/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code

ZDNET's key takeaways  — Cal is reluctantly moving away from open source for security.  — This move isn't about Mythos, but risks from modern AI tools.

ZDNET Steven Vaughan-Nichols

Context & Ripple Effects

Related coverage has focused on AI’s growing role in software production and repository infrastructure: OpenAI is reportedly exploring a GitHub alternative, while Entire is building tools to manage AI-written code. Cal.com’s decision adds a security-driven constraint to that developer-tool shift.

It also contrasts with earlier coverage of Meta using open source to extend its influence in AI. Here, access to source code is being treated less as a distribution advantage and more as an exposure that must be controlled.

First-order effects

  • Cal.com will restrict access to its core codebase, reducing the ability of outside developers to inspect, contribute to, or reuse that portion of the software.
  • The company is prioritizing protection from AI-enabled attacks over the collaboration and transparency associated with its prior open-source posture.

Second-order effects

  • Developers and organizations that depended on the public codebase may need to adjust contribution, integration, or auditing workflows around Cal.com’s software.
  • The move strengthens the case for repository-management and code-governance tools aimed at handling AI-generated code and AI-assisted security risks.

Third-order effects

  • If other open-source vendors reach similar conclusions, AI-assisted vulnerability discovery could push more commercial projects toward selective disclosure, dual licensing, or closed core repositories.
  • That would make trust and access governance a more central competitive variable in developer platforms, even as AI tools make code production and analysis easier to scale.

The trend: AI is changing software development from a primarily productivity-led story into one where code-access policies and security governance become strategic product decisions.

Discussion

  • @simonw Simon Willison on x
    I'm certain this isn't the message they intended to present, but this comes across to me as a company saying “we no longer trust in our own ability to keep your data secure”
  • @mjackson @mjackson on x
    This is wrong. Open source isn't dead just because AI can more easily reverse engineer your codebase. AI can reverse engineer your closed source system just as easily. The solution isn't to hide the source. The solution is transparency, publishing advisories, and hardening.
  • @migueldeicaza Miguel de Icaza on x
    New excuse just dropped. You can use this for the next 4-6 weekend before people realize it was a crass move. Chop chop people!
  • @johnonolan John O'Nolan on x
    Thinking that going closed source is going to save you from the onset of AI is just delusional tbh. Yes, the world is changing. The answer is to change with it and figure out new ways to succeed, rather than make decisions from a place of fear of losing what you have.
  • @xlr8harder @xlr8harder on x
    Imagine being this wrong.
  • @mitsuhiko Armin Ronacher on x
    We have to close source because AI finds out security issues is a pretty weak argument honestly.
  • @steipete Peter Steinberger on x
    If you look at GPT 5.4-Cyber and it's ability for closed source reverse engineering, I have bad news for you. I do very much feel the pain though, there's hundreds of teams that try to poke holes into @openclaw. Our response has been of rapid iteration and code hardening. Which
  • @pumfleet Bailey Pumfleet on x
    Open source is dead. That's not a statement we ever thought we'd make. @calcom was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security [video]
  • @film_girl Christina Warren on x
    this is what happens when you only use open source as a marketing invective anyway. because the concerns you have about code security don't disappear just because you close the source.