soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
𝗣𝗿𝗼𝗕𝗼𝘁:
https://thewhale.cc/posts/probot
GitHub Apps to automate and improve your workflow. Use pre-built apps to extend GitHub, and easily build and share your own.
I'm sure GitHub users will be tickled to read this.
"Reynolds notes that during hallway conversations with engineering leaders at the conference, drowning in pull requests was a recurring theme. And what he sees when talking to customers tends to split three ways: Some have raised their risk tolerance, some have a backlog they can’t manage, and most sit in the middle."
The New Stack: Harness rebuilt its Git repository for nonstop AI agent traffic https://thenewstack.io/harness-ai-code-review/ @TheNewStack #Github #bot #infosec #slop
Citizen Astronomy (CAst)
by ÖgetayKayali
https://github.com/OgetayKayali/citizen-astronomy
Every clear night, amateur telescopes around the world capture photons that professional observatories never will -- the right patch of sky, at the right moment, with enough patience to notice something change. Citizen Astronomy turns those images into science.
CAst is a desktop application (Windows installer primary; unsigned macOS .app zip available for alpha testers) that takes folders of FITS and XISF images and gives you the tools to measure variable stars, discover moving asteroids, build Hertzsprung-Russell diagrams, and explore the sky -- all from one guided interface, no command-line scripting required.
Please read more details in ALT-Texts of images. These images are just a few examples of the sophisticated use-cases of this software!
Another nice example:
https://defcon.social/@grobi/117234604503277917
Topic> Useful Code
https://defcon.social/@grobi/114797042323081686
or expand post & scroll up ^
#space #tech #science #astronomy #astrophotography #code #python #unix #linux #windows #commandline #plotting #github #apod
I think its not as much that #developers are gatekeeping, but more that work processes don't integrate well, or at all. To the benefit of the devs, who deliver the software at the end of the pipeline.
At the start of my career I worked at the largest Print company in Europe (now bankrupt) and we created several award-winning dynamic websites. At the time #UX wasn't a thing, but Interaction Design was and it was leading. It was also a time when we didn't have 'agile', and didn't have #Github where everything is either an Issue or a PR. There were waterfall processes, and on the agile side you later had things like #RUP (Rational Unified Process). These acknowledged specifally different IT roles and different stages in the overall development lifecycle.
For Social experience design, #SX, I got inspired by RUP when defining the #FSDL (the Free software development lifecycle, or Fediverse solution delivery lifecycle, depending on context). See:
https://coding.social/blog/reimagine-social/#free-software-development-lifecycle
TIL about the existence of IzzyOnDroid a fast repo for Open Source Android apps which scans github repos automatically and thus gives you built apps faster than fdroid.
I found IzzyDroid via catima.app which was mentioned to me a couple of days ago.
sources:
https://apt.izzysoft.de/fdroid/
Thanks to the power of the FediVerse
#IzzyDroid #catima #fdroid #programming #github #repo #sources #binaries #OpenSource
so I noticed something stupid about #github and it's #oidc system.
now if you didn't know, openID connect (OIDC) is basically a standard, which was a more modern successer to the traditional #saml (security assertion markup language) and it's basically like oauth2, but it's for a specific organization. think of it as like #oauth , hut for more specifically SSO and more security controls.
but I noticed GitHub OIDC is an enterprise feature in GitHub. the only exception is for automated tasks.
i'm really confused on why that would be an enterprise feature...but then again some of GitHub doesn't make sense
Tachyon: How Forking an Abandoned Webmail Client Escalated Rather Quickly
What started as “I’ll just fork SnappyMail” somehow turned into a full-blown webmail proje
https://schulz.dk/2026/08/27/tachyon-how-forking-an-abandoned-webmail-client-escalated-rather-quickly/?utm_campaign=blogpost&utm_medium=twitter&utm_source=twitter
#development #github #IMAP #javascript
RE: https://social.karotte.org/@moehrenfeld/117160783957960800
I totally agree, and have always thought this was a terrible end-user experience. It comes about because someone, somewhere, is tracking 'number of open tickets' and thinks that a smaller number is better than a big number.
No. A big number means your software is being used. ... OR, admittedly, it could be because the #AI #SlopBots have decided to dump their slop all over your project.
Introducing Tor Button! 🔘
My new #OpenSource Android app that routes ALL your TCP traffic through #Tor with one tap. No trackers, no ads.
Built to survive the worst phones: it finally stays up for hours on my Realme Narzo 30 (battery killer) on WiFi & mobile, with built-in IP leak protection.
FYI, you don't want to get banned on the #Gentoo org on #Microsoft #GitHub right now, because vibe-hub is broken and I can only ban people but "something goes wrong" when I'm trying to see who's banned (and therefore I can't unban anyone).
Oh, so #Microsoft explains that #GitHub wasn't down due to vibe-coding, but due to "a new peak" in traffic. So sorry to hear that, really. Who would have expected that would happen after they (checks notes) practically monopolized software hosting, and then started aggressively pushing for unethical technology that is killing the Internet. But don't worry, their best vibe-coders are now working on the ultimate prompt to make everything scale.
https://github.blog/news-insights/company-news/the-august-17-outage-and-the-work-ahead/
🔴 GitHub is DOWN
Major Outage on Actions, API Requests, Issues, Pull Requests and Copilot. Started 19:10 IST, still not fixed.
~20% of web and API requests are failing
~50% of raw file and archive downloads are failing
SSO login (SAML/OIDC) affected
Git push/clone has been slow since 20:51 IST
No root cause from GitHub yet. Don't retry aggressively — it makes recovery slower.
Live timeline and full details: https://www.cyberkendra.com/2026/08/github-down-outage-actions-api-copilot.html
Mojo becomes open source – Python-like language for CPUs and GPUs
Shortly after releasing version 1.0 of Mojo, Modular (Qualcomm) releases the compiler under the Apache-2 license.
#Compiler #GitHub #IT #OpenSource #Programmierung #Python #Qualcomm #news
yt-dlp has now added an explicit "No AI / No LLM policy" notice to their repo and Contributing guidelines.
The opening paragraph:
This project strictly forbids the usage of LLMs, agents, or any other AI tools for any kind of contribution.
Full text:
https://github.com/yt-dlp/yt-dlp/blob/master/.NO_AI/README.md
Complete set of files modified:
https://github.com/yt-dlp/yt-dlp/commit/249aa5d6e667308fbf95ae5cfb40eba8177a802c
When #GitHub UI is so broken that you can't mark a pull request ready to review when merge status can't be loaded, so you need to actually do that via API.
You're absolutely correct! When you asked me to "clean up and archive some old data" I should not have sent the command "DROP DATABASE github.master" to the SQL server.I'll make a note to ask before I do this next time.
I wonder if they're going to tell us that an AI "slipped through its guardrails" and deleted the whole of Github.
Oh, great. So apparently #Microsoft decided to add "#Copilot Pull Request Reviewer" to my "Authorized #GitHub Apps", behind my back.
If you need to check quick: https://github.com/settings/apps/authorizations
Awesome DigitalEscapeTools keeps growing!
Now featuring 290 privacy-focused tools across 32 categories open-source, self-hosted, secure, and privacy-friendly alternatives.
Built a privacy-respecting tool? Contribute it, and accepted tools will also be showcased in r/DigitalEscapeTools.
⭐ Explore, contribute, or suggest a tool: https://github.com/abdomk1998/awesome-digital-escape-tools
#OpenSource #Privacy #FOSS #SelfHosted #GitHub #PrivacyTools #Linux #Windows #Android #macOS
New from Cloudflare:
"We're introducing @cloudflare/computer, an agent runtime that dynamically orchestrates between fast, efficient isolates and full Linux containers to give every agent a computer of its own."
"The central piece of @cloudflare/computer is the workspace. A virtual filesystem backed by SQLite that can be populated from various sources including cloud storage and source control."
Cloudflare: Your agent needs a computer, not a container — introducing @cloudflare/computer https://blog.cloudflare.com/cloudflare-computer/ #infosec #bots #Cloudflare #GitHub #Linux
New #GitHub, #PyPI Policies Boost #SupplyChain Security
https://www.securityweek.com/new-github-pypi-policies-boost-supply-chain-security/
𝗗𝗲𝘃𝗛𝘂𝗯:
https://thewhale.cc/posts/devhub
DevHub, TweetDeck for GitHub. It helps you take back control of your GitHub workflow and stay on top of everything important going on.
India orders GitHub to remove Bluetooth-based chat app Bitchat
“The application enables anonymous communication without mandatory user registration, phone number verification, or centralised logging of communications. The technical architecture of the application significantly impedes lawful interception, attribution and investigation by law enforcement agencies,”
Can someone look at my #GitHub repos for Everrealm, my website, or WordPredictor and check that my new GitHub sponsor and Ko-fi buttons are showing?
I don't know what's more stupid: #OpenSSH using different authentication flow depending on whether you have a `.pub` file in addition to the private key or not, or #GitHub suddenly starting to reject one of the two valid RFC 4252 workflows.
Working on my #Github for screen readers guide, covers downloading assets, since that's what others seem to have the most trouble doing. I'm working on the GUI section, already finished the CLI section, and as a blind person, I've come to the conclusion the CLI is peak user interface. Yes, it's complicated to *learn* but I gotta tell ya, once you learn it, it never changes. Trying to provide evergreen GUI instructions is very fucking hard. #CLI #Git
#GitHub Status: there was no downtime recently.
My mailbox: two hours worth of cronjob failures that disagree.
Lessons Learned from #CISA’s Recent #GitHub Leak
https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
I just got this bill from #microsoft for #github usage. See if you can spot what is ridiculous about this bill.
& now there's YA reason: last week, #GitHub urged the FOSS community to *oppose* important #California legislation that places transparency and consumer rights requirements on deployment of LLM-gen-AI!
GitHub's tactic? Disinformation claiming #FOSS licenses are incompatible with Cal. Bus. & Prof. Code §22757 and California #SB1000 (which seeks to amend §22757).
Read the analysis: https://sfconservancy.org/blog/2026/jul/03/github-gen-ai-california-22757-ok-for-foss-license/
Congratulations. Now I'm actively worried to open a PR fixing my issue, because there's already been a few #slop PRs opened attempting to fix it. And I'm literally worried that mine would be taken as another slop PR…
New.
Arctic Wolf: Critical Remote Code Execution Vulnerability in libssh2 Client Library Require Urgent Mitigation https://arcticwolf.com/resources/blog/critical-remote-code-execution-vulnerability-in-libssh2-client-library-require-urgent-mitigation/ #infosec #GitHub #vulnerability
So to remove someone from repository's ACL on #GitHub, I need to click the trash icon next to their name. Is it just me, or is that symbolic troubling?
New.
"The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go module compromise involving the Verana Blockchain project."
Socket: Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem @SocketSecurity #infosec #threatresearch #GitHub #npm #malware #JavaScript
FYI @ifin
Apps for encryption, comms, Usenet, remailers ...
Ch1ffr3punk: https://github.com/Ch1ffr3punk
The owner is a denizen of the OG #Usenet scene.
#cypherpunk #cryptography #crypto #encryption #privacy #github #freesoftware
@cypherpunk@soc.octade.net @cryptography@soc.octade.net @usenet@soc.octade.net
WhatsApp Clone, but Decentralized with P2P Messaging
"Secure and private" is the general goal.
This is a technical/concept demo of a fairly unique approach using a browser-based, local-first and webrtc.
This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort.
Features:
* P2P
* End to end encryption
* Signal protocol
* Post-Quantum cryptography
* File transfer
* Local-first
* No registration
* No installation
* No database
* TURN server
Feel free to reach out for clarity instead of diving into the docs/code.
IMPORTANT: While this is aiming to provide a secure experience, it isnt audited or reviewed. **Shared for testing, feedback and demo purposes only.** Please use responsibly.
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics #P2P #WebRTC #PeerJS #ZeroData #EphemeralData #Encryption #E2EE #BrowserToBrowser #NoInstall #Privacy #Security #Decentralized #Messaging #VideoCall #NoTracking #PrivateMessaging #Prototype #Demo #WorkInProgress #CloseSource #OpenSource #WebDev #GitHub #TechDevelopment #WhatsApp #ChatApp #InstantMessaging #PWA
𝗔𝘄𝗲𝘀𝗼𝗺𝗲 𝗮𝗰𝘁𝗶𝗼𝗻𝘀:
https://thewhale.cc/posts/awesome-actions
A curated list of awesome actions to use on GitHub by Sarah Drasner
This is intended to introduce a unique approach in client-side managed secure cryptography. We can avoid registration of any sort.
Features:
PWA
P2P
End to end encryption
Signal protocol
Post-Quantum cryptography
Multimedia
File transfer
Video calls
Local-first
No registration
No installation
No database
TURN server
https://www.reddit.com/r/positive_intentions
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics #P2P #WebRTC #PeerJS #ZeroData #EphemeralData #Encryption #E2EE #BrowserToBrowser #NoInstall #Privacy #Security #Decentralized #Messaging #VideoCall #NoTracking #PrivateMessaging #Prototype #Demo #WorkInProgress #CloseSource #OpenSource #WebDev #GitHub #TechDevelopment #WhatsApp #ChatApp #InstantMessaging #PWA
The ‘#Miasma’ worm source code briefly leaked on #GitHub
https://www.bleepingcomputer.com/news/security/the-miasma-worm-source-code-briefly-leaked-on-github/
#Github Security Advisories program is struggling under the load of new submissions. Delays in CVE assignment up to a month are being reported. Apparently, May 2026 was the highest volume month ever, and they are working through a backlog.
source: https://www.openwall.com/lists/oss-security/2026/06/10/9
It is not very hard to figure out what is going on: The amount of AI-assisted reports is flooding the systems. Considering the asymmetric nature of the situation (limited human resources processing increasing number of reports), it is unlikely the it is getting any better soon.
If just tracking and assigning issues is getting this hard, it can't bode well for actually fixing and patching them.
React-like syntax with WebComponents.
After spending some time with Lit, I really appreciated its lightweight footprint but wasn't a fan of the class-based components. While Vue offers a great approach, I still prefer the intuitive nature of React's syntax for debugging and deterministic rendering. This led me to a challenge: could I build a UI framework using WebComponents that completely eliminates the need for transpilation?
I have written a breakdown of the concept, the architecture, and where I want to take it. I highly invite you to take a look, check out the code, and explore the live demo.
* How it works: https://positive-intentions.com/docs/projects/dim/dim-jsx-webcomponents
* Checkout the code: https://github.com/positive-intentions/dim
* Storybook demo: https://dim.positive-intentions.com
Please note, while the project is open-source, this is a personal exploration rather than an attempt to launch "yet another framework." It is not production-ready and is built for my own upcoming project migrations, but I am sharing it in hopes that the methodology is educational or interesting to the community.
I would love to hear your thoughts on this approach. Feel free to reach out if you have any questions or want to discuss the implementation details.
#WebDev #WebDevelopment #Frontend #FrontendDev #JavaScript #JS #TypeScript #TS #HTML #HTML5 #CSS #SoftwareEngineering #SoftwareEngineer #Coding #Programming #WebDesign #OpenSourceProject #IndieDev #SideProject #Tech #Technology #DevCommunity #Fediverse #FediverseDevs #WebStandards #CustomElements #ShadowDOM #VanillaJS #NoTranspiler #NoBuild #BuildStep #EsModules #ComponentDriven #UIUX #DesignSystems #TechExperiment #LearningInPublic #Developer #ComputerScience #OSS #Github #React #WebComponents #Lit #Vue #ReactJS #JSX #Storybook #TechArticle #TechBlog #TechWriting #WebDevArticles
Forgejo: https://forgejo.org ...
"Forgejo is a Free Software platform for collaboration and productivity in software development. It offers a familiar environment to GitHub users, easy installation and maintenance, and a focus on security, scaling, federation and privacy."... or cgit, which is very fast and slick for the barebones portal ...
... codeberg has a nice setup (via forgejo) if you don't want to self-host.
#git #forgejo #scm #vcs #sources #source #code #vps #gitlab #github #codeberg #hosting