TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

4.5M Suspected Fake Stars in GitHub

236 pointsby qianli_cs5 months ago

31 comments

halamadrid5 months ago
Another interesting way - and I personally think its fraudulent. This is how it goes - run hackathons or sponsor events in Universities. There are a ton of colleges who are constantly seeking support to run events.<p>Some companies take advantage of this by asking for stars in return of sponsorship. I have seen proposals that say for a $2000 sponsorship - 2000 stars guaranteed. The way it works is if a participant registers in the event they also have to show proof that they starred a specific repo that belongs to the company.
评论 #42582849 未加载
评论 #42580945 未加载
评论 #42580715 未加载
评论 #42581049 未加载
zitterbewegung5 months ago
All metrics will be gamed at some point. I don&#x27;t know exactly how you could even fight this.
评论 #42578304 未加载
评论 #42578248 未加载
评论 #42578621 未加载
评论 #42578252 未加载
评论 #42579985 未加载
评论 #42578405 未加载
评论 #42578493 未加载
评论 #42578213 未加载
评论 #42578626 未加载
评论 #42578409 未加载
评论 #42578867 未加载
prepend5 months ago
I don’t like stars as a metric. Or at least as a comparator. If you brag about having a millions stars that says something as a million is a lot.<p>But if you brag that your project as a million and your competitor has half a million, that is so illogical that I would discount your project and think it’s run by dummies.<p>Are there practical situations where people really need stars enough to buy them?
评论 #42578117 未加载
评论 #42578481 未加载
评论 #42577955 未加载
评论 #42578180 未加载
gitgud5 months ago
GitHub Stars are just one of many signals that describe the quality of a project.<p>If a project has 10,000 stars but 1 commit and a terrible README… then the star count doesn’t have as much weight…<p>You can’t trust any signal in isolation (like star count), but looking at many signals together is quite reliable
评论 #42581254 未加载
hobs5 months ago
<p><pre><code> Allow it a week to finish all iterations and expect it to read &gt;= 40TB of data. You can use nohup to put it as a background process. After a week, you can run the following command to collect the results into MongoDB and local CSV files: </code></pre> I just love the yolo nature of &quot;well let&#x27;s check in a week if that 40TB of data processing worked&quot;
评论 #42578059 未加载
mentalgear5 months ago
In a world with so much fake PR stuff and AI slop, any and all project that tries to verify what&#x27;s real and what&#x27;s not is an excellent choice of topic, fostering integrity again in the our industry.<p>Here&#x27;s the actual repo: <a href="https:&#x2F;&#x2F;github.com&#x2F;hehao98&#x2F;StarScout">https:&#x2F;&#x2F;github.com&#x2F;hehao98&#x2F;StarScout</a>
ashvardanian5 months ago
Not surprising at all, honestly. The incentive to farm stars is massive. According to the article, 10K stars can cost just $1K, whereas achieving those numbers organically often takes years of work, millions in R&amp;D, and countless deployments. When this seemingly trivial metric becomes a key factor in unlocking capital from VCs, it’s no wonder people resort to shortcuts. In a way, the real surprise is that not everyone is buying stars.
评论 #42583683 未加载
cvoss5 months ago
I&#x27;ve never once starred a GH project, nor ever looked at or considered the star count of a project in order to evaluate it. What do people actually use this metric for? (This is not a rhetorical question. If you use it, I&#x27;d like to know why&#x2F;how.)
评论 #42580398 未加载
评论 #42582176 未加载
评论 #42580412 未加载
评论 #42583013 未加载
评论 #42580383 未加载
评论 #42580424 未加载
attentionmech5 months ago
I think number of clones is a much better metric (it&#x27;s like proof of work, it needs compute to clone a repo). For me starring a repo is liking bookmarking it, nothing else. They might as well just mark it as &quot;Bookmarked&quot; instead of &quot;Starred&quot;.
评论 #42578985 未加载
评论 #42578666 未加载
评论 #42579173 未加载
评论 #42579918 未加载
评论 #42578688 未加载
评论 #42578697 未加载
评论 #42579937 未加载
评论 #42578914 未加载
评论 #42579737 未加载
评论 #42578919 未加载
评论 #42579956 未加载
评论 #42579809 未加载
simoncion5 months ago
IMO, Github stars and number of &quot;forks&quot; are just as good a metric as &quot;number of daily downloads&quot; of a library or Docker image or similar.<p>After noticing how many, many companies run many, many builds through their CI systems and (for a variety of reasons) end up re-downloading everything those builds require, regardless of whether or not it has changed since the last time they ran the build, I&#x27;ve come to the firm conclusion that these metrics are just plain bad if one uses them as a basis to make any significant decision.
johncoltrane5 months ago
$PROJECT was bookmarked 666 times with GitHub&#x27;s internal bookmarking mechanism doesn&#x27;t say much about a project.<p>The fact that so many people give those bookmarks so much value that an entire ecosystem was built around &quot;fake&quot; bookmarks is mind boggling.
ocean_moist5 months ago
The github social media features are so weird I get around 10 follow requests per week from random people who follow &gt;2k people something off happening there.
评论 #42579354 未加载
dzonga5 months ago
do stars even count ?<p>my determination to use a project is 1. the readme 2. the issues
评论 #42578394 未加载
评论 #42579066 未加载
评论 #42578800 未加载
评论 #42589808 未加载
评论 #42578476 未加载
评论 #42578350 未加载
medv5 months ago
This means 4.5M fake accounts. GitHub does a good job of detecting bots, but room for improvements still exists.
评论 #42578889 未加载
ivanjermakov5 months ago
In my experience, open&#x2F;closed issues ratio is much more important than star count.<p>Star count is how interested people are in this project, does not signify much about its quality. I would not star the repo of a tool I use everyday, but would star some obscure project to try it out later.
评论 #42584389 未加载
openrisk5 months ago
If you were wondering about fake forks, spoiler alert<p>&gt; counts in Cluster 1 come from merchants that only sell stars, while accounts in Cluster 2 come from merchants selling stars and forks simultaneously
cute_boi5 months ago
The best solution is to github buy start themselves and ban all those users after 1-2 months, so they wouldn&#x27;t even have a clue.
评论 #42584216 未加载
RecycledEle5 months ago
When people can make money off Internet credit, the con-artists take over and get more fake credit than the real creators earn. Then the con-artists drive away the real creators.<p>This has happened on many other sites, and now I suspect it&#x27;s happening on Git Hub.
Der_Einzige5 months ago
I wrote a whole benchmark which is not only resistant to this, but would automatically detect most fake stars!<p><a href="https:&#x2F;&#x2F;github.com&#x2F;Hellisotherpeople&#x2F;Bright">https:&#x2F;&#x2F;github.com&#x2F;Hellisotherpeople&#x2F;Bright</a>
评论 #42587674 未加载
nsoolo5 months ago
It is very easy to distinguish false stars, the important thing of a repository is not the stars but the activity of the contributors, I have seen many times repositories with malicious payloads with 1.7K stars or more.
a1o5 months ago
Not directly related, but I have seen Ads in Stack overflow for GitHub repositories - not any notable repository, clearly just random people trying to get some stars for reasons.
anshumankmr5 months ago
Ha, guilty as charged, I used the github profile that I had from my previous two companies to give stars to some of my favourite repos on my personal account.
bawolff5 months ago
What is even the point of stars in the first place.<p>This is github not facebook. Who cares how many stars your open source repo has as long as it is useful to someone.
knowitnone5 months ago
github should be the ones doing this research, or at least sponsoring this but you know they won&#x27;t because they don&#x27;t care.
albert_e5 months ago
split the current star function into a &quot;star rating&quot; and a &quot;save bookmark&quot; function<p>let both users and repos opt out of &#x2F; hide star ratings if they don&#x27;t care about this popularity contest<p>let bookmarks be always private to users -- so users can peacefully organize their bookmarks for what they are
评论 #42583546 未加载
lprd5 months ago
Do we need that type of metric anyways? Surely there are better ways to measure a repo&#x27;s activity...
评论 #42579478 未加载
kittikitti5 months ago
I think a repository should have at least 1 star, meaning at least the author liked it.
semiinfinitely5 months ago
sometimes I star my own github repos does that count as fake
评论 #42579503 未加载
remram5 months ago
What&#x27;s a &quot;real&quot; star on GitHub? Most real users will click the star button after reading the README, it does not indicate that they like it or even tried it. Having a &quot;star on GitHub&quot; button in a judicious place on your project&#x27;s website will already over-inflate your number of stars regardless of your project&#x27;s quality. You don&#x27;t have to be a professional developer to get a GitHub account either. The age of a project (or more precisely, how long it&#x27;s been on GitHub) also has a massive impact on the stars.<p>What was ever so good about the &quot;N strangers clicked the icon&quot; metric? Even when those users were human with a higher probability?<p>&gt; posing a security risk to all GitHub users<p>Please tell me no one takes the &quot;N strangers clicked the icon in the past&quot; as a signal of &quot;today&#x27;s releases won&#x27;t harm my computer&quot;.
casenmgreen5 months ago
I&#x27;m rather surprised it&#x27;s only 4.5m.
dang5 months ago
(We merged comments from <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42573954">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=42573954</a> to this thread.)<p><a href="https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;over-31-million-fake-stars-on-github-projects-used-to-boost-rankings&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;over-31-milli...</a>