1 393
Subscribers
No data24 hours
-37 days
-1830 days
Data loading in progress...
Similar Channels
Tags Cloud
Incoming and Outgoing Mentions
---
---
---
---
---
---
Attracting Subscribers
June '25
June '25
+3
in 0 channels
May '25
+3
in 0 channels
Get PRO
April '25
+1
in 0 channels
Get PRO
March '25
+13
in 0 channels
Get PRO
February '25
+7
in 0 channels
Get PRO
January '25
+9
in 0 channels
Get PRO
December '24
+78
in 5 channels
Get PRO
November '24
+19
in 0 channels
Get PRO
October '24
+25
in 0 channels
Get PRO
September '24
+28
in 1 channels
Get PRO
August '24
+45
in 5 channels
Get PRO
July '24
+396
in 0 channels
Get PRO
June '24
+19
in 5 channels
Get PRO
May '24
+40
in 4 channels
Get PRO
April '24
+2
in 5 channels
Get PRO
March '24
+29
in 4 channels
Get PRO
February '240
in 0 channels
Get PRO
January '240
in 4 channels
Get PRO
December '230
in 0 channels
Get PRO
November '230
in 4 channels
Get PRO
October '230
in 0 channels
Get PRO
September '23
+39
in 0 channels
Get PRO
August '23
+25
in 0 channels
Get PRO
July '23
+30
in 0 channels
Get PRO
June '23
+40
in 0 channels
Get PRO
May '23
+55
in 0 channels
Get PRO
April '23
+19
in 0 channels
Get PRO
March '23
+47
in 0 channels
Get PRO
February '23
+55
in 0 channels
Get PRO
January '23
+22
in 0 channels
Get PRO
December '22
+3
in 0 channels
Get PRO
November '22
+4
in 0 channels
Get PRO
October '22
+6
in 0 channels
Get PRO
September '22
+10
in 0 channels
Get PRO
August '22
+62
in 0 channels
Get PRO
July '22
+99
in 0 channels
Get PRO
June '22
+65
in 0 channels
Get PRO
May '22
+24
in 0 channels
Get PRO
April '22
+143
in 0 channels
Get PRO
March '22
+53
in 0 channels
Get PRO
February '22
+38
in 0 channels
Get PRO
January '22
+117
in 0 channels
Get PRO
December '21
+93
in 0 channels
Get PRO
November '21
+89
in 0 channels
Get PRO
October '21
+122
in 0 channels
Get PRO
September '21
+159
in 0 channels
Get PRO
August '21
+366
in 0 channels
| Date | Subscriber Growth | Mentions | Channels | |
| 25 June | 0 | |||
| 24 June | 0 | |||
| 23 June | 0 | |||
| 22 June | +1 | |||
| 21 June | 0 | |||
| 20 June | 0 | |||
| 19 June | 0 | |||
| 18 June | 0 | |||
| 17 June | 0 | |||
| 16 June | 0 | |||
| 15 June | 0 | |||
| 14 June | 0 | |||
| 13 June | 0 | |||
| 12 June | +1 | |||
| 11 June | 0 | |||
| 10 June | 0 | |||
| 09 June | 0 | |||
| 08 June | 0 | |||
| 07 June | 0 | |||
| 06 June | 0 | |||
| 05 June | 0 | |||
| 04 June | 0 | |||
| 03 June | +1 | |||
| 02 June | 0 | |||
| 01 June | 0 |
Channel Posts
חדשות FOSS
מאת | Fossery Tech |
גימפ (GIMP 3.0) שוחרר עם ממשק משתמש GTK3 מעודן, ניהול צבע משופר, תמיכה בטעינת שכבות מקובצי TIFF שנשמרו בפורמט Autodesk Sketchbook , תמיכה בתמונות של 64 סיביות לפיקסל לפורמט BMP, שיפורים בעריכה לא הרסניים, רכיבי GEGL ו- babl מעודכנים ועוד:
https://9to5linux.com/gimp-3-0-image-editor-is-now-available-for-download-heres-whats-new
(סוף סוף המם נגמר!)
פייר-טיוב (PeerTube 7.1) שוחרר עם תמיכה ב-Podcast 2.0, כתובת פלטפורמת האירוח מודגשת עבור כל סרטון (ניתן ללחוץ כדי לצפות בסרטונים אחרים שמתארחים באותו מופע), אפשרות לאמת ערוץ עם חשבון Mastodon :
https://alternativeto.net/news/2025/3/peertube-7-1-brings-podcast-2-0-support-enhanced-identification-and-mastodon-verification/
קליינט של מאסטאדון (Mastodon clinet Tusky 28) שוחרר עם תמיכה באנדרואיד15, מצב מקצה-לקצה, התראות דחיפה אמינות יותר, שיפורי ממשק משתמש, אפשרות לבחור משך השתקה וכו':
https://alternativeto.net/news/2025/3/mastodon-client-tusky-28-brings-android-15-support-improved-notifications-and-more/
פלטפורמת פרסום Ghost הטמיעה שילוב ביטא ActivityPub כדי להצטרף ל- Fediverse :
https://alternativeto.net/news/2025/3/publishing-platform-ghost-enters-the-fediverse-with-activitypub-integration-in-public-beta/
(שיא חדש! 3 חדשות Fediverse בפוסט!)
בנייה של פייר-פוקס נייטלי (Firefox Nightly build) מקבלת דגל ניסיוני של browser.taskbarTabs.enabled
ב- about:config, מוזיילה (Mozilla) מתכננת לתמוך ביישומי אינטרנט מתקדמים ( PWAs )
אך עם גישה אחרת הנקראת "Taskbar Tabs":
https://www.omgubuntu.co.uk/2025/03/firefox-nightly-supports-web-apps-taskbar-tabs
בלנדר(Blender 4.4) שוחרר עם תמיכה בשקעים שלמים בקומפוזיטור, מצב Fast Gaussian הרבה יותר מדויק ל-צומת/נוד Blur,
צומת/נוד Glare מחודשת לשליטה רבה יותר,
ותמיכה בעיבוד סרטונים באמצעות ה-codec H.265/HEVC וכו':
https://9to5linux.com/blender-4-4-released-with-a-big-update-for-the-experimental-vulkan-backend
גיט (Git 2.49) שוחרר עם אריזה מהירה יותר, מילוי כתמים היסטוריים בשיבוט חלקי ועוד:
https://alternativeto.net/news/2025/3/git-2-49-released-with-faster-packing-backfill-historical-blobs-in-partial-clones-and-more/
זד (Zed) מקבל תמיכה מקורית של Git במהדורת v0.177, באמצעות פאנל Git חדש עם אפשרויות commit, push, pull ו-stage:
https://news.itsfoss.com/zed-git-support/ "
דרך | @OSPopenSourcePlanet |
| 2 | FOSS news
By | Fossery Tech |
[...] "GIMP 3.0 released with refined GTK3 UI, improved color management, support for loading layers from TIFF files saved in the Autodesk Sketchbook format, support for 64 bits per pixel images for the BMP format, non-destructive editing improvements, updated GEGL and babl components and more:
https://9to5linux.com/gimp-3-0-image-editor-is-now-available-for-download-heres-whats-new
(Finally the meme is over!)
PeerTube 7.1 released with Podcast 2.0 support, hosting platform's address is highlighted for each video (can be clicked to view other videos hosted on that instance), option to verify channel with Mastodon account:
https://alternativeto.net/news/2025/3/peertube-7-1-brings-podcast-2-0-support-enhanced-identification-and-mastodon-verification/
Mastodon client Tusky 28 released with Android 15 support, edge-to-edge mode, more reliable push notifications, UI improvements, option to choose mute duration etc.:
https://alternativeto.net/news/2025/3/mastodon-client-tusky-28-brings-android-15-support-improved-notifications-and-more/
Ghost publishing platform implement beta ActivityPub integration to join the Fediverse:
https://alternativeto.net/news/2025/3/publishing-platform-ghost-enters-the-fediverse-with-activitypub-integration-in-public-beta/
(New record! 3 Fediverse news in a post!)
Firefox Nightly build gets experimental browser.taskbarTabs.enabled flag in about:config, Mozilla plans to support Progressive Web Apps (PWAs) but with a different approach called "Taskbar Tabs":
https://www.omgubuntu.co.uk/2025/03/firefox-nightly-supports-web-apps-taskbar-tabs
Blender 4.4 released with support for integer sockets in the compositor, a much more accurate Fast Gaussian mode of the Blur node, a revamped Glare node for greater control, support for rendering videos using the H.265/HEVC codec etc.:
https://9to5linux.com/blender-4-4-released-with-a-big-update-for-the-experimental-vulkan-backend
Git 2.49 released with faster packing, backfill historical blobs in partial clones and more:
https://alternativeto.net/news/2025/3/git-2-49-released-with-faster-packing-backfill-historical-blobs-in-partial-clones-and-more/
Zed gets native Git support in v0.177 release, via a new Git panel with commit, push, pull and stage options:
https://news.itsfoss.com/zed-git-support/ " [...]
Via | @OSPopenSourcePlanet | | 0 |
| 3 | מדענים משיקים את מערכת ההפעלה למחשבים קוונטים עם קוד פתוח
מאת | אוניברסיטת אוסקה |
[...] "אימוץ מוקדם ותוכניות עתידיות
בנוסף, שירות ענן המחשוב הקוונטי המוצע על ידי אוניברסיטת אוסקה החל לשלב את OQTOPUS בפעילותה ו- פוג'יטסו לימיטיד (Fujitsu Limited) תהפוך אותו לזמין עבור שותפי מחקר המשתמשים במחשבים הקוונטים שלהם במחצית השנייה של 2025.
בהמשך הדרך, צוות המחקר יניע את התקדמות המחשוב הקוונטי באמצעות הרחבה מתמשכת של היכולות של OQTOPUS ופיתוח של קהילה גלובלית משגשגת.
ה- ד"ר קייסוקה פוגיי במרכז למידע קוונטי וביולוגיה קוונטית ( QIQB) של אוניברסיטת אוסקה מזכיר,
"זה יקל על הסטנדרטיזציה של תוכנות ומערכות קוונטיות שונות תוך כדי יצירת יישומים קוונטיים חדשניים."
המחקר מומן על ידי סוכנות המדע והטכנולוגיה היפנית וה-מכונים לאומיים למדע וטכנולוגיה קוונטית.
ניתן למצוא את מאגר GitHub כאן ."
דרך | @OSPopenSourcePlanet | | 0 |
| 4 | Scientists Launch Open-Source Quantum Computer OS
By | Osaka University |
[...] "Early Adoption and Future Plans
Additionally, the quantum computing cloud service offered by the University of Osaka has begun integrating OQTOPUS into its operations and Fujitsu Limited will make it available for research partners using its quantum computers in the second half of 2025.
Moving forward, the research team will drive the advancement of quantum computing through the continuous expansion of OQTOPUS’s capabilities and the development of a thriving global community.
Dr. Keisuke Fujii at the Center for Quantum Information and Quantum Biology (QIQB) of The University of Osaka mentions,
“this will facilitate the standardization of various quantum software and systems while driving the creation of innovative quantum applications.”
The research was funded by the Japan Science and Technology Agency and the National Institutes for Quantum Science and Technology.
The GitHub repository can be found here."
Via | @OSPopenSourcePlanet | | 0 |
| 5 | "מראה למשתמש אליס שנכנס ל-גוגל באמצעות OpenID Connect/OpenPubkey ולאחר מכן מייצר אסימון PK"
OpenPubkey SSH (OPKSSH) במקור פתוח: שילוב כניסה יחידה עם SSH
מאת | איתן היילמן |
[...] " אופן-פאבקיי (OpenPubkey), המוצג למטה, מוסיף מפתחות ציבוריים לאסימוני זיהוי. זה מאפשר להשתמש באסימוני זיהוי כמו אישורים,
למשל "גוגל אומרת כי alice@example.com משתמשת במפתח ציבורי 0x123."
אנו קוראים לאסימון מזהה המכיל מפתח ציבורי בשם PK Token.
היופי ב- אופן-פאבקי (OpenPubkey) הוא שבניגוד לגישות אחרות, אופן-פאבקי (OpenPubkey) אינו דורש שינויים כלשהם בפרוטוקולי SSO קיימים
ותומך בכל OP תואם OpenID Connect.
למה זה חשוב
ה-OPKSSH משחררים את המשתמשים והמנהלים מהצורך לנהל מפתחות SSH ארוכים, מה שהופך את ה-SSH למאובטח ונוח יותר." [...]
דרך | @OSPopenSourcePlanet | | 0 |
| 6 | "Shows a user Alice signing in to Google using OpenID Connect/OpenPubkey and then producing a PK Token"
Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH
By | Ethan Heilman |
[...] "OpenPubkey, shown below, adds public keys to ID Tokens. This enables ID Tokens to be used like certificates,
e.g. “Google says alice@example.com is using public key 0x123.”
We call an ID token that contains a public key a PK Token.
The beauty of OpenPubkey is that, unlike other approaches, OpenPubkey does not require any changes to existing SSO protocols and supports any OpenID Connect compliant OP.
Why this matters
OPKSSH frees users and administrators from the need to manage long-lived SSH keys, making SSH more secure and more convenient.
" [...]
Via | @OSPopenSourcePlanet | | 0 |
| 7 | בידקו את מחולל הדמויות התלת-ממד החדש בקוד פתוח קאר-מורפ' (CharMorph)
מאת | ג'ים ת'קר |
[...] " מגיע עם דמויות בסיס מוכנות שניתן להשתמש בהן בפרויקטים מסחריים
למרות שחסרות לו חלק מהתכונות של MB-Lab, כמו מודלים אוטומטיים, ל-קאר-מורפ' (CharMorph) יש מספר יתרונות על פני קודמו, המפורטים בעמוד הגיטהאב (GitHub) של הפרויקט.
היתרונות העיקריים כוללים תמיכה ב-Rigify, מערכת יצירת אסדות דמויות מודולרית של בלנדר, כולל עבור ריגים לפנים (facial rigs), והתאמת בגדים בזמן אמת.
אפשר גם להגדיר ישירות את צבע העור והעיניים, ותזוזה נעשית ברמת החומר ולא באמצעות ה-Displace modifier, מה שמאפשר לצפות בתצוגה מקדימה של האפקט ב-Eevee.
אבל אולי הכי משמעותי, אפשר להשתמש בדמויות שנוצרו עם קאר-מורפ' (CharMorph) בכל סוג של עבודה מסחרית, כולל משחקי קוד סגור.
בעוד שלתו הבסיס מ-MB-Lab יש רישיון תחת רישיון AGPL, ל-קאר-מורפ' (CharMorph) יש שלושה דמויות בסיס חלופיים עם רישיונות Creative Commons: או רישיונות ייחוס CC-BY, או במקרה של הדמות Vitruvian שנוספה בעדכון האחרון, רישיון CC0 מלא.
בכתבה ב-BlenderNation, המפתחים מעירים שהם שואפים לספק מודלים של דמויות שיכולים להתחרות באלו מפתרונות קוד סגור כמו Character Creator או Daz Studio, "להשיג את רמת האיכות שנראית בסרטים שוברי קופות ומשחקי וידאו מהדור הבא".
ומתכננת לתמוך בדמויות שאינן אנושיות במהדורות עתידיות
בנוסף לדמות Vitruvian, CharMorph 0.4 כולל מספר שיפורים נוספים, כולל אפשרות להוריד דמויות או לעדכן את התוסף ישירות בתוך בלנדר (Blender).
צוות הפיתוח אומר שכעת הוא מתכנן להרחיב את התוכנה מעבר לדמויות דמויות אנושיות, ולאפשר ליצור חיות ויצורים אחרים.
דרישות רישיון ומערכת
קאר-מורפ' (CharMorph) תואם בלנדר 4.4. (Blender) וזו הורדה בחינם.
התוכנה היא בקוד פתוח: קוד המקור זמין תחת רישיון GPLv3. תווי הבסיס הבודדים זמינים תחת מגוון רישיונות: הדמות החדשה של Vitruvian היא CC0.
בקרו באתר CharMorph
קראו את התיעוד המקוון עבור CharMorph
הורידו את CharMorph מ- GitHub "
דרך | @OSPopenSourcePlanet | | 0 |
| 8 | Check out new open-source 3D character generator CharMorph
By | Jim Thacker |
[...] "Comes with readymade base characters that can be used in commercial projects
Although it lacks some of the features from MB-Lab, such as auto-modeling, CharMorph has a number of advantages over its predecessor, listed on the project’s GitHub page.
Key benefits include support for Rigify, Blender’s modular character rig creation system, including for facial rigs, and real-time fitting of clothing.
It is also possible to set skin and eye color directly, and displacement is done at material level rather than using the Displace modifier, making it possible to preview the effect in Eevee.
But perhaps most significantly, it is possible to use characters generated with CharMorph in any kind of commercial work, including closed-source games.
Whereas the base character from MB-Lab is licensed under an AGPL license, CharMorph has three alternative base characters with Creative Commons licenses: either CC-BY attribution licenses, or in the case of the Vitruvian character added in the latest update, a full CC0 license.
In a story on BlenderNation, the developers comment that they aim to provide character models that can compete with those from closed-source solutions like Character Creator or Daz Studio, “achieving the level of quality seen in blockbuster movies and next-gen video games”.
Plans to support non-humanoid characters in future releases
As well as the Vitruvian character, CharMorph 0.4 features a number of other improvements, including the option to download characters or update the add-on directly within Blender.
The development team says that it now plans to extend the software beyond humanoid characters, making it possible to create animals and other creatures.
License and system requirements
CharMorph is compatible with Blender 4.4. It’s a free download.
The software is open-source: the source code is available under a GPLv3 license. The individual base characters are available under a range of licenses: the new Vitruvian character is CC0.
Visit the CharMorph website
Read the online documentation for CharMorph
Download CharMorph from GitHub "
Via | @OSPopenSourcePlanet | | 0 |
| 9 | אונלי-אופיס (OnlyOffice): סקירה כללית של חבילת Office בקוד פתוח
מאת | Watson Tech World |
"גלו את אונלי-אופיס (OnlyOffice), חלופה רבת עוצמה בקוד פתוח ל-גוגל דרייב, Docs , Sheets ו- Slides.
בסקירה מקיפה זו, אדריך אותכם בדרכי יכולות האחסון של הפלטפורמה, עורך המסמכים, עורך הגיליון האלקטרוני ועורך המצגות.
למדו כיצד ליצור, לערוך ולשתף פעולה בקבצים שלכם תוך שמירה על שליטה על הנתונים שלכם.
עם 2GB של אחסון חינם ואפשרות לאירוח עצמי, אונלי-אופיס (OnlyOffice) הוא פתרון רב-תכליתי עבור אנשים וארגונים המחפשים פרטיות וגמישות."
אונלי-אופיס (OnlyOffice):
https://www.onlyoffice.com
עמוד ה-ג'יטהב הראשי של אונלי-אופיס (OnlyOffice):
https://github.com/ONLYOFFICE
דרך | @OSPopenSourcePlanet | | 0 |
| 10 | OnlyOffice: Open Source Office Suite Overview
By | Watson Tech World |
"Discover OnlyOffice, a powerful open source alternative to Google Drive, Docs, Sheets, and Slides.
In this comprehensive overview, I'll guide you through the platform's storage capabilities, document editor, spreadsheet editor, and presentation editor.
Learn how to create, edit, and collaborate on your files while maintaining control over your data.
With 2GB of free storage and the option to self-host, OnlyOffice is a versatile solution for individuals and organizations seeking privacy and flexibility."
ONLYOFFICE:
https://www.onlyoffice.com/
ONLYOFFICE's GitHub main page:
https://github.com/ONLYOFFICE
Via | @OSPopenSourcePlanet | | 0 |
| 11 | גוגל מפרסמת עדכון מרכזי עבור סורק הפגיעות בקוד פתוח
מאת | שבוע האבטחה |
[...] "האיטרציה החדשה של הסורק מתבססת על היכולות שהוצגו מוקדם יותר השנה עם שחרורו של OSV-SCALIBR (Software Composition Analysis LIBRary),
סורק מערכת קבצים הניתן להרחבה המחלץ מידע על מלאי תוכנה.
ה-OSV-Scanner V2.0.0 משלב תכונות OSV-SCALIBR והופך לכלי סריקת קוד שורת הפקודה הרשמי ולכלי סריקת עבור ספריית קונטיינר (container) לקוד הפתוח.
"מהדורת V2 זו מתבססת על הבסיס שהנחתנו עם OSV-SCALIBR ומוסיפה יכולות חדשות משמעותיות ל- OSV-Scanner, מה שהופך אותו לסורק ותיקון פגיעות מקיף עם תמיכה רחבה בפורמטים ומערכות אקולוגיות", אומרת גוגל.
באדיבות האינטגרציה הזו, הסורק יכול כעת לחלץ מניפסט מקור של פרויקטים וקבצי נעילה
(כולל .NET: deps.json , Python: uv.lock , JavaScript: bun.lock , and Haskell: cabal.project.freeze ו- stack.yaml.lock), וחפצים (כגון מודולי Node, גלגלי Python ,Java uber jars ו- Go binaries).
זה כולל גם סריקה מודעות (layer-aware) לשכבות עבור אלפיין, דביאן, ותמונות קונטיינר של אובונטו, מתן פרטים כגון היסטוריית שכבות ופקודות, שכבות בהן הוצגה חבילה, תמונת הבסיס, מערכת ההפעלה וההפצה שהמכולה פועלת, ופגיעויות שסביר שלא ישפיעו על תמונת הקונטינר." [...]
דרך | @OSPopenSourcePlanet | | 0 |
| 12 | Google Releases Major Update for Open Source Vulnerability Scanner
By | SecurityWeek |
[...] "The new iteration of the scanner builds on the capabilities introduced earlier this year with the release of OSV-SCALIBR (Software Composition Analysis LIBRary), an extensible file system scanner that extracts information on software inventory.
OSV-Scanner V2.0.0 integrates OSV-SCALIBR features and becomes the official command-line code and container scanning tool for the open source library.
“This V2 release builds upon the foundation we laid with OSV-SCALIBR and adds significant new capabilities to OSV-Scanner, making it a comprehensive vulnerability scanner and remediation tool with broad support for formats and ecosystems,” Google says.
Courtesy of this integration, the scanner can now extract from projects source manifest and lockfiles (including .NET: deps.json, Python: uv.lock, JavaScript: bun.lock, and Haskell: cabal.project.freeze and stack.yaml.lock), and artifacts (such as Node modules, Python wheels, Java uber jars, and Go binaries).
It also includes layer-aware scanning for Alpine, Debian,
and Ubuntu container images,
providing details such as layer history and commands, layers where a package was introduced, the base image, the OS and distribution the container is running, and vulnerabilities unlikely to affect the container image." [...]
Via | @OSPopenSourcePlanet | | 0 |
| 13 | "Image: Shutterstock / Built In"
הגנו על צוות ה-DevOps שלכם מפני שינויים ברישיונות קוד פתוח
מאת | builtin |
[...] "הנה פעולות שאתם יכול לנקוט כדי לצמצם את ההשפעה של שינוי רישיון, להפחית את הנזק שהוא יכול לעשות למערכת האקולוגית שלכם ולהשאיר לעצמכם אפשרויות כיצד להמשיך הלאה.
5 שלבים להגנה מפני שינויים ברישיונות קוד פתוח
הבנו את הבעיות של המערכת האקולוגית בקוד פתוח.
בדקו בקפדנות את מדיניות הממשל הזו.
שימו לב מי עומד מאחורי התוכנה.
חפשו את סימני האזהרה המוקדמים ביותר לשינויי רישיון.
הימנעו מלהפוך עצמכם אוטומטיים ולהיתקע בפינה.
הבנו את הבעיות של המערכת האקולוגית בקוד פתוח
הצעד הראשון הוא תמיד מודעות. זכורו שכל רישיונות ה-OSS אינם נוצרים שווים, כך שהתוכנה שבה אתם משתמשים עשויה לא להיות מוקדשת לעקרונות קוד פתוח כפי שאתם חושבים.
החברה שמאחוריה יכולה לשלוף את השטיח מתחתיכם, אז העריכו את מחויבותה לפתיחת מקורות בקפידה. עליכם לשקול את חשיפת הרישוי שלכם במונחים דומים לחשיפת האבטחה שלכם." [...]
דרך | @OSPopenSourcePlanet | | 0 |
| 14 | Protect Your DevOps Team From Open-Source License Changes
By | builtin |
[...] "Here are actions that you can take to mitigate the impact of a license change, reduce the damage it could do to your ecosystem and leave yourself with options for how to move on.
5 Steps to Protect Against Open-Source License Changes
Understand the problems of the open-source ecosystem.
Scrutinize those governance policies.
Pay attention to who is behind the software.
Look for the earliest warning signs of license changes.
Avoid automating yourself into a corner.
Understand the Problems of the Open-Source Ecosystem
The first step is always awareness. Remember that all OSS licenses are not created equal, so the software that you’re using might not be as dedicated to open-source principles as you think.
The company behind it could pull the rug out from under you, so evaluate its commitment to open sourcing carefully. You should consider your licensing exposure in similar terms to your security exposure." [...]
Via | @OSPopenSourcePlanet | | 0 |
| 15 | חיים ללא ווינדוס: וואה-וויי (Huawei) מכינה את ה-"מחשב בינה-מלאכותית" כדי להתמודד עם הסנקציות של ארה"ב
מאת | TechSpot |
[...] "לפי יו צ'נגדונג, מנכ"ל ויו"ר היחידה העסקית הצרכנית של וואה-וויי (Huawei), החברה נשארת ב-רשימת הישויות של משרד המסחר האמריקאי, ודורש רישיון מיוחד כדי להשתמש ב- ווינדוס.
וואה-וויי (Huawei) עשויה לאבד בקרוב את היכולת להשיג חידושי רישיון חדשים ממיקרוסופט, ובכך למעשה תסיים את הקשר העסקי בין שתי החברות.
כתוצאה מכך, מחשבי וואה-וויי (Huawei) הנוכחיים יהיו המערכות האחרונות שנמכרות עם מערכת הפעלה מערבית.
לפי הדיווחים, היצרנית הסינית מתכוננת להשיק "מחשב בינה-מלאכותית" חדש הכולל את ה-Kunpeng CPU הקנייני שלהם ואת האיטרציה האחרונה של HarmonyOS NEXT.
מערכת זו, שצפויה לצאת לאקרנים בחודש הבא, תכלול גם אפליקציות המופעלות על ידי מודל השפה הגדולה השנויה במחלוקת של דייפ-סייק (DeepSeek)".
דרך | @OSPopenSourcePlanet | | 0 |
| 16 | Life without Windows: Huawei preps "AI PC" to counter US sanctions
By | TechSpot |
[...] "According to Yu Chengdong, executive director and chairman of Huawei's consumer business unit, the company remains on the US Department of Commerce's Entity List, requiring a special license to use Windows.
Huawei may soon lose the ability to obtain new license renewals from Microsoft, effectively ending the business relationship between the two companies.
As a result, current Huawei PCs will be the last systems sold with a Western operating system.
The Chinese manufacturer is reportedly preparing to launch a new "AI PC" featuring its proprietary Kunpeng CPU and the latest iteration of HarmonyOS NEXT.
This system, expected to debut next month, will also include applications powered by DeepSeek's controversial large language model."
Via | @OSPopenSourcePlanet | | 0 |
| 17 | ספריות של צד שלישי גורמות ליותר בעיות אבטחה מאשר קוד של צד ראשון (first-party code), ופגמים בקוד-פתוח לוקחים יותר זמן לתיקון
מאת | טים אנדרסון |
[...] "ראוי לציין כי יותר בעיות אבטחה נמצאות בספריות או רכיבים של צד שלישי (70 אחוז מהיישומים) מאשר בקוד שנכתב במיוחד עבור אפליקציה (64 אחוז); וכי הבעיות בקוד של צד שלישי נוטות להיות חמורות יותר. הדו"ח קובע ש-לשלושה מתוך עשרה ארגונים שיותר מ-%96 אחוזי אבטחה הקריטיים שלהם נמצאים בקוד של צד שלישי.
בדו"ח יש סעיף המתמקד במיוחד בקוד קוד פתוח, שקובע כי בעוד ששיעור החוב הביטחוני הקשור לקוד כזה הוא "נמוך למדי", בכל זאת יש בו שיעור גבוה של הפגמים הקריטיים ביותר. בעיה נוספת היא שבעיות בקוד קוד פתוח נוטות להימשך זמן רב יותר לתיקון, עם זמן מחצית חיים של 12 חודשים לעומת 8 חודשים עבור קוד צד ראשון (first-party code).
ישנן מספר סיבות לכך שקוד צד שלישי עשוי להיות בעייתי יותר לאבטחה. לספריות עשויות להיות תלות רבה, שלא ניתן לעדכן בקלות בגלל שינויים שבירים בגרסאות חדשות יותר, או בגלל שפרויקט קוד פתוח הפך פחות פעיל וכבר לא מתוחזק היטב.
הגדרה מחדש של יישום כדי להסיר ספרייה אחת ולהחליף אותה באחת מאובטחת יותר עשויה להיות קשה. הערכת הסיכון האמיתי של פגיעות דורשת יותר מניתוח סטטי. ייתכן שחלק מבעיות האבטחה שזוהו בחומרה גבוהה לא יהיו רלוונטיות מכיוון שהן כרוכות בפונקציות שלעולם לא נקראות, או שנמנעות על ידי אמצעי אבטחה אחרים במקום.
"אבטחת תוכנה מודרנית עוסקת בתיקון סיכון אמיתי הדורש יצירת יותר הקשרים," אומרים מחברי הדו"ח, למרות שזו משימה לא טריוויאלית". [...]
דרך | @OSPopenSourcePlanet | | 0 |
| 18 | Third-party libraries cause more security woes than first-party code, open-source flaws take longer to fix
By | Tim Anderson |
[...] "It is notable that more security issues are found in third-party libraries or components (70 percent of applications) than in code written specifically for an application (64 percent); and that the issues in third-party code tend to be more severe. The report states that three in ten organizations have more than 96 percent of their critical security debut in third-party code.
The report has a section focused specifically on open source code, stating that while the proportion of security debt tied to such code is “fairly low,” it nevertheless has a high proportion of the most critical flaws. A further problem is that issues in open source code tend to take longer to fix, with a half-life of 12 months compared to 8 months for first-party code.
There are multiple reasons why third-party code may be more problematic for security. Libraries may have many dependencies, which cannot be updated easily because of breaking changes in newer versions, or because an open-source project has become less active and is no longer well maintained.
Refactoring an application to remove one library and replace it with one that is more secure may be difficult. Assessing the real risk of a vulnerability takes more than static analysis. Some security issues detected as high severity may not be relevant because they involve functions that are never called, or are prevented by other security measures in place.
“Modern software security is about remediating real risk which requires contextualizing more,” say the report authors, though this is a non-trivial task." [...]
Via | @OSPopenSourcePlanet | | 0 |
| 19 | הכלים הטובים ביותר לניהול ענן בקוד פתוח
מאת | ד"ר מאג'ש קסטורי - ד"ר אנאנד נ'יייר |
"הנה סקירה כללית של כלי הקוד הפתוח המובילים שארגונים יכולים לבחור מהם לניהול תשתית הענן שלהם.
כלי קוד פתוח הפכו לבחירה פופולרית לניהול סביבות ענן בשל האופי האגנוסטי של הענן, התאמה אישית, עלות-תועלת ותמיכה בקהילה.
הנה כמה מכלי הקוד הפתוח המובילים שיכולים לעזור לארגונים לנהל את תשתית הענן שלהם בקלות וביעילות." [...]
[...] "לסיכום, ניהול סביבות ענן ביעילות דורש את סט הכלים הנכון. כלי קוד פתוח כמו Kubernetes , Terraform , Ansible , Prometheus , OpenStack , Jenkins , Grafana , ו- Apache CloudStack מציעים תכונות עוצמתיות וגמישות כדי לעזור לארגונים לנהל את תשתית הענן שלהם בצורה יעילה.
על ידי מינוף הכלים הללו, ארגונים יכולים להפוך תהליכים לאוטומטיים, לנטר ביצועים ולהרחיב את הסביבות שלהם בקלות, להניע חדשנות וצמיחה."
דרך | @OSPopenSourcePlanet | | 0 |
| 20 | The Best Open Source Cloud Management Tools
By | Dr. Magesh Kasthuri - Dr Anand Nayyar |
"Here’s an overview of the top open source tools organisations can choose from to manage their cloud infrastructure.
Open source tools have become a popular choice for managing cloud environments due to their cloud-agnostic nature, customisation, cost-effectiveness, and community support.
Here are some of the top open source tools that can help organisations manage their cloud infrastructure with ease and efficiency." [...]
[...] "In conclusion, managing cloud environments efficiently requires the right set of tools. Open source tools like Kubernetes, Terraform, Ansible, Prometheus, OpenStack, Jenkins, Grafana, and Apache CloudStack offer powerful features and flexibility to help organisations manage their cloud infrastructure effectively.
By leveraging these tools, organisations can automate processes, monitor performance, and scale their environments with ease, driving innovation and growth."
Via | @OSPopenSourcePlanet | | 0 |
