11 ms·
We stopped AI bot spam in our GitHub repo using Git's –author flag
- standbyme 5mo agocool
- zer0tonin 5mo ago> Should we stop giving fun test tasks to our job candidates? Yes
- deleted 5mo ago[deleted]
- Chaosvex 5mo agoYeah, fun for who exactly?
- dymk 5mo agoMe. That sounds way more fun than inverting a binary tree, and they pay candidates for their time.
- FartyMcFarter 5mo agoIt seems this particular company makes a payment for completing those tasks, so it might not be that bad.
- motakuk 5mo agoWe do, it's a part of our hiring pipeline: https://archestra.ai/careers https://archestra.ai/careers
- jbellis 5mo agoDevelopers: stop doing whiteboard interviews, they don't measure anything relevant to the real job Also devs: stop giving us real world problems to solve
- gabeio 5mo agoThose are the only two options to finding quality candidates? Try talking more about the meta of coding itself. Get into the developers head by _talking_ to them and understanding how they would approach and attack different problems. You can show them code and ask them what they would do differently / how they would go about implementing X-Y-Z. Just because you can write foobar doesn't mean you understand how to apply algorithms or w/e specific problems [your] team has. It's _far_ better to understand how they would solve a problem over their syntax anyway.
- ildari 5mo agoHi HN community, I wanted to share our approach to reduce amount of AI slop PR's and issues in our repo. We enabled "require prior contribution" flag on GH and created a CI script that creates a tiny commit co-authored with you, if you pass captcha on our website. Worked really well and we were able to block at least 500 bots in the first week. Sharing a screenshot from cloudflare: https://archestra.ai/hn-comment-cloudflare-challenge-outcomes-do-not-delete.webp https://archestra.ai/hn-comment-cloudflare-challenge-outcome...
- satvikpendem 5mo agoYep, this is similar to some other version control tools like Tangled which has vouching. https://blog.tangled.org/vouching/ https://blog.tangled.org/vouching/
- tln 5mo agoThats a really elegant solution. How does the website trigger the CI script? Through GH rest API?
- ildari 5mo agothank you, yep through the rest API, here is the example: https://github.com/archestra-ai/website/blob/29ebdacbd8a22b91e2b14a9ab136a2c3cfe215af/app/app/api/contributor-onboard/callback/route.ts#L52 https://github.com/archestra-ai/website/blob/29ebdacbd8a22b9...
- halapro 5mo agoWho do you add as a contributor though? Wannabe-contributors? Then they appear in the list of contributors before you even see if they're capable of producing an acceptable PR. Your solution would be great if GitHub would also allow me to whitelist specific users, but unfortunately this still won't block "implementation plans" in comments.
- silverwind 5mo agoPR spam is a major problems for repo that run bounties. Maybe GitHub should temporarily block accounts from raising PRs if like 95%+ of them are getting rejected.
- marginalx 5mo agoProblem is the bots can create any number of github accounts and continue spamming. Though this would be a good simple defense to start with.
- hiccuphippo 5mo agoGitHub has not incentive for blocking AI. It's like asking an ad company to build an adblocker into their browser.
- rvnx 5mo agoIt's called Brave
- smaudet 5mo agoWhich is not chrome and still has ads...(Ironically). The issue here is the core model is broken (misaligned incentives). That's not something you are going to fix with a github "downstream". A token system could help but it's easy to imagine ways that could be gamed, if not implemented well.
- rvnx 5mo agoAds are the main business model of browsers. If search ads are blocked on search engines, then there is no revenue for the browser. It's that simple (on top of that Brave has other revenues, but the majority is search ads). So it's a game of hoping that the majority won't change the default. This is the main reason Brave does not block search ads specifically by default, but still block the other ads. Blocking the other ads there are no consequences, since anyway this revenue is not shared back to the browser. This is why the business model of Brave is cynical. -> It's the same model as AdBlock and the "Acceptable Ads" (block all ads, except the acceptable ads, unless you disallow them)
- maryamshafaqat 5mo ago[dead]
- hiccuphippo 5mo agoThe irony of the .ai domain.
- wafflemaker 5mo agoThanks for pointing it out. It has eluded me and it's incredibly funny
- dbgrman 5mo agoalso, could the website plz fix its scrolling code? its annoying. i can't read the article
- motakuk 5mo agoWould love to! Could you please share more? I can't quite see the issue
- nonethewiser 5mo agoI dont think anything is ironic about it because they aren't suggesting AI is bad. Just that it can be misused.
- bakugo 5mo ago"I never thought AI would slop my project!" Says company centered around AI slop
- edfletcher_t137 5mo agoNot just the domain: it's an agentic stack! In other words, I could use their product to create the exact type of PRs they're lamenting here.
- mococa 5mo agoFor now…
- philipwhiuk 5mo agoUntil the AI learns the workflow on the next model update, indeed.
- maxothex 5mo ago[flagged]
- petterroea 5mo agoWhat I see is a (clever) hack, and GitHub continuing to provide good tools to its users.
- skydhash 5mo agoWhat I see is a solution for a problem that is self inflicted, meaning lumping contributors and generic internet users in the same workflow. In big projects, you have the core team, a handful of well known contributors, and everyone else. I strongly prefer the git email model, where it’s often trivial to control the flow of changes proposal. GitHub does not have the same wealth of tools and versatility.
- petterroea 5mo agoI seem to have completely missed the "failing" when writing "this is GitHub failing to deliver tools". My bad
- ramon156 5mo agoSee, this is an article that uses dashes correctly. It adds value, creates a bit of buildup
- chrismorgan 5mo agoThis is funny to me because the title on this submission currently refers to “Git's –author flag”, which is an extremely incorrect use of a dash. (The original article doesn’t make the mistake. Not sure if the error is from the submitter or from an HN title mangulation.)
- arecsu 5mo agoMakes me wonder if an ELO-based system would work to mitigate these issues. People who merged PR successfully onto a project, that had real issues acknowledged, the quality of their responses measured by other users reactions or something, etc, multiplied possibly by the degree of importance of the project where their activity has been made. Won't be about human vs AI, but actual helpful effective being vs low effort/spammy contributions. Issues and PRs could be sorted and filtered by their ELO score. I'm saying ELO as analogy to "score based given the context", not really a 1:1 translation of the ELO system. Negative score would be reports from other users because of spammy content or not acknowledged issues, with a middle ground of neutral score (+-0) or little positive score to issues or whatever with clear good intention, but couldn't reach a proper merged PR or were not issues (e.g. issue existed but wasn't the correct repo to be addressed, PR was good but needed other stuff to be implemented prior to it, maybe in the long run, etc)
- philipwhiuk 5mo agoThe problem is you want the ELO score based on work on other community projects - you can't assume good faith here.
- btilly 5mo agoThe problem with that is that there are certain kinds of users that like to take control of community projects. And then they take control of more, and bigger ones. There are a lot of political tricks that get used. What is scary is that one of those kinds of users are malicious state actors. Like North Korea and Russia...
- doh 5mo agoI have built something like this and in process of collecting the data. Frontier users: 527,865 Light indexed: 527,865 Ready to queue: 9,083 Fast scores ready: 0 Activity events 24h: 30,266 Fast scores completed 24h: 19,123 Deep jobs completed 24h: 3,043 Fast-score ETA: n/a Deep-hydrate ETA: 69h Stale running jobs: 0 GitHub backpressure jobs: 19,113 High automation signals: 4,608 Medium automation signals: 1,327 Completed jobs: 74,714 Biggest challenge is Github's rate limits. At this pace it will take two more months to have 98% coverage. But after that the maintenance should be quite straight forward.
- captn3m0 5mo agoThis has a security implication which is overlooked. Contributors to a repository have higher rights, such as avoiding approval requirements for fork PR runs. GitHub warns in the docs: > When requiring approvals only for first-time contributors (the first two settings), a user that has had any commit or pull request merged into the repository will not require approval. A malicious user could meet this requirement by getting a simple typo or other innocuous change accepted by a maintainer, either as part of a pull request they have authored or as part of another user's pull request.
- ildari 5mo agofair point! We believe "Require approval for all external contributors" should be a default setting, as you cannot trust anyone who is not a member of the organization
- finseam 5mo agoInteresting approach. We’ve seen similar spam/noise problems appear in financial workflow automation too — especially when AI-generated submissions scale faster than manual review processes.
- opengrass 5mo agotoo — especially
- cermicelli 5mo agoyou can't trust org members either I have seen projects have inter maintainer fallouts. In general trust doesn't exist. If companies can screw you over and claim it's a mistake, there isn't much a person can do. It's all about level's of trust, a maintainer going rogue is less likely, a past contributor going rogue more likely but not too much, a stranger with a typo pr merged even more likely but still, a complete stranger least trust worthy.
- simgoh 4mo ago
- _joel 5mo agoWoudln't it be trivial to farm the stats needed to pass the bot checker's theshold?
- zzzeek 5mo agoso...they are manually re-setting the "interaction limits" over and over again, since they are only temporary? why not use hooks to automatically reject issue comments / PRs etc. from users that didnt go through onboarding, rather than repurposing GH features that aren't really designed for that use (and are hence in danger of being changed someday)?
- ildari 5mo agoGH sends the email notification to all subscribers at the moment of posting a comment. There is no cooldown or a way to unsend the notification using hooks
- IshKebab 5mo agoThat's a neat way to interface with GitHub's authentication system, but I don't see how they've solved the fundamental problem because their whitelisting process is just "click ok fine 10 times". Why won't the slop peddlers just do that too?
- mbreese 5mo agoI think the point is to add a bit more friction to the process. You want to make it so that people can do it with minimal effort and an AI bot will give up. If you're in an arms race over AI commits and PRs, this is a decent middle ground to start from. (Why there is a race for AI commits/PRs to projects is beyond me though...)
- ildari 5mo agoclick ok fine 10 times + captcha seems to be working fine
- optionalsquid 5mo agoI don't have a better solution, unfortunately, but it doesn't seem seem to like the spam problem has been solved. It has just been moved from pull requests to commits: Currently, more than 10% of all commits in the archestra repo are essentially noise (369 of 3521 commits), accounting for more than half of all commits in the last month (303 of 578 commits). But maybe (probably) the amount of such commits will go down over time, compared to the growing amounts of AI slop
- ildari 5mo agoAs those commits were made from our system they don't create any noise for us, as PR/issues/email notification do. We only include real people who could solve the captcha and their input is mostly valuable
- Muromec 5mo agoHow is the status revoked without rewriting git history?
- ildari 5mo agowe can block the user in github ui
- aizk 5mo agoI'm not sure why gh hasn't already implemented stricter measures / filters / tools for PRs. It would cut down on spam and also help save their servers that can't handle the increased AI load!
- jagged-chisel 5mo agoRepos get forked, code gets pushed, all before a PR is created. What kind of measures can be implemented to cut down on the AI-general forks and pushes?
- halapro 5mo agoYou can fork and push all you want. The problem is specifically when you show up in my notifications with your junk PR.
- jagged-chisel 5mo agoThe issue for GH isn’t your PR spam. It’s all the other operations before your PR spam ever arrives.
- xigoi 5mo agoThey want the number of PRs to be as high as possible because that’s what investors care about. Why would they do something that decreases it?
- infinitifall 5mo agoIs the solution to everything simply more catgirls [1]? Proof-of-work was, after all, about countering email spam. PR spam is but the latest in that long tradition. 1- https://anubis.techaro.lol https://anubis.techaro.lol
- drum55 5mo agoProof of work doesn’t work here same as it doesn’t work for email. The effort to mint a valid PoW is always going to put the legitimate user at a disadvantage, whatever the implementation is. Someone with an incentive to spam will always be able to do it faster, more efficiently than you. You can’t submit a PR because your laptop is too slow? Rent some hash rate from someone, and now you’ve just made a system of paying botnet owners to be able to make a typo fix on a github repo. HashCash was never used in the real world for a reason, it sounds cute but the incentives are so insane as to only work in a vacuum where you assume everyone isn’t cheating.
- smaudet 5mo agoAgreed, PoW is an especially poor solution here. We really need to solve SPAM itself here, I think there may be a way to do it. I.e., the problem of spam is NtoN scaling connections. The network has never been able to solve that problem (exponential is the hardest). Limiting communication in terms of mesh networking may be the ultimate solution - bots can't get to you because they can't reach you. What needs to be invented is a bridging protocol - some way to establish "legitimate" lines of communication over a network, while preserving (to some degree) privacy and decentralization. AI can only enter this network by being explicitly added to the channel, and thereby explicitly and easily blocked (and also solving the general SPAM issue once and for all).
- pocksuppet 5mo agoJust like we did with IP addresses. If yours is blocked by Cloudflare, you can pay a botnet operator a few dollars to use theirs! You can even use your credit card through a mostly-legitimate website. It's very convenient.
- Terr_ 5mo ago
- thih9 5mo ago> It's not a contract job— it's our optional way of saying thank you to the community. The writing style in their onboarding doc has common AI tells (in the quote: em dashes, “it’s not A, it’s B” sentence). I can understand that, perhaps they want to fight fire with fire or don’t have time as they already say. Still, it all feels like inadequate half measures to me.
- nlarew 5mo agoUsing AI for your own project is different than being overwhelmed by AI contributions from other people/bots
- rvnx 5mo agoI hope he is going to find the seasoned engineers that he is looking for
- ZoneZealot 5mo agoThe entire post is clearly LLM generated. I get that a person clearly put together some thoughts, but prompting an LLM to 'turn this into a blog post' is the kind of low effort content I thought was not appropriate for HN. At least bringing up the underlying method (restrict to contributors) has spawned the discussion about how that's probably a bad idea on the security side.
- duskdozer 5mo agoWell it is a .ai domain and they run some kind of AI product (unclear what exactly) so I guess they just don't see an issue with that sort of thing. I don't know if people are happily reading stuff like this or if they just get the "AI summary"
- jart 5mo agoThis is great example of the toxic effect money has on open source. Reward people with respect and recognition instead. Weird anonymous accounts no one's ever heard of will leave, because someone (or something) who's concealing their identity has nothing to gain from recognition. Honestly GitHub should have a real names policy. Because if you're not Satoshi Nakamoto then there's only three reasons I can think of to be anonymous on GitHub: (1) to avoid obtaining your employer's authorization, (2) to spam, harass, and engage in toxic behaviors, or (3) you're not even human. All three of these are the last things I want when engaging on the GitHub platform. Don't get me wrong, I love robots. But I'm perfectly capable of talking to the robot on my own. I don't want to talk to your robot. I also don't want people slipping me intellectual property below the board without their employer's consent. And I certainly don't enjoy all the hate and harassment. GitHub has tried to help with the last part, by making overt displays of hate something that can get you in trouble. The issue is that people just get more guilesome with more anonymous accounts, because the issue was never disrespect (which can actually be strategic and pro-social if we look at Torvalds' career), but rather bad faith participation. If GitHub can guarantee that all its users are human real names good faith actors, then we might be able to start talking about open bounties.
- pabs3 5mo ago> someone (or something) who's concealing their identity has nothing to gain from recognition The xz supply chain attacker hid their real identity, created fakes one and gained recognition over time in order to gain more access and add the backdoor. So TLAs and other bad actors at least are interested in gaining recognition.
- jart 5mo agoI know, right? It's like, finally—a threat actor who's intelligent enough to understand what capital means in the open source community and is willing to devote resources to engage with it authentically (even if it's for evil nefarious ends). The xz incident showed that the open source community has many other good defense mechanisms for verifying and spotting malicious work and then solving it. But we won't even get to play that game if we're inundated with anonymous agent spam so that GitHub can juice its MAU numbers. Maybe they should require every account buy a $40 yubikey. I don't know what the answer is. But I know that no one gains when your measure of success is driving the cost of burning open source developers out down to literally zero.
- embedding-shape 5mo agoSounds kind of weird that the blog post complains about `poisoning the conversation with pointless "implementation plans"` when literally they ask for that, after attaching $900 USD bounty to a very under-specified issue, and even replies with "Do you have an implementation plan in mind?" to some of the first "attempters". Sounds like they got exactly what they'd been asking for, and even before LLMs if you pulled something similar, the effects would have been similar.
- bradley13 5mo agoIt's fine for developers to provide a plan, even if it gets rejected. The problem comes when every script kiddie figures AI has made them into a developer. Imagine you want to get a doctor's opinion, or maybe a couple of opinions. But a zillion AI-amateurs have registered themselves as doctors. How do you separate wheat from the chaff?
- embedding-shape 5mo ago> Imagine you want to get a doctor's opinion, or maybe a couple of opinions. But a zillion AI-amateurs have registered themselves as doctors. How do you separate wheat from the chaff? Right, but that's not what happened though. Someone went to the public square, said "Hey, I'm looking for any sort of doctor, and I'll pay you $900 if you tell me your plan and then whatever plan I chose wins" and then they get surprised they get flooded by zillion AI-amateurs. You don't generate a ton of chaff then try to find the wheat, you ensure your process doesn't generate a ton of chaff in the first place. Offering large monetary rewards for relatively simple work for anyone in the public is bound to generate a ton of chaff...
- rglullis 5mo ago'I will take "problems that could be easily be solved by implementing a Pfand system" for $200, Alex.' Seriously. Just ask for a US$10 deposit for the each PR. If the PR is accepted (not even merged, just accepted as "this is a good effort"), give it back. Hell, give double the amount for good effort and you got yourself a cheap way to attract good contributors. Best case, bots will balk at the payment. Worst case, the funds can be used to hire someone specifically for triage.
- skrebbel 5mo agoEasily? You think the kind of people who think it makes sense to make bogus slop PRs are going to react reasonably to overburdened volunteer maintainers refusing to give them their US$10 back?
- rglullis 5mo agoYes. Once a PR is rejected, contact from that bot is blocked. No appeals.
- rtdq 5mo agoThe worst case is that someone loses out on $10, no? How does this work if the maintainer is the swindler?
- smaudet 5mo agoI don't think that is a (very realistic) concern. AI is slop, the problem is not that the real contributors are struggling to get PRs merged. The bigger issue being, raising the bar to students who may have otherwise had productive careers (but education is a general issue, where the students don't even yet recognize they are being scammed).
- rtdq 5mo agoI don't follow, and I'd be concerned that this opens up a cottage industry of bots generating plausible looking repositories that unwitting contributors would attempt to contribute to. We already know that bots are astroturfing repos to generate overinflated star counts. I'd say the least crap option here is to honeypot PR contributions from bots
- opengrass 5mo agosubmitting attempts — but soon... not just this issue — but the entire repo. contributors like @ethanwater, @developerfred, and @Geetk172 — people actively working on bounties — were getting buried. two identity fields — author and committer — and they can be different people. metric growth — a substantial part of
- exabrial 5mo agoSigned Commits from known authors would also help!
- krupan 5mo agoThis is what we get for telling everyone how amazing AI is at writing code. It started with the people selling AI and for some reason tons of independent developers, some quite well respected in our field, piled on. Facebook now laying people off and saying it's because AI is just so good adds more fuel to the fire. Now you have a bunch of people fully confident that their AI friend is pumping out amazing code and submitting it to projects that are completely overwhelmed
- smaudet 5mo ago> and for some reason tons of independent developers Cowboy coders got a virtual cowgirl coder and sold it to everyone, hmm, maybe... (respected or not, solo devs don't always have the requisite skills to not be a cowboy, either due to lack of experience or lack of innate skill) I don't know that I completely buy this narrative, though. There has been a strong, top-down push for this since the "beginning".
- marcus_holmes 5mo agoNo, this is a result of unintended consequences. We made "Github contributions" a metric for people applying for dev jobs. So, of course, because devs are the kind of people we are, they started working out how to game that metric. Some folks decided to start paying bounties on bug fixes, features, etc. Those bounties are fairly trivial by western standards, but are significant for developing countries. This creates a new career for developers; racing to collect the bounties on offer. LLMs have exacerbated these problems by allowing existing people doing this to do it faster, and also allowing more people to pretend to be software developers and get in on the action. If we stopped allowing LLM-authored contributions we'd still have too many shitty PRs. It would just be back to pre-LLM levels of "too many". The answer is to make Github contributions valueless. Stop paying bounties, and stop using them to assess candidates.
- watwut 5mo agoThis feels like an alternative history. OS contributions were never all that important metric and overwhelming majority of developers have literally none. And it is not like AI spam would be limited or even primary targetted at bounties.
- agunapal 5mo agoMy first thought after reading the blog was, let me share the blog with Claude and ask it how bots can circumvent this. imo AI bots have significantly affected OSS and we need better qualitative measures to define success
- metalliqaz 5mo agoWhy does this company use the Slashdot logo?
- pixel_popping 5mo agoIt's so ironic as the website screams vibe-coded design on top of that.
- xdennis 5mo agoIt's quite ironic to complain about AI slop in a piece that's quite clearly AI slop. Soon there will be no more AI doomer comments. The bots will take over that job too. --- I'm working for an open source company, and my God, are 95% of contributions useless. There are really dumb ones where the bot writes 10 paragraphs about how he implemented the feature, but the entire changeset is adding one line to .gitignore or adding a CLAUDE.md file. There are even worse ones where the bot submits 3000 lines of code that seemingly works, but you have to spend an hour to figure out why it doesn't work. The dumb ones are so much better.
- Serhii-Set 5mo ago[dead]
- halapro 5mo ago[flagged]
- jmuguy 5mo agoThis is the correct assessment. This is not up to the open source community or individual projects to "figure out", any more than its up to me to figure out how not to get spam email.
- 20k 5mo agoYeah well, our corporate overlords have decided that you're going to take your slop whether you want it or not, so its very much up to us to figure out. Capitalism isn't going to jump off the disaster train any time soon
- pydry 5mo agoGithub team are seemingly too busy fighting downtime with ever more slop.
- drusepth 5mo agoWhat is the benefit of deleting a PR over just closing it? It seems like closing has the benefit of signaling what kinds of PRs aren't acceptable, which deleting would lose.
- TuxSH 5mo agoClosing a PR or issue still makes it discoverable in PR/issue search results, as opposed to deleting an issue.
- karussell 5mo agoThis. But OP wanted special requirements to open a PR. I.e. if those requirements are not met the PR is never visible to all and so admins can reject spam PRs without giving them a platform.
- nubinetwork 5mo agoWhile git has always allowed this, I don't really like the idea that someone can write some code, slap my name on it, and push it to their repo.
- codazoda 5mo agoI think this is why signed commits are also supported. My first thought was that this probably doesn’t work with signed commits. But, maybe it does since they are listed as the commiter.
- mococa 5mo agoYou can sign your commits with OpenPGP.
- mschuster91 5mo agoYup. At the very least, the "big dogs" aka Github and Gitlab should allow you to "claim" an email address to an account and only link it up when the commit in question either directly got authored from the web UI or got cryptographically signed.
- syezdin 5mo agoInteresting
- KaiShips 5mo ago[flagged]
- cemoktra 5mo agoAI company annoyed by AI ... Surprise
- kazinator 5mo ago> Final Words > While GitHub reports massive metric growth — a substantial part of which is AI-generated — we as an open source project team have to do the heavy lifting of cleaning up AI slop from our repository and come up with esoteric workarounds to keep the level of legitimacy of our open source audience. AI generated slop!
- 9front 5mo agoMusk before the verdict: "It's not okay to steal a charity" Altman after the verdict: "It's okay to steal a charity"
- karel-3d 5mo agoI don't understand how clicking "I agree" a few times will stop the AI bots? The captcha - maybe.
- yieldcrv 5mo agoreindeer games
- xivzgrev 5mo agoI like how they are taking a stand against vanity metrics. Rare to see that these days
- foresto 5mo ago> If the email matches their GitHub account, GitHub links the commit to their profile and grants them contributor status. When the article mentioned email matching, I was concerned that it would break down when a contributor's email address changes. (I have contributed to more than a few projects over the years, using email addresses that no longer exist.) However, it looks like they're not using the email address recorded in the author's original git commit, but instead a GitHub-generated address whose unique parts are the GitHub user ID and username. That should survive authors changing their email addresses. It would still break down if a contributor loses access to their account and has to create a new one, but that's probably less common.
- kittikitti 5mo agoThere's got to be a concept to differentiate the industry plants who start an "open source" project that has enough funding for a $900 bug bounty. They are speaking and developing in the language of corruption and they don't even know it. Of course you will receive AI bot spam, but unfortunately it will continue if you don't take a hard look in the mirror.
- kestiny 5mo ago[flagged]
- syi0808 5mo ago[dead]
- bykhun 5mo agoYou should release this as a service.
- kspetkov79 5mo ago[dead]
- carschno 5mo ago> It's especially sensitive for a VC-backed startup that is measured thoroughly by GitHub activity, but we have to pull the trigger: This sentence also illustrates the absurdity of this investment model. It imposes a trade-off between building good software, and complying with the investor's metrics. They probably call such metrics evidence-based, but this example shows that they arbitrarily capture some numbers to obscure the lack of meaningful measurements.
- andrelaszlo 5mo agoI also found it a bit ironic that it comes from an "AI company" (whatever that means) with a GitHub agent as part of their product.
- bloppe 5mo agoIt's called a signaling game. Of course it's dumb, but how else do you measure traction besides revenue? Building good software is a small part of running a business.
- carschno 5mo agoI don't know, and I think there is no easy answer. The point is: the investors don't know how to measure traction either, so they just measure GitHub activity instead, even at the very moment in which it becomes obvious that it does not capture actual traction. The absurdity lies in the statement that the developers still need to gain actual traction while putting additional effort into gaming that metric to satisfy their investors.
- antran22 5mo agoAt this point we should be convinced that it's in Github and Macro$lop's narrative to encourage fully automated, LLM-assisted PR bombing, because "muh future of development" and what not. If they do care about combatting spam, they would have already: - Protect the PR submitting feature behind some CAPTCHA - Give repo owners some way to manage external contributors, instead of forcing them to do hack like this article Just move to Codeberg, src.hut, or Gitlab even. Serious contributors will go there with you, the lazy people with LLM farming Github karma probably won't.
- pierotofy 5mo agoI stopped most spam with a simple AGENTS.md. It actually seems to work (for now). https://github.com/LibreTranslate/LibreTranslate/blob/main/AGENTS.md https://github.com/LibreTranslate/LibreTranslate/blob/main/A...
- bunzee 5mo ago[flagged]
- adam_idress 5mo ago[dead]
- iiTzSYREX 5mo agoI think it's a great approach. I checked the repo and saw that each contributor onboarding triggers the full CI pipeline, which is visible from the CI logs, including a Docker image build, GCP authentication, and a full Helm deploy. Aren't you guys wasting GCP compute and other things? I am no expert in this, it's just something I noticed.
- zazibar 5mo agoLLM-generated slop about LLM-generated slop, wonderful.
- martinloop 5mo ago[flagged]