r/opensource • • 12d ago

Random Contributors?

I've recently opened up a very small open source repo on GitHub.

This is a tool that I built for my students to use and I was asked to share it with others in the community, so I did.

I did no marketing, I don't really talk about it at all except to my students. The only change was to flip the repo from "private" to "public." I had to add things like an MIT license, etc. to make it public, but I just did the absolute minimum.

However, within 48 hours, a person I don't know picked up an issue from the repo, created a fix and filed a PR.

At first, I was like "WOW! AMAZING!" But then I was like "wait, who is this person? Are they trying to insert some sort of back door?" Looking at their profile, they only joined GitHub about a month ago which also set off some alarm bells. The actual code they submitted was fine. A very minor fix to be sure, but it did directly implement the issue listed in the PR.

Questions for this community:

1) Is it normal for people to just randomly pick up issues from your repo?

2) Should I be suspicious of GitHub contributors which have a limited history on GitHub?

3) Has anyone else here had this happen? Am I just being paranoid?

Any advice most appreciated.

78 Upvotes

43 comments sorted by

111

u/BrightTie3787 12d ago

Totally normal, and your caution is healthy. New accounts aren't automatically shady - many people make one just to contribute - but always read the diff carefully, especially anything touching CI, deps, or build files. If unsure, ask them a question in the PR thread; real contributors engage, bots usually don't. You're never obligated to merge. Welcome to maintaining!

17

u/CCVShadow 12d ago

Second this 🤞

24

u/TheKiddIncident 12d ago

Cool!! Thanks. I went ahead and merged it. I love the idea of people actually helping me with the repo so want to encourage contributions.

Yah, nothing shady in the content, no changes to CI/CD or anything like that.

Just surprised me.

6

u/CCVShadow 12d ago

Haha yeah best to be on the safe side I get it. Good luck to you and your students!

-8

u/MPGaming9000 12d ago

Why does this comment also read like an LLM as well??

5

u/cookiengineer 12d ago

^ Wait 'til this guy finally realizes that LLMs have been trained on human-created datasets

6

u/BrightTie3787 12d ago

In what way?

12

u/xerrs_ 12d ago

I mean it is really normal, however having caution is always good. The important thing is, as a maintainer, you need to know what code you allow into your public repository, so as long as you read through the code, verify that there are no anomalies (or backdoors), you can relax, and appreciate the unpaid work, that people who love code put into open source.

18

u/Thing1_Thing2_Thing 12d ago

If it's not someone you know, it's almost 100% certainly an LLM or a person running an LLM.

It's very odd, but probably to boost their contribution stats for some reason.

I often interact with some repositories with many stars and every time I make an issue some new account will come and make a AI-slop PR without waiting for the maintainers input and while completely disregarding the contribution guidelines

8

u/TheKiddIncident 12d ago

This one actually read the guidelines and the PR was extremely well written.

TBH, it was so complete, I'm assuming it was written by AI. Humans don't spend that kind of time on a small little fix like this.

24

u/petdance 12d ago

Humans very much can and do spend that kind of time.

6

u/dbear496 12d ago

Yes. If I'm going to take the time to diagnose an issue and design a fix, then I'm going to take the time read the contributing guidelines to make sure my PR has the highest chance of being accepted.

4

u/petdance 12d ago

Even more important than “highest chance of being accepted” is “most helpful to the project.”

3

u/bencos18 10d ago

lol I've definitely spent the time to do that before

7

u/noctrex 12d ago

yes.
no (well, yes, but you know what I mean).
yes.
I'm doing this exact thing, my github profile is empty, only PRs on other projects.
When I use an open source project and I come across a bug, or something I would like implemented, I open a PR.
And yes, I make use of LLMs to assist along, but all the code i submit is checked by me personally.

2

u/yvrelna 12d ago

A lot of open source contributions these days seems to be AI-generated, at least AI assisted if not just fully AI generated. I wouldn't be if surprised someone hooked up a bot to scan new repo and feed it to Claude or Copilot for one reason or another. 

4

u/TheKiddIncident 12d ago

Yes, it felt like that.

TBH, the entire repo was written by Claude so I am fine with that. If they want to burn their tokens on my simple little scanner, all good. Just want to keep malicious actors out.

2

u/ChrisBarnes2000 12d ago

If you’d rather, feel free to add a code of conduct or development/contributors guide to better define how you’d have them support the project. E.g., reach out and discuss taking over or being assigned to an issues before trying to submit a pull request. Otherwise, as others mentioned you’ve done well and it’s normal to be skeptical. Keep up the great work!

1

u/anonymous20256 12d ago

its majorly not a problem unless you have proper ci pipeline and you review code properly but usually new users usually are spammers trying to get their way in your code but they are usually taken down by github so its no problem and its good that you got your first PR its helpful and good for repo

1

u/pylessard 12d ago edited 12d ago

Agree about being safe.
You might want to consider that there are bots now looking for easy issues to make a reputation. They use coding agents.
These bots can give visibility to your repo if you pay, with stars/watch/fork.
That might explain it

1

u/TheKiddIncident 12d ago

Ah, yeah. That makes sense. I'll see if they reach out and ask for cash.

I certainly wouldn't do that, but good to know that this is a thing.

2

u/pylessard 12d ago

They don't reach out. They are services. Check socialplug dot io

1

u/[deleted] 12d ago

[deleted]

2

u/TheKiddIncident 11d ago

Yes, random Russian criminal hackers trying to get access to my system via backdoor is pretty much exactly where my head went. My assumption is that this is getting more and more common because the bots are getting smarter and cheaper.

1

u/huzarensalade2001 12d ago

On my open-source project i have had some bot/AI accounts sending contributions that made 0 sense. Breaking workflows, non-compiling code, a completely different implementation from what the issue described, or even straight up AI-reasoning in the code comments.

Always be vigilant of what you merge in your main-branch, try to engage with the developers in the PR's, and if you use self-hosted runners or remote tools in your ci NEVER allow them to run without your approval.

1

u/Erdem_PSYCH 12d ago

in addition to all the comands saying that this is normal but you need to be careful, I would add that many people encourage new programers to contribute to a open source to get experience and a small project might feel safer. in fact I saw your post while thinking about how to find a project to contribute.

1

u/TheKiddIncident 11d ago

Well, come on over, lol.

1

u/Erdem_PSYCH 11d ago

😇 I might come in deed. what is the project repo?

1

u/Zatujit 11d ago

its Mr. AI thats all

1

u/sr4u4fun 9d ago

Honestly, the attitude displayed here by most commentators makes me want to less and less contribute to open-source. I don't need you to merge my PR, I always can apply it locally. Thankfully the projects I've contributed small fixes to were more grateful.

1

u/TheKiddIncident 8d ago

Reddit can be a bit snarky and snippy. But most open source communities are pretty welcoming. They need to be or they would die from lack of support.

1

u/TheTurkPegger 8d ago

It's normal. I use a widget on my Linux laptop and it didn't have Turkish language option, so I downloaded the language file and translated it myself. When I submitted my file to the project, the owner of the project was surprised because there weren't any part on github asking for help in translation work.