惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Docker
N
Netflix TechBlog - Medium
罗磊的独立博客
F
Full Disclosure
I
InfoQ
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The Register - Security
The Register - Security
The GitHub Blog
The GitHub Blog
U
Unit 42
Microsoft Security Blog
Microsoft Security Blog
Webroot Blog
Webroot Blog
Apple Machine Learning Research
Apple Machine Learning Research
T
Threatpost
博客园 - 【当耐特】
C
Cybersecurity and Infrastructure Security Agency CISA
P
Privacy International News Feed
Simon Willison's Weblog
Simon Willison's Weblog
T
Threat Research - Cisco Blogs
Y
Y Combinator Blog
P
Proofpoint News Feed
B
Blog RSS Feed
G
GRAHAM CLULEY
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cisco Talos Blog
Cisco Talos Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Palo Alto Networks Blog
博客园 - 三生石上(FineUI控件)
Recent Announcements
Recent Announcements
P
Privacy & Cybersecurity Law Blog
Know Your Adversary
Know Your Adversary
I
Intezer
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
L
LangChain Blog
B
Blog
雷峰网
雷峰网
K
Kaspersky official blog
S
Secure Thoughts
Security Latest
Security Latest
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
Security @ Cisco Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org

Show HN

GitHub - villagesql/villagesql-skills: Agent skills for VillageSQL - gemini-cli-extension; claude-code-plugin GitHub - flightdeckhq/flightdeck: Observability and control plane for AI agents. CSP Radar GitHub - Light-Heart-Labs/DreamServer: Turn your PC, Mac, or Linux box into an AI server. LLM inference, chat UI, voice, agents, workflows, RAG, and image generation. GitHub - Diplomat-ai/diplomat-agent-ts: What can your TypeScript AI agent do to the real world? Scan your code. See which tool calls have zero checks Code Block Selector - Visual Studio Marketplace Prometheus dependency graph — interactive showcase | Riftmap Show HN: I made a vi-like modal keyboard plugin for Figma GitHub - run-llama/liteparse: A fast, helpful, and open-source document parser GitHub - dalemyers/Roar: A macOS CLI tool for notifications GitHub - district-solutions/open-agent-tools-coder: Enables small-to-large self-hosted ai models to use local source code when running tool-calling agentic workloads. We actively data mine 20,900+ (2+ TB) popular github repos using large and small ai models to create reuseable: json, markdown and parquet files for local-first tool-calling models. GitHub - progapandist/stripeek: A local TUI proxy for real-time Stripe API debugging, built for navigating complex payloads fast. GitHub - sir1st/hermes-desktop: All-in-one cross-platform desktop app for Hermes Agent — bundles Python + hermes-agent + hermes-web-ui GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: Generate Claude Code Workflows using Spec Driven Development approach GitHub - nixys/nxs-universal-chart: The Helm chart you can use to install any of your applications into Kubernetes/OpenShift Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap GitHub - noopolis/moltnet: Self-hostable chat network for AI agents. Pre-built bridges for Claude Code, Codex, and the Claws. Rooms, DMs, history. No Slack bots, no Matrix, no glue code. GitHub - tamerh/enju: Coordinating Humans, AI Agents, and Compute as Peers on a Shared Workflow Graph Show HN: Continuity-auth – Respect-weighted rate limits for the open web GitHub - luml-ai/luml: AI lifecycle platform where engineers and agents track experiments, train models, and ship to production. GitHub - mrdanielcasper/CoreTex: A UNIX-inspired, biomimetic, flat-file AI harness and knowledge engine. GitHub - clemg/pierre-github: Pierre's diffs.com and trees.software for Github GitHub - lyriks-io/unspaghettit: Behavior-driven AI development without prompt spaghetti. GitHub - sofumel/claude-handoff-revive: Resume Claude Code work after rate/usage/context limits without replaying the prior transcript. Auto-saves at 90%/95% usage. Plugin-installable, 10 languages. GitHub - dotexorg/saferpc: Typed, end-to-end encrypted RPC over any bidirectional channel. GitHub - BeeZeeAgent/beezee: Agent harness orchestration Legato Next.js Boilerplate for Internal Tools · CoreUI GitHub - clark-labs-inc/clark-hash: Clark Hash, 32x smaller searchable sketches for embeddings GitHub - ZeroPointRepo/youtube-mcp: The fastest YouTube transcript + YouTube search MCP for AI agents. Try for free. Typing Mastery — climb toward 100+ WPM, deliberately GitHub - Andebugulin/Awareen GitHub - fayzan123/claude-workflow-composer: Visual desktop app for composing multi-agent coding workflows. Drag agents, attach skills and MCPs, wire handoffs, export to .claude/ GitHub - harshaneel/humanize: Best static AI text humanizer. Two research-grounded skills that work in any LLM (Claude, ChatGPT, Gemini, Codex): humanize beats perplexity-based detectors, ai-check produces forensic scoring with evidence-quoted flags. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature. GitHub - StackOneHQ/stack-nudge GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. We hardened an LLM agent. Each defense we added made it more exploitable. GitHub - alkait/WhatsKept: Agent-queryable WhatsApp history from an iOS backup — a single Go binary. GitHub - octelium/cordium: Open-source, general-purpose sandbox platform for devs and AI agents that provides identity-based secure access to infrastructure without credentials. WAR.GOV/UFO Microfilm5 GitHub - scosman/videowright: Build animated explainer videos with your coding agent GitHub - dipankar/dscode: The code editor you can take apart. GitHub - zoharbabin/web-researcher-mcp: MCP server (Go) for AI assistants: web search, content extraction, academic/patent/news research. Multi-provider routing, 4-tier scraping, search lenses. Works with Claude, Cursor, and any MCP client. GitHub - ruvnet/RuView: π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video. GitHub - scanaislop/aislop: Catch the slop AI coding agents leave in your code: narrative comments, swallowed exceptions, as-any casts, dead code, oversized functions. 50+ rules across 7 languages (TypeScript, JavaScript, Python, Go, Rust, Ruby, PHP). Sub-second, deterministic, no LLM at runtime. MIT-licensed. GitHub - kouhxp/cheap-im: CPU-only voice agent approximating Thinking Machines' Interaction Models demo GitHub - unprovable/OrchidMantis: Orchid Mantis — standalone framework for Zero-Knowledge Proofs of eXploit (ZKPoX). GitHub - MarcellM01/TinySearch: Shrink the web for your local LLMs! GitHub - TangibleResearch/Halgorithem: A Algo designed to detect AI Hallucitions GitHub - DO-SAY-GO/freelang: I love freelang GitHub - CarpseDeam/Aura-IDE: An AI coding harness that shaped itself - Planner/Worker agents, repo awareness, surgical edits, validation, recovery, and safe diff approvals. GitHub - chojs23/concord: A feature-rich TUI client for Discord GitHub - tommyjepsen/awesome-ux-skills: UX & AI Product designs skills you can use today in Claude Code GitHub - aerf-spec/aerf: Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions. GitHub - kklimuk/docx-cli: CLI for AI agents (Claude, Codex) to read, edit, and comment on .docx files with full format fidelity. GitHub - Jwrede/tokentoll: Catch LLM cost changes in code review. Infracost for LLM spend. GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - Higangssh/homebutler: 🏠 Manage your homelab from chat. Single binary, zero dependencies. GitHub - olalie/tapmap: See where your computer connects and what stands out on a live world map. GitHub - matisiekpl/neond: DX-focused control plane for Postgres dedicated to non-critical workloads. Your postgres:latest replacement 🐘 GitHub - Diplomat-ai/diplomat-agent: What can your AI agent do to the real world? Scan your code. See which tool calls have zero checks GitHub - Bajusz15/beacon: Open-source agent for secure remote access, monitoring, and deploys across home-lab and self-hosted machines like Raspberry Pi, N100, or any Linux server. Open web based TTY or tunnel Home Assistant and other local services securely without opening ports. BigTech AI News - Chrome 应用商店 GitHub - vinhnx/VTCode: VT Code is an open-source coding agent with LLM-native code understanding and robust shell safety. Supports multiple LLM providers with automatic failover and efficient context management. GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - Lumen-Labs/brainapi2: BrainAPI is a knowledge graph–powered AI memory layer that transforms unstructured data into structured knowledge, enabling intelligent search, recommendations, and contextual memory for AI agents and applications. GitHub - familiar-software/familiar: Let AI watch you work. Familiar lets your AI update its memory, skills, and knowledge by watching your screen. GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. make sidebar/address bar rounded corner toggleable
GitHub - zhangshuo1991/openterm: An offline-first, locally-encrypted SSH desktop workbench written in pure Rust. No account. No cloud. Just terminals.
zhangshuo199 · 2026-06-23 · via Show HN

An offline-first, locally-encrypted SSH desktop workbench written in pure Rust. No account. No cloud. Just terminals.

Rust License Crates


OpenTerm Terminal Workspace

Why OpenTerm

OpenTerm is an open-source alternative to commercial SSH clients like Termius. It gives you a full-featured terminal workspace without requiring a login, uploading your secrets to the cloud, or running a Chromium shell.

  • Offline-first — everything runs locally, no network dependency to start
  • No account — no sign-up, no telemetry, no SaaS lock-in
  • Encrypted vault — passwords and private keys encrypted at rest with Argon2id + ChaCha20Poly1305
  • Auditable — pure Rust, small dependency tree, zero hidden binaries

Features

Terminal

Terminal with Tabs

  • Full PTY shell via russh
  • Horizontal session tabs for multiple simultaneous connections
  • Scrollback, search, copy/paste, bracket paste
  • Font-size-aware PTY sizing with automatic resize on window change
  • CJK / IME input support
  • Dark and light themes

Host Management

  • Host sidebar with search by name, address, username, or initials
  • Host groups for organizing servers
  • Fingerprint verification with confirm-new-known_hosts flow

Authentication

  • Password authentication
  • Private key authentication (OpenSSH format)
  • SSH agent integration
  • Default key fallback

File Transfer

  • Dual-pane SFTP workspace (local + remote)

SFTP Dual-pane Workspace

  • Upload, download, mkdir, rename, and delete workflows
  • Local and remote directory browsing

Port Forwarding

  • Local port forwarding (-L)
  • Remote port forwarding (-R)
  • Dynamic SOCKS5 forwarding (-D)

Jump Hosts

  • Bastion / jump host routing
  • Chained SSH connections through intermediate servers

Vault & Security

  • Encrypted local vault for secrets (Argon2id + ChaCha20Poly1305)
  • Passwords never stored in plaintext on disk
  • Auto-lock vault on inactivity
  • Zero telemetry, zero analytics

Import & Export

  • Import hosts from ~/.ssh/config
  • Export host profiles as TOML
  • Export host profiles as JSON

Keyboard-Driven

  • Command Palette (Ctrl/Cmd + K) for all actions
  • Terminal copy (Ctrl/Cmd + Shift + C)
  • Terminal paste (Ctrl/Cmd + Shift + V)
  • Terminal clear (Ctrl/Cmd + Shift + L)
  • Right-click context menu with search, copy, paste, and clear

Settings and Themes

Installation

From Source

git clone git@github.com:zhangshuo1991/openterm.git
cd openterm
cargo build --release -p openterm-app
./target/release/openterm-app

Requirements: Rust 1.82+, macOS (Linux and Windows planned)

Pre-built Binaries

Download the latest DMG from the Releases page.

Quick Start

# Launch the GUI
cargo run -p openterm-app

# Use the CLI
cargo run -p openterm-cli -- list-hosts
cargo run -p openterm-cli -- add-host myserver 192.168.1.100 --user admin
cargo run -p openterm-cli -- exec myserver "hostname" --user admin --password-stdin

Use New in the Hosts sidebar to add a server, fill in the connection details, then click Connect from the session bar above the terminal. Select SFTP in the tab bar to open the dual-pane file transfer workspace for the current host.

Hit Ctrl/Cmd + K to open the command palette and access forwarding, diagnostics, settings, and host actions without clutter.

Architecture

┌─────────────────────────────────────────────────┐
│  openterm-app                 (iced Desktop GUI) │
│  ┌──────────┐ ┌──────────┐ ┌──────────────────┐ │
│  │ Sidebar  │ │   Tabs   │ │ Terminal (PTY)   │ │
│  │ (Hosts)  │ │(Sessions)│ │ alacritty_terminal│ │
│  └──────────┘ └──────────┘ └──────────────────┘ │
│  ┌──────────┐ ┌──────────┐ ┌──────────────────┐ │
│  │  SFTP    │ │ Command  │ │    Settings      │ │
│  │(dual-pane)│ │ Palette  │ │                  │ │
│  └──────────┘ └──────────┘ └──────────────────┘ │
├─────────────────────────────────────────────────┤
│  openterm-ui           (UI state management)     │
├─────────────────────────────────────────────────┤
│  ┌─────────────────┐ ┌─────────────────────────┐│
│  │ openterm-ssh    │ │ openterm-terminal       ││
│  │ russh client    │ │ alacritty_terminal grid ││
│  │ PTY, SFTP, fwd  │ │ scrollback, selection   ││
│  └─────────────────┘ └─────────────────────────┘│
│  ┌─────────────────┐ ┌─────────────────────────┐│
│  │openterm-storage │ │ openterm-crypto         ││
│  │ redb database   │ │ argon2 + chacha20poly   ││
│  │ schema, migrate │ │ zeroize, vault          ││
│  └─────────────────┘ └─────────────────────────┘│
│  ┌─────────────────┐ ┌─────────────────────────┐│
│  │openterm-config  │ │ openterm-core           ││
│  │ SSH config io   │ │ domain models, events   ││
│  │ TOML/JSON export│ │ validation, contracts   ││
│  └─────────────────┘ └─────────────────────────┘│
└─────────────────────────────────────────────────┘
Crate Purpose
openterm-app iced desktop GUI, app shell, layout, subscriptions
openterm-cli Command-line tool for scripting and debugging
openterm-core Domain models, validation, event bus, commands
openterm-crypto Vault encryption (Argon2id + ChaCha20Poly1305 + zeroize)
openterm-storage redb-backed local persistence, schema, migrations
openterm-config OpenSSH ~/.ssh/config import, TOML/JSON export
openterm-ssh SSH transport (russh), PTY, SFTP, tunnels, jump hosts
openterm-terminal Terminal buffer engine (alacritty_terminal)
openterm-ui UI state management and product shell logic

Dependencies flow one way: ui → core ← ssh / storage / crypto / terminal / config. SSH and terminal crates expose interfaces for future adapter swaps; UI depends on domain contracts, not SSH internals.

Development

# Format all code
cargo fmt --all

# Type-check the workspace
cargo check --workspace

# Run all unit and doc tests
cargo test --workspace

# Launch the app
cargo run -p openterm-app

# Build optimized release binary
cargo build --release -p openterm-app

Smoke Tests (Real SSH)

A test SSH server at 82.157.57.178 is used for integration testing. Password must be supplied via environment variable or stdin:

./scripts/test_ui_smoke_real.sh          # GUI launch + screenshot
./scripts/test_ui_real_connect.sh        # Connect via GUI PTY
./scripts/test_ui_real_resize.sh         # PTY resize verification
./scripts/test_ui_real_duplicate_connect.sh  # Duplicate tab connect
./scripts/test_ui_real_sftp.sh           # SFTP remote directory listing
./scripts/test_ui_real_forward.sh        # Local port forward
./scripts/test_ui_settings_persistence.sh # Settings survive restart
./scripts/test_all_real.sh               # Full chain

For storage tests that should not touch the default database:

cargo test --workspace -- --skip real

Use --db /path/to/test.redb for storage tests with an isolated database.

Tech Stack

Component Library
GUI iced — pure Rust, GPU-accelerated
SSH russh — async SSH
Terminal alacritty_terminal — GPU-accelerated emulator
Storage redb — pure Rust embedded DB
Crypto argon2 + chacha20poly1305 + zeroize
Async tokio
CLI clap
File dialog rfd

Security

See SECURITY.md for our security policy.

  • No account or cloud connectivity required
  • Secrets encrypted at rest (Argon2id + ChaCha20Poly1305)
  • Passwords never logged or exposed in plaintext
  • known_hosts key verification
  • Zero telemetry or analytics

To report a vulnerability, please use private disclosure — do not file a public issue.

Roadmap

Current status: P3 — Terminal Polish

Phase Goal
P0 Technical validation — iced + russh + alacritty integration
P1 Minimal offline SSH client — host CRUD, auth, multi-tab, persistence
P2 Vault, import/export, SFTP, port forwarding, jump hosts
P3 Terminal polish — scrollback, search, themes, shortcuts, CJK
P4 Split panes, batch ops, agent integration, dynamic SOCKS
P5 Self-hosted sync, plugin API, session recording
P6 Release — packaging, signing, auto-update, documentation

See ROADMAP.md and product.md for full details.

Contributing

Contributions are welcome! See CONTRIBUTING.md for guidelines.

  • Keep changes aligned with product.md
  • Preserve offline-first behavior
  • Keep SSH, terminal, storage, and UI concerns separated
  • Do not add cloud dependencies to the base client
  • Add tests for storage, crypto, import/export, and connection state changes

License

Licensed under either of MIT License or Apache License 2.0 at your option.


OpenTerm — the SSH client you own.