Ghostty is leaving GitHub

The author has been using GitHub daily for 18 years, finding it the place where they've been happiest and most productive. However, due to frequent outages and reliability issues, they've decided to leave GitHub and move their project Ghostty to a new platform.

Before GitHub

https://lucumr.pocoo.org/social/2026-04-28-before-github-social.png
The author reflects on GitHub's decline and its impact on the Open Source community, remembering a time when projects were more decentralized and had more autonomy. They advocate for a public archive to preserve Open Source history and suggest that the community should learn from the past to build a more resilient future.

OpenAI models coming to Amazon Bedrock: Interview with OpenAI and AWS CEOs

https://i0.wp.com/dithering.passport.online/assets/2026-04-DitheringCoverart.jpg?w=128&h=128&ssl=1
Matt Garman and Sam Altman discussed how AWS and OpenAI are partnering to make AI more accessible to businesses, with Bedrock Managed Agents being a key product that integrates OpenAI models with AWS infrastructure. The integration of models and harnesses is crucial for making AI work effectively, and the partnership aims to make it easier for businesses to build and deploy AI-powered agents.

Carrot Disclosure: Forgejo

User found multiple vulnerabilities in Forgejo, including SSRF, cryptographic malpractices, and RCE, but chose not to disclose due to low selling value. Instead, they plan to use Carrot Disclosure to incentivize vendor to fix issues.

Intel Arc Pro B70 Review

https://wp-cdn.pugetsystems.com/2026/04/Intel-Arc-Pro-B70-Review.jpg
Intel Arc Pro B70 is a professional GPU with 32 GB VRAM, offering improved performance over the B50, but still trailing behind NVIDIA and AMD GPUs in most workloads. It excels in AI-inference workloads, outperforming the R9700 in MLPerf and offering a promising configuration for multi-GPU inference workstations.

Warp is now Open-Source

https://private-user-images.githubusercontent.com/7353770/584950695-9976b2da-2edd-4604-a36c-8fd53719c6d4.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Nzc0MDQwMjAsIm5iZiI6MTc3NzQwMzcyMCwicGF0aCI6Ii83MzUzNzcwLzU4NDk1MDY5NS05OTc2YjJkYS0yZWRkLTQ2MDQtYTM2Yy04ZmQ1MzcxOWM2ZDQucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI2MDQyOCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNjA0MjhUMTkxNTIwWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9MGQ2OWYzYzcxYTU5ZWMwYmM0ODIxNjE4MjU0Y2EyNDdmOGY1NTNmMjg2MWQ5MmFhNTMwYTBiZTU2MDY5NDQzMCZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QmcmVzcG9uc2UtY29udGVudC10eXBlPWltYWdlJTJGcG5nIn0.rxkrTu7dIfVIwyEat2kWtWHFe1Y5-oilJtoKNv9vgbM
OpenAI sponsors Warp, an open-source agentic development environment powered by GPT models. Warp has a client codebase open to community contributions and follows a Code of Conduct.

I won a championship that doesn't exist

https://raw.githubusercontent.com/ronaldstoner/ron/gh-pages/images/6nimmt/champion.png
The user manufactured a fake 6 Nimmt! World Championship title by creating a seeded website and a Wikipedia edit, demonstrating a cheaper and easier attack on LLM trust models. This attack, known as the circular citation pattern, can compromise LLMs by creating a fake source that appears trustworthy, highlighting the need for better source verification and provenance surfacing in AI systems.

Behavioral timescale synaptic plasticity rewires the brain after an experience

https://www.quantamagazine.org/wp-content/uploads/2025/06/Yasemin-Saplakoglu-article-profile.webp
Neuroscientists have discovered a new form of neuroplasticity called behavioral timescale synaptic plasticity (BTSP) that helps the brain learn from a single experience. BTSP strengthens synapses across several seconds, allowing the brain to capture behavioral processes of learning.

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown

https://www.datocms-assets.com/75231/1777300906-github-2x-100-1.jpg?fm=webp
Wiz Research discovered a critical vulnerability (CVE-2026-3854) in GitHub's internal git infrastructure that allowed remote code execution on shared storage nodes and full server compromise on GitHub Enterprise Server. GitHub mitigated the issue within 6 hours and released patches for all supported versions.

CJIT: C, Just in Time

https://dyne.org/cjit/assets/dyne-mark.CcSJn4AU.svg
🤏🏼One file <2MB big, no EULA to sign, no IDE to install

Your phone is about to stop being yours

https://keepandroidopen.org/img/logos/gnome.org.png
Google is imposing a developer verification requirement on Android, which critics say is a move to consolidate power and control over the open ecosystem. This change could effectively make Google the gatekeeper for all apps on certified Android devices.

APL\? (1990)

Patch applies fake diffs from commit messages

User found that GNU patch can apply diff from commit message as part of real patch. This can be a security issue as it allows injection of arbitrary files.

Who owns the code Claude Code wrote?

https://substackcdn.com/image/fetch/$s_!fZ2S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c45efbc-1881-4750-bdf5-aad04220b0a2_1456x816.png
Using AI coding tools like Claude Code raises complex questions about code ownership, copyright, and regulatory compliance, and developers must document their creative contributions to establish meaningful human authorship. Employment contracts and IP clauses can also impact code ownership, and developers should read their contracts and consider using personal tools and accounts to avoid ...

Parry Parries Again: Reanimating the Famous Paranoid Chatbot (In a Day)

https://lh3.googleusercontent.com/sitesv/AA5AbUBpEFq8MVp_girbZpq4tayQ_u1IG46SPcj8usa-MHfvhCsHoIfS0UQd2Ax4cbw3LVwbSzO_-IxbIi4EeaIx8eXKqz-8EBWHcfkFz725n2qXH7RV4ou9-0BE7pUIjZVfhjIT5ERCd6iEqJqrZp37bebqFk7amQoVXGK_6crv6Z4X-fHqAgLEMVFLgfDtUMfYvldRZ3rf7QZsbt8TWwA-pckDD-UCv3Ke--S3_kA=w1280
A few days ago, I posted an inquiry to the PiDP-10 forum asking whether anyone had a running IPL-V interpreter on their system. (I've been working on reanimating the earliest AI programs created by Simon, Newell, and Shaw, programs originally written in IPL-V, and a working interpreter would let me bring some of these back to life.) I didn't get an IPL-V interpreter, but the thread ...

I have officially retired from Emacs

https://nullprogram.com/img/elfeed2.png
The author has retired from using Emacs after 20 years, replacing it with modal editing and Vim, and is now transferring two of its applications, the Emacs Calculator and Elfeed, to new maintainers.

Warp is now open-source

https://www.warp.dev/_next/image?url=%2Fimages%2Fblog%2Fwarp-is-now-open-source%2Fhero.png&w=3840&q=75
Warp's client is now open-source, allowing the community to participate in building it using an agent-first workflow managed by Oz. This change aims to accelerate product development and give developers a chance to shape the future of agentic development.

A playable DOOM MCP app

https://chrisnager.com/images/blog/doom-runs-in-chatgpt-and-claude/chrisnager-doom-claude-web.png
The user created a playable DOOM app using MCP that can launch inline in compatible AI clients or fall back to a browser URL. The project involved overcoming browser security policies and adapting the app to work across different clients with varying rules around iframes, CSP, and UI rendering.

Drone pilot makes US rescind no-fly zones around unmarked, moving ICE vehicles

https://cdn.arstechnica.net/wp-content/uploads/2026/04/powderhorn_jan_10.jpg
Federal agents killed 37-year-old Renee Good and 37-year-old Alex Pretti during protests in Minneapolis. The FAA issued a no-fly zone warning that was later revised to an advisory after a lawsuit was filed by a freelance photojournalist.

Infisical (YC W23) Is Hiring Full Stack Software Engineers (Remote)

https://app.ashbyhq.com/api/images/org-theme-logo/b20c5955-beb4-4422-87a4-a5fac3e4e5af/b4ec8d2e-abe1-4f48-9e0e-4bef3b7b949a/01a88b46-b8b1-4a8b-b89c-e7916f4eb898.png
Infisical is hiring a Full Stack Engineer to build and expand its open source security infrastructure platform. The ideal candidate has deep technical mastery of JavaScript and a bias toward action, with experience in React.js, Node.js, and TypeScript.

Localsend: An open-source cross-platform alternative to AirDrop

https://camo.githubusercontent.com/f0ab3879f57aff14cff2cbecd2dde800add5c488f3b84443215dbd599ec5a722/68747470733a2f2f6c6f63616c73656e642e6f72672f696d672f73637265656e73686f742d70632e77656270
LocalSend is a free, open-source app for secure local file sharing and messaging over a network without an internet connection. It uses HTTPS encryption and a REST API for secure communication between devices.

Waymo in Portland

https://lh3.googleusercontent.com/UPun1Qt7__4wiDBjwVmycX6nHcPeo8-O1740UaePpfNI9u0UoOVyLiW9jKmgmTaROQTLF1AhIUm7jVBAfV-9v-qxY54SwKFsUz8=e365-s420
Waymo is coming to Portland, partnering with city officials to bring safe, reliable, and stress-free transportation. The company aims to support Portland's Vision Zero goals by deploying its autonomous vehicles.

VibeVoice: Open-source frontier voice AI

https://raw.githubusercontent.com/microsoft/VibeVoice/main/Figures/VibeVoice_logo.png
VibeVoice is an open-source AI framework for speech synthesis and recognition, supporting multiple languages and long-form audio processing. It includes models for text-to-speech and automatic speech recognition, with features like speaker tracking and customized hotwords.

UAE to leave OPEC

The following information can help our support team to resolve this issue.

Claude.ai unavailable and elevated errors on the API

Claude's Status Page - Claude.ai unavailable and elevated errors on the API.

Show HN: Drive any macOS app in the background without stealing the cursor

https://raw.githubusercontent.com/trycua/cua/main/img/logo_black.svg
cuabot is a tool for automating computer tasks with a seamless sandbox for coding agents. It allows running native macOS apps in the background and recording trajectories for training.

Show HN: Live Sun and Moon Dashboard with NASA Footage

https://sdo.gsfc.nasa.gov/assets/img/latest/latest_1024_0304.jpg
Lumara is an app tracking solar activity, lunar phases, and space weather in real-time from NASA data. It uses Jean Meeus's algorithms and fetches imagery directly from NASA servers, with no data collection.

Talkie: a 13B vintage language model from 1930

https://talkie-lm.com/images/papers-composite.png
Researchers have created a 13B vintage language model called talkie-1930-13b-base trained on 260B tokens of historical pre-1931 English text to simulate conversations with people from the past. The model's performance is compared to its modern counterpart, with talkie underperforming in some standard LM evaluations but showing similar performance on core language understanding and numeracy tasks.
https://nesbitt.io/images/boxes.png
The author discusses a series of open source supply chain incidents caused by GitHub Actions features behaving as documented, but with unintended consequences. These incidents include credential harvesting, cache poisoning, and malicious package publishing.

AISLE Discovers 38 CVEs in OpenEMR Healthcare Software

https://aisle.com/_next/image?url=https%3A%2F%2Faisle.com%2Fapi%2Fmedia%2Ffile%2FOpenEMR%2520-%2520blog%2520hero%2520(1).webp%3F2026-04-28T13%3A51%3A48.965Z&w=3840&q=100
AISLE researchers discovered 38 CVEs in OpenEMR, including SQL injection vulnerabilities and IDOR issues, which could have enabled attacks against patient data. AISLE's AI analyzer found these vulnerabilities in just one quarter, significantly faster than prior independent security audits.