Back To All Blog
April 1, 2026 - 9 minutes read
AI coding tools create cheap PRs but not reviewers. Map six dimensions of open-source supply chain risk—and how to manage them before it hits your stack.
April 1, 2026 - 8 minutes read
Contributing to open-source projects is supply-chain risk mitigation, not charity. Learn the fork/fund/migrate framework and how to start at SMB scale.
April 1, 2026 - 7 minutes read
GitHub’s February 2026 maintainer tools, criteria-based PR gating, Mitchell Hashimoto’s Vouch project, and what meaningful OSS contribution looks like at scale.
April 1, 2026 - 11 minutes read
Assess OSS maintainer health as supply-chain risk: zombie components, Contributor Absence Factor, CHAOSS viability framework, and a quarterly review process.
April 1, 2026 - 8 minutes read
The curl bug bounty shutdown, Node.js’s 19,000-line AI PR, Ghostty’s closed doors — documented incidents proving AI slop is breaking open source for real.
April 1, 2026 - 10 minutes read
OSS AI contribution governance: the Prohibitionist, Boundary-and-Accountability, and Quality-First orientations compared via LLVM, EFF, and Ghostty policies.