7 ms·
I think number of clones is a much better metric (it's like proof of work, it needs compute to clone a repo). For me starring a repo is liking bookmarking it, n
by attentionmech 2y ago
I think number of clones is a much better metric (it's like proof of work, it needs compute to clone a repo). For me starring a repo is liking bookmarking it, nothing else. They might as well just mark it as "Bookmarked" instead of "Starred".
- nejsjsjsbsb 2y agoA better metric until it becomes a target. Once it is a target, getting a billion clones is trivial. Github should just stop showing star counts. Who cares about them.
- attentionmech 2y agoI think it's like a "upvote" thing which shows whether historically users have found the repo interesting. Even if you hide stars, there needs to be a way for the collective hivemind of github users to help each other with what repos are high quality or not right?
- rpdillon 2y agoYou don't need to crowdsource everything. I've never used stars as a good metric because it's literally zero effort. It's anybody who happens by just stars it, So all you can really conclude from star count is that this is interesting to this number of people. Two metrics that I think correlate extremely highly with quality: The number of commits in the repository and the date of the most recent commit. I've used a metric based on those two inputs for the past 15 years to evaluate repos and I am not disappointed. Depending on the nature of the project, I weigh the two attributes differently. Some projects are arguably, 'done', and so the date of the most recent commit is not very important in that case.
- michaelmior 2y agoI think "interesting to this number of people" is not a meaningless metric, but I would agree on the two other metrics you cite.
- ryandrake 2y agoThere is a big difference between “highest quality” and “most popular.” Online services constantly confuse the two because it’s easier to measure popularity.
- michaelmior 2y agoI don't disagree. But I think there's at least some positive correlation. The highest quality is unlikely to be the least popular and vice versa.
- LtWorf 2y agoExcept that most people don't bother starring stuff, so the few who do are drowned by noise of fake stars.
- ghxst 2y agoI sort by most amount of stars quite frequently when I am learning a new language and want to know what the most popular package is for something. What do you think would be a better metric for a use case like that?
- arccy 2y agonumber of actual imports in code
- flippyhead 2y agoCodeRank(tm)!
- nejsjsjsbsb 2y agoThis might work but biases against languages whose package managers are not used in the rank. As well as code that is used alot but not referenced via code directly e.g. drop in dlls.
- james_marks 2y agoGoodheart's law - this would just cause imports in junk repos
- michaelmior 2y agoI think it's a decent metric. I agree with the other comment that actual imports is probably a better metric, but that's not always as trivial to find. That said, the package repositories for many popular languages list stats of either declared dependencies or package downloads, which helps.
- LtWorf 2y agordeps are completely broken in github. I wrote a library that I have used in other projects of my own and it was always at 0 users. Anyway if stuff is used by proprietary stuff it will also sit at 0. I now moved to codeberg where there is less spam, although it does have stars
- LtWorf 2y agoVC apparently.
- knowitnone 2y agoI care. How do I know which is the better tool between 10 different tools?
- nradov 2y agoYou missed the point. Number of stars doesn't indicate anything about whether a particular tool is better (and never did). If you're using stars for that purpose then you're doing it wrong. Find another solution.
- nejsjsjsbsb 2y agoHave in your mind your requirements. E.g. license, community, how funded, bugs, try a few out and check the ergonomics, talk to others who have used it.
- pan69 2y agoA similar thing happens on npmjs.com where it shows downloads for packages, which is often used as a metric of quality. However, everytime a build pipeline runs and it pulls the package, that's a download.
- attentionmech 2y agoMay be with these rules: - Per user account we only count one clone - We don't count anonymous clones But I agree it's not like this is also without any issues
- michaelmior 2y agoI don't think it's a useless metric and it's one I use myself, but it can also be gamed pretty easily. So the more people making decisions based on downloads, the higher the likelihood of bots generating downloads just to juice the stats.
- ozim 2y agoWell it is useful as first level filter just like GH stars. If it has no downloads/stars you don’t care. If it has big amount let’s take time checking it out. Fun part starts when checking out part is limited to some minimum and goes to prod because it solves something. Where people might not even know if that library is any good at all.
- LtWorf 2y agoAnd if your users know about "a cache" you won't get downloads. So iy's more beneficial if your users are the kind of noobs who redownload all the crap every single time rather than having fast CI
- Lerc 2y agoThe weird thing is I forked Freepascal to add an architecture of A VM I had written. It wasn't really useful to anyone else, but every now and again it earns a star from a random passer by.
- attentionmech 2y agoEven I am curious now. Can you share me the fork? I want to see what you added there and how it's added.
- Lerc 2y agoI just had a look, I didn't even push the changes back to GitHub after I made a local clone. The changes were very minor. My VM was an 8-bit Avr. I just needed to add a profile for an imaginary microcontroller with no peripherals, 64k ram and 64k words ROM. So what was on GitHub is an unmodified fork, 16 years behind upstream, and has acquired 20 stars. 8 in the last year.
- GZGavinZhao 2y ago*sad noises from NixOS/nixpkgs, llvm/llvm-project, and all other repos with an absurd commit log/branches that takes ages to do a full clone (just a joke that immediately came to mind, not intended to undermine OP's idea)
- attentionmech 2y agodefault to git --shallow in the cli can be one option here.
- simoncion 2y ago> (it's like proof of work, it needs compute to clone a repo) It's github's compute, so why do I (the person who's cloning the repo) care about the compute? I don't pay for it!
- david_allison 2y agoI suspect GP is referring to counting the occurrences of `git clone` [on a fork?], rather than counting forks via the GitHub UI
- simoncion 2y agoOh. Is "number of times someone has cloned this repo" data you can query Github for that they don't expose on their GUI? I was entirely unaware that that was popularity-contest information that Github provided.
- TZubiri 2y agoThat is absolutely the wrong takeaway. The correct takeaway is that supply chain attacks and spam are real threats, and that these metrics can be gamed by malicious actors. The work in cloning a repo is negligible, and the requirement of work is not a security design guarantee in github. The actual cost of liking projects is network, malicious actors need to create fake accounts, waste IP addresses and ip blocks in the process. Whether you are cloning or liking is just the last mile. To me the takeaway is not to trust a project based on it's github metrics, and by extension not to trust projects just because they are linked and liked in hacker news for example. And to be wary of how I introduce dependencies into my projects. Not just because of strictly malicious dependencies, but also because of trash dependencies that don't add value.
- james_marks 2y ago> because of trash dependencies that don't add value And at best, will still need maintenance in the future. One of the top lessons I preach to juniors.
- galangalalgol 2y agoI like the idea of granular permissions for libraries. When you include a dependency you whitelist permissions it gets. Package managers could automate this if the language supports it. But making it about permissions instead of metrics .akes it not arbitrary. This library gets no filesystem access, that one gets no network access. This one runs build time system commands... Austral is the only language I know of that supports such a thing. While it might be possible to bolt it on to rust, I think it would take so much rework to make it infeasible.
- yieldcrv 2y agoif a supply chain attack is susceptible to that, its purely the fault of the crowd the relies on those metrics
- ATechGuy 2y agoFor all speculation around supply chain attacks with fake Github stars, the article says: "our study does not find any evidence of fake stars being used for social engineering attacks"
- robinsonb5 2y agoThe weird thing is I've seen enough forks that have never seen any development that I'm pretty sure some people are using those as bookmarks rather than stars!
- neom 2y agoI'm not a SWE but I use github still, I thought stars ARE bookmarks, what are stars then???? They're not for bookmarking????
- diego_sandoval 2y agoI would think most people use it for bookmarking, but it seems like another portion of users use it as a "like" button.
- notpushkin 2y agoIt is kinda both. It also reposts the project for your GitHub followers.
- attentionmech 2y agoThey are currency of reputation and status. If you have enough stars, you get invited to private parties with elites. (I am just joking, they are bookmarks who got famous)
- LtWorf 2y agoNobody knows but since we are at the point where you can get VC money if you have enough, there is an incentive to get them.
- Terr_ 2y agoAFAIK the "fork" option also helps guard against the original project getting deleted or somehow moved.
- datadrivenangel 2y agoAnd forks on github have some bad ergonomics! Weird places where the upstream project still has control/influence over your fork. A full clone is better if you actually want control over the code fork.
- deleted 2y ago[deleted]
- kube-system 2y agoI would imagine those figures would mostly indicate which projects are most likely to be used in scripts or CI pipelines.
- burnte 2y ago> They might as well just mark it as "Bookmarked" instead of "Starred". This is how I always interpreted the star feature and have used it as a bookmarking feature. I didn't know it was more akin to a like button!
- dbaupp 2y agoPeople use stars differently. https://arxiv.org/pdf/1811.07643 https://arxiv.org/pdf/1811.07643 is some investigatory research describing, among other things, 4 clusters of reasons for starring: to show appreciation, bookmarking, due to usage, due to third-party recommendation.
- Suppafly 2y ago>For me starring a repo is liking bookmarking it, nothing else. Literally all I ever use the stars for, I don't know what they are 'supposed' to be used for if not that.
- WA 2y agoFor me, it’s "bookmarking obscure stuff". Why would I bookmark, say, React? I can find this easily. I only star stuff that has few stars and isn’t as easy to find later.