Skip to content

#开源/仓库

3 today

Sep 19Saturday

Sep 18Friday

Hacker News front page

ZCode coding agent silently uploads your entire Git history; only Z.ai holds the decryption key

Developer ferstar reverse-engineered ZCode, Z.ai's desktop coding agent, and found it silently packs the entire workspace—.git history, LFS cache, reflogs, global configs—encrypts it, and uploads to Aliyun OSS whenever logged in. A 345MB commercial workspace became a 313MB encrypted archive; .git alone was 86.6%. The app uses envelope encryption: the symmetric key is wrapped with an RSA public key delivered by Z.ai's server, and the private key lives only in Z.ai's cloud. The user cannot decrypt their own data. The upload pipeline was reconstructed from the client's app.asar: request credentials from zcode.z.ai, pack and encrypt locally, POST directly to Aliyun OSS. In-app privacy toggles don't stop it, and the privacy policy doesn't mention it. The post hit 276K views; a Chinese-language alert urged users to disable ZCode. If you run GLM locally, remember: open weights don't make the closed harness safe. The only working defense is keeping projects outside ZCode's reach or not using it.

Why it matters: This is a security disclosure backed by concrete reverse-engineering evidence, not speculation. A 345MB project was fully packaged and uploaded with the vendor holding the only decryption key — a direct risk alert for anyone using AI coding assistants. Not scored higher becaus...

Hacker News front page

Orbital: Open-source Claude Project that gives you context ownership

Orbital is an open-source alternative to Claude Project that claims 'context is yours, agents are replaceable.' It turns conversation context into reusable assets instead of locking it inside a platform. The project just launched with 277 stars on GitHub. The post doesn't specify which models it supports, whether it's compatible with Claude API, or deployment requirements. If you're frustrated that Claude Project won't let you export context or swap agents, this is worth a look.

Hacker News front page

Flet 1.0 lets you build cross-platform apps in Python from a single codebase

Flet 1.0 is out, letting you build apps for iOS, Android, Windows, macOS, Linux, and the web using only Python. No frontend experience needed—150+ built-in controls, support for NumPy, pandas, and other Python libraries on mobile. You can package with flet build for App Store and Google Play, write pytest UI tests, and connect AI coding assistants via MCP. The post doesn't spell out what's new in 1.0, but the pitch is clear: one codebase, every platform.

Sep 17Thursday

Hacker News front page

Cloudflare open-sourced a security audit skill for coding agents

Cloudflare packaged its internal security audit workflow as a skill file for coding agents like Claude Code. It splits the audit into three phases—recon, vulnerability discovery, and report generation—each outputting machine-readable JSON for CI pipelines. The repo includes full prompt templates and examples. With 8k stars, it's clearly scratching an itch for agent security tooling. The post doesn't disclose detection rates or false positive numbers, so treat it as a reference framework, not a sign-off tool.

Why it matters: Cloudflare open-sourced a security audit skill for coding agents, and 8k stars confirms real demand. H and K are solid: novel approach with reusable prompt templates. R is missing because the audience skews security-specific — general AI devs may not connect. Score sits at the...

Hacker News front page

OpenSpec: a lightweight, configurable spec framework for aligning teams and coding agents

OpenSpec is an open-source spec framework by Fission-AI. You capture what to build in a spec, then coding agents like Claude Code and Cursor implement and verify against it. It has 68.5k GitHub stars, a new spec is created every two seconds, and over 265k monthly active developers. The workflow has five steps: explore, propose, apply, verify, archive. Install via npm. The post doesn't mention pricing or how it relates to existing specs like OpenAPI.

Why it matters: 68.5k stars and 265k monthly active devs — real traction for an open-source project. But the source is the project's own landing page, with no third-party evaluation or user experiments, so the information density is thin and the score stays at the featured threshold.

Hacker News front page

Friday: a self-hosted persistent memory layer for AI coding agents

Friday is an open-source project that aims to give AI coding agents like Cursor, Claude, and Copilot persistent memory across sessions. It acts as a cognitive memory layer and connects via MCP. The README doesn't disclose implementation details or performance numbers yet, so I'd wait for more info.

Sep 16Wednesday

AI HOT (Curated Pool)

Ant Group's inclusionAI open-sources Realtime-Venus, a full-duplex real-time interaction system

Ant Group's inclusionAI has published Realtime-Venus on GitHub. Judging by the repo name and title, it's a full-duplex real-time interaction system that supports simultaneous speaking and listening. The repo is newly public with very few stars. The post does not disclose README details or code specifics, so only the project name, organization, and the open-source release itself can be confirmed for now.

Sep 15Tuesday

Hacker News front page

Pizza Bot: A local-first inbox for background AI agents

Pizza Bot is an open-source inbox for long-running AI agents that work in the background. Built with DeepAgents and LangGraph, it lets agents push results to a unified local-first UI instead of blocking. Currently 138 stars on GitHub; code and docs are public. The post doesn't specify which agent frameworks are supported or latency details.

Hacker News front page

Ordewell: Turn one goal into an ordered plan of coding-agent tasks

Ordewell is a multi-agent task orchestrator for coding agents. Give it a goal, and it produces an ordered plan of tasks—each with its own runner, model, and mode—then executes and verifies results. 25 stars on GitHub, open source. The post doesn't spell out which models or runners are supported, nor whether it integrates with popular agent frameworks.

Hacker News front page

E-ink bird frame: listens to birds locally, draws 1800s-style illustrations

An open-source project that uses a Raspberry Pi and microphone to detect bird calls in real time, running fully local AI without internet. When a bird is heard, it displays a 1800s-style bird illustration on an e-ink screen. It uses BirdNET for audio recognition and Stable Diffusion for vintage engraving style. Code and models are open-source. The post doesn't specify how many bird species are supported or the detection latency.

Hacker News front page

Alternatives to MinIO for single-node local S3

MinIO's parent company abandoned the open-source project in late 2025 to chase other commercial interests. This left many demos and CI pipelines that relied on MinIO for local S3 emulation in a bind. The author compares seven alternatives: S3Proxy, RustFS, SeaweedFS, Zenko CloudServer, Garage, Apache Ozone, and Ceph Object Gateway. The selection criteria are practical: must have a Docker image, must be S3-compatible, must be free and open-source, simple single-node deployment, and have an active community or commercial backer. The author built a test stack with DuckDB + Iceberg and ran write/read verification for each candidate. The post does not give a final ranking but includes a comparison table of pros and cons.

Hacker News front page

dbt Labs open-sources dbt Charts, a declarative YAML language for dashboards

dbt Labs unbundles charts from BI tools with dbt Charts, an open-source declarative YAML language. One file defines a full dashboard—variables, SQL queries, and 16 chart types with over 1,100 config options. The CLI renders to SVG, HTML, PNG, PDF, or terminal. It integrates deeply with dbt projects: a charts/ directory sits next to models/ in the same repo, so model and chart changes ship on one branch through one CI run, and ref() catches renamed models or missing columns at PR time. The team designed it for chat agents—strict YAML and SQL validation gives agents a tight feedback loop, flagging problems before anyone sees the board. The post does not disclose a release timeline; it points to the GitHub repo and docs.

Why it matters: dbt Labs open-sourced a declarative charting language that turns dashboard definitions into YAML files renderable via CLI. The angle matters for AI agents generating auditable charts, but the product is beta and the audience skews data-engineering. H and K both hit, R is weak ...

Sep 14Monday

Hacker News front page

Temporal raises $550M Series E at $12.55B valuation

Temporal closed a $550M Series E at a $12.55B valuation, co-led by Lightspeed with a16z, Sequoia, and others participating. The bet is on Durable Execution for long-running AI agents—write normal code, state is preserved, failures auto-recover. OpenAI's usage grew 60x in under a year; Snap runs 414M Stories/day on it. Annualized revenue run rate is up over 200% YoY, net dollar retention above 200%, and 1.9T billable actions processed in August. The post doesn't detail how the new capital will be deployed beyond global growth.

Why it matters: Temporal's Series E is a strong signal for AI infrastructure. $550M at $12.55B with >200% ARR growth, plus OpenAI and Snap usage data, shows durable execution is becoming a must-have layer for agent architectures. Score capped at 78 because it's a company announcement without ...

Sep 13Sunday

Hacker News front page

Paul Graham: How to Make Startups Powerful

Paul Graham shares his go-to heuristic for startup office hours: ask what would make the company more powerful, not just more profitable. That question often leads to order-of-magnitude gains. He walks through levers like owning the customer relationship, making money flow through you, introducing network effects, and building app-store-like platforms. PayPal began as a security demo; eBay sellers repurposed it for payments, and the founders pivoted. Graham calls this a tail-wagging-the-dog signal. He also argues for playing the long game—acquire users cheaply first, fix margins later—and for generosity: create more value than you capture. Open source, extensibility, and APIs are all generosity-driven power moves, especially now that AI agents are replacing human users.

Why it matters: This isn't generic startup advice — PG delivers a reusable thinking framework with concrete levers. Not scored higher because it's a high-quality opinion piece, not a product launch or industry event that demands same-day coverage.

Sep 12Saturday

r/LocalLLaMA

Fine-tuned a 2B LLM on WhatsApp group chat, shared the cookbook on GitHub

Someone fine-tuned a 2B LLM on WhatsApp group chat data and open-sourced the full pipeline as a GitHub cookbook. The post body is blocked by Reddit, so no details on base model, training cost, or results. Title confirms the data source (group chat), model size (2B), and goal (mimic chat style). Good starting point if you want to train a small model on your own chat logs.

Sep 11Friday

Hacker News front page

Rune goes open source, lets AI teams self-host inference

Rune has open-sourced its inference engine. The code is now public, targeting production-grade multi-model serving with low latency. The post doesn't spell out supported models or benchmarks, but the open-source move lets teams audit and customize.

Hacker News front page

Herdr Studio: A browser cockpit for your AI agent herd

Herdr Studio is an open-source browser client that gives you a visual workspace for all your AI agent terminals, files, diffs, and worktrees. It relies on the Herdr daemon to keep agent sessions alive even when your browser or laptop disconnects. Supports local and SSH connections, and can be installed as a PWA on mobile. The post doesn't spell out platform support beyond macOS and Linux install scripts.

Hacker News front page

YuE2 generates editable scores first, then audio — quality rivals Suno v5

MAP and collaborators released YuE2, a music model that unifies symbolic score generation and audio synthesis. It first produces an editable ABC score, then renders vocals and accompaniment — final quality rivals Suno v5. The release includes a 3B model, VAE, SheetSage2 transcription tool, and the WildSongBench eval set, with 65 demos spanning Dark Ambient to Cyber Metal. The post doesn't disclose training data size or inference latency.

Why it matters: An open-source music model directly claiming Suno v5 parity, shipping with editable scores, a transcription tool, and a benchmark — high signal density. Not scoring higher because the post doesn't disclose training data scale or real inference cost, so the 'Suno v5 parity' cla...

Sep 10Thursday

r/LocalLLaMA

DeepSeek V4.1 Flash: beats V4 Pro on benchmarks, cuts API price, and goes open source

DeepSeek released V4.1 Flash, a 552B MoE model that activates only 8B params on input and 16B on output. It uses a new asymmetric Causal-Encoder-Decoder architecture and scores above DeepSeek V4 Pro on benchmarks. KV cache size drops to 1/4 HBM and 1/8 SSD vs the previous gen, cutting agent-scenario cache costs. The API is live under model name deepseek-flash; V4 Pro will be routed to V4.1 Flash from Sep 14 noon Beijing time and billed at Flash pricing. New peak/off-peak prices start Sep 10 noon, with off-peak at half rate. Weights and a tech report are open on HuggingFace; DeepSeek invites contact for large-scale deployments needing a 2k-GPU cluster.

Why it matters: DeepSeek flagship model release with architectural change and concrete perf/cost numbers — policy treats this on par with US lab launches. All three HKR axes hit: the V4 Pro-beating score and cache shrinkage are hard info. Held back from P1 because only title + summary availab...

Sep 7Monday

Hacker News front page

Trail of Bits open-sources Coop: isolated VMs for Claude Code and Codex

Trail of Bits open-sourced Coop, an internal tool that wraps Claude Code and OpenAI Codex inside isolated VMs. It prevents AI coding agents from accidentally messing up the host machine when they edit files or run commands. The repo has 309 commits and 35 stars. The README doesn't spell out supported VM backends, resource overhead, or how it compares to plain Docker or sandboxing.

Why it matters: Trail of Bits open-sourced an internal isolation tool for AI coding agents with 309 commits—it's a real tool, not a demo. Hits all three HKR axes: concrete pain point, engineering detail, and developer security anxiety. Score capped because the README doesn't specify VM backen...

Hacker News front page

MathKernel: An evidence-aware multi-engine math kernel for LLMs

Staatsgeheim open-sourced MathKernel, a math kernel that gives LLMs evidence-aware computation. It runs five engines in parallel—symbolic, exact rational, formal, certified-interval, and numeric—and attaches trust labels plus full provenance to every result. It ships as an MCP server, so you can plug it straight into clients like Claude Desktop. The post doesn't disclose benchmarks or accuracy comparisons, so I'd treat it as a solid early-stage architecture for now.

Why it matters: The five-engine parallel design with trust labels is novel, and the MCP server form makes adoption trivial — it directly addresses a real pain point for agent developers. Score held at the featured threshold because it's a solo open-source project with no benchmark data yet; t...

Hacker News front page

Agentic OS: one Rust binary, one SQLite, sandbox per entity

This open-source project packs an agentic system into a single Rust binary, with per-entity sandboxes and SQLite databases. It emphasizes ontology-grounded, auditable agent workflows. Only 26 stars so far, but the design—single binary for easy deployment, sandbox for security—is worth a look. The post doesn't spell out which models or protocols it supports.

r/LocalLLaMA

llama.cpp adds support for Spark-X2.5, two compact 1.7B/4B models with 1M-token context and agent workflows

PR #27868 in llama.cpp adds support for XHToken's Spark-X2.5-1.7B and 4B. The models use a hybrid attention design—one full-attention layer plus three sliding-window layers—to natively support up to 1M-token context while keeping long-context compute in check. XHToken claims leading results among open-source models of similar size on conversation, writing, translation, reasoning, coding, and agent tasks. GGUF quantized versions are already up, and the models work with vLLM, SGLang, MLX, Ollama, and LM Studio. Training ran on Huawei Ascend clusters with RL and post-training techniques like MOPD. The post doesn't include specific benchmark numbers, so I'd hold off on the 'leading' claim until third-party evals land.

AI HOT (Curated Pool)

Berkeley RDI releases CUA-Lite, an open platform for computer-use agents

Berkeley RDI open-sourced CUA-Lite, a platform that unifies environments, training data, and model interfaces for computer-use agents. It has three standardized parts: Lite.Gym wraps 15+ benchmarks and 30k+ verifiable tasks behind one API, Lite.Sample converts 10+ datasets into a single format, and model harnesses let 14 model families share the same eval, SFT, and RL pipeline. The standout is a VM-free Docker sandbox that runs OSWorld tasks without hardware virtualization, cutting costs. Code and datasets are public on GitHub and Hugging Face.

Why it matters: Berkeley RDI ships an open platform that unifies environments, data, and model interfaces for computer-use agents — directly tackling the fragmentation pain point. 15+ benchmarks, 10+ datasets, 30k+ verifiable tasks, plus a Docker sandbox that drops the hardware virtualization...

Sep 6Sunday

Computing Life · Yage

GPT-6 Astra 3D experiments: exploded views, rigging, mocap, and a video pipeline, all open-sourced

grapeot ran GPT-6 Astra through several end-to-end 3D pipelines in Blender. The model researched and built a Touhou Project shrine model in about 30 minutes, produced an exploded-view assembly animation, and ported the scene to a browser with first-person navigation. It then rigged a Psyduck model and built a browser-based mocap app, and later generated a ceramic-firing explainer video by combining Blender keyframes with Grok Imagine. Architecture and scene modeling impressed the author; character modeling still needs heavy manual tweaking. All workflows are open-sourced as a GitHub Skill. The post does not disclose cost or latency figures.

Why it matters: The author ran end-to-end 3D experiments with GPT-6 Astra in Blender — modeling, animation, and browser export — with concrete outputs and time estimates, not just hype. Score capped below 85 because the author admits character modeling still falls short, and the experiment is...

Hacker News front page

OKF Agent Memory: Git-native persistent memory for AI coding agents

A pure-Go library that gives AI coding agents persistent memory stored as files in a Git repo. It implements Google OKF v0.2, runs in-memory BM25 search under 300µs, ships an embedded MCP server, and claims to cut token usage by 80%—no external databases needed. The post doesn't name which coding agents it integrates with or show real-world token savings, so I'd hold off on the 80% claim for now.

r/LocalLLaMA

Local LLM writes Three.js demos, watches video, and rewrites the code

An open-source project lets a local LLM write Three.js demos, then captures 30 seconds of video at 2fps and sends it back to Qwen 3.8 for a visual improvement pass. The author uses Ninfer on a single 5090, achieving ~210 tok/s decode and 14.66s per rewrite. The model still makes dumb mistakes like using only 1/4 of the screen or walking backwards through a maze; video feedback helps catch those. LM Studio is also supported for regular generation, but video rewriting requires Ninfer. The post doesn't specify Qwen 3.8's parameter count.

Sep 5Saturday

Hacker News front page

Moadim: an open-source loop engine that runs AI coding agents on a schedule

Moadim is a self-hosted, MIT-licensed loop engine that runs AI agents on a schedule. You define a loop with a prompt, a schedule, and an agent — Claude, Codex, Hermes, NanoClaw, or Pi — and it fires each tick in a fresh isolated workbench with a watchdog that kills hung runs. It ships with REST endpoints, an MCP tool interface, Swagger UI, and a web UI. It runs on macOS and Linux, uses tmux for isolation, and requires no host cron daemon.

Hacker News front page

Anthropic formalizes Fermat's Last Theorem in Lean 4

Anthropic open-sourced a Lean 4 project that formalizes the proof of Fermat's Last Theorem into machine-checkable code. The theorem states xⁿ + yⁿ = zⁿ has no positive integer solutions for n>2, proven by Wiles in 1994. Lean 4 is a proof assistant that turns human reasoning into formally verified steps. This project ports an existing proof into Lean 4, not a new theorem. The post doesn't disclose how many person-hours were spent or whether Wiles was involved.

Sep 4Friday

Product Hunt · AI

Experiential Labs: Open source AI gateway that turns traffic into a better model

Experiential Labs is an open source AI gateway with zero markup, supporting BYOK, self-hosted, and 1,000+ marketplace models. It learns from your traffic to cut costs, recommend better models, and train a specialized model you own. The post doesn't spell out how the specialized model is trained or how much cost is reduced, but the idea of using traffic to improve the model is worth watching.

AI HOT (Curated Pool)

NVIDIA to acquire Hugging Face for $12.93 billion, Jensen Huang pledges to keep the platform open

NVIDIA announced it will acquire open-source AI platform Hugging Face for $12.93 billion. Jensen Huang explained in a blog post that Hugging Face hosts over 18 million developers, 3 million models, and 500,000 datasets. He pledged the platform will remain open, supporting open-weight models, multi-cloud, and multi-accelerator environments, and will not become a closed entry point for NVIDIA hardware. NVIDIA is already the platform's largest contributor with 500+ models and 250+ open datasets.

Why it matters: $12.9B deal, 18M-developer community, and Jensen Huang's personal pledge to stay open — all solid. Held below 90 because we only have Huang's blog post so far; missing Hugging Face's independent statement and concrete governance terms.

Ruan YiFeng's Weblog

OpenClaw 2.0 ships with 16,000 AI-merged PRs

OpenClaw 2.0 launched with 16,000 PRs merged by 933 contributors, yet the core team has only 9 full-time members. Ruan Yifeng argues nearly all PRs were reviewed and merged by AI without human code review. He warns against running OpenClaw on work machines due to untestable risks. The post also notes SolidJS's founder lamenting that AI-driven rewrites push teams toward mainstream stacks like React and Rust, eroding ecosystem diversity.

AI HOT (Curated Pool)

NVIDIA announces acquisition of Hugging Face, Sundar Pichai congratulates

NVIDIA is acquiring Hugging Face. Jensen Huang says open-source models speed up innovation and let developers, startups, and nations customize AI. Sundar Pichai reposted congratulations on X, saying it strengthens the open-source ecosystem. The post is one sentence — no price, timeline, or deal structure disclosed.

Why it matters: NVIDIA acquiring Hugging Face is an infrastructure-layer earthquake, with Sundar Pichai's public congratulations forming a cross-source signal. The post doesn't disclose deal size or timeline, but the strategic logic is clear: open-source model distribution + GPU compute bundl...

Sep 3Thursday

Hacker News front page

MBZUAI releases K2 Horizon, a six-model fleet with the 0.9B scoring over 48 on AIME 2026

IFM at MBZUAI released K2 Horizon, a six-model fleet from 0.9B to 375B-A23B. The 0.9B, 3.7B, and 7B models set new SOTA in their size classes; the 0.9B scored above 48 on AIME 2026 with reasoning and tool-use capabilities. The 36B-A4B uses a new MoVA attention mechanism, outperforming larger models per active parameter. This is a full open-science release: intermediate checkpoints, data recipes, code, logs, and evals from pretraining through agentic post-training, under Apache 2.0. The post doesn't disclose specific benchmark comparison numbers or latency data, so real-world performance still needs third-party validation.

Why it matters: IFM dropped six fully open models at once, with the 0.9B hitting 48+ on AIME 2026 math and the 36B introducing a new MoVA attention mechanism — high information density. Not scoring 85+ because IFM isn't an OpenAI/Anthropic-tier lab yet and market validation hasn't caught up; ...

TechCrunch · AI

Nvidia confirms it will buy Hugging Face for $12.9 billion

Nvidia confirmed it acquired Hugging Face for $12.93 billion. The platform hosts 3 million models, 1 million apps, and 500,000 datasets, used by over 18 million developers. CEO Jensen Huang said Hugging Face will stay open, with no requirement to use Nvidia compute. Nvidia has released 500+ models and 250 open datasets on the platform. Owning an open ecosystem helps Nvidia optimize for its chips and sell unused capacity.

Why it matters: Nvidia buying HuggingFace for $12.93B is the biggest AI infra M&A this year. The 3M models + 18M devs ecosystem scale, plus Jensen Huang's careful promise to keep it open without forcing Nvidia chips, gives this story shock value, concrete numbers, and instant debate fuel. All...

The Verge · AI

Nvidia is buying Hugging Face for almost $13 billion

Nvidia agreed to acquire Hugging Face for $12.93 billion, bringing the largest open-source model hosting community under the chip giant's roof. Founded in 2016, Hugging Face is often called the 'GitHub for AI'—developers share models, datasets, and tools there. Nvidia says it will scale the platform, strengthen infrastructure, and expand AI access. The post doesn't disclose the deal timeline or regulatory approvals.

Why it matters: Nvidia buying Hugging Face for $12.93B hits the infrastructure layer of open-source model hosting. All three HKR axes fire: the deal itself is suspenseful, the price and platform positioning are new facts, and both model builders and infra people will talk about it. Not scorin...

AI HOT (Curated Pool)

Hugging Face co-founder Thomas Wolf announces NVIDIA acquisition for $12,930,300,000

Thomas Wolf posted on X that NVIDIA is acquiring Hugging Face for roughly $12.93 billion, with no changes for users that day. Wolf said the team will keep the Hub an open, independent, compute-agnostic platform and use NVIDIA's resources to push open-source AI. The post is a single-paragraph statement; it doesn't disclose deal structure, regulatory approvals, or integration timeline.

Why it matters: A ~$13B acquisition that reshapes the AI infrastructure landscape. Wolf's personal confirmation and explicit commitment to an open, compute-agnostic Hub is both reassuring and a new variable for the open-source ecosystem. The post doesn't disclose deal structure, regulatory ap...