Geek-Guy.com

Category: open source

Backstage access: Spotify’s dev tools side-hustle is growing legs

Spotify generates the vast bulk of its income from ads and subscriptions, but for the past few years the music-streaming giant has also been quietly building out a developer tooling business. Backstage, a project it open-sourced in 2020, has been adopted by more than 2 million developers across 3,400 organizations, including Airbnb, LinkedIn, Twilio, and…

Ai2’s new small AI model outperforms similarly-sized models from Google, Meta

‘Tis the week for small AI models, it seems. On Thursday, Ai2, the nonprofit AI research institute, released Olmo 2 1B, a 1-billion-parameter model that Ai2 claims beats similarly-sized models from Google, Meta, and Alibaba on several benchmarks. Parameters, sometimes referred to as weights, are the internal components of a model that guide its behavior.…

Kubernetes Resource Optimization & Best Practices with Goldilocks

Kubernetes is now the industry standard for orchestrating containerized workloads, but efficient resource management remains a challenge for many organizations. It’s important to get right though! Over-provisioning leads to wasted cloud spend, while under-provisioning risks instability, throttling, or outages. When we first open-sourced Goldilocks in October 2019, our goal was to offer a dashboard utility…

What’s happening with MITRE and the CVE program uncertainty

Yesterday’s headlines have sent ripples through the cybersecurity and software supply chain communities: MITRE announced that U.S. government funding for the CVE (Common Vulnerabilities and Exposures) database was set to expire today. Overnight, the CVE Foundation emerged with a plan to maintain the program before the Critical Infrastructure and Security Agency (CISA) announced it has…

Jim Zemlin on taking a ‘portfolio approach’ to Linux Foundation projects

The Linux Foundation has become something of a misnomer through the years. It has extended far beyond its roots as the steward of the Linux kernel, emerging as a sprawling umbrella outfit for a thousand open source projects spanning cloud infrastructure, security, digital wallets, enterprise search, fintech, maps, and more. Last month, the OpenInfra Foundation…

Ente wants to take on Google Photos with its privacy-first photo storage service

Despite Google’s intentions for its default image viewing and editing app for Android, the Photos app has, over the years, become one of the most popular photo backup services around. In fact, it was one of the most attractive offerings for years until it stopped offering unlimited storage in 2020. That change in the tech…

Temporal lands $146 million at a flat valuation, eyes agentic AI expansion

Seattle-based Temporal has made its name over the last several years in the world of microservices — specifically providing a platform to orchestrate the messy business of building and operating integrations and updates across disparate services and apps in the cloud. But the AI boom has come at the company fast. Now, Temporal has raised…

Ebay backs WunderGraph to build an open-source GraphQL federation

A fledgling open-source startup that’s setting out to tackle API sprawl in the GraphQL ecosystem has secured the backing of e-commerce giant eBay. WunderGraph, as the company is called, today said it has raised $7.5 million in a Series A round of funding to “scale its open source GraphQL federation.” Investors include eBay’s VC arm…

String of defects in popular Kubernetes component puts 40% of cloud environments at risk

More than 40% of cloud environments are at risk of an account takeover due to a series of five recently discovered vulnerabilities — one regarded critical — in the Ingress Ngnix Controller for Kubernetes, according to security research published this week. Upon discovering the string of vulnerabilities in one of most widely used ingress controllers…

Researchers raise alarm about critical Next.js vulnerability

Researchers warn that attackers could exploit a recently discovered critical vulnerability in the open-source JavaScript framework Next.js to bypass authorization in middleware and gain access to targeted systems. Vercel, the San Francisco-based company that created and maintains Next.js, released a patch for CVE-2025-29927 in Next.js 15.2.3 on March 18 and published a security advisory on…

Dapr’s microservices runtime now supports AI agents

Back in 2019, Microsoft open-sourced Dapr, a new runtime for making building distributed microservice-based applications easier. At the time, nobody was talking about AI agents yet, but as it turns out, Dapr had some of the fundamental building blocks for supporting AI agents built-in from the outset. That’s because one of Dapr’s core features is…

Why Onyx thinks its open source solution will win enterprise search

Enterprises have troves of internal data and information that employees need to complete their tasks or answer questions for potential customers. But that doesn’t mean the right information is easy to find. Onyx wants to solve that problem through its internal enterprise search tool. There are other big names in the category, like Glean —…

Open web initiatives Project Liberty and Solid could be teaming up

Two initiatives to create a more open web, where users are in control of their own digital identities and data, may be coming together. At SXSW 2025, entrepreneur Frank McCourt, whose Project Liberty is developing open internet infrastructure (and is throwing its hat in the ring as a potential buyer for TikTok), announced that his…

Chainguard’s FIPS-compliant Cassandra addresses security demand of federal and regulated markets

Open-source software security firm Chainguard announced Wednesday that it is now building FIPS-validated images for Apache Cassandra, achieving what it describes as a first-of-its-kind accomplishment in the open-source community.  The project enables organizations in regulated industries — including government, health care, and finance — to deploy Cassandra with cryptographic libraries compliant with the National Institute…

Automattic CEO Matt Mullenweg talks succession — ‘I don’t want to pass it to a committee’

Calls for WordPress co-founder and Automattic CEO Matt Mullenweg to step down from his leadership role have increased in recent months amid his controversial fight and legal battle with hosting company WP Engine. Mullenweg not only intends to stay, he’s also thinking about how he plans to manage succession planning. He doesn’t want to pass…

When Your SaaS Vendor Goes Dark: A Guide to Protecting Your Business

When a SaaS vendor unexpectedly shuts down, your business faces significant risks. This comprehensive guide provides actionable strategies to recover your data, find alternative solutions, and implement preventative measures to ensure business continuity. The post When Your SaaS Vendor Goes Dark: A Guide to Protecting Your Business appeared first on Security Boulevard.

Continue wants to help developers create and share custom AI coding assistants

A new startup wants to help developers create customized, contextual coding assistants that can connect with any model and integrate seamlessly with their development environments. Founded in June 2023 by CEO Ty Dunn and CTO Nate Sesti (pictured above), Y Combinator alum Continue has already garnered some 23,000 stars on GitHub and 11,000 Discord community…

DeepSeek to open-source parts of online services code

Chinese AI lab DeepSeek plans to open-source portions of its online services’ code as part of an “open source week” event next week. DeepSeek will open-source five code repositories that have been “documented, deployed and battle-tested in production,” the company said in a post on X on Thursday. Code repositories are storage locations for software…

Projecting the next decade of software supply chain security

With the rapid pace of innovation accelerating under a new administration, discussions over whether software security will be sidelined in favor of speed are heating up. However, security leaders have long been saying that security protocols shouldn’t slow down development plans — and they don’t when done correctly. This perception must be adopted more widely…

Why the ‘spirit’ of open source means much more than a license

Arguments about what is and isn’t “open source” are often resolved by deferring to the Open Source Initiative (OSI): If a piece of software is available under a license rubber stamped as “open source” by the OSI’s formal “definition,” then that software is open source. But waters muddy when you get into the nuts and…

Hugging Face researchers aim to build an ‘open’ version of OpenAI’s deep research tool

A group of developers at AI dev platform Hugging Face, including Thomas Wolf, the company’s co-founder and chief scientist, say they’ve built an “open” version of OpenAI’s deep research tool. Deep research, which OpenAI unveiled during an event Sunday, crawls the web to compile research reports on any subject. While impressive, deep research is currently…

Here’s all the ways an abandoned cloud instance can cause security issues

There is a line of thought among the public that “the internet is forever.” A security company published research Tuesday that showed why “forever” can be a security nightmare.  Over the course of four months, cybersecurity researchers at watchTowr monitored and ultimately took control of what they referred to as “abandoned” digital infrastructure, focusing on…

Privacy Concerns with Digital Driver’s Licenses, The Rise of DeepSeek AI

In this episode, we explore the rollout of digital driver’s licenses in states like Illinois and the potential privacy issues that come with them. Can digital IDs truly enhance convenience without compromising your privacy? We also discuss the new Chinese AI model, DeepSeek, which is affecting U.S. tech companies’ stock prices. Join us as we…

MLCommons and Hugging Face team up to release massive speech data set for AI research

MLCommons, a nonprofit AI safety working group, has teamed up with AI dev platform Hugging Face to release one of the world’s largest collections of public domain voice recordings for AI research. The data set, called Unsupervised People’s Speech, contains more than a million hours of audio spanning at least 89 different languages. MLCommons says…

Video: How DeepSeek And Emerging AI Models Could Impact The IT Channel

It’s been a wile week in the world of AI! DeepSeek went from breaking the mold with its new AI models that the Chinese startup reported were cheaper, faster, and less resource intensive to make by using fewer, sub standard GPU chips. Now, OpenAI accuses the emerging AI leader of copying its models. What does…

DeepSeek Chatbot Beats OpenAI on App Store Leaderboard

The Chinese firm said training the model cost just $5.6 million. Alibaba Cloud followed with a new generative AI model, while Microsoft alleges DeepSeek ‘distilled’ OpenAI’s work.

Hugging Face researchers are trying to build a more open version of DeepSeek’s AI ‘reasoning’ model

Barely a week after DeepSeek released its R1 “reasoning” AI model — which sent markets into a tizzy — researchers at Hugging Face are trying to replicate the model from scratch in what they’re calling a pursuit of “open knowledge.” Hugging Face head of research Leandro von Werra and several company engineers have launched Open-R1, a…

AI startup DeepSeek pauses signups amid cyber incident

DeepSeek, the Chinese AI startup that made waves in the AI world last week when it released its open-source R1 model, is pausing new user signups. The company has temporarily paused new user registrations this morning, according to CNBC reporting, due to a cyberattack. Existing users can still access their accounts with no issue. TechCrunch…

Open-source security spat leads companies to join forces for new tool

A conflux of open-source developers and application security companies has been embroiled in a complex debate after a recent change in the licensing policy of a widely used static code analysis tool, resulting in a faction of organizations creating a new, open-source rival.  The issue started with a recent change in the licensing policy of…

Open source alternatives to Instagram, TikTok, and WhatsApp raise funds on Kickstarter

The developer behind Pixelfed, Loops, and Sup, open source alternatives to Instagram, TikTok, and WhatsApp, respectively, is now raising funds on Kickstarter to fuel the apps’ further development. The trio is part of the growing open social web, also known as the fediverse, powered by the same ActivityPub protocol used by X alternative Mastodon. The…

Dub.co is an open-source URL shortener and link attribution engine packed into one

In the last few weeks, PayPal-owned Honey, which claims to find you the best coupon codes for a deal, has been at the center of controversy. Allegedly, the tool sneakily earned affiliate money by changing attributes of product links creators posted on their videos. At the center of it, the problem was how affiliate links…

Open source licenses: Everything you need to know

Open source makes the technology world go ’round, forming as much as 90% of the modern software stack via frameworks; libraries; databases; operating systems; and countless standalone applications. The benefits of open source software are well understood, promising greater control and transparency. However, there’s a perennial struggle between the open source and proprietary realms, leading…

Researchers open source Sky-T1, a ‘reasoning’ AI model that can be trained for less than $450

So-called reasoning AI models are becoming easier — and cheaper — to develop. On Friday, NovaSky, a team of researchers based out of UC Berkeley’s Sky Computing Lab, released Sky-T1-32B-Preview, a reasoning model that’s competitive with an earlier version of OpenAI’s o1 on a number of key benchmarks. Sky-T1 appears to be the first truly…

Open source companies that go proprietary: A timeline

Open source might be the building blocks of the modern software stack, but companies building businesses off the back of open source software face a perennial struggle between keeping their community happy and ensuring that third parties don’t abuse the permissions afforded by the license. Many companies have launched with lofty open source ambitions, only…

Microsoft debuts Phi-4, a new generative AI model, in research preview

Microsoft has announced the newest addition to its Phi family of generative AI models. Called Phi-4, the model is improved in several areas over its predecessors, Microsoft claims — in particular math problem solving. That’s partly the result of improved training data quality. Phi-4 is available in very limited access as of Thursday night: only…