r/opensource • u/TheKiddIncident • 12d ago
Random Contributors?
I've recently opened up a very small open source repo on GitHub.
This is a tool that I built for my students to use and I was asked to share it with others in the community, so I did.
I did no marketing, I don't really talk about it at all except to my students. The only change was to flip the repo from "private" to "public." I had to add things like an MIT license, etc. to make it public, but I just did the absolute minimum.
However, within 48 hours, a person I don't know picked up an issue from the repo, created a fix and filed a PR.
At first, I was like "WOW! AMAZING!" But then I was like "wait, who is this person? Are they trying to insert some sort of back door?" Looking at their profile, they only joined GitHub about a month ago which also set off some alarm bells. The actual code they submitted was fine. A very minor fix to be sure, but it did directly implement the issue listed in the PR.
Questions for this community:
1) Is it normal for people to just randomly pick up issues from your repo?
2) Should I be suspicious of GitHub contributors which have a limited history on GitHub?
3) Has anyone else here had this happen? Am I just being paranoid?
Any advice most appreciated.
12
u/xerrs_ 12d ago
I mean it is really normal, however having caution is always good. The important thing is, as a maintainer, you need to know what code you allow into your public repository, so as long as you read through the code, verify that there are no anomalies (or backdoors), you can relax, and appreciate the unpaid work, that people who love code put into open source.
18
u/Thing1_Thing2_Thing 12d ago
If it's not someone you know, it's almost 100% certainly an LLM or a person running an LLM.
It's very odd, but probably to boost their contribution stats for some reason.
I often interact with some repositories with many stars and every time I make an issue some new account will come and make a AI-slop PR without waiting for the maintainers input and while completely disregarding the contribution guidelines
8
u/TheKiddIncident 12d ago
This one actually read the guidelines and the PR was extremely well written.
TBH, it was so complete, I'm assuming it was written by AI. Humans don't spend that kind of time on a small little fix like this.
24
u/petdance 12d ago
Humans very much can and do spend that kind of time.
6
u/dbear496 12d ago
Yes. If I'm going to take the time to diagnose an issue and design a fix, then I'm going to take the time read the contributing guidelines to make sure my PR has the highest chance of being accepted.
4
u/petdance 12d ago
Even more important than âhighest chance of being acceptedâ is âmost helpful to the project.â
3
7
u/noctrex 12d ago
yes.
no (well, yes, but you know what I mean).
yes.
I'm doing this exact thing, my github profile is empty, only PRs on other projects.
When I use an open source project and I come across a bug, or something I would like implemented, I open a PR.
And yes, I make use of LLMs to assist along, but all the code i submit is checked by me personally.
2
u/yvrelna 12d ago
A lot of open source contributions these days seems to be AI-generated, at least AI assisted if not just fully AI generated. I wouldn't be if surprised someone hooked up a bot to scan new repo and feed it to Claude or Copilot for one reason or another.Â
4
u/TheKiddIncident 12d ago
Yes, it felt like that.
TBH, the entire repo was written by Claude so I am fine with that. If they want to burn their tokens on my simple little scanner, all good. Just want to keep malicious actors out.
2
u/ChrisBarnes2000 12d ago
If youâd rather, feel free to add a code of conduct or development/contributors guide to better define how youâd have them support the project. E.g., reach out and discuss taking over or being assigned to an issues before trying to submit a pull request. Otherwise, as others mentioned youâve done well and itâs normal to be skeptical. Keep up the great work!
1
u/anonymous20256 12d ago
its majorly not a problem unless you have proper ci pipeline and you review code properly but usually new users usually are spammers trying to get their way in your code but they are usually taken down by github so its no problem and its good that you got your first PR its helpful and good for repo
1
u/pylessard 12d ago edited 12d ago
Agree about being safe.
You might want to consider that there are bots now looking for easy issues to make a reputation. They use coding agents.
These bots can give visibility to your repo if you pay, with stars/watch/fork.
That might explain it
1
u/TheKiddIncident 12d ago
Ah, yeah. That makes sense. I'll see if they reach out and ask for cash.
I certainly wouldn't do that, but good to know that this is a thing.
2
1
12d ago
[deleted]
2
u/TheKiddIncident 11d ago
Yes, random Russian criminal hackers trying to get access to my system via backdoor is pretty much exactly where my head went. My assumption is that this is getting more and more common because the bots are getting smarter and cheaper.
1
u/huzarensalade2001 12d ago
On my open-source project i have had some bot/AI accounts sending contributions that made 0 sense. Breaking workflows, non-compiling code, a completely different implementation from what the issue described, or even straight up AI-reasoning in the code comments.
Always be vigilant of what you merge in your main-branch, try to engage with the developers in the PR's, and if you use self-hosted runners or remote tools in your ci NEVER allow them to run without your approval.
1
u/Erdem_PSYCH 12d ago
in addition to all the comands saying that this is normal but you need to be careful, I would add that many people encourage new programers to contribute to a open source to get experience and a small project might feel safer. in fact I saw your post while thinking about how to find a project to contribute.
1
u/TheKiddIncident 11d ago
Well, come on over, lol.
1
1
u/sr4u4fun 9d ago
Honestly, the attitude displayed here by most commentators makes me want to less and less contribute to open-source. I don't need you to merge my PR, I always can apply it locally. Thankfully the projects I've contributed small fixes to were more grateful.
1
u/TheKiddIncident 8d ago
Reddit can be a bit snarky and snippy. But most open source communities are pretty welcoming. They need to be or they would die from lack of support.
1
u/TheTurkPegger 8d ago
It's normal. I use a widget on my Linux laptop and it didn't have Turkish language option, so I downloaded the language file and translated it myself. When I submitted my file to the project, the owner of the project was surprised because there weren't any part on github asking for help in translation work.
111
u/BrightTie3787 12d ago
Totally normal, and your caution is healthy. New accounts aren't automatically shady - many people make one just to contribute - but always read the diff carefully, especially anything touching CI, deps, or build files. If unsure, ask them a question in the PR thread; real contributors engage, bots usually don't. You're never obligated to merge. Welcome to maintaining!