Report by The Next New Thing.
Scroll for the report ↓
One login that works across every app your company uses — but the login system runs on a machine you control, instead of a service you pay for by the user.
View on GitHub →If you run a small company or a home lab, this is SSO — one login that works across all your apps — without paying Okta or Auth0 every month per person. The login data stays on your server.
Pitched explicitly as a way to “securely replace existing IdPs such as Okta, Auth0, Entra ID, and Ping Identity.”
Docker Compose, Kubernetes Helm, AWS CloudFormation, or a DigitalOcean 1-click install.
The core is MIT-licensed and free; enterprise features sit under a separate EE license.
An engineer wired authentik into Vault, Grafana, Nextcloud and kubectl and documented the traps — including an empty-groups-claim that silently breaks access. His line for it: “the plugs fit, but the pins are wired differently in every single socket.”
Read the write-up →Point it at the system running your company’s apps and it lists everything set up insecurely, scored against the standards auditors actually cite — then repairs a lot of it for you.
View on GitHub →One command hands back a plain report of what’s insecure, graded against the standards an auditor would use. And because it exposes an MCP server, you can point an AI assistant at it and ask, in English, what’s wrong.
The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.
This projects contains pre-made policies for Kubernetes Validating Admission Policies. This policy library is based on Kubescape controls, see here a comlete list https://hub.armosec.io/docs/controls
A Lens extension for viewing Kubescape security information
kubescape fix auto-repairs misconfigurations; kubescape patch rebuilds vulnerable images.
Ships an MCP server — the plug that lets an AI assistant call a tool — so you can just ask what’s wrong.
Created by the security firm ARMO, now a CNCF incubating project under Apache 2.0.
The only large HN thread this project has ever had, and it’s a pile-on: a security scanner asking you to pipe a script from the internet straight into your shell. Also the best head-to-head against kube-bench and OpenSCAP. It’s from 2021 — backstory, not news.
Read the thread →A free kit of ready-made website parts — buttons, menus, forms, dialogs, tables — that developers drop in instead of designing and coding each one from scratch.
View on GitHub →If your team is building a web app, this is why it can look finished before you hire a designer — the parts are already built, free, and tested by millions. It’s also a working example of open source that pays its bills with sponsors and a template store.
Unstyled UI components for building accessible web apps and design systems. From the creators of Radix, Floating UI, and Material UI.
MUI X: Build complex and data-rich applications using a growing list of advanced React components, like the Data Grid, Date and Time Pickers, Charts, and more!
Date & Time pickers for Material UI (support from v1 to v4)
The README claims more than a decade of development by thousands of open-source contributors.
MIT-licensed and free; MUI also sells finished templates and themes in the MUI Store.
Diamond sponsors pledge $1,500/month, Gold sponsors $500/month — the amounts are printed in the README.
MUI X Pro and Premium moved to application-based licensing effective April 8, 2026, and priority support became Enterprise-only. The core stays MIT and free — this is the tension of running an open-source project as a business, published in the open.
Read the pricing post →Imagine giving your AI helper a big key ring. One connection lets it use thousands of apps, such as Gmail and Notion, to do everyday chores for you.
Try Zapier MCP →Exposes 8,000+ tools as MCP resources any agent can call.
Claude Code, OpenCode, Cursor — anything that speaks MCP.
Enable the tools you want in Zapier, grab the MCP endpoint, paste it into your agent.
Zapier handles auth, rate limits, and reliability for you.
A big hand-curated directory of Mac software, sorted by category, with a little icon on each entry telling you whether it’s free, open source, or a paid App Store app.
View on GitHub →Next time you need a screen recorder, a note app, or a password manager, this is where you check for a free or open-source option first. Subscribe to the RSS feed and new Mac apps come to you.
Linux命令大全搜索工具,内容包含Linux命令手册、详解、学习、搜集。https://git.io/linux
面向开发者的技术速查清单(Cheat Sheets)集合,整理常见技术、工具与开发流程,帮助快速查阅关键信息,提高开发效率。
➷ A robust Javascript library for capturing keyboard input. It has no dependencies.
1,200+ linked entries across 25 top-level categories, from AI Tools to VPN clients.
Stuffed with brand-new Claude Code and AI-agent utilities — the reason an old list is trending again.
The README opens with paid sponsor placements and ~30 of the maintainer’s own Mac apps.
There is no English commentary on this repo anywhere — no qualifying tweet, no video, no article. So here is the proof it’s alive instead: a dated feed of exactly what gets added, current through August 10, 2026. Not a dead trophy.
See what was added this week →A plain-English explanation of how sites like Twitter or Pastebin are built to handle millions of people, written as a free book you read in your browser.
View on GitHub →If you’ve ever nodded along while an engineer said something “doesn’t scale,” this is the plain-English version of what they meant. If you hire engineers, it’s also exactly what your candidates are studying the night before.
120+ interactive Python coding interview challenges (algorithms and data structures). Includes Anki flashcards.
Data science Python notebooks: Deep learning (TensorFlow, Theano, Caffe, Keras), scikit-learn, Kaggle, big data (Spark, Hadoop MapReduce, HDFS), matplotlib, pandas, NumPy, SciPy, Python essentials, AWS, and various command lines.
A curated list of awesome Amazon Web Services (AWS) libraries, open source repos, guides, blogs, and other resources. Featuring the Fiery Meter of AWSome.
Full solutions for designing Pastebin, a Twitter timeline, a web crawler, and Mint.com.
Free Anki decks use spaced repetition so the concepts actually stick.
Complete Japanese and Chinese editions, with open translation threads for 16 more languages.
The skeptic panel on a repo with a third of a million stars: “the vast majority of ‘systems’ are small-scale” — and a blunter one, “I fundamentally distrust these sort of guides.” Worth hearing next to the star count.
Read the pushback →Free software that locks a drive so nobody can read it without your password. This spring it nearly died, because the one company that signs Windows software switched it off.
View on GitHub →You can put an encrypted container on a laptop or thumb drive so a bag left in a cab stops being a client-data problem — free, on Windows, Mac and Linux. It’s also a lesson in dependency: one vendor’s signature nearly ended a tool millions rely on.
VeraCrypt EFI Bootloader for EFI Windows system encryption (LGPL)
Command line tool to get technical information about VeraCrypt mounted volumes and system encryption
Conceal a disk partition from Windows
In March, Microsoft terminated the developer’s account — no email, no warning, no human to appeal to.
Once Microsoft revoked the old certificate in July, machines using full-disk encryption risked not starting at all.
June’s 1.26.29 adds bootloaders signed under Microsoft’s new UEFI CA 2023 — the crisis resolved in one line.
501 comments, and in the top one Jason Donenfeld says Microsoft did the same to him — “what if there were some critical RCE in WireGuard… Microsoft would have my hands entirely tied.” One company’s signature is a single point of failure for security software everyone depends on.
Read the thread →A command-line tool that takes a single username or email address and checks more than 600 websites to show you where that name has an account.
View on GitHub →Run it on your own handle and you get a map of every public site where that name is registered — a fast way to audit your own footprint, or find someone squatting your name. It reads only public information, and its README says permission first.
A single command checks a username or email across 600+ platforms and prints where it’s found.
Every run re-downloads its site list from the community-run WhatsMyName project.
No commits since July 2025. Its creator is now CTO of Sherlockeye, a commercial OSINT product.
Ten months after his last commit, Lucas Antoniaci wrote about Blackbird — on the blog of Sherlockeye, a commercial OSINT product, bylined as its CTO. The post presents Blackbird as active and never mentions the gap. Bellingcat, cataloguing the tool, records the last commit as 2025-07-13.
Read his post →A constantly refreshed public list of next summer’s tech internships. The README itself is the product — there’s barely any code in here.
View on GitHub →If you have a college-age kid or you mentor students, this one page replaces checking dozens of career pages — and swelist.com will email them the moment a role opens. It’s also a clean example of a repo used as a live public database rather than as code.
A collection of full time roles in SWE, Quant, and PM for new grads.
Collection of 2024 tech job opportunities for new grads!
Add hot reloading to your webpack WebExtension! 🔥
SWE 121, Data Science/AI/ML 116, Quant 76, Product 32, Hardware 12.
The README says daily. The commit log shows automated commits every ~30 minutes, around the clock.
A community member’s site, SWEList, emails students the moment a new role lands.
Software you install on your own server that turns an ordinary WhatsApp account into something your other programs — and AI agents — can send and read messages through.
View on GitHub →If you run a business on WhatsApp, this wires it into your own tools — auto-replies, a shared support inbox, or an AI assistant that reads and answers for you. It’s free and self-hosted, but unofficial, so it’s your account at risk.
/mcp lets an AI agent send and read messages — five tools cover sending, editing, chats, groups and login.
Multi-account support runs multiple WhatsApp numbers at once, each with its own webhook.
The README states plainly: “This project is unofficial and not affiliated with WhatsApp.”
It drives the ordinary web client, not Meta’s approved API. From the thread: “I’m uncertain if it’s worth the risk of losing the account” and “if you have a real business it does not worth the risk.” The README says the same thing in its own words — unofficial, not affiliated with WhatsApp.
Read the thread →A Trello-style task board you run on your own server. Last week’s update moved single sign-on out of the free version and into the paid one, and users were not happy.
View on GitHub →If your team pays per seat for Trello or Jira, you can run this yourself for the price of a small server. But check the sign-on change first: if your team logs in through Google or Okta, the newest free version dropped that support.
v2.2.0 on Aug 9 removed single sign-on from the free Community edition, moving it to paid Pro.
The maintainers’ own announcement issue drew 51 comments and 86 negative reactions, none positive.
Three days later the thread was locked. A maintainer’s parting line: “Please stop calling us a open source project.”
51 comments, 86 👎 and not a single 👍. The contributor who wrote the original sign-on code said the community built it. A school district said it would have to leave. Three days in, the team closed and locked the thread — parting line: “Please stop calling us a open source project.” Within days a rival, Kaneo, shipped a tool to migrate your boards out.
Read all 51 comments →A stock-picking tool that runs a pick past 21 legendary investors — Warren Buffett, Michael Burry, Peter Lynch and 18 more — then shows you exactly where they agree and where they don’t.
View on GitHub →Vik Dhir wanted an AI that could analyze a stock through the perspectives of investors he trusted. He built the whole thing inside Claude Code — no backend, no database, no API keys, no signups. Just plain text files and reasoning across 21 points of view.
Building something? Send it in and it runs on a future show.
A self-hosted AI agent that triages production errors on its own — reading git history, logs, traces and source code — then opens a pull request with a proposed fix for a human to review.
View on GitHub →Rutvej was losing the start of every day correlating code changes, server changes, Redis restarts, logs and alerts. So he wired his team’s existing observability tools into a stateless agent that runs on the team’s own LLM keys and does the correlating for him.
Building something? Send it in and it runs on a future show.
New hot repos every week — don't miss the next drop.
It tells YouTube to show this to more builders like you.
Tell me which repo you'll try first — or what to cover next.
New hot repos every week. Subscribe so you never miss the next drop.