June 26th, 2024

Reputation Farming Using Closed GitHub Issues

Reputation farming on GitHub involves manipulating closed issues and pull requests to falsely boost accounts' reputation. Maintainers are urged to monitor activity, report suspicious behavior, and automate checks to prevent this deceptive practice.

Read original articleLink Icon
Reputation Farming Using Closed GitHub Issues

Reputation farming using closed GitHub issues and pull requests has been reported by maintainers in discussions on OpenSSF's Slack. This suspicious activity involves commenting or approving on closed items, allowing accounts to boost their GitHub reputation falsely. While reputation farming may appear harmless, recent incidents highlight the need for OSS maintainers to be vigilant against illegitimate trust-building efforts. To address this, it is recommended to monitor repository activity, report users engaging in such behavior, and consider locking old issues, pull requests, and discussions. GitHub actions can automate this process after a period of inactivity. This activity is actively exploited for reputation farming, with potential for further malicious use. Resources provided include links to discussions on OpenSSF Slack and GitHub actions to lock old threads. Maintainers are advised to increase awareness and take proactive measures to prevent reputation farming in OSS repositories.

Link Icon 0 comments