Starring your repo does not give you permission to spam me
github.com
github.com
We didn’t intend to SPAM you or send unsolicited emails, we just wanted to ask for feedback. Being an open-source/boostrapped service, feedback is really important for us, so that’s why we thought it might be a good idea to reach out to people directly. But now it's clear that that was a wrong decision. We stopped doing that and won’t do it again.
Sorry, it won’t happen again.
For the future, you can utilize the tools given in GitHub - add a link and/or call-for-action in docs/README/release notes, pin an issue, Discussions.
Depending on your jurisdiction, status, and purpose, merely scraping and processing e-mail addresses associated with GH handles could be a regulatory violation without even sending anything. It's certainly against GH ToS. You'd do best in ensuring you wipe anything acquired without consent.
This kind of thing was seen differently in the 90s and early 00s. Times change.
There's one thing I'm honestly curious of, because I've seen this technique before, and it's not necessarily a question to you, but to anyone who might read this: do these pretend-personal emails actually work on anyone? Your product is targeted at users with a pretty high technical skillset, do you think they really believe you hand-wrote that email? Because I could smell the automation right away, even before I checked the message source and saw the HTML structure and the tracking image. It's fake, it feels fake, and to me it's actually worse than an openly-automated message, because it insults me by assuming I can't tell it's not sent by a human. I think perhaps tactics like these work better on less-technical people (though they still shouldn't be employed at all!)
I was once gone from home for two days traveling with family. Two days. HBOMax sent me an email with this exact subject line (edit: I went and checked through my past emails before unsubscribing, they sent four emails with the subject line over the holidays):
“I can’t help but wonder why you aren’t watching” as an attempt to inform me about the latest series that was now on the platform.
Why? Because I have a life HBO that doesn’t involve you lol. I do other things with my time. I’m not addicted to television. Like come the hell on. I’m already a paying customer. Get out of here with this “why aren’t you wasting more of your time on our platform?” BS
I feel genuinely bad for whoever had to write that, and worse for whoever thought it was a good subject line for ad copy.
At least the emails are no more.
Create a pinned issue with title "We ask for feedback"
> We didn’t intend to SPAM you or send unsolicited emails, we just wanted to ask for feedback
You _did_ want to send unsolicited emails, that's exactly what you did. You saying you didn't want to send spam, and hiding what you did intend to do behind "we didn't intend to spam you" is burying the lede.
> Being an open-source/boostrapped service,
Being bootstrapped is not an excuse for sending unsolicited marketing emails. Hiding behind being "open source" when you're actually a commercial offering with an open source repo is _again_ trying to hide what you did.
> But now it's clear that that was a wrong decision
It's only clear after someone called you out on HN and flagged your repository as abusing the terms of service?
If you really wanted to get GitHub data in bulk for illicit purposes and you know how to work with big data you can get it from the GitHub Archive but that’s a topic for another day. (Although it may not have user emails)
I’ve never quite understood why there isn’t a private way to bookmark repos.
I suggest using a fake, or at least a dedicated, e-mail address for commit messages. If you are talking about the e-mail in your GH profile, you can mark it as private in settings. Or use their built-in function to mask it (they will replace it with an address under their domain and forward incomings to you).
There are many valid complaints about GitHub but with regards to this I think they've done what they can already. If you don't want spam to your address, don't put it in public. It will be scraped.
OP put their e-mail in cleartext, unobfuscated, in their profile. The blame is on part of the spammers. Countermeasures should be done by OP (and their e-mail host), not by GH.
What thought processes went into asking this question? You are the person who commented on this same topic that "scraping and processing e-mail addresses associated with GH handles could be a regulatory violation without even sending anything[...] It's certainly against GH ToS".
To state what should be the obvious here: when GitHub goes through the effort of writing an acceptable use policy, and I have evidence that certain users/orgs are sending out spam despite that, then I expect GitHub to, you know, actually investigate and do something about it using the leverage that they have, e.g. by ultimately suspending the accounts of the spammers if they don't knock it off.
> I suggest using a fake, or at least a dedicated, e-mail address for commit messages.
I'm not talking about commit messages.
> If you are talking about the e-mail in your GH profile, you can mark it as private in settings.
That's the default. I have deliberately gone through the effort to make it public so that people who are making acceptable use of GitHub can use it for what it's there for—not for people who aren't to abuse it.
> There are many valid complaints about GitHub but with regards to this I think they've done what they can already.
Bullshit. To set up an intake form for people to report abuse and then never act on reports of abuse is not doing "what they can". (If nothing else, then take the damn form down so I can cut my losses at the time I've wasted dealing with the initial receipt of the spammy stuff and I don't additionally waste even more time reporting it on the belief that they're going to act on it and so that it to save other people time in the long run.)
Regardless, even if Github did take the sender account down and you removed it from your profile, your e-mail address is most likely on lists used to send spam not linkable to GH accounts and will continue being so for a long time moving forward. Whomever you're reporting is just a drip in that ocean.
Spam is frustrating and illegal but you're barking up the wrong tree.
Yeah, that could happen—under two conditions: (a) if that's what actually happened here, and (b) if GitHub's process for handling abuse reports were so bad that they went from receipt of abuse report to immediate suspension. But neither of those are relevant to anything being discussed here—only to contrarians with but-what-if imaginations.
> your e-mail address is most likely on lists used to send spam not linkable to GH accounts and will continue being so for a long time moving forward. Whomever you're reporting is just a drip in that ocean.
I know how big the ocean is, thanks, and you make a lot of assumptions. Consequently, you have no idea what you're talking about (which makes your un-self-aware remark about "barking up the wrong tree" doubly annoying).
Every commit I author is signed with a single-purpose email address tied to the repo that I'm committing to. The email address I have listed on my GitHub profile is a different address further still. I have received close to zero spam to any of the addresses I've signed commits with. (I'm pretty sure it's actually zero.) Meanwhile, a substantial chunk of all spam I've received across all sources is from dum-dums scraping the address listed on my GitHub profile page and trying to promote their junk. It used to be close to a majority, which only changed due to a recent (COVID-era) uptick of spam coming from other sources—and because I took my profile down by deleting my account. But even most of the non-GitHub-originating spam is obvious spam that already automatically gets flagged and filtered accordingly.
> Spam is frustrating and illegal but you're barking up the wrong tree.
I'm going to repeat what I said before: my expectation is that GitHub takes their own acceptable use policy and reports of abuse seriously. Want to go into detail how that constitutes "barking up the wrong tree"?
I can only conclude by the contradiction between your general position in your your reply to me and your comments elsewhere about GitHub ToS violations that you're mostly here to argue, though, so don't be particularly surprised to find that this is my last response to you.
Generally, I do not think that platforms should be regulated (as has been proposed in some places) to be legally responsible for all actions of users on their platforms.
Separately from all that, if you expect fairness, individual attention, and consistency from Microsoft, I stand by my case that you are barking up the wrong tree.
According Github's site policies [0], they've explicitly outlawed this type of behavior meaning it's their responsibility to police and enforce this by punishing users on their platform who they find to be engaging in it:
"You may not use information from the Service (whether scraped, collected through our API, or obtained otherwise) for spamming purposes, including for the purposes of sending unsolicited emails to users"
[0] https://docs.github.com/en/site-policy/acceptable-use-polici...
If you want to be selective in what people email you about, you can always move your email to your personal readme with further restrictions.
For myself, I have very few stars on my repos (the one that got a bunch has been passed on to a different team, and I'm happy to have it off my table).
I'm totally fine with that. I write software for myself. Publishing it as shipped, supported, documented, and tested product is more an exercise in Quality, than it is an effort to get stars. The fewer people that depend on my stuff, the better.
I used to use watch but I could care less about every individual commit on anything other than projects I'm actively working on.
Watch is not a good substitute for a way to learn about important changes on an infrequent, regular basis (i.e. once a month emails).
Email is the only reliable way to send/receive important updates for any meaningful project.
[EDIT] Answer appears to be "yes, there is" (append ".atom" to the releases URL for a repo) with the caveat that the handling of pre-releases is less than ideal.
Spammers are not entitled to private and nonadversarial communication.
Note that in numerous jurisdictions both sending spam and not including unsubscribe link is actively illegal.
No, absolutely not. You put an unsubscribe button in the footer of the email or I'm marking it as spam. That's _entirely_ on you if you don't do that.
I get the hustling nature of HN, but this behaviour crosses a line and breaks laws in various juristictions. I don't feel the need to politely explain this to people.
For example, when I built https://github.com/pdepip/mmap.it I made the conscious decision to not require any log in information but quickly found I was unable to find who was using my product and then ask them for feedback - so user led development stalled.
GitHub discussions not enabled on the repo
404 Page not found
The way to get feedback without being obnoxious is to provide ways for users to give you feedback on their own terms. Bonus points if you build a community where you can ask questions as needed.
Mention it in the Readme.
This is not the way.