DigitalOcean's Hacktoberfest Is Hurting Open Source
blog.domenic.me
blog.domenic.me
I can see why this happens, though. I've noticed that a whole bunch of projects have `good-first-issue` being something like "Re-architect module loading system" while most commits are like "correct typo". Like, jeez, man.
The participants are probably just pattern-matching against the commits available.
EDIT: Decided to go look at the spam that OSM got (a project close to my heart) and what the hell, man, look at this diff
<removed>
* Tom Hughes [@tomhughes](https://github.com/tomhughes/)
* Andy Allan [@gravitystorm](https://github.com/gravitystorm/)
+
+
+ Made with Love
This is just awful! I really feel for the maintainers. This user is just adding nonsense to a bunch of places.'EDIT again: Whoops, guys, I didn't mean to cause more spam to the project. Removed the diff link. Jesus Christ, I ended up becoming the villain I was complaining about by linking it.
I can’t understate the simplicity of doing it, and I’d be nervous about someone taking the other approach as indicative of their technical depth. Then again, they’re already spamming READMEs so it’s not as if it was a strong signal to start with.
I don't ever see that as a negative signal, but I do see it as a positive signal if I can just read your code, so if you write good code in public and you hide it, I can't find it.
Of course, whether you care is up to you, but if I find solid code there I'm going to recommend skipping technical evaluation if you're considering working with me.
It doesn't hide your work at all (commit frequency is an awful metric of valuable work, some people do a lot of "fix typo" commits).
Every employer worth working for will at least look at some actual code you've written, both in your own projects and in contributions to others.
And even then an in-person interview should be able to offset any github activity or lack thereof.
It's a fitting allegory, though. This contest has used free T-shirts to solicit open-source contributions in the same way that the industry has used high salaries to solicit creative and impactful contributions.
Now imagine that you're trying to fill a position, and these pull requests are analogous to candidate interviews. You might start to have some sympathy for people who believe that we need some sort of professional certification for the trade.
It's unfortunate considering the democratizing promise of low-cost computing, but how else can you effectively deal with this "market for lemons" caused by large swaths of people acting in blatant bad faith?
When seeming is taken for being, being becomes seeming. \
When nothing is taken for something, something becomes nothing.Which just goes to show how bad the status quo is.
Be very careful assuming that a payment motivates open source developers. If you offered to help me do something for an hour for whatever internal motivation you might have, and afterwards I offer you $5 for your time, you would likely be demotivated.
On the other hand if you offered to buy them a beer or a coffee it would probably be very motivating. I'm not sure why this is. Maybe cash just feels lazy and impersonal, so the amount being offered has to be big enough to counter that feeling.
That is certainly a plus, but I don't think that's all of it. If I was working on something for a friend, that they had no idea how to help with. Then at some point they dropped off a snack or drink as a thank you, I would be happy about that. If they offered me a $100 bill I would be offended because they're not my boss, and my time is worth more than that.
I want to say that a small token of appreciation feels better than having my value quantified to an insulting amount. However, it may be even more basic than that. Food is a powerful reward, there is a reason it is used to train animals. It also could be that introducing money makes something feel like an obligation.
For anyone who is working, people are "giving" them $5 all the time. But they probably don't have people buying them coffee/beer/lunch all the time.
here is the work that you cited if i am not wrong.
"Volunteer work is an increasingly large, yet ill-understood sector of the economy. We show that monetary rewards undermine the intrinsic motivation of volunteers."
-- https://ideas.repec.org/p/zur/iewwpx/007.html
The earlier sentence make it clear they are talking about monetary rewards specifically, not any kind of reward. A t-shirt might notionally have a $ value, but it is not a monetary reward. Plus, the nature of a branded t-shirt has an obvious team-participation / prestige value.
If rewards demotivate people, we should also avoid positive recognition, or praise, which is a form of reward; of course this is unintuitive, so I assume monetary rewards are a special case.
We all hear the stories of the person who saves a company a million dollars, and then gets giving a coffee cup (or an attaboy) for recognition.
It gets even trickier when the giver and the receiver have wildly different incomes.
Generally I find money to be a terrible proxy for what I actually value, but other options are worse proxies!
Good PRs are valuable, but require lots of work. Spam is not valuable, but it also does not require basically any work.
Hacktoberfest equally rewards both good PRs and spam equally. With those incentives, what are people logically going to produce?
Well, the answer is clearly "a lot of people," unless you can think of an alternate explanation for the increase is spam during Hacktober.
Why they want a damn T-Shirt so much is a totally valid question, though. I don't understand that either.
In both cases I get that what I care about gets into the project. It's enough for me.
You already got payment up front: software that the author(s) have made available to you for free.
You get payment by the author spending time to review your changes.
You also get payment afterward: free maintenance for your pet feature. (Not guaranteed of course but generally the case.)
I've been saying it for a long time, but the reason that this and other problems (like high developer burnout) seem like especially bad problems that the world of "software development" is facing is primarily because they're especially bad in the GitHub culture (and as a consequence of that culture), and the developers who are experiencing the worst of it are part of that community. Ditch the 'Hub, its userbase, and what is considered "best practice" there, and then many of these problems get dialed back a lot.
Much like follower counts on other social media sites, GitHub's contribution graph and profile timeline should have never been public. They should have been neat features of your personal dashboard that you alone are able to see when you're signed in—providing some form of encouragement à la the Seinfeld hack and to help you manage your work—but not for others' eyes. The gamification of "social" leads to degenerative behavioral patterns.
Please revisit my original comment. When I wrote it, I put some effort into qualifying things to make it clear that I'm not talking about just what happens on GitHub on the site. I referred to its culture. The things you just described are part of that culture, and very notable elements of it.
This sounds like "Without GitHub you will get less spam", which is probably true, but I think the reason is not "github is bad", it's: Less people will find your project.
Maybe that's a worthwhile trade-off, but it's very different from "all will be better without Github"
Making up quotes is not cool; those aren't my words, and that's not my position, so I'm not going to be gulled into defending it or kept from calling attention to what amounts to a sleight of hand here, even if it wasn't intentional.
(And this really chafes, because after I wrote what I meant, I even revised it to pre-empt[1] getting sucked into a discussion where someone responds to the wrong reading—specifically trying to avoid things like this. But when people don't even respect the constraint of sticking to others' actual words and instead conjure up other words that make for a more convenient world[2] to operate in, then there's almost nothing that can be done.)
> This sounds like "Without GitHub you will get less spam"
Well, it shouldn't; that's reductive.
If the bad stuff that arises from GitHub, its culture, and its practices were proportionate to its size, that would be one thing. (But also not itself a good reason not to consider ditching it—just like it's not obviously true that it would be a good idea to use Windows because the risk of malware is rational given its size as a target.) What's bad about GitHub, though, might in fact be disproportionate to its size—and in some cases, especially with respect to the practices that get promoted in that world, are things that are bad irrespective of GitHub's size.
1. https://pchiusano.github.io/2014-10-11/defensive-writing.htm...
2. https://wiki.lesswrong.com/wiki/Least_convenient_possible_wo...
You have explained your criticism of GitHub, and I agree that it should have done things differently from the beginning. Still, your proposed solution for users is literally to "Ditch the 'Hub", promising that "many of these problems get dialed back a lot". It's really not a far stretch to "all will be better without Github".
This is accurate. Let's let that be the place we stay.
> I find that "all will be better without Github" is a reasonable short approximation [...]
Well I don't, and it's my position, isn't it? It's not accurate. I don't think that "all will be better without GitHub"—and what's more is that I practice the "without GitHub" part; I have the firsthand experience to be able to say it's not true, so I wouldn't try to tell anyone that it is—and I didn't. I'm responsible for my own ideas, not ones imagined upon me.
Moreover, if I argue that A and B are not equivalent and that I prefer deal with A in its original form and not B, and you argue that they are equivalent, it's not rational for either party to insist that we deal with B in place of A. So let's not.
That is false. Firstly, even if your project is not hosted on github, clones of it will appear on github anyway.
Secondly, planting yourself in the middle of a vast ocean of garbage is not a good strategy for being found. You might be thinking of the Github of twelve years ago.
Don't think it's devolved at all this has been the norm from the 80's onwards (perhaps earlier).
Look at how fractured open source is today and the sort of egos that come with it everywhere you look. While the points made in this article are valid, it's great that someone is incentivising people to interact with various projects rather than do their own thing rather than climb blindly up the same treacherous mountains others have done long ago.
Hey, also why not rewrite it in rust :)
Being a contrarian is easy, fixing these well acknowledged problems is hard.
This quote can be applied to organizations on the wane.
This happen a few years back in UI design when designers started to put more work into presentation of projects than projects themselves.
~1000 single line/word pull requests in the last 3 hours, almost all worthless rubbish. The scale of the problem is pretty severe.
To pick a single example: https://github.com/Geng-WD/websiteTest
A little personal Java project, unchanged in 3 years, where a new "contributor" has submitted a pull request where they add a comment with their own name in one commit, and then remove it and replace it with "Awesome coding website" in a second commit. 19 hours earlier another new "contributor" submitted a pull request to add a completely irrelevant mock gym web page (and they've done the same thing to a bunch of other randomly chosen repos).
If these people had to demonstrate valuable contributions over a longer span of time, I don't think any of this nonsense would be happening. There's no reason new CS students can't be respectful and put a little effort into doing something worthwhile, and they'll learn a lot more than from this mindless spamming.
I'll not advocate calling DigitalOcean on the phone, but tagging the CEO on the complaints on twitter might be more effective than tagging the community manager who professes he is not listened to.
I run engineering at Operation Code https://operationcode.org/ https://github.com/operationcode/
We've been massive fans of Hacktoberfest for the last 3 years because it has brought a MINIMUM 300% increase in quality pull requests compared to even the next best month of the year.
I even put my own money on the line to double down on the incentives with extra prizes in exchange for resolving multiple issues. I've made friends and long-term coding partners from the event as well.
I hope they never end Hacktoberfest, but I think they should definitely offer the ability for you to signal/flag that you're not interested in participating as a repository.
I understand there's negative consequences, I also anecdotally believe that Hacktoberfest is a net positive for open source.
That said, last year many repositories popped up with the sole purpose of letting people make garbage PR's to hit the minimum. I have a hard time understanding why someone who is a developer and wants the shirt is comfortable doing this, when all you have to do to really earn it is making meaningful improvements to someone's `README.md`.
not good enough. it needs to be opt-in. why is a random private company generating even more work for open source maintainers?
And of course one size does not fit all.
https://hacktoberfest.digitalocean.com/details#quality
> There's a seven-day review window for all pull requests before they count toward completing the challenge. Once a participant has submitted four eligible pull requests (ready-to-review, not drafts), the review window begins. This period gives maintainers time to identify and label spammy pull requests as invalid. If the pull requests are not marked as invalid within that window, they will allow the user to complete the Hacktoberfest challenge. If any of the pull requests are labeled as invalid, the user will return to the pending state until they have four eligible pull requests, at which point the review period will start again.<
So all the spammer needs are four projects with maintainers who are too busy IRL to flag spam posted to their repos?
Are we all now to be unpaid conscripts of DO's marketing department?
https://github.com/MattIPv4/hacktoberfest-data#diving-in-pul...
> "Of the 483,127 PRs submitted during Hacktoberfest, only 23,299 (4.82%) were identified as spam"
That is insanely high noise for hacktoberfest, especially when tagging spam "correctly" takes a non-insignificant amount of effort from the maintainers.
I was ready to rant about this post but … no, wow, this is very much warranted.
So, the spammers are probably intentionally targeting repos where folks aren't likely to bother marking as spam.
On a separate note, I do not understand why people care so much about mid-quality t-shirts...
Most likely a mix of "it's free", "it's easy", and "it looks nice on a CV". Perfect storm for a lot of students and juniors to spend an hour of their time on, without bothering to spend the extra two to actually make the contributions useful.
> Of the 483,127 PRs submitted during Hacktoberfest, only 23,299 (4.82%) were identified as spam, with 19,587 (84.07%) of those being in a repository that the Hacktoberfest team excluded from the competition for not following the shared values and 3,712 (15.93%) being labeled as "invalid" by project maintainers.
Spam submissions were sent to spam repositories, that hasn't been known for years.
From the article, they act like it's their burden alone:
> Their solution, per their FAQ, is to put the burden solely on the shoulders of maintainers.
But, as a contributor, I see plenty of links for me all over Hacktoberfest to report repositories that are also trying to skirt the system.
No, I didn't read the FAQ, but I imagine neither did a lot of maintainers, especially those that don't participate. The undercounting must be massive.
Here you go, you're an open source maintainer already in an often thankless role, take some extra work, with a side dollop of extra work labelling the crap extra work you're getting.
No kidding. GitHub requires you to wait several minutes (they don't say how much time exactly, but in my experience it's definitely > 2 min) between reporting something as spam. So you can't just go through your spam PRs in the morning and report them easily, you need to leave the browser tabs open and come back from time to time to submit spam reports. Not reporting is much easier, so the real figures are certainly higher.
EDIT: Ah, they don't even mean reporting spam to GitHub. Maintainers need to "opt in" to Hacktoberfest's own rules and change their own PR labeling system according to Hacktoberfest's wishes. What a pile of nonsense.
I had a great experience with Hacktoberfest last year. I tagged a few issues with Hacktoberfest and got a nice PR from someone showing me how to configure my Vue project for unit testing.[0] It was a non-trivial PR and a useful contribution.
1. Only count PRs that contain something like "#Hacktoberfest" in the GitHub comment accompanying the PR. This would make it easier for maintainers to weed out the spam or at least understand where it's coming from and what term to search for when they encounter this unprepared. Also, it would give "visibility" to the event, so it should even fly with management!
2. Only count merged PRs. Apparently DigitalOcean have a "reason" for not doing this, because some projects don't use the PR merging feature directly. I think they should reward users who educated themselves on this point and only opened PRs on projects that do merge them.
2. I think the other argument you could make against that is not everyone has the same time to merge. If it takes two weeks to get merged, I basically have to have the PR in by the second week of October.
Yeah same here, but as a contributor. I decided I wanted to make my PRs count and decided on a targeted effort of taking one mans tiling WM for Windows[1] and fixing enough of the stability issues and race-conditions I found to the point where I should be able to use it myself.
Not a single one of those PRs was “cheap”, and the resulting improvements in quality and stability has lead that WM now to seemingly have more users and doing better than it used to.
And now I have a tiling WM whick is actually usable the times I have to use Windows. Win win, as far as both I and that project-owner is concerned.
https://github.com/promcon/website/pull/158#issuecomment-701...
Some people were saying this could also be used to detect repositories that have "auto-merging" in order to add vulnerabilities to them later, perhaps using Hacktoberfest as a cover for more nefarious activities. That's strange, I haven't heard of projects that automatically merge certain PRs from arbitrary accounts.
I recently read "Working in Public" which was great, I recommend it. One interesting observation that was made: The perceived pipeline of user => casual contributor => active contributor => maintainer...is a lie. In the book they argue (convincingly) that you do not convert someone from casually contributing to actively contributing, it's instead that active contributors also make casual contributions.
What does that mean in this context? This company is operating under the assumption that they are helping by getting more people into the pipeline. In reality, what we need are active contributors who are invested in projects, not fly-by-night-i-want-a-shirt contributors.
For context I maintain https://www.CodeTriage.com which is a community of about 55,000 devs interested in open-source.
Many repos have a sharp bifurcation between tiny PRs by passers-by and big chunky ones by the fulltimers. The space between is a desert.
Who’s going to put in all the time to learn to understand a repo, only to make a small change. At that point you might as well keep going.
Yeah. How the maintainer(s)s of a repo respond to trivial typo fixes (real ones, not spam) is also a good way to test things / check for any weird attitudes.
Most of the time, PR's are accepted easily and swiftly. But sometimes (rarely), the response is strange or off putting.
There is the occasional PR that just sits there forever without being looked at too, which just shows the repo at that URL is dead / unmaintained. Also good to know before putting much time/effort in. ;)
I disagree.
As Github has been acquired by Microsoft, I would love to see other alternatives being supported by more projects/sites.
> Another promising route would be if GitHub would cut off DigitalOcean’s API access
I am pretty sure DigitalOcean is not doing this in bad faith or try to damage open source community but the author seems to be out for blood for what seems to be an oversight on the part of DigitalOcean, suggesting that this is a how DigitalOcean treats open source community and one should boycott their products.
That's not an "oversight".
The contest seems to be in good faith but had unintended consequences. Regrettable, but it happens. Give them a chance to fix it before trying to ruin their day over it.
Sometimes a really over-the-top reaction is the only way to get the attention of a large organization.
If it does motivate people and they like them, then fine: I guess it's just different strokes for different folks.
It pretty much boils down to this. Not only are vendor t-shirts actually a physical item but they are also often uniquely designed; many vendors only provide certain designs for certain events. So they really become a badge of honor and can gain in emotional value: "been there, got the t-shirt..."
It is. T-shirts are wear items and getting a free one that looks decent is one less that you’ll have to buy.
It’s a shame it has led to people spamming repos, however.
Just look at the kind of mayhem Black Friday precipitates, and that's not even free - just a promise of exceptional discounts.
The comedian Doug Stanhope has an amusing bit about free healthcare and how wastefully it would be consumed by Americans conditioned to maximally abuse anything offered free of charge.
Edit: I don't mean to suggest Americans have a monopoly on this sort of behavior, it's just the country/culture I'm by far most familiar with.
Thousands of students are all trying to get a low effort contribution in to have an extra line of "experience" on their resume and a T-Shirt from a western Silicon Valley company as signaling? Judging by the poor quality of the contributions, and the fact it's on GitHub, maybe folks studying IT?
That type of academic spam isn't new sadly [0].
[0] https://academia.stackexchange.com/questions/41687/what-is-b...
In most of these cases, it usually starts with someone really talented doing it with all the good intentions, and everyone else wanting to get in on that 'swag' and appear just as 'talented' and 'unique' amongst their peers. The freebies are mostly for 'show off'.
A few hours ago this link showed extremely low effort LeetCode/Programming Challenge problems and solutions aggregation repos created by us Indians (disproportionally more than any other country at the time I checked) with very silly open issues created & marked as 'hacktoberfest2020' (looks like some of them are gone now)[1].
But, from what I heard from my uni recently, things are improving and this year folks are trying their best to form groups to focus on meaningful contribution over spam.
Even after all that, unfortunately for us though, we'll still have bad actors, probably at the same percentage as any other country, but amplified due to our population and hyper-fixation with an unreal perception about most things we do.
[1] https://github.com/search?p=1&q=label%3Ahacktoberfest+state%....
is it fair to place the blame squarely on them or is it better to recognize that the global system we are complicit in has created this tremendous waste of human potential?
By GDP per capita, India is where the US was at in the 1950s. Would we excuse this behavior in the 1950s West just because "they lack privilege, don't know any better, resort to what they know and have been taught to do..."? Of course not, because relative poverty is no excuse for unethical behavior.
Identifying a privilege gap is not racist. India is definitely not in the same place as 1950s America which was the post-WWII boom. Sometimes called the Golden Age of america.
Then again, we do have some cultural issues to overcome, and yes, a lot of the cultural issues are a result of a traumatic period spent under the boot of the colonizers.
That being said, blame is not useful, the people responsible are dead, and hopefully we can mature as a culture. I see lots to be hopeful about, but lots to be fearful about too. The transition of power from colonials to our republic was botched, and now we're stuck with a broken political machine, and the powerful are trying to break it further.
Comparing the raw GDP of the US in the 1950s to India now is glossing over a lot of points. For example, GDP per capita does not capture the (in)equality of wealth distribution in a country. Or how that GDP ranks on a scale: The US in the 1950s was in a high, probably even the top position (I didn’t check exactly which) - India with the same GDP now is definitely not. That makes a huge difference in perception.
It’s easy to dismiss the status value of a brand name piece of clothing or any token that elevates your status if you’re already high up on the ladder.
None of that excuses the behavior in the sense that it makes it “ok”. But it contributes to the explanation of why such behavior clusters in specific communities.
For me, that I’m ahead, it’s easy to look down and say that this is unethical behavior, but it’s important to keep in mind that I’m applying my ethics from a privileged vantage point - and likely you’re doing so as well.
In the 1950s the US's GDP per capita was the highest. Is that the case for India today?
> Would we excuse this behavior in the 1950s West
I mean the 1950s West was no bastion of ethical behavior. Wasn't that when the cigarette industry in the US started its decades-long campaign of misinformation, obfuscation, and false advertising to cover up the harmfulness of their products? And this was flagrantly unethical behavior by some very privileged people. This is without even getting into how women or minorities were treated.
> relative poverty is no excuse for unethical behavior.
One man's "unethical behavior" is another man's "playing by the letter of the rules, not the spirit". Spamming PRs for a free T-shirt is no way comparable to call center scams.
Thanks for writing -- I like that way of thinking about spammers etc -- that they could have been doing something meaningful instead, if the world and society made more sense
Well, not exactly. There are a lot of people in India who are very passionate about open source and who actively try to get others to participate. So they organise events teach others how fork a repo and submit PR's. Batch-mates are either forced or join after seeing the enthusiasm. Unfortunately, these are not moderated and things go downhill soon where a PR is sent for the sake of it.
Of the 483,127 PRs submitted during Hacktoberfest, only 23,299 (4.82%) were identified as spam, with 19,587 (84.07%) of those being in a repository that the Hacktoberfest team excluded from the competition for not following the shared values and 3,712 (15.93%) being labeled as "invalid" by project maintainers.
1. https://github.com/MattIPv4/hacktoberfest-dataSo yeah, I suspect it's massively undercounting.
>[...] please give them an `invalid` or `spam` label and close them. Pull requests that contain a label with the word `invalid` or `spam` won’t be counted toward Hacktoberfest.
>const totalInvalidLabelPRs = await db.collection('pull_requests').find({'labels.name': 'invalid'}).count();
They also mention the label "invalid" multiple times and never the label "spam." So even if they count "spam" for making entries invalid for a reward their stats do not seem to take that into account.
In a sea of 5B PRs, 24k would look impossibly good.
And the number of "nice PRs" is essentially irrelevant here: this is not a zero sum game, a thousand good PRs don't cancel out a project getting flooded with bad PRs.
If your event can't prevent substantial abuse of the community you pretend to do this for, you should stop your event and figure out how to do better.
It's the T-shirt that's the primary reason but also thr flaunting on social media as if I'm some kind of certified open source contributor.
PS: I've also been part of Hacktoberfest launch events where some people literally created their first PR.
If a reasonable (heh!) percentage of those people continue on to create meaningful further PR's, then it's probably a success for that piece of things. ;)
I intended to make meaningful contributions last year and accidentally hit the quota just by making PRs to my own projects.
> Do pull requests made on my own repositories count?
> Yes, but we strongly encourage you to make quality contributions to other repositories.
A first step would be to only allow contributions to selected projects that have first approved to be included in Hacktoberfest.
The numbers quoted elsethread look like that to me. Not necessarily the full 10x difference, of course, but choosing just between these two systems it appears clear to me that there would be more work for maintainers and/or significantly less people being eligible for T-Shirts because few maintainers are actually aware of Hacktoberfest if every PR had to be tagged by the maintainer to count for eligibility.
I know for some other projects GSoC worked out well. I'm sure people will pipe up telling us how we're doing it wrong if we couldn't get good results from GsoC candidates, but after a couple of years I was tired of being involved with it and got cynical about it.
It's reasonable to bow out if it's not working for your project. Maybe check us out every few years to see if we've addressed your problem :-)
Coming from the other side, as someone who was a GSoC student, but whose involvement with open source ultimately dropped off over the years, I think one of the problems here is the timing. GSoC students are typically in their third or fourth years of undergraduate study, which are followed by internships and on-campus data structures & algorithms interviews which require a lot of preparation. Then for the first couple of years in the industry, most haven't sorted out their work life balance sufficiently to want to code in their free time. It's only recently (2-3 years after I graduated) that I started feeling like I had enough time to get back into open source.
The fact that there as many Indians applying as there are, I think is due to a combination of the factors that 1. there are a lot of Indian CS undergrads 2. internships are extremely competitive, so GSoC is perceived to be an alternative (which it really is not)
edit: and it's worth saying, sometimes a newbie's first PR is pretty indistinguishable from spam. It would be ironic if one of the results of this project was teaching a bunch of young programmers that they're not needed or wanted in FOSS.
Maybe suggest that in an issue on that stats tracking repo?
Such an effort would have to start with them voluneering a test dataset and/or schema.
I have asked - https://github.com/MattIPv4/hacktoberfest-data/issues/5
My gut says that Hacktober probably spawns some productive contributions, but most of them would likely have been submitted anyway.
Projects tagged with the Hacktoberfest tag tended to signal either projects that were both active and had low barriers of entry for newbies, or weird mechanical turk-esque spam. While the latter is unfortunate, the former isn't nearly as easy to find as it should be the other 11 months of the year.
I myself have submitted small PRs during Hacktoberfest but they were still meaningful corrections and in addition to at least 5 significant contributions. We do need better signalling. I tend to pick projects I already follow or have been tagged for Hacktoberfest.
I've seen people say they benefit from Hacktoberfest and some people say they get a lot of spam, and it's hard to know which outnumbers which, but I don't think anyone should be saying with confidence that it's a pure negative, and I think DigitalOcean's suggested fixes (disallow new accounts, disallow people who've gotten too many contributions marked as spam) are probably the right direction to go.
I'd love it if we're able to preserve the high trust nature of open source. I also wouldn't be surprised if it starts eroding. If that's the case, this kind of thing is the tip of the spear, and in that light it makes sense to get pretty upset about it.
My most fervent hope is that DigitalOcean will see the harm they are doing to the open source community, and put an end to Hacktoberfest. I hope they can do it as soon as possible, before October becomes another lowpoint in the hell-year that is 2020. In 2021, they could consider relaunching it as an opt-in project, where maintainers consent on a per-repository basis to deal with such t-shirt–incentivized contributors.
It seems like what could be done that's better for all involved, since there are reportedly (here in the comments) some repo maintainers that really like the program, would be to:
- Immediately suspend it while attempting to contact all the repo maintainers that are on the list
- Explain what's going on, apologiz, and give them the option at that point to opt in if they see benefit otherwise do nothing or decline to not be included
- Note on the Hacktoberfest project page the temporary suspendion for maybe a week while they get info back on who still wants to be included (and maybe some other repos volunteer, who knows).
To me that seems like a sane way to handle this (as opposed to the somewhat hyperbolic statements and suggestions in the article).
Step 2: Set up a system that creates an account and automates some pull request.
Step 3: Tie the two together and drop ship the shirts to the person who paid for it through your site.
Step 4: Profit a small/moderate amount and have a repo you're the primary dev on that looks really attractive as a proof of work, resourcefulness, and willingness to ignore ethical questions to a lot of Silicon Valley startups.
Regardless of whether they actually monetize the shirts much, I wouldn't put it past someone to use that as an interesting thing to offer up in an interview, depending on the company and how they perceive the interviewers. :/
By my count, the rate of these PRs has increased from about 20/hour (averaged over the past month) to about 200/hour (in the last 12 hours), with the vast majority of the recent ones being worthless spam.
"Update readme" is similarly terrifying: https://github.com/search?o=desc&p=2&q=is%3Aopen+is%3Apr+%22...
* next year will be opt in because ... * we are considering of making next year opt in ... * we considered of making next year opt in but we discarded the option because ...
One of my coworkers shared Hacktoberfest details and I got really fired up! I looked through repositories I could reasonably contribute bug fixes or light features to. Got myself familiar with the codebases, PR process, Hacktoberfest guidelines (that are very clear about spammy contributions).
Then reading this and seeing some of the bogus contributions myself (some by contributors who coincidentally share my name!), I don't know how to feel about this. Maybe keep up my laziness streak and punt my contributions to November (and reward myself with nerdy apparel!)? Or take this as a fun opportunity to redeem my name?
The Julia Language [0] gets some spammy issues/pull requests as well (not only during October) and while we have the benefit of dozens of maintainers such that it's bearable, I definitely sympathize with the issues OP is dealing with. Opt-in could be a good idea, although as usual, the issue is scaling and verification.
This is quite annoying
Luckily noone has found mine :D
Edit: LOL, those PRs are cancer.
One was something like build the worst implementation possible of aspects of the .Net framework, but while a joke project, it's been around for a few years, and you actually had to make something that _worked_ and in a reasonable amount of time. It was a fun challenge.
The other one was a bit of a lark, but it led to me and the maintainer having some discussions, working out some code, and then them taking about 2/3 of the PR just because there were constraints that were immutable for them, and neither of us could come up with a viable workaround, and we parted friends.
This is something that should be fun/interesting, and presumably, adding to the open source community. The T-shirt is a cool idea, but I think I ended up doing 7 or 8 of them just because I had gotten into the mode of "I'll just skim through the list of open projects and provide some real help while I have some free time."
Maybe it's time to make it opt-in. Register your projects with DO and Hacktoberfest, and those will be the only ones that get counted. Assumption being though that if you sign up your projects, you're going to stay up to speed on PRs and merge or mark as spam in a reasonable amount of time.
I like incremental games so I usually end up helping out people who are new to making them add things like save systems, or sprucing up their CSS so everything aligns better.
Sure it's not as grand as contributing to something used by a ton of people, but I'm not sure I'm good enough to be able to do that.
They probably should validate a somewhat matching commit with the same e-mail address ending up in a branch or something. Few if any projects modify those.
I frequently perceive a sense of entitlement from drive by PR contributors, as if they are giving a gift to the maintainer, when in reality, it often takes more time for the maintainer to test, review, and give feedback on contributions than if they’d done it themselves.
I imagine the people spamming repositories for a T-shirt are the same people who will harass maintainers to “just merge it already.”
This means not all os projects are likely to yield you a t-shirt, but it does mean your contributions must be good and relevant to have a chance.
There is some technique to reviewing a project and knowing what is likely to be pulled based on its context.
That aught to cut down on it.
Fwiw, DO should be doing something for the projects that accept a PR from this “fest” either t-shirts or a donation to a foss advocacy org or similar.
However, I don't see how that works with a hackaton mindset.
If that's what you think then why accept pull requests at all on your project?
And on balance, I love open source!
It’s just one of those unfortunate things where it’s hard and slow to be considerate while being easy and cheap to be inconsiderate.
(I maintain a handful of small libraries that meet your description, and only recently "awakened from slumber" to release a new version of https://github.com/hunterloftis/throng after five years)
>When a measure becomes a target, it ceases to be a good measure.
In the OpenFaaS community we've suffered every year from spam and low quality PRs that completely ignore the contribution guidelines. The worst part is that we cannot opt out.
I would love to see the team listening to maintainers and coming up with new ideas.
Yeah, it's pretty bad.
At least that doesn't inconvenience open-source maintainers, I guess. It's clear that the spirit of the event has been lost, though.
- please let that site know of the problem instead. Thanks!</p>
+ please let that site know of the problem instead.We will try to better ourself Thanks!</p>
Wow.+ This PR would need another PR to fix white spaces and punctuation.
Do I get my free T-shirt now?
+#...
---[0]: https://github.com/OscarZhou/CSharpTraining/pull/1/commits/8...
I can even understand the initial thinking behind the FAQ entry - on the surface, it seems like a decent solution that works in theory. But as the blog post highlights, it just drove an entirely new kind of negative behavior.
I'd personally wait to see how DO responds/adapts (or doesn't) before investing the time to move my servers.
One such measure could've been to make it opt-in, but as mentioned on Twitter that was proposed internally and rejected. That to me already clearly signals that they were aware of the problems they were causing for maintainers (maybe not the extent), but chose to prioritize their bottom line, which to me is very much "blatant discrespect".
I don’t know the solution for this. But sheer number of PRs/commits is obviously meaningless. We just don’t have a better (cheaper) proxy to latch on to.
https://github.com/phpmyadmin/website/pulls?q=is%3Apr+is%3Aclosed+label%3Aspam
The changes are not even positive contributions, it literally breaks the documentations and adds some useless or unwanted meaningless SPAM.There are four types of contributors. Project maintainers and team members who are invested in the project. Contributors who want a bug or feature implemented and will do it themselves. Those who want to contribute to opensource projects but can't decide on which project or issue to work on but hacktoberfest gives them an excuse to just pick any project and if you ask them directly they might stick. Finally there are those who only do it for external rewards.
The people you can reach only through hacktoberfest are the last two groups and only the third group might stay over the long run. The first two groups will always be there, even without hacktoberfest.
It's possible that differences in the way the event is announced and explained may lead to different expectations and results.
And sure, some people are just going to spam, especially if there are incentives involved. Looking at a few of the pull requests linked in the post, some of them definitely are of questionable contribution value.
An ideal outcome should likely still incentivize participation: for some folks, this may be their first time contributing to open source at all, and there's a non-zero chance that could lead to massive learning opportunities for them, and future contributions to open source projects -- but yes, maintainer burden is a real problem to balance against too.
Providing opt-in/out for repositories is certainly one possible approach. What other techniques are available to manage large quantities of inbound communication and filter signal/noise?
[1]: https://twitter.com/MattIPv4/status/1311366041897971712
[2]: https://twitter.com/MattIPv4/status/1311395478244818945
We also noticed an uptick in spammy PR's and we are working on a bunch of immediate and long term changes to improve the situation for Open Source maintainers like you.
Here's an official post where we walk through currently proposed changes: https://hacktoberfest.digitalocean.com/hacktoberfest-update
suggests to me that DO expected that maintainers would email DO about spammy users. is that the case?
The problem with most "spam flagging" solutions is: 1. They only kick in _after_ the PR is created and the maintainer's time is wasted. 2. In some cases they might actually cause more harm than good. A user is flagged for spamming, gets blocked, creates another account and spams some more... etc.
For that reason we are focusing our efforts on just re-routing these impatient users into guides that have them creating PR's on their own repos.
Long term we are definitely committed to updating the program to make sure it's delivering on the mission of getting people positively involved in open source.
Many maintainers put “Hacktoberfest” labels on issues they’re happy for newcomers to work on.
That's why, to deal with the immediate issue we're creating an obvious, even lower-effort route for the impatient participants to take (follow a guide to create 4 PR's on your own repo) - and longer term we'll make bigger changes (maybe including an opt-in only model) that solve the perverse incentive issues that seem to be driving this PR spam.
> This year, the first 70,000 participants who successfully complete the challenge will be eligible to receive a prize.
How about choosing 70,000 participants at random? Or any other criterion that doesn't encourage quick content-less contributions?
This program would be better off just sponsoring projects instead. Otherwise use opt-in repos and invites/approvals of people who want to work on them, or other rules like limiting new accounts and personal repos.
The first improvements this October should be to the hackathon itself.
If a maintainer reports your pull request as spam or behavior not in line with the project’s code of conduct, you will be ineligible to participate.
"Changing the email doesn't expire the session on your web app". Should it? The email isn't the login, why should the session expire? It should expire on password change, maybe username change (but even then, why?). It's just a bunch of spam templates basically from people who don't really even understand the reports they are making.
And then they ask for public recognition so they can get points on one of those public security leaderboards.
"Prototype pollution" from transitive dependencies of our frontend build scripts in node was another one where we would get spam security issues, though thankfully without the same tight deadline.
Initially, at least from what I remember, the "spam" mostly was purpose-made repos a la "make a PR in this repo to add your username to this list and get a Hacktoberfest point", which didn't drain others time. But now it spreads to random projects, since they try to block those purpose-made repos.
Haven't figured out yet which repos are picked why, it doesn't seem to be entirely random. Seen it on some projects I'm involved with, others not at all. As mentioned in the article, the HTML spec is hit every year. ...
Free t-shirts are also pretty controversial due to child labor often involved at some point in the manufacturing.
I was under the impression PRs only applied if they fixed an issue tagged as “Hacktoberfest”. Is that not the case anymore or am I missing something?
Edit: looks like the rules changed at some point and now it’s any repo. I wonder if they should stick with labelled issues only to resolve this problem?
I would be very sad to see Hacktoberfest end.
And take care, hope you don't drown in the PRs.
Incentivizing spam should be criminalized over the next decade if we are to maintain our humanity.
- Only honor PRs against repositories that have opted-in
- Only allow repositories that meet certain "notability" criteria to opt-in (to prevent the creation of "fake" repositories)
- Only honor PRs that are merged within a specified time-period
- If DO has the resources, volunteer some folks to filter/close spammy PRs on the participating repos
I maintain several open-source projects, and the spam would annoy me. That said, if the constraints above were applied to Hacktoberfest, I would opt-in my own projects. I think these constraints would do a reasonable job of disincentivizing people opening spammy PRs (because I simply wouldn't merge them), while bringing my projects to the attention of developers that are looking to make a contribution to open-source in good faith.
Isn't it possible to disable pull requests? I thought GitHub had that capability by now. It's unfortunate but if the abuse persists on GitHub I suppose it's always possible to go back to sending patches via email.
However I agree, it is strange that you can disable features like issues but not PRs.
Interestingly, this year one can choose between a t-shirt or planting a tree. In other words, everyone who chooses a t-shirt is now considered a person valuing some "useless stuff" over doing something good for the world, which looks like a moral trap from DigitalOcean's side. They should just drop the t-shirt option, which would be both more useful and hopefully stopping at least some of the spammers.
I love the idea, but maybe let me opt in or something instead of putting the burden on me to reduce your spam. It would be trivial to have projects put a "hacktoberfest" label on something if they want to participate, for example.
That would dramatically reduce the incentives for spam, since a spam PR is very unlikely to be merged.
https://github.com/learnbyexample/Python_Basics/pulls?q=is%3...
I'll have to see if this prompts useless PRs to my other repos. Hope not.
I'm pretty sure that's 100% intentional.
> where alcoholics from around the world join their ranks and collectively destroy their livers and promote destructive drug taking
Also called "having fun" and "taking a break from the ordinary". You know, things commonly considered recreation.
Of course some people are going to be over-doing it, but that applies to anything anywhere.
I have only little time these days but I like the design and would like to add to the good cause behind it.
And then run another script to try to find high-value/non-spam PRs and suggest those to the maintainers for a second look.
Why would you save $6 to turn yourself into an unpaid walking billboard for someone else?
To me, wearing clothes with logos or names on them that depict a company or brand that you don’t personally own is the ultimate low-status move.
Digital Ocean, please stop this.
He threw a fit though in response about us "not building a community" in the mirror repo. Heh. Get fucked buddy.
This happened because DigitalOcean displayed my issues on their Hacktoberfest page.
Anyway there is a simple solution... Archive the repo for the month of October, take a break from OSS, and chill out.
During such events, I think maintainers(for popular projects) should get some help for spam filtering PRs.
Opt-in could help. So could better access control tools from GitHub.
DO could make it so that users have to use a specific tag on the PRs; there are tons of ways maintainers could filter on that.
DO could switch the prizes to be something less likely to draw spam than a t-shirt would - like free cloud resources.
TLDR; in the spirit of software - let's iterate on this imperfect event instead of junking it outright.
(Although the free cloud resources idea sounds worse to me - those have actual value (spam, mining, ...), so there'd be a real incentive to try and automatically game this)
Please stop blaming the victims for not doing enough.
Oh yes you did: by using github.
You can self-host and nobody will bother you in a way that you can do little about.
This is a comms problem, not a "corporate-sponsored distributed denial of service attack against the open source maintainer community". The well-meaning frequently cause more problems than they solve, but it is better to have them on the inside of the tent pissing out than on the outside of the tent pissing in, it is said.
No, this article never even implies DO is doing this intentionally. The tone is annoyed, even aggrieved, but not really angry. The author, in fact, seems to be rightly applying Hanlon's Razor, and is constructively figuring out how to fix this unintended down-side to what should be a nice gesture by DO.
Which is not constructive. I think DO should sort this out and there’s any number of decent options just in this HN thread, but this post is only going to help if it generates enough negative publicity on HN for DO to recognize. In and of itself, it’s just another fed-up dev.
compare e.g. clear spam, which adds a copy of someones website into the HTML specification repo: https://github.com/whatwg/html/pull/5972/files There is no scenario in which that is even a potential improvement.
15 spam PRs in last two hours https://github.com/phpmyadmin/website/pulls?q=is%3Apr
9 spam PRs in the last day https://github.com/whatwg/html/pulls?q=is%3Apr+is%3Aclosed+l...
Take a look at this user who has made 21 commits this year. 20 of the commits are from today and all of them are for valuable additions like:
* "made with love"
* "you will love it"
* " with "
* "Please do try we have made this for you"
* "That was amazing dud"
* "lovely i loved it"
* "and awesome"
* "and cool"
EDIT: Formatting
I am also an open source maintainer, and would love for Digital Ocean to drive by my project.
Isn't this what we signed up for as open source developers?
Maybe I'm just lonely.