8 ms·
Show HN: Turn GitHub Usernames into Emails
- pavel_lishin 11y ago> "temp_email" already exists That could be solved by using this, I believe: http://ruby-doc.org/stdlib-2.0.0/libdoc/tmpdir/rdoc/Dir.html http://ruby-doc.org/stdlib-2.0.0/libdoc/tmpdir/rdoc/Dir.html
- kwl 11y agoYup! It's been updated to use tmpdir so that isn't an issue anymore
- thebiglebrewski 11y agoOoooooh this is gonna be controversial
- detaro 11y agoevery few months someone discovers that either a) there are e-mail addresses in git commits!!! Public!!! or b) You can put ANY e-mail address there and commit code as SOMEONE ELSE! and it seems the general reaction always is: "Yeah, that's how it works." That stuff is just to easy and obvious to be that interesting... Now what are appropriate ways to use that data, that's an interesting question. related: https://github.com/ghtorrent/ghtorrent.org/issues/32 https://github.com/ghtorrent/ghtorrent.org/issues/32 (Ghtorrent archives the public timeline of GitHub)
- parennoob 11y agoa) is fine (which is what this "Gitmail" service provides), but shouldn't b) be preventable if you tied email addresses to the public keys uploaded by the user? So if I tried to push commits to Github with an email address that belongs to Linus Torvalds, Github should be able to reject the push based on the fact that I authenticated with a key pair that is not in Torvalds' keys. (Perhaps I don't understand the way in which git pushes work well enough?)
- detaro 11y agoYou have to be able to push commits other people have made. E.g. if you work together in a different repo and then publish the result to github, one person pushes all the commits. Maybe GitHub should indicate more precisely who pushed the commit, but on the other hand that's often unnecessary noise as well. If you want to be able to trust the data in a commit, it has to be signed (which nearly nobody does, and AFAIK GitHub doesn't display)
- parennoob 11y ago> You have to be able to push commits other people have made. If you work together in a different repo and then publish the result to github, one person pushes all the commits. I completely missed that use case. Thanks for the explanation! You're right in that no one signs commits (unfortunately, including myself).
- willeyeam 11y agoSomeone should build a tool that autosigns your commits for you if you have proper SSH keys and emails.
- everfree 11y agoThere's an interesting discussion on Stack Exchange about whether it's useful to sign every commit: http://programmers.stackexchange.com/questions/212192/what-are-the-advantages-and-disadvantages-of-cryptographically-signing-commits-a http://programmers.stackexchange.com/questions/212192/what-a...
- cyphar 11y agoSigning commits bumps the size of the repo substantially. Not to mention that you then have to maintain your WoT connection in order to make sure people can verify that your key is actually yours (although you can use keybase for that).
- aaronbasssett 11y agoIt's not so much about who pushes the branch to a repo and more about verifying who made the commits within a push (as a single push could contain commits from multiple people) and for verifying commit authors we already have commit signing[1]. It's just a pity nobody uses it. [1]: https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work
- deleted 11y ago[deleted]
- bdcravens 11y agoShouldn't be. Data's already there.
- aioprisan 11y agoIf you just want a list of contributors' emails, you can just run git log --pretty=format:'%ae' | sort | uniq
- aioprisan 11y agoEven better, take those results through something like Mailgun email validation REST service, and you've got valid emails: https://documentation.mailgun.com/api-email-validation.html https://documentation.mailgun.com/api-email-validation.html
- deleted 11y ago[deleted]
- michaelmior 11y agoWarning > Mailgun’s email validation service is available for free to all Mailgun customers. It is intended to validate email addresses submitted through forms like newsletters, online registrations and shopping carts. It is not intended to be used for bulk email list scrubbing and we reserve the right to disable your account if we see it being used as such.
- dbarlett 11y agoInstall Flanker [1] and you can do it locally. Just make sure your ISP/firewall allows outgoing SMTP connections on port 25, and ideally have Redis running for caching [2]. [1] https://github.com/mailgun/flanker/ https://github.com/mailgun/flanker/ [2] https://github.com/mailgun/flanker/blob/master/docs/User%20Manual.md#validating https://github.com/mailgun/flanker/blob/master/docs/User%20M...
- nailer 11y agoWhat is mail verification in 2016? SMTP VRFY is normally disabled these days.
- spinningarrow 11y agoOr `git shortlog -se`
- MajesticHobo 11y agoThis is why I commit with username@users.noreply.github.com
- orlandohill 11y agoGitHub's documentation: # Set your email address git config --global user.email "username@users.noreply.github.com" https://help.github.com/articles/keeping-your-email-address-private/ https://help.github.com/articles/keeping-your-email-address-...
- state 11y agoLooks like a great way for recruiters to harvest email addresses.
- emodendroket 11y agoThat was exactly my thought as well. Who else is just going to send e-mails to random people from Github repositories?
- adrianpike 11y agoNot surprisingly, they've been doing it for years.
- jkot 11y agoI would recommend everyone to create separate email for their open-source work. After ten years on SourceForge, Google Code and now Github I get 200 spam messages a day.
- kwl 11y agoDefinitely. When I first started programming I felt weirdly happy about getting spam related to github (because it meant at least one other person thought I was a 'real' programmer), but quickly that turns into annoyance at having such a cluttered inbox.
- yeukhon 11y agoThe spam source of my inbox are open source DLs because apparently they are based on either google groups or mailman and they almost always require registration. sigh
- nickysielicki 11y agoIn bash, if anyone is interested in something they can throw in their .profile gitspam () { if [ -z "$1" ] || [ "$#" -gt 1 ] || [ "$#" -lt 1 ] || grep -v "http\(s\)\?://\(.*\)\.git" <(echo "$1") &>/dev/null ; then echo "usage: gitspam http://somedomain.tld/path/to/repo.git" return fi tmpdir=$(mktemp -d) git clone --bare "$1" "$tmpdir" &>/dev/null cd "$tmpdir" git log --pretty=format:'%ae' | sort -u cd "$OLDPWD" rm -rf "$tmpdir" }
- nickysielicki 11y agoI hit my noprocrast before I could edit this, but I believe that this: git shortlog -se |& sed 's/^.*\(<\(.*\)>\)/\2/g' | sort -u is a quicker replacement for git log --pretty=format:'%ae' | sort -u By about 50%
- subsection1h 11y agoI hate how people refer to email addresses and email accounts as "emails". Half the time, I don't know if they're referring to addresses, accounts, or messages. I'm not looking forward to when these people start referring to phone numbers as "phones".
- Grue3 11y ago>I'm not looking forward to when these people start referring to phone numbers as "phones". In my native language (Russian) people already do (and have done long before email existed). In fact, I don't see why that would be unusual. When faxes were used, everyone used to refer to fax numbers as "fax", right?
- dheera 11y agoOn that note, I hate how Hamiltonian, Jacobian, and Lagrangian are nouns while Brownian, Newtonian, and Freudian are adjectives. It's about time we standardize our language and namespace conventions so these things are clearer.
- DyslexicAtheist 11y agoforgot Orwellian: "1984" has a strong theme of standardizing namespace conventions to make things clearer. They call it "Newspeak". A terrifying idea.
- dheera 11y agoI think the terrifying part of Newspeak is more in brainwashing people by removing certain words from vocabulary. Standardized namespace conventions isn't scary, and many human languages are close to standardized. English is just a mess. Spanish is a lot better in this respect (e.g. all verbs end in -er, -ir, -ar, period).
- stevekemp 11y agoI wonder if this is similar to what spamming companies are using: "We've seen your contributions to github and think you'd be an excellent fit for our startup ... PS Please move to Paris".
- cyphar 11y agoYeah, this is why we have spam filters. Although, to be fair, I got my job at SUSE because of my free software contributions. So there is a benefit of including a real email (one that you check) in your commits.