Settings

Theme

AI Is Spamming Open Source Repos with Fake Issues

thenewstack.io

17 points by CurtHagenlocher 10 months ago · 4 comments

Reader

robrtsql 10 months ago

It's like Hacktober (where a few YouTube assholes showed a bunch of non-developers how to waste maintainer's time with bogus PRs in order to get free stuff from DigitalOcean) except substantially worse because these issues take longer to dismiss. Horrible.

  • cratermoon 10 months ago

    Also, there are (or were) organizations that give their programmers incentives for finding and filing CVEs. Naturally that's lead to lots of low-quality CVEs, and with AI and other automated tools it's become easy for low-information programmers to generate reports on code they have zero understanding of.

Lockal 10 months ago

Examples: https://github.com/apache/airflow/issues?q=is%3Aissue%20stat...

Other than the content (which indeed makes no sense), these usually can be recognized by subjective adjectives and polish language[1].

[1] https://news.ycombinator.com/item?id=42864854

cratermoon 10 months ago

A related problem has hammered the National Vulnerability Database and similar repos with CVEs, as far back as 2023: https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-eve...

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection