【文章标题】:Please stop flooding our projects with AI slop to furnish your CV
【文章标题】:请停止用AI生成的垃圾内容充斥我们的项目来装饰你的简历

【文章正文】:
Successful contributions to open source projects are a kind of currency. GitHub in particular encourages this in a number of ways: by showing avatars of contributors on repository pages, by showing your contributions to your followers via the activity feed and by signalling contributions per day on the activity graph of your profile. Potential hiring managers often take note of this. Recruiters often find and screen candidates this way. If you are a software developer (either existing or aspiring) looking for work, tuning these signals can often work to your advantage.
对开源项目的成功贡献是一种硬通货。GitHub尤其通过多种方式鼓励这种行为:在仓库页面展示贡献者头像、通过动态信息流向关注者展示你的贡献、以及在个人资料的活动图表中显示每日贡献量。潜在的招聘经理往往会注意到这些。招聘人员也常通过这种方式寻找和筛选候选人。如果你是一名正在求职的软件开发者(无论经验丰富或初出茅庐),优化这些信号通常对你有利。

As an open source maintainer, it’s quite noticeable how the pattern of external contributions has changed in the last year. We’re far more likely to receive pull requests instead of issues. If we do receive issues, they often come with an AI-generated analysis attached. We’re receiving far more security vulnerability reports than ever before and often they even come with AI-generated fix proposals attached too.
作为开源维护者,过去一年外部贡献模式的变化非常明显。我们收到拉取请求的概率远高于问题报告。即便收到问题报告,也常常附带着AI生成的分析。我们接收到的安全漏洞报告数量激增,其中许多还附带AI生成的修复方案。

I don’t doubt that some of these contributions are from people who are genuinely interested in what we do, but the cynical part of me believes that a substantial amount of this is that people are realising that AI can be used to game GitHub to their own benefit. It’s now easy to ask Claude to generate a list of interesting open source projects, then ask Claude to find some problems in them, and then ask Claude to raise some PRs to fix them. You don’t even have to use the projects or care about them, but you can easily create the illusion to outsiders that you care, or that you found a problem, or that you put the time into fixing it. On the internet, nobody knows you’re a dog, but with the help of LLMs, you can effortlessly overstate your human abilities on your GitHub profile.
我不怀疑部分贡献者确实对我们的工作感兴趣,但 cynical 的一面让我相信,更多人只是意识到可以利用AI操纵GitHub谋取私利。现在只需让Claude生成有趣的开源项目列表,再让它找出问题并提交修复PR。你甚至不需要使用或关心这些项目,却能轻松制造出你关心项目、发现问题或投入时间修复的假象。互联网上没人知道你是一条狗,但借助大语言模型,你可以毫不费力地在GitHub资料里夸大自己的能力。

Recently, a contributor with virtually no GitHub-wide contributions from late 2018 up until a couple weeks ago, with no prior engagement with our project that we know of, raised three separate PRs to correct spelling and grammar mistakes in comments. Claude made the fixes, presumably wrote the PR descriptions, even signed off the commits on behalf of the user and then helpfully inserted its co-authorship into the commit message trailers. Maybe it even opened the PRs itself, who knows. I’d be fascinated to know whether the prompt was to “go and find issues” or whether to focus on spelling and grammar issues in particular for whatever reason.
最近,一位自2018年底至几周前几乎没有任何GitHub全域贡献、与我们项目素无交集的用户,连续提交了三个PR来修正注释中的拼写和语法错误。Claude完成了这些修改,可能还撰写了PR描述,甚至代表用户签署提交,并”贴心”地在提交信息尾部添加了自己作为合著者的声明。说不定连PR都是它自己开的。我很好奇用户输入的指令是”去找问题”,还是特意要求聚焦拼写语法问题。

The changes were harmless and correct, but that did not make me feel better about accepting or merging them. Instead I couldn’t help but ask myself: why this, why now? Why, out of all of the issues and TODOs and FIXMEs in our codebase are they submitting this? And then it dawned on me that these contributions weren’t about our project at all.
这些修改无害且正确,但并未减轻我接受或合并它们的不适感。我不禁自问:为什么是这些?为什么是现在?代码库里有那么多issue、TODO和FIXME,为何偏偏提交这些?后来我恍然大悟——这些贡献根本与我们的项目无关。

I closed all three PRs without comment.
我未作说明直接关闭了这三个PR。

Maybe this was unreasonable, but truthfully, I’m just not interested in encouraging people to take up our time with this kind of busywork. I do not want to set a precedent of accepting PRs that materially improve nothing, nor do I want our contributor list to become a reward for asking a robot to fix typos.
或许这不够通情达理,但说实话,我不想鼓励人们用这种琐事占用我们的时间。我不愿开创接受毫无实质改进PR的先例,也不希望我们的贡献者列表沦为调用机器人改错别字的奖池。

The same pattern has emerged with security vulnerability reports. CVEs traditionally are credited to their reporters, but all of the reports that we have received recently have been obviously AI-generated. Security fixes are always important of course, but again I find myself wondering if this is happening because people care about the fixes or because they are looking for an easy credit. We have been far more selective lately when evaluating the severity of such reports and, in some cases, declining to issue CVE notices for low-severity items. I have some feelings about the fact that private disclosure is dying anyway, which I may write about another time, but the effort involved in coordinating private fixes and disclosure notices and releases is substantial enough to require us to be selective.
安全漏洞报告也出现同样模式。传统上CVE会标注报告者,但我们近期收到的所有报告明显都是AI生成的。安全修复固然重要,但我再次怀疑:人们是真心关注修复,还是只想轻松获取署名?我们最近会严格评估这类报告的严重性,有时甚至拒绝为低危项发布CVE通知。关于私下披露机制日渐式微的现象我有些想法(或许另文探讨),但协调私下修复、披露通知和版本发布的工作量实在太大,我们必须精挑细选。

Ultimately, open source is built on trust. The metric that matters is not how many pull requests you can persuade an LLM to produce, nor how many CVEs you can accumulate, but whether you can make a project meaningfully better. If you want to contribute to open source projects, contribute because you care. If all you want is another green square or another contributor badge, please go elsewhere.
归根结底,开源建立在信任之上。重要的不是你能否说服大模型生成大量PR,或积累多少CVE,而是能否让项目真正变得更好。如果你想为开源项目做贡献,请出于关心而贡献。若你只想要多一个绿色方格或贡献者徽章,请另寻他处。