I went down the rabbit hole of buying GitHub Stars, so you won't have to
the-guild.dev
the-guild.dev
> It took six hours for my order to complete, and the accounts look legit; each has a profile picture, different companies that they work for, a couple of repositories, and a contribution to one or more open-source projects, next to being a GitHub member for over a year.
This is the motivation for garbage AI-generated PRs or insubstantial docs changes that "people" make. It doesn't matter if they're good. They only exist to add surface level legitimacy to fake accounts so that services like this one can exist.
I imagine contributors won’t exactly be happy with that though.
OK, a credit, but really, who cares? People can see what an accepted pull request consisted of, so I'm not sure they're kidding anybody in terms of boosting their reputation with credits for fixing typos.
All the same, I'm just glad to see people improve their presentation, especially typos.
I do that when I see typos in documentation.
I've also submitted PRs that just fixed typos, and I've considered that a legit contribution.
But if I maintained a high-profile project right now, I'd at least take pause in thinking some of these accounts could be spam reputation-boosting accounts that only make comments/PRs to lend legitimacy to the account when it ultimately stars some artificially boosted repo.
And making it harder to detect star manipulation erodes the signals of trust which have been used on Github, and ultimately can be a security concern (historically I've looked at numbers of contributors, stars, downloads, and issues open/closed as a rough idea of how secure some npm dependency might be.. basically the idea that "more eyeballs" can mean slightly less chance of a massive security issue, especially in security-critical code like oauth libraries)
I don't know what the solution is here. Maybe requiring people sign a CLA like some corporate open source projects do is at least enough of a barrier
IMO, the solution is simple: allow project maintainers to disable pointless metrics that would incentivize the GitHub equivocal to karma farming.
I also think the quality of comment on HN suffers for the fact that the karma score is visible metric to the end-user. Reddit particularly. The view count on tweets too.
A lot more people will read the docs than the code, and typos are annoying and for some people highly distracting (OCD)
These are always either bots or people looking to bolster their CV by bragging they "contributed" n PRs to n repos. I signed up to collaboratively make some (hopefully nice) software, not to deal with a stream of PRs like this.
Typos in README or publicly facing docs are different; I usually merge those (and those are almost always good faith too, because usually a real human picks up on them before the bots/script kiddies do).
Or are people actually deploying LLMs to inspect code and produce usable optimizations?
Because that would be an interesting beneficial side effect to an otherwise "nefarious" marketing hustle.
For what it's worth, I've seen lots of examples of this, and "usable optimizations" is entirely false. The PRs are often not working code. It's scattershot. The point isn't to make a PR that benefits the project in any way, it's to fill in the green square on the profile so it looks like there's a human doing things.
Anyone giving this stuff more than a cursory glance would see that it's all bullshit. But the point isn't to stand up to scrutiny. It's to defeat abuse protection measures with legitimate-looking activity. And in the case of stars, to make it look to anyone who's just glancing at the star-ers that there are real people starring the repos.
It's deviously clever and absolutely terrible.
If someone wants to write "check_spelling_bot" and get a ton of github karma, I have 0 issue with it. In fact, I encourage GitHub to do it :).
If you got spam, but the spam was useful to you personally, not marking it as spam prevents your email provider from flagging the account as spam to the wider world.
Relevant xkcd: https://xkcd.com/810/
That is absolutely false. Spam is not defined based on it's utility, but based on whether a message is solicited.
If the author of a repo hasn't signed their repo up for an automated PR bot, that bot sending out PRs is absolutely spam.
Edit: Emergency alerts are solicited by owning a phone in a country that mandates that cell carriers send those messages.
Before getting sidetracked on definitions of other words, I would be deeply surprised if asking a bunch of people on the street "If you received a message you didn't ask for and didn't expect, but it turns out you are very glad you received it and it provided you value, is that spam?" resulted in a broad consensus around "yes"
Unwanted and unsolicited are definitely not the same thing, whether or not you solcit something has nothing to do with if you want it, I'm not sure how those are synonymous. And if being mandated to recieve a message by someone else counts as you soliciting the message, where solicit in its most common definition means to ask for, then I guess that means that everything is solicited?
> Unsolicited e-mail, often of a commercial nature, sent indiscriminately to multiple mailing lists, individuals, or newsgroups; junk e-mail.
Note, "unsolicited" is the first word and "irrelevant" does not appear anywhere and there is no discussion of the utility of the message to the recipient.
That's so pedantic, I'm inclined to disagree - if it's even correct. Not everything that's unsolicited is spam. An unsolicited thank you note isn't spam.
More components of spam are traditionally a large, indiscriminate number of receivers, and low quality messaging. Irrelevancy does partially capture both of these.
There is a complex set of social expectations around when a thank you note is unsolicited. I could start trying to describe them, but then you'd probably call me pedantic again.
Not all bots have bad intent. Some compensate for a lack of a protocol/platform-native feature. Which makes all bots occasionally annoying, because human time is spent.
I'm sure that from the perspective of a publication that paywalls, those bots are not a good thing.
A few months back, I noticed that there were some accounts posting issues on open source repositories, but their issues were a direct copy/paste of mine. I couldn’t figure out why they would copy/paste my issue so I dismissed it.
Now it makes sense!
If you think you won’t succeed because you just refuse to buy likes, I think you’re still way off the mark.
You need to release to a market, that you directly engage with. Releasing into the void is a mostly self-serving exercise.
What usually does cause me to adopt something new is 2+ co-worker / colleague recommendations. For example, I would never have started using k9s until 2+ colleagues started to hound me to stop typing out kubectl commands and to switch to k9s ASAP.
Nobody knew about it, so it didn't make any profit. Great concept? Absolutely! Look at Amazon today.
https://www.vice.com/en/article/z4444w/how-reddit-got-huge-t...
"started"?
They are still doing that today to inflate their user count...
Obviously some fraction of the population will lie about being honest and upright.
Why not?
The idea that any creator or advertiser NOT buying views is “almost certainly a loser by default” is an exaggeration.
This... doesn't sound much better. In some sense, it's buying view with extra steps. Both methods are about gaming YouTube instead of creating quality content.
So no in the end, the winner of the algorithm is the one creating the "quality content".
Or in other words, if your viewer retention is terrible, it's probably because your videos are just not that good.
If you scrape away the abstractions for a second, what you will find is Mr. Beast used data to tailor his videos to get his viewers to watch lots of ads and buy lots of products and love his videos and become repeat customers. Mr. Beast is rather transparent about all of this. If you think he’s a creepy manipulative guy, you just don’t watch his content.
The whole thing with buying engagement is that you’re confusing the signal. Instead of coming through the legitimate channel where you openly pay for advertising, you intentionally deceive people, you make it just a little bit harder for the poorer and unconnected to achieve social mobility, you pollute a useful signal with false data, and you do a large number of things which annoy netizens in particular.
All I’m just saying, is that there’s more than one path to be successful. I know people who used cert dumps on the pretence that everybody else is doing it and they won’t put themselves behind, and I know others who literally just did the work and it really didn’t take THAT long in the grand scheme of things and they actually came away having learned something useful at the end of the day. Both kinds of person succeeded.
My way is way better - just simply look at the entire code base, read every file, make sure nothing phones home, internally criticize the design choices, realize I could have written something way better, start on the project, get halfway done, realize I wasted a lot of time trying to do a stupid project just to save a few keystrokes on a tiny program I almost never use, give up, and finally, realize I didn't want that package anyway.
Clearly. obviously. better.
(There's probably a krazam on this, but /s if anyone needs it)
Next I try to read through issues and PRs to see how the maintainers deal with the community.
Finally I try to develop a bit with the package. Stars generally don't factor in.
* stars - the likelihood that an issue affecting us will affect someone else. More people affected, the more likely it gets fixed.
* age and commit frequency - old projects with continuous commit history are preferable. It's okay for recent commits to become trivial/minor. Likely a sign of mature software in a maintenance mode. It's _very_ concerning when there are no commits.
* issues. This is typically a lot harder to simulate simply by buying likes. There are four factors here:
* Do the number of issues line up with the seeming popularity of the project?
* Do the types of issues line up with the types of problems you'd expect from the project?
* Are there any issues, particularly open issues, that block certain functionality or use cases?
* Do the maintainers actually interact/discuss issue?So you are equating stars with adoption, which they are really aren't a good measure of. Even in the most favorable interpretation stars can only serve as a proxy for adoption when used in combination with a lot of other signals.
Especially for hyped topics, even ungamed stars are more directly a proxy for interest rather than adoption. And as many startup founders of failed freemium products can tell you, very often interest doesn't translate to adoption.
I had to learn that myself the hard way when I helped create a top 5 starred Rust project at the time (~5k stars), which I can tell you for certain no more than a handful of people outside the company used.
As I explained, we're building an aggregate view across a bunch of metrics with human judgement making the final call. Further, we're often comparing against alternatives so this isn't really a Yes/No type of thing (especially on stars). It's a general sense of a project's well-being and stability.
----
LangChain is a great example:
* 44k stars, 5.1k forks
* Roughly 8 months old (very young)
* Very active commit history
* Insane number of issues
* Lots of open PRs
This is a tool that we'd be hesitant to use without proper risk mitigations. It's young, it's moving very quickly. While it has a lot of visibility, it's not clear if that's all moving in the right direction.
By contrast, underscore:
* 27k stars, 5.6k forks
* 11+ years old
* Stalling commit history
* Some issues, but not many.
* Not many open PRs
This is clearly a project on the opposite side of the spectrum. If you didn't know about mature alternatives (lodash, rambda, etc), it'd be a safe project to approve.
To me, the choice of Git repo should be one of the more portable aspects of a project. I know there are hideous lock-in mechanisms like issue lists and wiki discussions, but hopefully someone will standardise them one day into Git objects.
If enough people act like it has value, eventually it kinda does.
Stars are a vanity metric but, they can help with monitoring some early growth.
Everyone on this thread should list their projects, then we all star each others stuff all the way up!
I think this was Oxide and Friends show, but I'm unsure.
Makes sense on its face, popular projects = potential money. Whether that's a good signal or not is a different discussion. I even think on the episode they mention how misguided this was, people using something might not mean there is potential for revenue if the people are using it solely because it is free and licensed appropriately.
People are just looking for patterns anywhere to justify whatever they want. I've seen npmtrends used to justify adopting certain libraries. Really makes you wonder.
The Shopify acquisition of Remix (https://news.ycombinator.com/item?id=33405997) established the viability of this investment strategy.
1. People already have accounts, so it lowers the barrier to reporting issues and contributing.
2. GitHub provides some level of discovery that's hard to replicate otherwise.
Both of these are a function of GitHub being popular. It doesn't have to be a particularly great tool if it's what people are already familiar with. I wish it were otherwise, but I don't see a real alternative that can compensate for these advantages in the short term.
I love your idea of having issues/discussions/etc managed directly in Git—that seems like a more flexible and adaptable system. Even if somebody developed a standard like that, though, it seems impossible to get any of the big repo hosting sites to adopt it since it directly competes with their own value proposition :(.
Github is a package registry for NPM, Docker, Ruby Gems, Maven, Gradle, and NuGet. Quite a lot of things would break if it disappeared.
Mailing-list likers have not come to grips with this in the last twenty years and I don't expect them to start now, but the dismissive attitude might be preventing you from learning something. "Principal Skinner, it is probably not the children who are wrong."
Like: what?
Stars are basically the laziest possible way of doing anything with a repo besides looking at it. What possible signal of any value could anyone possibly hope to discern from a repo's star count? And yet not only is there an economy of counterfeit stars (flares? c.f. pieces of flair, which are equally meaningless. Also, the budget ones are ephemeral, just like a road flare), there are people who care so much about stars and flares that there's a whole 'nother economy behind discerning which are which.
Mind. Blown.
[0] Astronomer, mentioned in TFA https://github.com/Ullaakut/astronomer
I wonder, when you go to StackOverflow, if you would start by checking answers at the bottom since votes are so meaningless?
I usually read from top down to the point where the answers get to a "have you tried sticking a fork in your toaster?" levels of bad if I don't already have enough domain knowledge to know whether an answer is good for myself. It's frequently of value to me to know what the wrong way of doing something is so that I don't inadvertently go down that road myself.
It's also lower effort to read a stackoverflow answer before voting. I have greater confidence that the person voting may have actually read the answer than that a person starring a repo us actually looked at even the first bit of code.
I was actually doing my own kind-of research in hopes of starting an open-source-focused start-up. While I know stars aren't the definitive indicator of the project quality or popularity, it certainly helps build a good image, as it's one of the easiest public stats potential users can track. Also, unless gained in nefarious manners, like described in the post, they also roughly align with the project's current stage.
I was exploring how other start-up projects gain their stars, mainly by aligning the visible bumps in their star count to various events related to the project.
Pretty much all official start-up or seed funding announcements I've seen happened in the range of 300~3000 stars, mostly at ~1000. The main drivers behind the star bumps of the projects were e.g. viral HN or Reddit posts, PH launch, or getting to GitHub Trending.
For some projects however, I couldn't find any events related to the stars increases which, considering this post, makes the possibility of them being bought higher than 0.
As it gets easier and cheaper to run LLM-based bots, I wonder how long this approach will keep working. Devs in mid-to-large companies should have colleagues they can ask directly, but smaller startups might be vulnerable to being artificially swayed towards specific options.
Also, Twitter has a fomo/cool bias which is really terrible for software imo. Boring is usually better.
To all of you out there who host their open source projects on sites like github: please provide ways for your community to help out. PRs are not helpful as if you get 100 PRs in a week, there is no way that you, as a single maintainer can ever evaluate and merge all of them. You will get tired, exhausted and start looking at your project as a second job which pays nothing.
Your project will be used by fortune 500 companies and when you find out about it, you will regret not having opened a gateway for donations.
I want to support projects like semantic ui, but please help me help you. Stop hunting “stars”, as this very article clearly shows how worthless they are (github should remove this feature imho).
I can keep working on it provided there are indicators of adoption from outside Orange. In this case, the only KPI are stars and forks numbers. So stars are really important to us.
That said - perhaps I haven't looked hard enough, but it just doesn't seem like projects that accept donations make enough money (on the whole) to be worth the time spent setting up donations.
Sure, I've seen maybe two where a developer ends up being able to work on their project full-time (that's the dream), but most seem to make like $5/year or whatever.
Am I wrong? I would love to be wrong.
I'm terrible at marketing myself. I suppose that is a hurdle that I must overcome. I'll check out your projects to see what I can learn.
Congrats on your success!
Tracking the Fake GitHub Star Black Market - https://news.ycombinator.com/item?id=35207020 - March 2023 (284 comments)
Then we looked together for ways to buy that in minutes. To be honest, I knew this existed but didn't know it was so easy and widespread. It was a learning opportunity for both of us and it gave them more encouragement to continue working.
As such, I will be examining open source projects that emphasize their star count in marketing a lot more closely from now on.
This is actually more worrying, as those are frequently used for voting and can really influence the direction on a project for contentious issues: "Look at all the +1/-1!"
It's funny that the author things he discovered a "signal", from a company whose business is selling signals.
> Well, the biggest one is that those are brand new accounts — they were created at the time of my order. They don't have any fake personal information or repositories or contributions.
> And after a month, they are all gone. GitHub detected and banned them.
Obviously, the cheap option is there only to prove to the clients that expensive option is worth it. Here the author believes he found a signal - stars disappear after a month. I would bet that the people collecting the money are making they disappear to make a point.
The order number is a poor indicator of the number of orders.
I basically write my code for my own consumption. Some of my projects are kinda weird[0], because they were designed to fill a specific need at the time.
Your all probably bots too
Hashtag Elon Meta Mask anyone?
(Human or not I think I was already too annoyed with the whole thing/had annoyed them too much with the accusation to get whatever help it was I was looking for.)
Enjoy humans while they still matter.
I've never used github to find repos and don't even know how, for public projects I've heard of them some other way and went to their github page if they were hosted there...
Do they have some social networking features that I've managed to ignore so far?
I am not sure how much the advertising industry isn't just a zero-sum thing just like the casinos and exchanges for stocks and crypto. For someone to win, someone else has to lose. And the house always takes a cut from everything lol.
Github does more than just "rent space for git repos". It does do that, but there are two sides of GitHub. There is the legit CI/CD Git platform side, and then there is a social network of code side. The stars are a mechanism that contribute to the social network side of github.
There are basically three metrics on GitHub:
1. Stars - Akin to "likes" on other platforms, or favorites, or hearts. They represent a thumbsup, or a soft-bookmark to find a project later. Indicates appreciation or interest in a repo/project. These are the most common form of karma or metric on Github
2. Watch - This is like following a specific repo. You can get updates when a new release is made, pull requests are made, issues are submitted, etc.. It expresses deeper interest in a project/repo because you want to see updates as they happen.
3. Follows - These happen at the account level. So you can follow an entire organization or developer and see everything they do. This is like subscribing to someone on YouTube or following them on Instagram. You want to see more projects and updates for them in your feed.
All these metrics combine into an internal "SEO" on GitHub search (and Google search). So stars actually do tangibly contribute to the likelihood of a project being discovered by strangers. Which is what gives them value.
The author also points out that having a lot of stars is often perceived as being more trustworthy of a project. This is an intangible benefit that the author was expressing he wanted to test. However, as the author stated, this is a bad metric in practice, but it doesn't mean that other people don't perceive it that way. Similar to a twitter account with a 100,000 followers, you will assume is more noteworthy/trustworthy/prominent than someone with 1,000 followers. This is not necessarily the case, which is similar to how it works on github as well. It is often perceived this way, although it shouldn't be.
I'd assume they're better at catering to the lowest common denominator tbh.
As for libraries/project trying to solve a technical problem, I'd look for 3rd parties saying they're using them and how it's going for them. Definitely wouldn't trust "stars".
They used to be described as a "bookmark" for a repo, same as browsers do for web pages.
Thinking that over a bit more, it's still probably the more accurate mental picture of what they're for vs a "like". But, that might just be me. :)
I know it's not a perfect measure but I don't have infinite time to spend researching every choice I make, and this is (for now) a pretty reasonable heuristic that a library is maintained and has eyeballs on it.