Hacktoberfest Is Now Opt-In
github.com
github.com
This is what Hacktoberfest should have been from the start. A company incentivizing pull requests against your repo should require your consent. A maintainer needs to affirmatively sign up for this sort of work; they can't have it thrust upon them. As a maintainer, all the other half-measures people have suggested (e.g., accepted PRs only; account age measurements; filtering out README changes) do not actually reduce the unasked-for burden on me.
That said, I'm not sure this year can be salvaged. It's not clear whether all the existing spammers will get the message. I hope DigitalOcean emails all folks signed up to notify them of this change. (They haven't communicated any of their changes so far in such a way.) Notably, a day ago, the DigitalOcean staff thought this wouldn't make a difference. [1] And it's even possible this will just result in issue spam begging maintainers to add the Hacktoberfest topic.
But it's also possible that this will work out. The best version of this is that low-quality contributors looking for a t-shirt get directed toward honeypot repositories, and folks interested in making substantial contributions will continue using issue labels like GitHub's own "good first issue", or the Hacktoberfest repository topic, to find places to contribute.
We'll see in a day or two whether this is enough.
Why?
But incentivizing people to make pull requests is a different matter.
(Yes, of course, blatant spam doesn't help anyone and is disgusting, I'm talking about in general)
In your scenario, it would be like incentvizing "donating a vial" and hoping it will be filled with blood, but 99% of people are donating an empty vial.
I think the problem was not as much incentivizing pull requests but incentivizing low effort pull requests and outright spam.
The people who participate are different and pull requests are different.
I think the biggest problem DO will have to address somehow is that Hacktoberfest now has become such a big event that they are getting attendees which they strictly speaking do not want to have, and the liberal “everything is open for everyone”-approach is now too open for the “game” to work.
Finding a way to encourage (new) people to contribute to open-source projects while at the same time keeping the bad people out (opportunists, spammers, etc) is not going to be easy. Locking things down (like only opt-in repos count) will severely limit genuine contributions way beyond just spam.
Whatever they end up doing, I suspect we will see Hacktoberfest 2019 as peak Hacktoberfest and from now on the event will be a mere shadow of what it used to be.
This is the challenge of our time, TBH. From the Eternal September onwards we’ve struggled to sustain community quality in the face of infinite connectivity. You start open & welcoming, but eventually you get overwhelmed with new folks and you can’t socialize them fast enough to preserve what was attractive about your community in the first place.
This is the work of institution building. It’s not easy. The best examples I’ve seen are HN, Lobste.rs and some focused subreddits. All of these have strong mod teams and spam controls.
The quality standards are so low, I am honestly not surprised by the amount of spam this has generated.
> Last but not least, one pull request to fix a typo is fine, but 5 pull requests to remove a stray whitespace is not.
https://hacktoberfest.digitalocean.com/details#spam
And to make matters worse, the onus falls on the maintainer to mark a PR as spam. This honestly feels like a DDoS attack on open-source rather than promoting open-source.
I don't think there's any way to save this.
EDIT: I think DigitalOcean completely missed the point on promoting open-source. It's not about the PRs. It's about everything that goes before you submit your first PR. Reading mailing lists. Actively participating in discussions with the maintainers. Reading the docs. It seems like they wanted an easy way out to promote their brand without putting in the effort to review the PRs and filtering out spam by raising the bar on what qualifies for a PR (i.e. not requiring all the leg-work for writing your first PR).
https://docs.github.com/en/github/building-a-strong-communit...
https://docs.github.com/en/github/building-a-strong-communit...
But that still means maintainers have to build an active list of blocked users. That's definitely not scalable.
Yes, there is a lot more than writing a random PR to FLOSS, but getting people involved in that is still a positive thing overall.
To me it _is_ surprising that people would create spam PRs to get a t-shirt.
Anyway, it seems like adding their own layer of pre-filtering would have been the best solution.
Don't get me wrong. I am not saying DO is a terrible brand. I am just saying this was not very well thought out for such a wide reaching event. It just makes me question their motivation.
I’m not sure it’s as badly thought as you are suggesting it is. More like someone found a way to game it and promoted the crap out of gaming it (we even know who the someone and their videos are!).
I've only had 5 or so PRs accepted[0], and all of them have been tiny bugfixes for broken tools. I have no goddamned idea how to get an actual feature merged, because maintainers never comment on the proof-of-concept PRs I put up, even if they have tests and documentation updates. Maybe it's all about mailing lists and out-of-band communication.
[0] not for Hacktober, just in general
Bug fixes tend to not need justification (since the maintainers presumably already agreed), but new features depend on the maintainers agreeing that they want it in the project. Before making the PR, try to find the relevant issue (or create one if it doesn't already exist), and get the maintainer to indicate that they want the feature. Once they've written that down, they're primed to accept it because they'd feel worse about not processing the thing they already committed to.
Do unless you see them engage with past pull requests like that, assume they don't.
I believe that all those were valuable even though they did not involve close participation in the project. But I have not always done that: only after learning how low the barrier to entry was by doing it the first few times, does the thought of submitting a PR now arrive automatically when I encounter such a situation.
So, my take is that DO should take a longer view and try to raise the profile of Hacktoberfest by making it more exclusive -- eg take a step toward GSoC. For ex, there are a handful of oss-bounty sites (bountysource, issuehunt, etc) where people post bounties for things they want implemented. Could DO partner here in some fashion? Such as matching bounties in a certain range ($10<x<$50?) with a tshirt? Or matching bounties? Make it a year-round promo instead of one month?
These are Indian students with good hustle and poor technical skills who market themselves as technologists. They're going to be managers making purchasing decisions at tech companies in a few years time, and they lack the technical sophistication to choose between DO and competitors on axes other than "I've heard of them"/"they have a good reputation"/"they gave me a t-shirt once". These customers are both more valuable and a thousand times more numerous than the ones capable of earning even a $10 bug bounty.
I'm generalising here, but hopefully not racially stereotyping too much.
"Generalising" isn't the word I would use.
Let's not generalise in either direction. There are plenty of people who try to make meaningful contributions as part of Hacktoberfest.
https://www.digitalocean.com/open-source/
Please stop telling people how to spend their money.
I got one PR that did exactly what I asked. Great, merged! Good experience all around -- exactly what I expected!
Then I marked a PR "invalid" because they made changes to a README that weren't helpful (in fact, actively misleading!). Clearly low-effort PR spam. BTW, the same low-effort PR spam I'm also getting on a bunch of other repos where I didn't solicit help.
And now, because I marked unsolicited incorrect changes to a README file as "invalid", I'm getting new pull requests calling me an asshole.
So... that's my experience with Hacktoberfest. I guess it's my fault for assuming the outcome would be anything else in the month after the Eternal September. Especially with free t-shirts on the line.
I'm not a fan of this change because:
- It significantly reduces the pool of repos that you can PR to. I've contributed to repos which haven't explicitly opted in to Hacktoberfest this year and in the past as well. Repos in which I am more comfortable contributing in than some random GitHub search result for the "hacktoberfest" tag. With this change, I am forced to look into those, or convince the maintainers to tag their repos.
- For intermediate or experienced programmers it voids the whole event because the vast majority of OSS projects won't get involved.
- After the spam fest that this year was, people aren't inclined to add the tag to their repos because it paints a target for spam over them.
- Maintainers can now gatekeep your contributions, so even if it's something meaningful the maintainer can deny you a +1 PR for your work. It can be frustrating spending a non-insignificant amount of time to get the t-shirt the right way and then have that time nullified.
- It doesn't address "hello world" spam repos. In fact, it encourages them because of the reduced amount of repos available to contribute to.
That is a very false premise. You can help any open source project! That's the spirit of open source! It'll make things better for you and for others. Now, if you want that free t-shirt, sure there are rules. But no one is "forcing" you not to contribute to OSS. All of the points here seem based on this false premise.
The GP is talking about Hacktoberfest... Not sure how you got the impression that they are talking about OSS in general.
As someone else replied, if you say you are making a significant contribution but the maintainer says you are not, you are not. If you strongly believe the maintainer is wrong and care enough, forks are always there.
Would also like to note that "putting a non-insignificant amount of time" is also not a valid premise for contributing to OSS, what counts is your actual contribution, not the time you spent making it. (e.g. for a given fix, it doesn't matter if it took 1 min or 10 hours, what matters is other things like the quality of it).
I just opted it in to Hacktoberfest. Best case scenario, I actually get a great PR because someone was looking for Hacktoberfest-eligible repos and thought my app looked cool. Worst-case scenario, I get a bunch of spam PRs that I reject—but since I basically never get any PRs, this doesn't seem like such a huge problem.
That's what I thought. Now I'm getting spammed with PRs containing personal insults.
Take care.
I'd say the spam tactics executed on such a large scale killed Hacktoberfest. This is just damage control.
I've just checked and am now running at over 40 rejected changes, many with really offensive comments added to them.
Open source developers often come across as very rude and argumentative and this sort of response to legitimate fixes kills any interest I had in helping. Looking through some of the projects I they are also treating code changes the same way. I'd suggest that that future hacktoberfests will have much less participation
1. I think the opt-in should have been there at the start. Repo maintainers should have been informed, and given ample time to decide if they want to participate or not, so that participants are likely to have a wider range of repos to choose from. From the organiser's POV, it will help them to measure the impact of this event on open source events. However, this doesn't seem to be planned at the start (didn't happen in the past years either?) The explanation I can think of is that either they didn't have a nice talk with GitHub to get their support, or like many ppl have said, it's more of a publicity stunt.
2. It could have been done with better communication. If not for this HN thread, I wouldn't have known the change in rules. No email sent. Even the official website still has rule sections that say any public repo will work.
3. I'm discouraged to participate further. I do love the t-shirt. I'd be lying to say that I wasn't motivated by the shirt from the start. I also wanted to beat the crowd by making PRs early by sacrificing my time for other hobbies/work. However, I made PRs that are welcomed and the maintainers were happy to merge. But now I feel the shirt will only bring me the suspicion and disgrace of potentially being a spammer.
4. I don't have many choices of repo to contribute now. In the hacktoberfest topic, there's 0 repo in my preferred language. The first repo I see with the highest number of stars is some algo repo. The 2 repos I've contributed and likely to contribute again are not qualifies anymore.
There are still good things from my experience. I have made PRs before, but I'm not actively contributing. I'd rather spend my free time on other hobbies. But now, I do see that I can find joy in open source. I'm likely to contribute to repos that interest me again in the future.
I understand why this change is needed - jerks often ruin things. But I hope that DO will refine the approach a bit, as opt-in-only will probably kill Hacktoberfest for me.
The intersection of projects that I use or care about, the projects that are in a language that I'm interested in using (or even learning), the projects that are on github, and the projects that will actually opt in even after the events of the last few days, well... I'm guessing that set is going to be pretty small. Quite frankly I don't want to spend more time searching/scrolling through github trying to find contributions to make than I do actually contributing.
Of course, none of that probably matters, as I realize I'm not the target audience for Hacktoberfest: I regularly contribute to open source projects. Whether or not I get a t-shirt won't change that, but I'm not going to lie - I've enjoyed getting the shirts (and stickers!), and wear them often. They can be good conversation starters, and it's also nice to have a tangible reminder of my contributions, since so much of what we do in this field is completely intangible. Though, to your point, the potential implications of the t-shirts going forward may change my feelings on wearing them.
And I completely agree w/r/t to communication. Earlier today I made a PR and refreshed my Hacktoberfest profile to make sure it picked it up, only to see it marked as not valid due to not being in an approved repository. So I went looking for an explanation and eventually wound up in this thread. As you noted, there was no mention of it on the site, no email, etc. There also doesn't appear to be a contact email listed anywhere on the Hacktoberfest site.
https://www.atlasobscura.com/articles/hanoi-rat-massacre-190...
I just opted in to Hacktoberfest PRs for two of my projects: bat and fd. For bat, I opened three special issues for Hacktoberfest in order to help contributors who are completely new to the open source world:
- https://github.com/sharkdp/bat/issues/1211
- https://github.com/sharkdp/bat/issues/1213
- https://github.com/sharkdp/bat/issues/1216
Curious to see how this works out. The first PRs are already coming in :-)
Github has become like a social media of programming. Even before I heard of hacktoberfest I had noticed people building hollow or shallow profiles on github to attract employers.
Most recruiters won't go deeper than your profile, so they'll see a bunch of contributions but those might just be Issues created, PRs rejected or documentation adjustments.
- projects can opt in by adding a keyword to their project description on github for a month. That's barely any effort for projects that care, and
- PRs that are merged won't count unless the project maintainers welcome hacktober contributions and are willing to add a label that marks a PR as "this one counts".
And if "not getting a $20 T-shirt for free" is the only thing making a difference between you contributing a meaningful PR to a project, and not contributing a PR at all, then let's face it: the open source world really isn't worse off.
Just like past years, I have a similar todo list with 10-or-so items this year and started working on it yesterday. All of the contributions I have planned have had open issues for a while and I've discussed them with the maintainers for sometimes months. Now none of them will count towards the shirt.
And I want that god damn shirt! I know it's stupid, but it was really nice to get something sorta-exclusive for doing something good for the open-source community, even if my contributions weren't particularly groundbreaking. I'd gladly pay shipping costs if necessary (actually, I think that would be a good anti-spam measure). But now I'll have to spend more time looking for tagged projects to contribute to and probably end up not finishing some of my planned PRs.
Your comment reminded me of a 1-word PR I sent that fixed a bug in a project, and it gives me a glow in my stomach thinking about now, months later.
You can go on cafe press and by yourself any t-shirt you want.
I'd still keep the repo wide tag for opt-in, but also optionally provide issue level opt-in.
Alternatively, you can provide a platform where participants can self regulate...e.g. like spammers called out on r/programming or maybe a spam detection algo.
Edit: maybe the incentives can also be altered. E.g. sticker for non opt-in repos, t-shirt for opt-in ones. Hmm solving bad actor behaviour is an interesting problem
At least for Prometheus the ones we tagged with hacktoberfest are ones we'd expect a new developer to have a good chance to be able to complete.
I don't think we should be disincentive people who attempt to instead tackle more thorny issues.
Unfortunately, the majority is mostly silent, so I'll just say: Digital Ocean, good job on trying to make things better. Whatever your motives, you created a discussion about open-source promotion and hopefully some good will come out of it.
A better way to do this IMO would be to kick off a year long contest; for example: you sign up, every week you need to average +7 lines of code on your own repo. Bonus points if the repo actually does something useful. After a year of that, you get a Tshirt.
Weeds out the lazy, encourages people to actually build something.
Sincerely, John Smith
/* comments */
and welcome any and all pull requests! This way everyone can be an FOSS contributor and win t-shirts and stickers.They should have acknowledged their failure and cancelled the game altogether.
That’s looking at things a wee bit one-dimensional isn’t it?
Until this year Hacktoberfest has been a fun event where people of all levels of skill has learned how one can help out in open-source projects.
They have learned how to fork, make changes and propose that those changes get upstreamed. You may take these skills for granted, but they first needs to be learnt.
They have learnt what sort of reception to expect based on how they have presented their changes to the upstream repo and/or maintainers and how to adjust it based on a feedback and consensus. You may take this experience for granted, but it needs to come from somewhere.
In both these respects Hacktoberfest has helped.
Looking at entire Hacktoberfest and what it has done over all its years as simply a t-shirt because some Indian spammers tried to game the system for that single price this single year is absolutely not fair.
> They should have acknowledged their failure and cancelled the game altogether.
You should acknowledge that such confrontational attitude and vitriol won’t do the discussion any good.
You could come up with all kinds of constructive criticism here instead, but that might take some effort on your part. It will get you a more fruitful discussion though.
Disclaimer: Maintainer for various projects and Hacktoberfest attendee.
Also this is why I have my own CVS with hookers and blackjack.