frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We stopped AI bot spam in our GitHub repo using Git's –author flag

https://archestra.ai/blog/only-responsible-ai
77•ildari•48m ago

Comments

ildari•48m ago
Hi HN community, I wanted to share our approach to reduce amount of AI slop PR's and issues in our repo. We enabled "require prior contribution" flag on GH and created a CI script that creates a tiny commit co-authored with you, if you pass captcha on our website. Worked really well and we were able to block at least 500 bots in the first week. Sharing a screenshot from cloudflare: https://archestra.ai/hn-comment-cloudflare-challenge-outcome...
satvikpendem•35m ago
Yep, this is similar to some other version control tools like Tangled which has vouching.

https://blog.tangled.org/vouching/

tln•23m ago
Thats a really elegant solution.

How does the website trigger the CI script? Through GH rest API?

ildari•16m ago
thank you, yep through the rest API, here is the example: https://github.com/archestra-ai/website/blob/29ebdacbd8a22b9...
silverwind•20m ago
PR spam is a major problems for repo that run bounties. Maybe GitHub should temporarily block accounts from raising PRs if like 95%+ of them are getting rejected.
marginalx•14m ago
Problem is the bots can create any number of github accounts and continue spamming. Though this would be a good simple defense to start with.
hiccuphippo•12m ago
GitHub has not incentive for blocking AI. It's like asking an ad company to build an adblocker into their browser.
cdrnsf•5m ago
GitHub and Microsoft are actively contributing to the problem, why would they admit fault?
zer0tonin•19m ago
> Should we stop giving fun test tasks to our job candidates?

Yes

hiccuphippo•14m ago
The irony of the .ai domain.
delduca•12m ago
For now…
ramon156•11m ago
See, this is an article that uses dashes correctly. It adds value, creates a bit of buildup
chrismorgan•3m ago
This is funny to me because the title on this submission currently refers to “Git's –author flag”, which is an extremely incorrect use of a dash. (The original article doesn’t make the mistake. Not sure if the error is from the submitter or from an HN title mangulation.)
arecsu•11m ago
Makes me wonder if an ELO-based system would work to mitigate these issues. People who merged PR successfully onto a project, that had real issues acknowledged, the quality of their responses measured by other users reactions or something, etc, multiplied possibly by the degree of importance of the project where their activity has been made. Won't be about human vs AI, but actual helpful effective being vs low effort/spammy contributions. Issues and PRs could be sorted and filtered by their ELO score. I'm saying ELO as analogy to "score based given the context", not really a 1:1 translation of the ELO system
petterroea•8m ago
What I see is a (clever) hack, and GitHub continuing to provide good tools to its users.
captn3m0•5m ago
This has a security implication which is overlooked. Contributors to a repository have higher rights, such as avoiding approval requirements for fork PR runs. GitHub warns in the docs:

> When requiring approvals only for first-time contributors (the first two settings), a user that has had any commit or pull request merged into the repository will not require approval. A malicious user could meet this requirement by getting a simple typo or other innocuous change accepted by a maintainer, either as part of a pull request they have authored or as part of another user's pull request.

First Streaming Fraud Case: A Musician's Alleged $10M Scam

https://www.rollingstone.com/music/music-features/streaming-fraud-fake-streams-mike-smith-1235500...
1•Geekette•2m ago•0 comments

Show HN: ThreeFour – run multi-step procedures one step at a time

https://threefour.app
1•onwardwild•2m ago•1 comments

How to Read Like a Child Again

https://www.theatlantic.com/newsletters/2026/05/childrens-books-adults/687191/
1•paulpauper•3m ago•0 comments

Microsoft testing adjustable taskbar, Start menu in Windows 11

https://www.bleepingcomputer.com/news/microsoft/windows-11-finally-gets-a-resizable-taskbar-and-s...
1•Brajeshwar•3m ago•0 comments

AI Has Broken Containment

https://www.theatlantic.com/technology/2026/05/ai-inflection-point-trump-china/687202/
2•paulpauper•4m ago•0 comments

News.Y Combinator.com/Submit

https://agentmemo.vercel.app
1•pulsoai•4m ago•0 comments

Antislop: Identifying and Eliminating Repetitive Patterns in LLMs

https://iclr.cc/virtual/2026/poster/10008156
2•Der_Einzige•5m ago•0 comments

ImpactArbiter – A PyTorch autograd trap for LLM memory bugs

https://github.com/msunda17/impactarbiter-cli
1•maniksundar•6m ago•0 comments

The US space enterprise is desperately waiting for Starship

https://arstechnica.com/space/2026/05/the-us-space-enterprise-is-desperately-waiting-for-starship...
1•tosh•6m ago•0 comments

A Rust-Python thing I am working on. Apache 2 licence

https://github.com/KevinKenya/nairobi-connector-open-source
2•kevinkenya•6m ago•0 comments

Bachelors Without Bachelor's: Gender Gaps in Education and Declining Marriage

https://www.nber.org/papers/w35179
1•paulpauper•7m ago•0 comments

Skybridge – the MCP Apps framework released v1.0

https://github.com/alpic-ai/skybridge/releases/tag/v1.0.0
3•Eldodi•8m ago•0 comments

Windows 11 brings back much-missed taskbar options

https://arstechnica.com/gadgets/2026/05/five-years-later-windows-11-brings-back-much-missed-taskb...
1•tosh•8m ago•0 comments

Everything You Need to Know About Black Cocoa Powder (2022)

https://saltandbaker.com/black-cocoa-powder-guide/
1•thomassmith65•9m ago•0 comments

Show HN: Eazip – Password-protected ZIPs (AES-256) in the browser, no upload

https://www.eazip.ch/
2•Zmaon•10m ago•0 comments

At Protocol for Agents

https://davidgasquez.com/atproto-agents
1•kalendos•12m ago•0 comments

For 20 years, Stephen Colbert distinguished truth from truthiness

https://www.npr.org/2026/05/18/nx-s1-5815315/stephen-colbert-final-show
3•geox•15m ago•0 comments

Preventing AI agents from executing destructive terminal commands

https://github.com/7Majesty-M/terminal-guardian-mcp
1•majesty-m•15m ago•1 comments

OVCS: Raspberry Pi–powered electric car

https://www.raspberrypi.com/news/ovcs-raspberry-pi-powered-electric-car/
1•Brajeshwar•16m ago•0 comments

Can we combine excellent design and branding simultaneously?

https://antar.me/blog/branding-vs-good-design/
1•redaantar•17m ago•0 comments

Show HN: Citycal – Collaborative Events Calendar

https://citycal.com
1•oliv__•17m ago•0 comments

How India's cooking fuel shortage is driving up California's gas prices

https://www.reuters.com/business/energy/how-indias-cooking-fuel-shortage-is-driving-up-california...
1•tartoran•18m ago•0 comments

Show HN: Kaption – Live OCR subtitle overlay

https://github.com/wojciechowskiapp/Kaption
1•wojciechowskiap•18m ago•0 comments

Clojure Freed Me from the Ceremony

https://carlosblanco.github.io/clojure/functional-programming/2020/10/15/functional-programming-c...
1•zonotope•18m ago•0 comments

HTML5/EPUB3 Version of SICP

https://github.com/sarabander/sicp
3•caminanteblanco•21m ago•0 comments

Judge grants accused CEO killer Mangione's bid to suppress evidence

https://www.reuters.com/legal/government/luigi-mangione-due-court-ruling-backpack-evidence-ceo-ki...
5•tartoran•21m ago•0 comments

Information for most known natural bodies in our solar system

https://ssd.jpl.nasa.gov/
4•mooreds•24m ago•0 comments

A Master's Degree Isn't the Job Guarantee It Used to Be

https://www.wsj.com/lifestyle/careers/a-masters-degree-isnt-the-job-guarantee-it-used-to-be-53e237aa
6•JumpCrisscross•24m ago•1 comments

Linux 6.6 LTS To Linux 7.1 Bechmarks: Performance Up 13% Threadripper Over 3 yrs

https://www.phoronix.com/review/linux-66-linux-71
1•Bender•24m ago•0 comments

Amazon is deploying these cargo e-bikes for deliveries

https://electrek.co/2026/05/17/amazon-is-deploying-these-massive-cargo-e-bikes-for-deliveries/
1•Bender•25m ago•1 comments