text extraction and search, are marked experimental. For scans you need text recognition first, and Edition 27 covered ocrmypdf/OCRmyPDF, which makes a scan searchable and then hands it to a tool like this one. A note on checking: the usual mirror this report uses for code dates refused this repository on three attempts, so currency here rests on its release of 15 June 2026, confirmed at the package registry, and on a test list that includes Python 3.14.
- It draws a picture of the table it detected, which turns a failed extraction into a fixable problem.
- Four table-finding strategies and twenty settings, so an awkward layout is usually reachable.
- MIT licence, read from the file, plain, and a command-line mode for when you do not want to write code.
- No text recognition. A scanned document gets you nothing until you run it through something else first.
- Slower than the alternatives, which the README states itself, and page caching can use a lot of memory on big files.
- Version 0.11.10, before 1.0, with several features marked experimental, and the table system changed in a breaking way at 0.5.0.
pymupdf/PyMuPDFThe fast alternative, at 10,876 stars, which this project's own README names as substantially quicker; its AGPL-3.0 licence with a paid commercial option is the real difference.
Track this in Scout
py-pdf/pypdfPure Python, at 10,250 stars, better at splitting, merging and writing PDFs and weaker at tables; Edition 46 covered it.
Track this in Scout- camelot-dev/camelot
Tables only, at 3,790 stars, narrower in scope and sometimes better on ruled tables.
Track this in Scout
python3 -m venv venv source venv/bin/activate pip install pdfplumber # Command-line use pdfplumber statement.pdf --format csv --pages 1-3 > rows.csv
2,280 stars · MIT, read from /blob/master/LICENSE, plain and unmodified, 'Copyright (c) 2024-2026 Paymenter', with no enterprise carve-out anywhere in the tree · v1.5.9 (2026-10-02), read from /releases/latest; the year was absent and was settled against TWO second sources — ungh's releases endpoint (2026-10-02T09:40:54Z) and packagist.org, which dates the same version 2026-10-02 09:19 UTC · Track this in Scout · Share this tool
A self-installed shop, invoicing and renewal system for selling a service people pay for every month.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You install it on a Linux machine with a web server in front of it. You then define what you sell, and customers order through a storefront, which is the public-facing shop page. It produces invoices and billing records, and it runs subscriptions on a schedule so renewals and reminders happen without anyone pressing a button. There is an administration panel for the operator. It is a Laravel application, which is a PHP framework, and the install needs PHP 8.3 with eleven extensions, a MariaDB 10.11 database, a web server, a cache service, a scheduled job every minute and a background worker. What it does not do is run everywhere: the documentation states "Windows is not supported", lists seven supported Linux versions and names no others, and documents only MariaDB as the database. The README itself gives no install commands at all and points at the project's own site.
Why it matters
Who it suits. Anyone selling a service on a monthly or yearly plan who would rather not pay a percentage to a hosted billing company. It fits a small operator with a handful of products and a few hundred customers. Skip it if you sell one-off items, because a general shop system will fit better, and skip it if you are not comfortable keeping a PHP application patched for years, because that is the real ongoing cost.
Verdict. Worth one evening if the problem is yours, and at 2,280 stars it is the kind of project that solves a specific job well and gets almost no attention for it. The licence is a genuine plus: plain MIT, read from the file, copyright 2024 to 2026, with no enterprise carve-out and nothing added. The release on 2 October 2026 is nine days old, so it is actively worked on. Four things to plan for. The documentation warns that the application key in the settings file must be backed up off the machine, because losing it makes encrypted data unreadable even with a database backup — do that on day one. There is a marketplace for extensions and themes, and when we looked it was empty and did not state what licence its items carry. The install guide and the README disagree about whether you need the PHP dependency manager, and the guide never mentions it, so have it to hand. And no memory, disk or processor figure is published anywhere, so size the machine by trial. The main free alternative is FOSSBilling/FOSSBilling, which Edition 46 covered.
- Plain MIT licence, read from the file, with no paid edition carved out of the code.
- A release on 2 October 2026, nine days before this edition, and a live demonstration site to try before installing.
- Covers the whole job in one place: storefront, orders, invoices, renewals and an administration panel.
- Windows is not supported, only seven named Linux versions are, and only MariaDB is documented as the database.
- A real evening of setup: web server, database, cache, a scheduled job every minute and a background worker.
- No memory, disk or processor figures anywhere, and an extension marketplace that was empty and silent about its licensing when we looked.
FOSSBilling/FOSSBillingThe closest free alternative, at 1,712 stars, with code on 9 October 2026; Edition 46 covered it.
Track this in Scout- invoiceninja/invoiceninja
Much larger at 10,239 stars and better at invoicing generally, but source-available rather than open source, so read its licence.
Track this in Scout - ClientXCMS/ClientXCMS
The same job for the same kind of business, at 16 stars, which is a very small project to depend on.
Track this in Scout
# The pieces it needs
apt -y install software-properties-common curl apt-transport-https ca-certificates gnupg
LC_ALL=C.UTF-8 add-apt-repository -y ppa:ondrej/php
curl -sSL https://downloads.mariadb.com/MariaDB/mariadb_repo_setup | sudo bash -s -- --mariadb-server-version="mariadb-10.11"
apt update
apt -y install php8.3 php8.3-{common,cli,gd,mysql,mbstring,bcmath,xml,fpm,curl,zip,intl,redis} \
mariadb-server nginx tar unzip git redis-server
# The application itself
mkdir /var/www/paymenter && cd /var/www/paymenter
curl -Lo paymenter.tar.gz https://github.com/paymenter/paymenter/releases/latest/download/paymenter.tar.gz
tar -xzvf paymenter.tar.gz
chmod -R 755 storage/* bootstrap/cache/
cp .env.example .env
php artisan key:generate --force
php artisan storage:link
php artisan migrate --force --seed
php artisan app:init
php artisan app:user:create1,111 stars · AGPL-3.0 WITH AN ADDED HEADER carving two directories out of it, read from /blob/master/LICENSE: 'Portions of this software - namely all files that reside under the following directories of this repository -' packages/server/ee and packages/theme/src/ee 'are licensed under the license defined in "packages/server/ee/LICENSE".' Copyright 'Shinkly Private Limited'. THAT SEPARATE FILE COULD NOT BE OPENED on two attempts, so the terms covering those directories are UNVERIFIED and are recorded as such rather than guessed · v0.9.2 (2026-09-05), read from /releases/latest; the year was absent and was settled against ungh's releases endpoint, which dates it 2026-09-05T12:39:02Z · Track this in Scout · Share this tool
A self-installed board where customers post requests, others agree with them, and the popular ones go on a public roadmap.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You install it and give customers the address. They post a request; others can agree with it rather than duplicating it. You group the posts onto boards and arrange the chosen ones on a roadmap, which is a public list of what is planned. There is a dashboard for the operator and the look can be branded. It is a Node.js application with a PostgreSQL database behind it, and the code pins Node to a single major version: "node": ">=22 < 23". What it does not do is state any product limits in its README: there is no section listing unsupported cases, no database version floor anywhere we could reach, and no install commands — the production guide lives on a documentation site that refused our fetch. The restrictions it does state are about contributing: discuss ideas in public first, get approval from a core team member, and "No private DMs."
Why it matters
Who it suits. Anyone with more incoming requests than they can keep track of, and who would rather see which ones are actually popular than guess. It fits a small product team or a single maintainer. Skip it if you have very few customers, because an empty request board looks worse than no board at all, and skip it if you cannot run Node 22 exactly, because the pin excludes anything newer.
Verdict. Worth an evening if requests are genuinely piling up, with two things read carefully first. The licence is the more interesting one. The file is AGPL-3.0 with a header prepended above it, carving two directories out of that licence: packages/server/ee and packages/theme/src/ee, each governed by a separate licence file inside the repository. We tried twice to read that file and could not, so the terms covering those directories are unverified, and this report is saying so rather than guessing. The copyright holder named in the licence is a private limited company, which the README never mentions — that combination, a company plus an enterprise directory, is the standard shape of a project with a paid edition, even though no paid tier is advertised. The second thing is the Node pin: >=22 < 23 will break the moment your platform moves on, and that is a maintenance appointment you are making for yourself. The main live alternative is getfider/fider at 4,573 stars, which Edition 46 covered as a repeat.
- One public place for requests, with agreement rather than duplication, so you can see which ones are actually wanted.
- Boards and a public roadmap in the same tool, so the answer to "what are you doing about this" has an address.
- A release on 5 September 2026, and the core of the code is AGPL-3.0, which is a real open-source licence.
- Two directories are carved out of the AGPL licence under a separate licence file we could not read, so part of what you install is on unverified terms.
- Node is pinned to version 22 only, and the project states no PostgreSQL version at all.
- Version 0.9.x, before 1.0, with 144 issues open, and its own installation guide was unreadable to us, so the production steps below are the development ones.
getfider/fiderThe closest match, at 4,573 stars, with code on 9 October 2026; Edition 46 covered it as a repeat after a security release.
Track this in Scout- riggraz/astuto
The same job, at 2,350 stars, and quieter: its last code landed 9 January 2026, which is inside the bar, so it is not dormant.
Track this in Scout
formbricks/formbricksSurveys and in-app questions rather than a request board, at 13,047 stars; adjacent rather than the same job, and Edition 32 covered it.
Track this in Scout
git clone https://github.com/logchimp/logchimp.git logchimp cd logchimp cp ./packages/server/.env.example ./packages/server/.env cp ./packages/theme/.env.example ./packages/theme/.env pnpm --filter="@logchimp/types" build docker compose -f ./docker/local/docker-compose.dev.yml up -d cd ./packages/theme && pnpm dev
640 stars · GPL-3.0, read from /blob/0.9.x/LICENSE, the plain unmodified FSF text. The README and docs say 'version 3 of the GPL' while the link beside that text points at a GPL-2.0 page; the file settles it as version 3, and the broken link is a documentation defect rather than a licence ambiguity · v0.9.9 (2025-11-16) — THE YEAR TRAP. /releases/latest read '16 Nov', which would have been recorded as 2026 and ~11 months too new. pypi.org/project/eyeD3/ dates 0.9.9 to 16 November 2025 and settled it. ungh's releases endpoint refused this row · Track this in Scout · Share this tool
Reads and rewrites the artist, album and title tags inside MP3 files, from the command line or from a script.
▶Repo detailsthe review · specs · pros & cons · install
What it does
You run eyeD3 with a file name and it prints that file's tag: artist, album, title, track, and the audio details such as play time, bit rate and sampling frequency. Pass options and it writes the values back into the file. It supports four families of tag format — version 1.x, version 2.2 as read-only, and versions 2.3 and 2.4 — and it ships fourteen plugins for particular jobs, including extracting and setting cover art, generating statistics across a music collection, fixing up a directory, and writing the tag out as JSON or YAML. It is also importable as a Python module, so a script can do the same work in a loop. What it does not do is handle anything but MP3: the documentation describes MP3 and ID3 only, and frames other audio formats as a future possibility rather than a current feature. It also cannot write version 2.2 tags, only read them.
Why it matters
Who it suits. Anyone with a music folder that was assembled over twenty years from a dozen sources, with tags to match. It is at its best in a script: read a thousand files, fix one field, write them back. Skip it if your music is in FLAC, Ogg, M4A or anything else, because none of those are supported, and skip it if you want a window to click in rather than a command to type.
Verdict. Worth twenty minutes if the folder is a mess, and it is the smallest project in this edition at 640 stars. Two facts to hold together. Releases are slow and uneven: there was a gap of about three years between October 2022 and April 2025, and the newest release, 0.9.9, is dated 16 November 2025. But code landed on 26 May 2026, so the project is not dormant and this report does not call it so — a release date is not a code date, and the newer of the two is the one that counts. The licence is GPL-3.0, read from the file and completely unmodified, which matters if you plan to link the library into something you distribute: the documentation's own text says version 3 while the link beside it points at version 2, and the file settles it as version 3. If you need more than MP3, quodlibet/mutagen is the Python library that handles many formats, and it took code on 20 August 2026.
- GPL-3.0 licence, read from the file and plain, with the project maintained by a named individual since 2017.
- Fourteen plugins for specific jobs, including cover art, collection statistics and exporting a tag as JSON.
- Both a command you type and a Python module you import, so one install covers one-off fixes and bulk scripts.
- MP3 only. No FLAC, no Ogg, no M4A, and no metadata format other than ID3.
- Version 2.2 tags can be read but not written, and the newest release is from 16 November 2025.
- The project's own sources disagree about which Python version is needed: the README says 3.10 or newer, the documentation says 3.9, and an installation page still mentions 3.7.
quodlibet/mutagenThe Python library for many audio formats rather than MP3 only, at 1,969 stars, with code on 20 August 2026.
Track this in Scout
taglib/taglibThe long-established C++ library behind a great many music players, at 1,461 stars, with code on 10 October 2026.
Track this in Scout
beetbox/beetsA whole music library manager that looks tags up in an online database and corrects them, at 15,560 stars; broader than tag editing.
Track this in Scout
python3 -m venv venv source venv/bin/activate pip install eyeD3 # Read one file's tag eyeD3 song.mp3 # Write some fields eyeD3 --artist "Some Artist" --album "Some Album" --title "Some Title" --track 3 song.mp3
Checked, and left out
Nothing to show for this edition. Recording the repositories that were checked and rejected began with Edition No. 4, and every edition from there on has the list.
Coming tomorrow