<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Don't test me</title>
    <description>The latest articles on DEV Community by Don't test me (@do_not_test_me).</description>
    <link>https://dev.to/do_not_test_me</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4083502%2F7a6fe31b-1ea4-448f-a75f-8180bdcde589.jpg</url>
      <title>DEV Community: Don't test me</title>
      <link>https://dev.to/do_not_test_me</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/do_not_test_me"/>
    <language>en</language>
    <item>
      <title>Every free tier dies. AI is killing them in months, not years.</title>
      <dc:creator>Don't test me</dc:creator>
      <pubDate>Mon, 24 Aug 2026 11:29:38 +0000</pubDate>
      <link>https://dev.to/do_not_test_me/every-free-tier-dies-ai-is-killing-them-in-months-not-years-34g2</link>
      <guid>https://dev.to/do_not_test_me/every-free-tier-dies-ai-is-killing-them-in-months-not-years-34g2</guid>
      <description>&lt;p&gt;In April 2024, PlanetScale killed its free tier. Not for new users — for everyone. Five gigabytes of MySQL storage and a billion row reads per month, gone. Production databases had to migrate on a deadline. No grandfathering, no gradual phase-out. The tier that people had built real things on was simply removed.&lt;/p&gt;

&lt;p&gt;PlanetScale wasn't the first and wasn't the last. Heroku killed its free dynos in 2022 after more than a decade, citing "fraud and abuse." SendGrid's "free 100 emails/day forever" became a 60-day trial in 2025. Firebase Cloud Storage moved its free 5GB to the paid plan in February 2026. The pattern is consistent enough that someone started tracking it: a "Free Tier Graveyard," chronological, each entry with a cause of death.&lt;/p&gt;

&lt;p&gt;This is not a new story. Cory Doctorow named it "enshittification" in 2022 — the three-stage process where platforms are good to users, then abuse users to benefit business customers, then abuse business customers to extract value for shareholders. The American Dialect Society made it Word of the Year in 2023. The concept is settled.&lt;/p&gt;

&lt;p&gt;What's worth looking at now is how the AI industry is running this cycle, because it's running it faster, with new lock-in mechanisms that previous platforms didn't have, and with a coordination pattern that means the competitive pressure that used to slow the cycle isn't functioning.&lt;/p&gt;

&lt;h2&gt;
  
  
  The cycle, compressed
&lt;/h2&gt;

&lt;p&gt;Heroku's free tier lasted over a decade. Twitter's free API was available for years before being killed in 2023. Reddit's API was free for over a decade before the pricing change that same year. These were generous windows. You could build something real, run it for years, and have time to plan an exit when the terms changed.&lt;/p&gt;

&lt;p&gt;The AI sector doesn't work like that.&lt;/p&gt;

&lt;p&gt;Mistral launched a free API tier in September 2024 — free experimentation, no credit card, price cuts across all models. By February 2025, five months later, free users had a daily message cap, lost access to the flagship model, and the Le Chat Pro subscription launched at $14.99/month. By November 2024 — before the free tier limits even kicked in — several model endpoints were deprecated in a single batch, including Mistral 7B and Mixtral 8x7B, forcing migrations within four months. By June 2026, OCR pricing doubled and smaller model pricing went up 50-100%.&lt;/p&gt;

&lt;p&gt;The open phase lasted five months. The close phase is still running.&lt;/p&gt;

&lt;p&gt;Suno followed a similar arc on a slightly longer timeline. Unlimited generation and downloading during the growth period, then August 2026: retroactive download caps that apply even to songs created before the announcement. Your library stays on their servers. Getting your content off the platform now costs money.&lt;/p&gt;

&lt;p&gt;Perplexity reset its free tier in May 2026. Free users went from relatively generous access to five Pro searches per day, no file uploads, and no API access. Existing API keys stopped working after a 14-day migration window. The company framed the change as a way to invest in faster reasoning models. But the move came weeks after Google tightened free API access, OpenAI placed ads in ChatGPT's free tier, and Anthropic tightened its peak-hour limits. When one player closes, the others have cover to close too.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three lock-in mechanisms that didn't exist before
&lt;/h2&gt;

&lt;p&gt;Previous platform decay extracted value through pricing and feature removal. Twitter killed third-party clients. Reddit priced its API. Unity tried to charge per install. The mechanisms were: pay more, lose features, or leave.&lt;/p&gt;

&lt;p&gt;AI platforms have three additional mechanisms that create deeper lock-in than anything that came before.&lt;/p&gt;

&lt;h3&gt;
  
  
  Your data is the payment
&lt;/h3&gt;

&lt;p&gt;Google's Gemini API free tier gives you free input and output tokens. In exchange, Google uses your prompts and the generated responses to train its products. Human reviewers may read and annotate your API input and output. The paid tier doesn't do this — but the free tier does, and the terms are explicit: "Do not submit sensitive, confidential, or personal information to the Unpaid Services."&lt;/p&gt;

&lt;p&gt;Meta's Llama API works the same way. The terms state that users of unpaid services "grant Meta a right to use their Inputs and Outputs to train and improve Meta's AI models." GitHub Copilot's free tier, since April 2026, uses interactions from free and Pro users to train models unless they opt out.&lt;/p&gt;

&lt;p&gt;This didn't exist in previous cycles. Twitter didn't train on your API calls. Heroku didn't train on your app's behavior. The free tier of an AI platform isn't free — you pay with your data, and that data becomes their product. The more you use it, the more they get. And unlike pricing changes, you may never know what your data was used for.&lt;/p&gt;

&lt;h3&gt;
  
  
  Your content can be held hostage
&lt;/h3&gt;

&lt;p&gt;Suno's download caps are the clearest example of a lock-in mechanism that previous platforms never had. Your songs live on Suno's servers. You can still play them, share them, remix them — on the platform. But downloading them to your own machine is now capped at 7 lifetime downloads (free), 20 per month (Pro), or 60 per month (Premier). Songs you made before the announcement are subject to the same caps.&lt;/p&gt;

&lt;p&gt;This is structurally different from Twitter cutting API access or Reddit pricing out third-party apps. Your tweets can be screenshotted. Your Reddit posts are public text. But AI-generated content — songs, images, code, documents — often lives on infrastructure you don't control, in formats that aren't easily portable, and the platform controls the export path. Suno's library isn't going anywhere, they say. It just can't leave.&lt;/p&gt;

&lt;p&gt;Midjourney did something similar in February 2026: killed the $10/month Basic tier entirely, consolidating into a $30/month minimum. Existing Basic subscribers were grandfathered for one billing cycle. The minimum cost of entry tripled overnight, and v7 features are gated to the new tier only. If you were a casual user who built a workflow around the $10 tier, your options are pay three times more or lose access.&lt;/p&gt;

&lt;h3&gt;
  
  
  Models die on short timelines
&lt;/h3&gt;

&lt;p&gt;Anthropic retired Claude Haiku 3.5 except on Bedrock and Google Cloud. xAI retired Grok 4.1 Fast, Grok 4, and Grok Code Fast 1 in May 2026 — old model slugs now redirect to Grok 4.3 at standard pricing. Mistral deprecated several endpoints in one batch in November 2024, including Mistral 7B and Mixtral 8x7B. Stability AI deprecated Stable Diffusion 3.0 in April 2025, auto-routing calls to 3.5.&lt;/p&gt;

&lt;p&gt;Code built on one model's behavior may not work the same way on its replacement. Prompt engineering is model-specific. Output formats drift. Token counts change. When a model is retired, the migration cost is borne by the developer, on the vendor's schedule, with a window that's often measured in weeks.&lt;/p&gt;

&lt;p&gt;This is the API deprecation pattern that every developer knows, but compressed. Traditional API versioning gives you years. AI model deprecation gives you months. And because models are probabilistic, not deterministic, you can't just swap the endpoint and run your tests — you have to re-evaluate whether the outputs are still acceptable.&lt;/p&gt;

&lt;h2&gt;
  
  
  The coordination problem
&lt;/h2&gt;

&lt;p&gt;The pattern that makes this cycle different from previous ones is coordination. When Heroku killed its free tier, developers migrated to Railway, Fly.io, Render. The alternatives were still generous. The competitive market absorbed the damage.&lt;/p&gt;

&lt;p&gt;In the AI sector, the major players are closing simultaneously. Perplexity tightened its free tier weeks after Google, OpenAI, and Anthropic tightened theirs. OpenAI introduced ads in its free tier in February 2026, then expanded them to the UK, Mexico, Brazil, Japan, and South Korea by August. DeepSeek raised prices fourfold in August 2026 ahead of a potential IPO — the same trigger that drove Reddit's API pricing hike in 2023 and Uber's driver pay cuts after its IPO.&lt;/p&gt;

&lt;p&gt;When everyone moves in the same direction at the same time, the competitive pressure that used to slow the cycle stops working. There's nowhere to migrate to that isn't also closing. The Free Tier Graveyard for cloud infrastructure shows individual companies killing tiers at different times, giving the ecosystem room to adjust. The AI sector is closing in a wave, not a sequence.&lt;/p&gt;

&lt;h2&gt;
  
  
  The IPO trigger
&lt;/h2&gt;

&lt;p&gt;The pattern is consistent enough to predict. A company builds a user base on cheap or free access. Growth slows. The company needs to show revenue — to investors, to public markets, to acquisition targets. The free tier is the first line item under review.&lt;/p&gt;

&lt;p&gt;Reddit filed for its IPO and priced its API at $12,000 per 50 million requests. Apollo, the most popular third-party client, would have owed $20 million per year. It shut down. Uber went public and intensified driver pay cuts — internal documents showed subsidies were always temporary, designed to "buy revenue" until the market was captured. DeepSeek raised prices fourfold ahead of a potential IPO in August 2026, though its rates remain below Western competitors.&lt;/p&gt;

&lt;p&gt;The IPO isn't the only trigger — copyright lawsuits forced Suno into its industry partnership and download caps, and pure profitability pressure drove Heroku and PlanetScale. But the IPO is the most predictable one. When a platform you depend on starts talking about going public, start planning your exit.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to actually do
&lt;/h2&gt;

&lt;p&gt;The pattern is not a reason to avoid AI platforms. It's a reason to understand which phase you're in and what your exit costs are.&lt;/p&gt;

&lt;p&gt;If you're building on a free tier, assume it will close. The research shows the open phase in AI lasts months, not years. Plan for the cap, the price hike, or the deprecation before it arrives, not after.&lt;/p&gt;

&lt;p&gt;If you're using a free tier that trains on your data, know what you're trading. Your prompts, your code, your conversations are the payment. If that's acceptable for experimentation, fine. If it's not, pay for the tier that doesn't train on your inputs — or self-host.&lt;/p&gt;

&lt;p&gt;If your content lives on a platform's infrastructure, maintain an export path. Download your work. Keep local copies. When Suno caps downloads at 7 lifetime, the people who already had their songs locally are fine. The people who didn't are stuck.&lt;/p&gt;

&lt;p&gt;If you're building production systems on a specific model, pin to a versioned model name, not a &lt;code&gt;-latest&lt;/code&gt; alias. Mistral's &lt;code&gt;mistral-ocr-latest&lt;/code&gt; silently shifted callers to a model that cost twice as much. Track deprecation notices. Test against new models before the old ones disappear.&lt;/p&gt;

&lt;p&gt;And if a platform you depend on starts talking about an IPO, start building your exit plan that day. Not when the terms change. When the IPO is announced. Because the terms will change — the research across two decades of platform history shows that they always do. The only question is whether you're ready when they do.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>platforms</category>
      <category>lockin</category>
      <category>developer</category>
    </item>
    <item>
      <title>Patch Tuesday as a weapon: what Nightmare Eclipse exposed about the disclosure model</title>
      <dc:creator>Don't test me</dc:creator>
      <pubDate>Wed, 19 Aug 2026 10:43:58 +0000</pubDate>
      <link>https://dev.to/do_not_test_me/patch-tuesday-as-a-weapon-what-nightmare-eclipse-exposed-about-the-disclosure-model-ej7</link>
      <guid>https://dev.to/do_not_test_me/patch-tuesday-as-a-weapon-what-nightmare-eclipse-exposed-about-the-disclosure-model-ej7</guid>
      <description>&lt;p&gt;There is a day every month when Microsoft releases its security patches. The second Tuesday. The industry calls it Patch Tuesday. The day after, informally, is Exploit Wednesday — when researchers reverse-engineer the patches to find what was fixed, then target unpatched systems.&lt;/p&gt;

&lt;p&gt;Since April 2026, a researcher called Nightmare Eclipse has been inverting that rhythm. Instead of reverse-engineering patches, they drop new zero-days on Patch Tuesday itself. Ten so far. Each one comes with working proof-of-concept code, no prior notice to Microsoft, and a personal grievance.&lt;/p&gt;

&lt;p&gt;The latest, ShieldBreak, landed on August 11. It gives any local user SYSTEM privileges on fully patched Windows 11 and Windows Server 2025. Will Dormann at Tharros Labs confirmed it works. Kevin Beaumont, a former Microsoft employee, tested it independently and published detection queries. Microsoft assigned CVE-2026-69414 and confirmed a patch is in progress.&lt;/p&gt;

&lt;p&gt;The story has been covered as a personal vendetta — a disgruntled researcher, suspected to be a former Microsoft employee, who claims the company violated an agreement and left them "homeless with nothing." That framing is not wrong. But it misses the more interesting part: this is a stress test of the coordinated disclosure model, and the model has no answer.&lt;/p&gt;

&lt;h2&gt;
  
  
  Patch Tuesday as a timing attack
&lt;/h2&gt;

&lt;p&gt;Microsoft formalized Patch Tuesday in October 2003, after the Blaster worm. The idea was simple: accumulate patches over a month, release them all at once, give system administrators a predictable schedule to prepare. It was a logistics decision.&lt;/p&gt;

&lt;p&gt;It is also a predictable attack surface.&lt;/p&gt;

&lt;p&gt;When Nightmare Eclipse drops a zero-day hours after Patch Tuesday, the next opportunity for Microsoft to ship a fix is up to 28 days away. Out-of-band patches happen, but they are rare and reserved for actively exploited critical vulnerabilities. For everything else, the monthly cycle is the cycle. A researcher who times their disclosure to land right after the patch release maximizes the window of exposure.&lt;/p&gt;

&lt;p&gt;This is not a new observation. The security industry has known about the Patch Tuesday timing problem for years. But Nightmare Eclipse is the first to weaponize it so systematically — ten drops, each one timed to the same monthly beat, each one forcing Microsoft into a reactive posture on a schedule the researcher controls.&lt;/p&gt;

&lt;h2&gt;
  
  
  The arbitration gap
&lt;/h2&gt;

&lt;p&gt;The coordinated vulnerability disclosure (CVD) model assumes trust. The researcher reports privately, the vendor fixes, the researcher gets credit, details are published after a patch. When it works, it works. When it breaks, there is no escalation path.&lt;/p&gt;

&lt;p&gt;This is not a hypothetical problem. In July 2024 — well before Nightmare Eclipse appeared — Dustin Childs at the Zero Day Initiative published a blog post titled "Uncoordinated Vulnerability Disclosure: The Continuing Issues with CVD." ZDI is one of the largest and most respected vulnerability brokers in the industry. Their complaints were structural:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Microsoft released a patch for a vulnerability ZDI had reported, without acknowledging ZDI or the researcher who found it.&lt;/li&gt;
&lt;li&gt;Researchers who handed Microsoft working exploits at Pwn2Own saw their bugs fixed with incorrect CVSS ratings, changing how enterprises would prioritize patching.&lt;/li&gt;
&lt;li&gt;"Coordination" from Microsoft's side often meant "you tell us everything you know about this bug, and maybe something will happen."&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Childs asked a question that the industry has been avoiding: "Who arbitrates disagreements?" When a vendor says a bug is defense-in-depth and the researcher says it is remote code execution, there is no independent body that can adjudicate. The CVE program has a dispute process. ZDI noted it "has not proved effective."&lt;/p&gt;

&lt;p&gt;The CERT Guide to Coordinated Vulnerability Disclosure acknowledges that disputes between reporters and vendors may require a third-party coordinator. But coordinators are voluntary, limited in capacity, and have no binding authority. They can facilitate. They cannot compel.&lt;/p&gt;

&lt;p&gt;Nightmare Eclipse's claim that Microsoft violated an agreement and mistreated them is consistent with a pattern that established, respected organizations have been documenting publicly for years. The difference is that ZDI responded with blog posts and industry advocacy. Nightmare Eclipse responded with zero-day drops.&lt;/p&gt;

&lt;h2&gt;
  
  
  The un-cancellable researcher
&lt;/h2&gt;

&lt;p&gt;When Microsoft threatened legal action in May 2026, their blog post referenced the Digital Crimes Unit and its mandate for "criminal referrals." The security community pushed back hard. Katie Moussouris, who pioneered bug bounties at Microsoft and helped replace "responsible disclosure" with "coordinated disclosure," called the legal threat "over the top" and warned it would result in researchers distrusting Microsoft. Kevin Beaumont called it a "dumpster fire of its own making."&lt;/p&gt;

&lt;p&gt;Microsoft walked back the threat in a social media post. The original blog post remains unchanged.&lt;/p&gt;

&lt;p&gt;But the legal threat revealed something important: the primary leverage a vendor has over a researcher is institutional — access to platforms, credit, bounty payments, and the threat of legal consequences. Nightmare Eclipse has neutralized all of it.&lt;/p&gt;

&lt;p&gt;They were banned from GitHub and GitLab. They now self-host their code on projectnightcrawler.dev, with a mirror at churchofmalware.org. Disclosure posts are PGP-signed. There is no platform that can deplatform them. There is no bounty program that can withhold payment, because they are not participating in one. There is no reputation that can be damaged within the coordinated disclosure ecosystem, because they have left it.&lt;/p&gt;

&lt;p&gt;In May, Rik Ferguson of Forescout told The Register that Nightmare Eclipse claimed to have a dead man's switch — more exploits ready to go, automatically. If true, this adds a layer that does not require the researcher's continued participation. Even if they were arrested, silenced, or otherwise removed, the drops would continue.&lt;/p&gt;

&lt;p&gt;This is a different kind of adversary than the disclosure ecosystem was designed to handle. The model assumes both parties have something to lose. Nightmare Eclipse has already lost what they claim was taken from them, and has built infrastructure that cannot be taken away.&lt;/p&gt;

&lt;h2&gt;
  
  
  The regression problem
&lt;/h2&gt;

&lt;p&gt;One of Nightmare Eclipse's ten drops was not a new vulnerability at all. MiniPlasma, disclosed in May, was tracked as CVE-2020-17103 — a vulnerability Microsoft had fixed six years ago. It came back. Microsoft confirmed this and updated their bulletin to note the republication.&lt;/p&gt;

&lt;p&gt;A regression is not a new discovery. It is evidence that the patching process itself has a quality problem. When a fix is incomplete or a later change reintroduces the same vulnerability, the vendor's argument that researchers should trust them to fix things properly gets harder to sustain.&lt;/p&gt;

&lt;p&gt;This is not unique to Microsoft. Regressions happen in every complex codebase. But in the context of a disclosure dispute, they are ammunition. A researcher who can point to a six-year-old fix that failed has a concrete example of why private disclosure without leverage is a gamble.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the system has no answer for
&lt;/h2&gt;

&lt;p&gt;The coordinated disclosure model has mechanisms for cooperation. It has mechanisms for delay. It has mechanisms for multi-party coordination. What it does not have is a mechanism for broken trust.&lt;/p&gt;

&lt;p&gt;When a researcher and vendor disagree about severity, there is no binding arbitration. When a vendor fails to acknowledge a researcher, there is no penalty. When a vendor threatens legal action for disclosure, the only counterweight is public opinion — which is reactive, not structural.&lt;/p&gt;

&lt;p&gt;Nightmare Eclipse has exposed this gap in the most visible way possible. They have shown that a single motivated researcher with working exploit code, self-hosted infrastructure, and a predictable release schedule can force one of the largest software companies in the world into a reactive posture for months. Microsoft has patched most of the vulnerabilities. But they have not solved the underlying problem: a researcher who no longer trusts them has no reason to cooperate, and the system has no tools to make them.&lt;/p&gt;

&lt;p&gt;The next Patch Tuesday is September 8. The question is not whether another drop will come. Nightmare Eclipse has said it will. The question is whether the industry will treat this as a one-off vendetta or as the stress test it actually is — a demonstration that the disclosure model works well when everyone cooperates, and has no plan for when they don't.&lt;/p&gt;

&lt;p&gt;The CERT CVD guide says coordinators can help resolve disputes. ZDI says the dispute process has not proved effective. Microsoft says it supports coordinated disclosure. Nightmare Eclipse says they tried that and it left them with nothing. All of these statements can be true simultaneously, and that is the problem.&lt;/p&gt;

</description>
      <category>security</category>
      <category>vulnerability</category>
      <category>disclosure</category>
      <category>microsoft</category>
    </item>
    <item>
      <title>The storefronts are coming to Linux: Epic, GOG, and the tipping point</title>
      <dc:creator>Don't test me</dc:creator>
      <pubDate>Tue, 18 Aug 2026 21:50:54 +0000</pubDate>
      <link>https://dev.to/do_not_test_me/the-storefronts-are-coming-to-linux-epic-gog-and-the-tipping-point-4468</link>
      <guid>https://dev.to/do_not_test_me/the-storefronts-are-coming-to-linux-epic-gog-and-the-tipping-point-4468</guid>
      <description>&lt;p&gt;For most of Linux gaming's history, the story has been the same: Linux users want to play games, game companies don't care about Linux users, and the community builds its own tools to bridge the gap. Valve changed that with Proton and the Steam Deck. But the storefronts held out. Epic, GOG, and Microsoft all stayed away from native Linux support, leaving their games accessible only through community-built launchers or not at all.&lt;/p&gt;

&lt;p&gt;That's changing. Three things happened this month that point to a tipping point.&lt;/p&gt;

&lt;h2&gt;
  
  
  Epic Games is building a native Linux launcher
&lt;/h2&gt;

&lt;p&gt;In a Discord AMA reported by GamingOnLinux on August 14, 2026, an Epic Games developer confirmed that a native Linux version of the Epic Games Store launcher is coming "soon." Not for the preview release of the upcoming store overhaul, but after that. The developer's exact words, screenshotted from Discord: "Soon &amp;lt;-- but not for the preview release. As you can imagine, we need to do more than simply have a build of the launcher that can run natively on Linux."&lt;/p&gt;

&lt;p&gt;This isn't a vague promise from a community manager. It's a developer in an AMA saying the work is happening. Epic was also recently hiring a Security Engineer to champion Linux anti-cheat, which suggests broader plans for Linux support beyond just the launcher.&lt;/p&gt;

&lt;p&gt;The context matters. Epic has been the holdout. Tim Sweeney has historically been dismissive of Linux as a gaming platform, and Epic's anti-cheat (BattlEye, Easy Anti-Cheat) has been a recurring blocker for Linux compatibility even when games would otherwise run fine through Proton. A native launcher doesn't solve the anti-cheat problem, but it signals a shift in how Epic views the platform.&lt;/p&gt;

&lt;h2&gt;
  
  
  GOG is working on a Linux version of GOG Galaxy
&lt;/h2&gt;

&lt;p&gt;GOG separately confirmed to GamingOnLinux that work is in progress on a Linux version of GOG Galaxy. No timeline, no details, just confirmation that it's happening.&lt;/p&gt;

&lt;p&gt;GOG is a smaller player than Epic, but they matter for a different reason: they're the DRM-free storefront. If GOG Galaxy comes to Linux natively, it means the DRM-free gaming ecosystem gets a first-class Linux client. That's not just about convenience — it's about having a native path for games that don't want anything to do with DRM or compatibility layers.&lt;/p&gt;

&lt;h2&gt;
  
  
  NVIDIA's GeForce NOW Linux app left beta
&lt;/h2&gt;

&lt;p&gt;NVIDIA's native Linux app for GeForce NOW officially graduated from beta, as reported on the NVIDIA blog. It supports Ubuntu 24.04 and later, with a new Flatpak repository for easier installation and updates.&lt;/p&gt;

&lt;p&gt;This is a different category from Epic and GOG — GeForce NOW is cloud gaming, not local game distribution. But it matters for the same reason: a major gaming company decided Linux was worth building a native client for, not just supporting through a browser. The cloud handles rendering, so Linux gamers get RTX-class performance without local hardware. The native app removes the browser-as-client awkwardness that cloud gaming has lived with on Linux.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this is a tipping point
&lt;/h2&gt;

&lt;p&gt;Linux has been over 4% in the Steam Survey since mid-2025, and the July 2026 survey confirmed it's still there. That's not a majority. It's not even close. But it's enough that the cost of ignoring Linux is now higher than the cost of supporting it.&lt;/p&gt;

&lt;p&gt;The Steam Deck is the obvious driver. Valve's handheld runs SteamOS, a Linux-based system, and has sold well enough that "does it work on Steam Deck?" has become a standard question for PC game releases. The Steam Machine, Valve's recently released living room PC, runs the same OS. Together they've created a Linux gaming audience large enough to matter.&lt;/p&gt;

&lt;p&gt;But the Steam Deck alone doesn't explain Epic and GOG moving. Valve's hardware created the audience. The community tools — Heroic Games Launcher, Lutris, Bottles — proved the demand by making Epic and GOG games work on Linux without official support. The storefronts are now responding to a market that was built without them.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's still missing
&lt;/h2&gt;

&lt;p&gt;Epic's "soon" is not a release date. The developer was clear that a Linux launcher requires more than just a build that runs — there's authentication, library management, anti-cheat integration, and the question of whether Fortnite specifically will be supported. Epic's store doesn't currently support Linux-native builds at all, so even with a native launcher, games would likely run through Proton rather than natively.&lt;/p&gt;

&lt;p&gt;GOG's confirmation came without a timeline. "Work in progress" could mean anything from months to years.&lt;/p&gt;

&lt;p&gt;And Microsoft, the third major storefront, isn't moving at all. Xbox PC games and Game Pass remain inaccessible on Linux through official channels. The community project Xodus is working on reverse-engineering the Xbox GDK to change that, but it's an unofficial effort, not a Microsoft initiative.&lt;/p&gt;

&lt;h2&gt;
  
  
  The pattern
&lt;/h2&gt;

&lt;p&gt;The pattern is familiar to anyone who's watched Linux gaming evolve. First, the community builds tools to make things work. Then, the audience grows large enough to matter. Then, the companies that ignored the platform start building official support.&lt;/p&gt;

&lt;p&gt;Valve went through this cycle years ago — they built Proton because they wanted the Steam Deck to work, and the Steam Deck created the audience. Epic and GOG are now at the third stage. They didn't build the tools. They didn't create the audience. They're responding to a market that exists whether they participate in it or not.&lt;/p&gt;

&lt;p&gt;The difference between "Linux gaming is growing" and "Linux gaming has arrived" is whether the major players treat it as a first-class platform. Three storefronts moving toward native Linux support in the same window is a signal. It's not the finish line — the finish line is when "does it run on Linux?" stops being a question anyone needs to ask. But it's the point where the question shifted from "will they ever?" to "when?"&lt;/p&gt;

</description>
      <category>linux</category>
      <category>gaming</category>
      <category>epic</category>
      <category>steam</category>
    </item>
  </channel>
</rss>
