Live data from Hacker News

PR spam today looks like email spam in the early 2000s

greptile.com

71–80 of 167 posts

Re: PR spam today looks like email spam in the early 2000s

#71
post #37

AI agents who review the slop created by other AI agents is not the answer here. I much prefer a blanket ban on PRs and issues created by AI agents (which is what I personally do for my repos; so far I have closed one[1]). In fact I would love a github alternative which considers AI contributions to be a breach of their terms of use and ban any people who let AI agents loose on their platform. 1: https://github.com/r…

But what about the good AI driven contributions though? Do you categorize all AI changes as slop by default or only the real bad ones that mix refactoring and tons of other unrelated changes with a fix? Some can fix real issues, with a well targeted fix (not rewriting the world), well defined test and write up. If you accepted PRs before for other issues, you should be able to review and accept those too.

I think the litmus test is roughly "is this obviously AI created" - if it's a well crafted PR that doesn't do the things you mention, and solves a genuine issue in a sensible way then you'd not be able to tell.

The other part of the litmus test is "does the person submitting actually understand what they're submitting and why" - which is arguably not required for PRs that you'd otherwise accept, but since you have to put time and effort into determining whether a given contribution is ok to merge, it's common decency for the submitter to have done a self review first (AI or no AI)

Re: PR spam today looks like email spam in the early 2000s

#72

If anyone is interested in what it was like fighting spam in the early 2000s, I worked for a company that captured spam, analyzed it and then passed the analysis s on to the law firms of the big email providers for targeting under CAN-SPAM. Twitter thread about it below but happy to do a AMA here. https://x.com/alexpotato/status/1208948480867127296?s=20

It's the same scaling issue we've had since the advent of the internet, and why spam and social media became such a dumpster fire. There are many things in life that are perfectly fine when uncommon / rare, but are disastrous when done cheaply at scale.

Re: PR spam today looks like email spam in the early 2000s

#73
post #37

AI agents who review the slop created by other AI agents is not the answer here. I much prefer a blanket ban on PRs and issues created by AI agents (which is what I personally do for my repos; so far I have closed one[1]). In fact I would love a github alternative which considers AI contributions to be a breach of their terms of use and ban any people who let AI agents loose on their platform. 1: https://github.com/r…

But what about the good AI driven contributions though? Do you categorize all AI changes as slop by default or only the real bad ones that mix refactoring and tons of other unrelated changes with a fix? Some can fix real issues, with a well targeted fix (not rewriting the world), well defined test and write up. If you accepted PRs before for other issues, you should be able to review and accept those too.

> But what about the good AI driven contributions though?

If even a preponderance of AI driven contributions were good, there wouldn't be blog posts and announcements making HN's front page daily about how various OSS projects and/or prominent figures were figuring out how to filter them/exclude them entirely.

If AI code was good, there wouldn't be such a thrust among so many varying communities to remove it, or ignore it.

There is, because it isn't, and because maintainers are getting fed up with it. There are good PR's just like there are emails that aren't spam that get caught in spam filtering, but spam filtering is still the default position because to allow it all is onerous to the people involved.

I think the biggest issue is simply that these tools, like any labor-saving tool, are being marketed most heavily to people who do not know how to create software. "Write code even if you know nothing about writing code." "This will let people who aren't software engineers make software." "Democratize development." On and on.

This isn't even new, we've been dealing with this since I was a little one, back then we called them script kiddies. Now they're vibe coders and their existence continues to be a boil on the ass of proper software engineers. Instead of claude, you copied code off of Stack Overflow without understanding what it did, and often foot-bulleted yourself in the process.

Re: PR spam today looks like email spam in the early 2000s

#74
post #70

Earlier quoted context omitted.

Unfortunately "I donated money/tokens to open source" doesn't land interviews as well as "I'm a big contributor to open source" People spamming Open Source repos with AI PRs aren't trying to help Open Source, they're trying to build a brand, some kind of credible online presence with their username on it, or whatever else. It's purely selfish and completely opposite to the spirit of Open Software imo

Maybe I'm optimistic or not typical but in my experience people submit random PR to open source projects because they really want the project to do xyz for their own project/reasons, and the project doesn't do xyz. And the PR is considered "spam" because the maintainer doesn't see xyz as part of his needs or his vision for the project.

Being able to donate tokens won't help with that, unless the project maintainers also want the project to do xyz.

Re: PR spam today looks like email spam in the early 2000s

#75

If anyone is interested in what it was like fighting spam in the early 2000s, I worked for a company that captured spam, analyzed it and then passed the analysis s on to the law firms of the big email providers for targeting under CAN-SPAM. Twitter thread about it below but happy to do a AMA here. https://x.com/alexpotato/status/1208948480867127296?s=20

Ironically one of the first recognizable spam campaigns was perpetrated by lawyers: https://en.wikipedia.org/wiki/Laurence_Canter_and_Martha_Sie...

Re: PR spam today looks like email spam in the early 2000s

#76

Earlier quoted context omitted.

I would argue this is naive and there's very little evidence to support this opinion other than just wishing it was true. It may happen on smaller projects with few users but not in meaningful large projects.

> there's very little evidence to support this opinion other than just wishing it was true Building a brand doesn’t require submitting to someone else’s open source project. You can do the same thing by creating your own OSS project. For a lot of them it’s probably a little of column A and a little of column B. If people are submitting in their real name it’s more likely they’re building a brand. I also think it’s po…

Oh but you see, own OSS projects are not worth much unless they got stars. Anyone can now fill their GitHub space with a hundred vibecoded projects in an afternoon, it's worth nothing unless it comes with social proof.

Re: PR spam today looks like email spam in the early 2000s

#77
post #19

Earlier quoted context omitted.

Like a video/phone call?

I'm not sure if AI can do those today, but they probably can in the near future. (probably we will be able to see obvious "that can't be human" for a while longer)

If you (or even your pet LLM) is able to set up v4l-loopback and some convincing realtime image/audio gen I think that's a signal that your PRs might be worth reading.

Re: PR spam today looks like email spam in the early 2000s

#78
post #19

Earlier quoted context omitted.

Like a video/phone call?

I'm not sure if AI can do those today, but they probably can in the near future. (probably we will be able to see obvious "that can't be human" for a while longer)

The point at which an AI can convince me in a video call revolving around a complex social interaction like an introduction and discussion of interests that it's human I'm gonna go ahead and let it have the title.

Re: PR spam today looks like email spam in the early 2000s

#79
post #19

Earlier quoted context omitted.

Like a video/phone call?

I'm not sure if AI can do those today, but they probably can in the near future. (probably we will be able to see obvious "that can't be human" for a while longer)

It already can and it’s a big problem in recruitment. But for PRs I suspect it isn’t a big concern because this filter is to weed out PR spam from people who want to invest time in the project.

Re: PR spam today looks like email spam in the early 2000s

#80
I remember that on the not so early days of the internet around 1993, I managed to exchange emails with pretty much important people, known professionals and even got responses to my questions. It looked like a very very small world. Then, came the spam.

I really hate the marketing people mindset. It fucks everything that is nice.

Post reply on HN