Community News
Java primitives and instanceof: Why the rule is changing
For decades, Java has drawn a clear distinction between primitive types and reference types, with each category following its own rules in the language. One of those rules was simple: instanceof applies to reference types, not primitives. That separation has shaped how generations of Java developers reason about type checks and conversions.
ORC Monthly: Momentum After FOSDEM
Following a strong presence at FOSDEM and our second Code & Compliance event, conversations around the Cyber Resilience Act (CRA) continue to mature — shifting from awareness to practical implementation. The sessions and workshops helped advance key ORC deliverables, including the voluntary security attestations project and ongoing work around due diligence.
Hardening the Open VSX Registry: Keeping it reliable at scale
As the Open VSX ecosystem continues to grow, keeping the registry stable is a top priority. Behind the scenes, we are strengthening the infrastructure so that even during peak loads or major provider outages, developer workflows remain uninterrupted.
Eclipse Ankaios 1.0.0 released
The Eclipse Ankaios project community announced the general availability of Eclipse Ankaios 1.0.0, the first major stable release.
Eclipse S-CORE 0.6.0 introduces full dual-language support for C++ and Rust
The Eclipse S-CORE project team has announced the release of Eclipse S-CORE 0.6.0, the third milestone version of its open source automotive middleware platform developed under the Eclipse Software Defined Vehicle (SDV) initiative.
When an SBOM becomes operationally useful: lessons from Eclipse Kura
Supply chain security has become a critical topic in the security world in recent years, and while SBOMs are a foundational piece, they are still infrequently generated and even less frequently used in a way that meaningfully improves software supply chain security.
Why ecosystem-specific trust frameworks don’t scale across data spaces
As long as an organisation participates in a single data space, ecosystem-specific trust frameworks work reasonably well: rules are defined, compliance is checked, and trust decisions stay inside a bounded context. The challenge begins when organisations need to operate across multiple data spaces at the same time, a scenario that is becoming the norm rather than the exception.
ORC’s First Whitepaper on Open Source Software Stewards and the Cyber Resilience Act
The adoption of the EU Cyber Resilience Act (CRA) represents a major shift in how cybersecurity responsibilities are defined across the software ecosystem. For the first time, the regulation explicitly recognises Open Source Software Stewards as a distinct category of legal actors, separate from manufacturers, and subject to a tailored set of obligations.
Scaling the Open VSX Registry responsibly with rate limiting
The Open VSX Registry has become widely used infrastructure for modern developer tools. That growth reflects strong trust from the ecosystem, and it brings a shared responsibility to keep the Registry reliable, predictable, and equitable for everyone who depends on it.
Eclipse Theia 1.68 Releases: News and Noteworthy
Eclipse Theia 1.68 lands with Copilot integration, a significantly improved Architect Plan Mode, Skill Support, Shell Execution,an upgraded Coder Agent Mode (Next), improved UI Testing, and more. Read the highlights (and note it’s the RC for the 2026-02 community release).
Beyond compliance: What the Cyber Resilience Act means for software trust
In his OCX 26 session, “Rebuilding Trust: From open source to open accountability”, John Ellis will draw a clear distinction between meeting regulatory expectations and understanding whether software systems can still be trusted as they evolve.
Enterprise Java Persistence beyond the JPA mindset
Otavio Santana explains why JPA remains relevant, but no longer sits at the centre of every persistence decision and how Jakarta EE 12 reflects the realities of modern, polyglot systems.
Please don’t make your CRA due diligence a DoS attack!
When carrying out the required due diligence for all components in a product, there’s a real risk of unintentionally contributing to a denial-of-service attack on the open source maintainers. Let’s work together to make sure it doesn’t happen. The Open Regulatory Compliance working group is starting to work on a best current practice, and we’d like to tell you more about this important project.
AI Coding: The 5 most common rabbit holes
The 5 most common bad habits in AI coding. Spoiler: it's not about your prompts. It's about what happens after that first generation.
We found one pattern connecting all five. Once you see it, you can't unsee it.
Generating an SBOM is not enough for Java teams
Attend the session "CRA, NIS2, DORA: What senior Java engineers must deliver before 2027" at OCX to gain practical guidance on making your Java systems SBOM-ready ahead of CRA enforcement.
IoT architecture at scale: why device-centric design no longer works
Explore IoT virtualisation and distributed architectures at OC for Research at OCX 2026.
From Code to Compliance at FOSDEM 2026
Over the FOSDEM week, one message became unmistakably clear: attestations and due diligence are no longer optional side topics; they are becoming foundational to the sustainability of open source in a regulated world.
If You Depend on Eclipse Platform Technologies, Now Is the Time to Act
If your products rely on Eclipse Platform technologies, this matters.
🧭 Eclipse Platform (aka RCP) components remain widely deployed, but the model sustaining them is under pressure.
From long term maintenance to EU Cyber Resilience Act compliance, relying on open source platform technologies for free is no longer a responsible option.
👇 Read the full article to understand the risk and the concrete ways to act 👇
The Timpani project: A drumbeat for vehicle workloads
A first glimpse into a new Eclipse SDV project proposal