EN
Back to the archive

The archive · Developer & Business Tools · Operational decision · 2024–2026

Ladybird bets AI-era browsers need closed gates: maintainers-only PRs, HN 900 pts

Ladybird, the from-scratch browser non-profit, stops accepting public pull requests ahead of alpha — AI code eroded trust; HN front page, 900 points

Ladybird Browser Initiative

The betThat a from-scratch browser free of Google's ad-funded engines can ship — and that in the AI era, security means code only maintainers can write.Building

What the business is

Ladybird is a web browser built on an engine written from zero — no Chromium, WebKit, or Gecko — by the Ladybird Browser Initiative, a 501(c)(3) non-profit co-founded by SerenityOS creator Andreas Kling and GitHub co-founder Chris Wanstrath; sponsors include Cloudflare, Shopify, FUTO, and 37signals.

How it started

Andreas Kling built SerenityOS and its browser as a from-scratch hobby OS project; the browser was split into its own repository in 2022 as it outgrew the OS. In June 2024 the Ladybird Browser Initiative was formed as a 501(c)(3) with GitHub co-founder Chris Wanstrath as co-founder and major funder, later joined by sponsors including Cloudflare, Shopify, FUTO, and 37signals.

What happened

As the project prepared its first alpha (targeted for 2026 on Linux and macOS), Kling announced on June 5, 2026 that public pull requests would no longer be accepted: only maintainers can introduce code, all open PRs were closed, and forks, patches, or emailed code would not be treated as a review queue. He argued AI tools changed the economics of open source — a substantial patch no longer implies substantial effort — and cited patient, well-resourced campaigns to earn maintainer trust and abuse it; coverage also documented a single AI agent opening 103 PRs across 95 repos to farm GitHub reputation. Ladybird itself uses AI daily; the change is about accountability for code, not banning AI.

No ending yet — it is still running.

Background

Ladybird is a from-scratch web browser — no Chromium, WebKit, or Gecko underneath — developed by the Ladybird Browser Initiative, a 501(c)(3) non-profit co-founded by SerenityOS creator Andreas Kling and GitHub co-founder Chris Wanstrath, who donated the seed money in 2024. Sponsors include Cloudflare, Shopify, FUTO, and 37signals, and the project grew to 62.3k GitHub stars and over 1,200 contributors in its first two years.

On June 5, 2026, as the first alpha release (Linux and macOS, targeted for 2026) approached, Kling announced that public pull requests would no longer be accepted: only project maintainers can introduce code, all open PRs were closed, and there is no alternative patch channel. The reason was AI: with coding agents, a substantial patch no longer implies substantial effort, so 'effort as a proxy for good faith' no longer works — and a browser that runs untrusted input cannot risk one disguised vulnerability.

The announcement hit the HN front page with 900 points and 570 comments and drew broad press coverage. Ladybird remains open source — the code stays public, and outside participation continues through bug reports, reductions, testing, standards and design discussion, and security reports — but the project explicitly traded 'anyone can contribute code' for 'anyone can propose, only maintainers commit' as it prepares to ship to real users.

What has to be true

  • Every major browser engine is funded by Google's advertising empire; Ladybird's whole bet is that an independent, from-scratch engine can be built and adopted.
  • AI made patch volume cheap, destroying the old trust signal; closing public PRs protects the browser's attack surface before its first real users.
  • The non-profit's paid, sponsor-funded staff made the closure affordable — a governance option most volunteer projects do not have.
  • HN's 900-point, 570-comment thread and coverage of the 103-PR reputation-farming case made this a visible precedent for open source in the AI era.

What can be applied

When AI makes contributions cheap, effort stops proving good faith; security-critical open source may keep code open but shrink who writes it — a tradeoff only funded maintainers can afford.

Aftermath

As of 2026-09-02, Ladybird is still pre-alpha, with the first alpha for Linux and macOS targeted later in 2026. Development is maintainer-only: the source stays public under an open-source license, and outside input flows through bug reports, reductions, testing, standards and design discussion, and security reports. The repo had 65.5k stars and 3,100 forks by Aug 2026, and Kling has been moving the codebase toward Rust. The decision is a precedent — tldraw closed external PRs in January 2026 — and critics note it works because the initiative has paid maintainers and sponsors, not volunteers.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases