Settings

Theme

Ask HN: Someone has committed 20K+ LoC to a PR, exhausting my CI & AI workflows

4 points by zacian 4 months ago · 11 comments · 1 min read

Reader

Hi HN, I'm maintaining an OSS project, and someone raised a PR a few days earlier, and since then, 20K+ LoC has been added to the PR. There are two new accounts, but they lack details on how to contact them, only providing usernames.

PR: https://github.com/srbhr/Resume-Matcher/pull/497

Accounts: 1. https://github.com/lololop67 2. https://github.com/ririyoungG

I've also found out from the PR that they're hosting the project somewhere, without any data disclaimer. Since this project is an AI resume builder, the accounts hosting the project can easily extract private data, such as phone numbers, emails, and addresses, and use it for malicious purposes, scams, etc. And that's what I'm more worried about. :(

I never intended to paywall this project. My goal was to provide a local first alternative to some online resume builders, and the accounts are doing the exact opposite, and they've hosted it at: https://gojob.ing/

I've tried commenting on the PR about the features they're working on, but I haven't received any replies so far.

What am I supposed to do here?

franky47 4 months ago

Close the PR, and if they open a new one, block them from the org.

There is a setting to prevent PRs from recently created accounts, you might want to turn that on too: https://docs.github.com/en/communities/moderating-comments-a...

  • zacianOP 4 months ago

    Thank you, I've done this. I've discovered that many such repositories have been hit by spam and commits that inject RCE or Adware in the name of contributions.

dv_dt 4 months ago

You probably want to turn on manual approval for running ci on external prs

  • jjice 4 months ago

    As much as it's great to have a fully automated process, sometimes a thin audit layer is worth it's weight in gold. Seems like the volume on this repo wouldn't be too bad in this case.

    • zacianOP 4 months ago

      > sometimes a thin audit layer is worth it's weight in gold.

      Yes, 100%

  • zacianOP 4 months ago

    Yes, I'll set that up and establish some rules for communicating your change and contribution to the project.

zacianOP 4 months ago

[Update]: Surprisingly, both accounts are either gone or have changed their usernames. The closed PR has been deleted and is no longer available.

akkad33 4 months ago

Close it?

  • zacianOP 4 months ago

    Yes, I've done that. Tried reaching out to those accounts again, but still no response.

Patt_ 4 months ago

just close it

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection