I find it ironic that the people who originate the idea of AI-code-spam are being negatively impacted by this.
But all they will do is build an AI agent to review the code written by an AI agent, that probably never needed to be written to begin with.
They're also happy to leave it to "open source" to navigate the fall out.
I can't see those pull request limits working very well. It's like trying to filter email spam by just rate limiting people. It's going to be annoying for the people you actually want to talk to, and you're still going to get at least 1 spam message from every spammer out there.
Unless I totally missed that people are also making new accounts of each PR.
Disappointing, it seems that those also need limits too, although the limit could be higher.
I could easily see the limit for PRs be at 1 for untrusted contributors, and drafts at 3-5.
As long as it's taken as an indicator for WIP, it works. It just doesn't work when acting illiterate of this distinction; and I have often have had PRs switched to "ready", reviewed + merged in a couple of hours.
But when the change list grows, and the PR ages, while still being intentionally maintained, the Draft signal is strong and helpful IMO. Switching an old Draft PR to "ready" after reviving it with changes seems like a useful signal to me.
> Or using it correctly...
Note that people using AI to make spam pull requests are not using the system correctly.