# Discourse is Not Going Closed Source

**URL:** https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863
**Category:** Blog
**Created:** [April 17, 2026, 3:20am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863 "2026-04-17T03:20:48Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [April 17, 2026, 3:20am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/1 "2026-04-17T03:20:48Z")

</div>

[Cal.com](http://cal.com/?ref=blog.discourse.org)&nbsp;have announced&nbsp;[they’re closing their codebase and will no longer be an open-source product](https://x.com/pumfleet/status/2044406553508274554?s=20&ref=blog.discourse.org). Their reasoning is that AI has made open source too dangerous for SaaS companies. Code gets scanned and exploited by AI at near-zero cost, and transparency is now becoming exposure.

* * *
This is a companion discussion topic for the original entry at [https://blog.discourse.org/2026/04/discourse-is-not-going-closed-source](https://blog.discourse.org/2026/04/discourse-is-not-going-closed-source)

---

<div class="post-metadata">

### Author: ![Lilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lilly/32/575047_2.png) [@Lilly](https://meta.discourse.org/u/Lilly)
#### Post date: [April 17, 2026, 4:04am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/2 "2026-04-17T04:04:27Z")

</div>

thank you sam. i appreciate you addressing this head on like this.  
i have been following the recent related ai news (as best i can keep up) and this question has certainly been in the back of my mind. keep up the great work. :discourse:

---

<div class="post-metadata">

### Author: ![darkpixlz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/darkpixlz/32/549896_2.png) [@darkpixlz](https://meta.discourse.org/u/darkpixlz)
#### Post date: [April 17, 2026, 4:49am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/3 "2026-04-17T04:49:23Z")

</div>

Lots of respect here, this was something I was concerned about in the back of my mind for a while now with Discourse. Thank you guys for being on the right side of this and continuing to not [enshittify](https://en.wikipedia.org/wiki/Enshittification) the core product. I can’t imagine we’ll get AI regulation for a while longer for many reasons but things are very grim right now.

I hope you all know how much everybody appreciates not self-hosting the product and still being begged to cough up money to unlock basic features (like many “open source” products do). :meow_heart:

---

<div class="post-metadata">

### Author: ![elmuerte](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elmuerte/32/456517_2.png) [@elmuerte](https://meta.discourse.org/u/elmuerte)
#### Post date: [April 17, 2026, 5:51am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/4 "2026-04-17T05:51:13Z")

</div>

Suddenly closing your source doesn’t magically fix all existing security issues in your code which have not been identified yet. But it sure will prevent the community from helping to fix it.

Besides that, it is also a dick move to everybody who helped grow your product. Why would I now, or ever do anything with/for [cal.com](http://cal.com) after this action. Why would I do anything for their hobbyist “fork” cal.dyi . They just threw away all the trust they created.

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [April 17, 2026, 9:33am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/5 "2026-04-17T09:33:29Z")

</div>

Thanks for the blog article, it was an interesting reading Sam 🙂

> [@sam](#):
>
> OpenAI and Anthropic are both extremely concerned about the vector, and in response [GPT-5.4-Cyber](https://openai.com/index/scaling-trusted-access-for-cyber-defense/?ref=blog.discourse.org) and [Anthropic Mythos](https://red.anthropic.com/2026/mythos-preview/?ref=blog.discourse.org) are being rolled out cautiously.

This has been all over the internet, but is the security threat (“our models are too dangerous”) the real or main reason for not releasing it?

Some people claim it leans more toward a PR stunt, though not completely erasing the potential strength of the models. One example: [On Anthropic's Mythos Preview and Project Glasswing - Schneier on Security](https://www.schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html)

I certainly don’t know anything about all those complex topics, but I’m cautious when I read articles that spread lightning fast on all news sites and online communities. I assume there are some caveats on what is claimed. That there’s probably some truth and some other information that needs clarification, or is overhyped.

I don’t have any doubt over the fact that models are incredibly fast to find and probably exploit vulnerabilities, and you even highlighted this with the Discourse code example.

* * *

About the article itself, just pointing out something I felt weird reading:

> Closed source has always been a weaker defense for SaaS than people want to admit. A web application is not something you ship once and keep hidden. Large parts of it are delivered straight into the user’s browser on every request: JavaScript, API contracts, client-side flows, validation logic, and feature behavior. Attackers can inspect all of that already, and AI makes that inspection dramatically cheaper. Closing the repository may hide some server-side implementation detail, but it does not make the system invisible. What it mostly does is reduce how many defenders can inspect the full picture.

Then, later:

> Closed source can buy some obscurity, but obscurity is brittle. Code gets leaked, binaries get reverse engineered, APIs get mapped, and attackers learn a lot just by interrogating the running system. The real defense is not keeping the code hidden forever. It is building software and operational practices that hold up when scrutiny arrives.

When I read the 2nd paragraph, I had the feeling I already read that.  
I scrolled up, and I noticed that the two paragraphs are very, very similar. They both state the same things, but using different phrasing.

I understand the need to summarize, but in this case, I really had the feeling I had read basically the same things a few paragraphs earlier.

---

<div class="post-metadata">

### Author: ![chapoi](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/chapoi/32/537252_2.png) [@chapoi](https://meta.discourse.org/u/chapoi)
#### Post date: [April 17, 2026, 9:57am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/6 "2026-04-17T09:57:18Z")

</div>

This was truly an inspiring read, Sam. Makes me proud to work at Discourse.

_[frantically thinking of something to say that will make me sound less like a suck-up…]_

Might even do some work now. 😉

---

<div class="post-metadata">

### Author: ![zhanfeng](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@zhanfeng](https://meta.discourse.org/u/zhanfeng)
#### Post date: [April 17, 2026, 10:24am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/7 "2026-04-17T10:24:19Z")

</div>

Reading this really moved me. The line about choosing courage over hiding behind a locked door is so powerful. Thank you for standing by open source for 13 years, and for reminding us what it’s all about. These words will stick with me.

---

<div class="post-metadata">

### Author: ![manuel](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/manuel/32/468169_2.png) [@manuel](https://meta.discourse.org/u/manuel)
#### Post date: [April 17, 2026, 11:48am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/8 "2026-04-17T11:48:37Z")

</div>

Great statement!

[https://releases.discourse.org](https://releases.discourse.org) also works and looks amazing now @david, @derek and everyone who built it! 😎

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [April 17, 2026, 12:07pm UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/9 "2026-04-17T12:07:34Z")

</div>

Oh that’s tasty! And beautifully clear and very useful, great job!

---

<div class="post-metadata">

### Author: ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)
#### Post date: [April 18, 2026, 6:13am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/10 "2026-04-18T06:13:49Z")

</div>

> **[Cal.com Closes Core Codebase Due to AI Security Risks | Bailey Pumfleet...](https://www.linkedin.com/posts/baileypumfleet_open-source-is-dead-thats-not-a-statement-ugcPost-7450175178396889088-Kxic)**
>
> Open source is dead.
> 
> That’s not a statement we ever thought we’d make.
> 
> Cal.com was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up.
> 
> AI has fundamentally...

---

<div class="post-metadata">

### Author: ![elmuerte](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/elmuerte/32/456517_2.png) [@elmuerte](https://meta.discourse.org/u/elmuerte)
#### Post date: [April 18, 2026, 11:20am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/11 "2026-04-18T11:20:39Z")

</div>

If Open Source is dead, then why are they still using it. Why haven’t they moved from PostgreSQL to Oracle DB. Why haven’t team moved from Linux to MS Windows. etc.

Their whole application, middleware, even large parts of the infrastructure is build on Open Source.

---

<div class="post-metadata">

### Author: ![fuse](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fuse/32/221005_2.png) [@fuse](https://meta.discourse.org/u/fuse)
#### Post date: [April 18, 2026, 12:09pm UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/12 "2026-04-18T12:09:08Z")

</div>

This is a great announcement and topic.

I understand the risk of AI accelerating zero day exploits.

Not in any way underestimating the effort, I wonder if discourse would consider some sort of relative real time CI/CD pipelines for updates?

Maybe this already happens at meta and discourse managed sites, I’m specifically thinking about self hosted where a feature flag could enable updates as released, or on a delay as an automated process.

Or maybe it manifests as an automated security update feature that can be enabled independent of other updates.

Regardless, let me continue to offer my thanks and appreciation for the discourse software and the people behind it. Thank you!

---

<div class="post-metadata">

### Author: ![darkpixlz](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/darkpixlz/32/549896_2.png) [@darkpixlz](https://meta.discourse.org/u/darkpixlz)
#### Post date: [April 18, 2026, 4:47pm UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/13 "2026-04-18T16:47:36Z")

</div>

There are good reasons why this isn’t a good idea here:

> [@Auto updates via cronjob - is this safe?](https://meta.discourse.org/t/auto-updates-via-cronjob-is-this-safe/241232):
>
> I’m thinking of auto-updating Discourse via cronjob. For example every two weeks in the night a cronjob with the following: cd /var/discourse ./launcher rebuild app Do you think this is safe to do? Or should I do this manually?

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [April 18, 2026, 9:52pm UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/14 "2026-04-18T21:52:18Z")

</div>

> [@elmuerte](#):
>
> Their whole application, middleware, even large parts of the infrastructure is build on Open Source.

Exactly! And that means they inherit the vulnerabilities of that middleware, and those are disclosed publicly regardless of what they choose to hide.

This is all a big charade. Every undergrad knows that security by obscurity does not work.

Discourse shows that it is possible to stay open source, to build a sustainable SaaS business AND to keep pace in the vulnerability landscape rather than trying to hide from it.

---

<div class="post-metadata">

### Author: ![ted](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ted/32/283882_2.png) [@ted](https://meta.discourse.org/u/ted)
#### Post date: [April 19, 2026, 5:42am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/15 "2026-04-19T05:42:17Z")

</div>

So happy to see Discourse not only staying open source (which I never doubted), but also deciding to take a stand here. ❤ I don’t mind Cal’s decision, it’s theirs to make, but the whole spin-doctoring is extremely frustrating.

One thing AI code generation and exploit hunting has taught me is we’re still fighting the same bad but popular ideas that executives have held since the dawn of time. In this case the “security by obscurity” argument against open source.

---

<div class="post-metadata">

### Author: ![Mathive\_Smith](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mathive_smith/32/488128_2.png) [@Mathive\_Smith](https://meta.discourse.org/u/Mathive_Smith)
#### Post date: [April 24, 2026, 10:38am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/16 "2026-04-24T10:38:59Z")

</div>

Glad to see Discourse staying open source and taking a clear stance. Transparency usually leads to stronger security, not weaker—especially compared to relying on obscurity.

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [April 24, 2026, 1:16pm UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/17 "2026-04-24T13:16:32Z")

</div>

I don’t know how many LinkedIn comments are from bots but this one makes sense to me:

> Respect the call, but worth naming what it is.  
> Companies don’t execute a move this coordinated (blog, press release, podcast, cal.diy brand) in the 8 days since Mythos dropped. This was planned. AI gave you the permission slip to ship it now rather than in six months.  
> […]  
> Just a business model decision wearing a security jacket.

Not that I care very much about this move from a company I don’t even know anyway 🙂

---

<div class="post-metadata">

### Author: ![eisammy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/eisammy/32/528804_2.png) [@eisammy](https://meta.discourse.org/u/eisammy)
#### Post date: [April 24, 2026, 2:53pm UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/18 "2026-04-24T14:53:16Z")

</div>

I’ve been saying for two years that Discourse is the best CMS of the last decade, and here’s one of the main reasons! Congratulations, folks—you’re amazing.

---

<div class="post-metadata">

### Author: ![Bathinda](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bathinda/32/135888_2.png) [@Bathinda](https://meta.discourse.org/u/Bathinda)
#### Post date: [May 4, 2026, 5:47am UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/19 "2026-05-04T05:47:11Z")

</div>

I am awfully amazed at the level of thinking of all you people!!

Just happen to stumble upon this topic and it compelled me to read the related blog also.

Don’t know where this world train is going!  
But I definitely seem to be sitting not (only) in the very last bogey of this train, but perhaps being dragged by the train on its rails (behind the train that is).

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [June 25, 2026, 4:20pm UTC](https://meta.discourse.org/t/discourse-is-not-going-closed-source/400863/21 "2026-06-25T16:20:05Z")

</div>

Hello from the office hours 👋
