
Technology News — 2026 Week 8
The biggest story this week was the personal and commercial trajectory of OpenClaw creator Peter Steinberger — the featured profile traced his arc from selling… Compiled for immediate developer deployment.


Securing the AI software supply chain: Security results across 67 open source projects
CPython, Node.js, LLVM, Rustls), network libraries (curl, urllib3, Netty, quic-go), build and CI tooling (Jenkins, webpack, PyPI Warehouse, Apache Airflow), and identity/secrets frameworks (Keycloak, external-secrets, WebAuthn). Session 4 opens for applications in April 2026. Funding partners include Microsoft, Stripe, Shopify, Vercel, Datadog, and 1Password.
Enterprise-wide credential management tools for incident response - GitHub Changelog
"Manage enterprise credentials" — lets owners delegate these powers to trusted administrators. GitHub warns these actions can break automations and disrupt developer workflows, and recommends using them only during major security incidents; for routine token rotation, setting maximum token lifetimes is advised instead.
Open sourcing the Liveblocks sync engine and dev server | Liveblocks blog

Google's Gemini 3.1 Pro is mostly great

Beyond the vibe code: The steep mountain MCP must climb to reach production

We need to talk about Sonnet 4.6
Claude.ai OAuth tokens (from free, Pro, or Max subscriptions) in any third-party product or tool, including the Agent SDK, directly contradicting earlier statements by developer advocate Tarek that the Agent SDK with subscription tokens was explicitly allowed. Theo details how OpenClaw was hard-coded into Anthropic's server as a blocked term, contrasts this with OpenAI's openly collaborative stance (sharing Codex app-server auth for third-party builds), and argues Anthropic's reluctance to engage publicly — refusing to clarify whether open-source, non-commercial UIs can use subscriber tokens — reflects a deeper organizational culture problem.
Who is OpenClaw creator Peter Steinberger? The millennial developer caught the attention of Sam Altman and Mark Zuckerberg | Fortune
We need to talk about Sonnet 4.6
Claude.ai OAuth tokens (from free, Pro, or Max subscriptions) in any third-party product or tool, including the Agent SDK, directly contradicting earlier statements by developer advocate Tarek that the Agent SDK with subscription tokens was explicitly allowed. Theo details how OpenClaw was hard-coded into Anthropic's server as a blocked term, contrasts this with OpenAI's openly collaborative stance (sharing Codex app-server auth for third-party builds), and argues Anthropic's reluctance to engage publicly — refusing to clarify whether open-source, non-commercial UIs can use subscriber tokens — reflects a deeper organizational culture problem.Securing the AI software supply chain: Security results across 67 open source projects
CPython, Node.js, LLVM, Rustls), network libraries (curl, urllib3, Netty, quic-go), build and CI tooling (Jenkins, webpack, PyPI Warehouse, Apache Airflow), and identity/secrets frameworks (Keycloak, external-secrets, WebAuthn). Session 4 opens for applications in April 2026. Funding partners include Microsoft, Stripe, Shopify, Vercel, Datadog, and 1Password.Enterprise-wide credential management tools for incident response - GitHub Changelog
"Manage enterprise credentials" — lets owners delegate these powers to trusted administrators. GitHub warns these actions can break automations and disrupt developer workflows, and recommends using them only during major security incidents; for routine token rotation, setting maximum token lifetimes is advised instead.Open sourcing the Liveblocks sync engine and dev server | Liveblocks blog
Google's Gemini 3.1 Pro is mostly great
Beyond the vibe code: The steep mountain MCP must climb to reach production
The biggest story this week was the personal and commercial trajectory of OpenClaw creator Peter Steinberger — the featured profile traced his arc from selling PSPDFKit for 100 million euros, through burnout, to returning to code and watching a local-first autonomous agent framework accumulate 145,000 GitHub stars and 2 million weekly visitors in months. His decision to join OpenAI over a Zuckerberg offer, while pledging to move OpenClaw to an independent foundation, illustrated the tensions between open-source ideals and frontier infrastructure access that recurred across the week.
That tension was sharpest in Theo's lengthy critique of Anthropic's policy shift, which prohibited using Claude.ai OAuth tokens in any third-party tool — directly contradicting earlier statements — and included hard-coding OpenClaw as a blocked term server-side. Against that backdrop, the Gemini 3.1 Pro launch offered a counterpoint: strong benchmark improvements (77.1% on ARC-AGI-2 versus the prior generation's 31.1%) at $2/$12 per million tokens, though it trails Sonnet 4.6 sharply on real-world task benchmarks like GDPval-AA. MCP's field report from London's MCPconference was sobering: the protocol remains largely behind-firewall, with OAuth 2.1 complexity and security elicitation still unsolved for production paths.
On the security side, GitHub closed out its Secure Open Source Fund Session 3 — $670,000 to 67 projects, 191 new CVEs — while also shipping enterprise-wide credential revocation tools designed for rapid incident response. Both moves reinforce a week in which open-source supply-chain health and AI policy boundaries were the clearest fault lines.
- OpenClaw hit 145,000 GitHub stars and 2M weekly visitors months after launch; its creator joining OpenAI signals how frontier infrastructure access shapes open-source strategy
- Anthropic's OAuth token policy reversal and Gemini 3.1 Pro's ARC-AGI-2 leap (31% to 77%) are reshaping AI developer market dynamics simultaneously
- GitHub's Secure Open Source Fund Session 3 deployed $670K across 67 projects issuing 191 CVEs — Session 4 opens for applications in April 2026