The work in cloning a repo is negligible, and the requirement of work is not a security design guarantee in github. The actual cost of liking projects is network, malicious actors need to create fake accounts, waste IP addresses and ip blocks in the process. Whether you are cloning or liking is just the last mile.
To me the takeaway is not to trust a project based on it's github metrics, and by extension not to trust projects just because they are linked and liked in hacker news for example. And to be wary of how I introduce dependencies into my projects.
Not just because of strictly malicious dependencies, but also because of trash dependencies that don't add value.
And at best, will still need maintenance in the future. One of the top lessons I preach to juniors.
"our study does not find any evidence of fake stars being used for social engineering attacks"
Github should just stop showing star counts. Who cares about them.
Two metrics that I think correlate extremely highly with quality: The number of commits in the repository and the date of the most recent commit. I've used a metric based on those two inputs for the past 15 years to evaluate repos and I am not disappointed. Depending on the nature of the project, I weigh the two attributes differently. Some projects are arguably, 'done', and so the date of the most recent commit is not very important in that case.
That said, the package repositories for many popular languages list stats of either declared dependencies or package downloads, which helps.
Anyway if stuff is used by proprietary stuff it will also sit at 0.
I now moved to codeberg where there is less spam, although it does have stars
This is how I always interpreted the star feature and have used it as a bookmarking feature. I didn't know it was more akin to a like button!
https://arxiv.org/pdf/1811.07643 is some investigatory research describing, among other things, 4 clusters of reasons for starring: to show appreciation, bookmarking, due to usage, due to third-party recommendation.
But I agree it's not like this is also without any issues
If it has no downloads/stars you don’t care. If it has big amount let’s take time checking it out.
Fun part starts when checking out part is limited to some minimum and goes to prod because it solves something. Where people might not even know if that library is any good at all.
The changes were very minor. My VM was an 8-bit Avr. I just needed to add a profile for an imaginary microcontroller with no peripherals, 64k ram and 64k words ROM.
So what was on GitHub is an unmodified fork, 16 years behind upstream, and has acquired 20 stars. 8 in the last year.
Literally all I ever use the stars for, I don't know what they are 'supposed' to be used for if not that.
(just a joke that immediately came to mind, not intended to undermine OP's idea)
It's github's compute, so why do I (the person who's cloning the repo) care about the compute? I don't pay for it!