Skip to content

#GitHub

1 today

Apr 21Tuesday

QbitAI · WeChat

GitHub Stars are openly sold for RMB 0.5 each, with AI projects hit hardest by fake stars

Carnegie Mellon University reports about 6 million suspected fake GitHub Stars from 2019 to 2024, spanning 18,617 repositories and over 300,000 accounts. Its StarScout tool flags bot accounts and synchronized starring, with 81% accuracy; 78 heavily inflated projects reached Trending. The key point for AI practitioners: the post says AI/LLM projects rank first in fake-star volume among non-malicious repos, and the boost lasts under two months.

Why it matters: HKR-H, HKR-K, and HKR-R all pass. The CMU study turns fake GitHub Stars into a quantified issue—6M suspect Stars across 18,617 repos with 81% detector accuracy—and links the heaviest non-malicious abuse to AI/LLM repos; strong featured story, but not a model or product launch.

Hacker News front page

CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production

Brex open-sourced CrabTrap, an HTTP proxy that intercepts every agent request and allows or blocks it against a policy in real time. The page shows a dual path of static rules plus an LLM judge, and logs whether each decision came from rule matching or model judgment; the post does not disclose the model, latency overhead, or error rates.

Why it matters: This lands on HKR-K and HKR-R, with HKR-H from the 'LLM-as-a-judge HTTP proxy' hook. The open-source artifact and execution-layer mechanism are concrete, but the post does not disclose the judge model, latency overhead, or false-positive rate, so it stays in the high 70s.

X · @dotey

GitHub paused new sign-ups for Copilot Pro, Pro+, and Student on April 20

GitHub paused new sign-ups for Copilot Pro, Pro+, and Student on April 20, leaving only Copilot Free open to new users. The post says Pro+ now has more than 5x Pro usage, Claude Opus 4.7 is limited to Pro+, and users can request cancellation with a full April refund from Apr 20 to May 20. What matters is the price stayed fixed while access, quotas, and model tiers tightened first.

Why it matters: This is not a capability launch; it is a meaningful Copilot packaging clampdown on entry, quotas, and model access. HKR-H/K/R all pass on the unexpected restrictions, concrete tier changes, and direct developer impact, but the source is an X post rather than a primary GitHub note

Apr 16Thursday

Latent Space

[AINews] RIP Pull Requests (2005-2026)

GitHub is, for the first time 21 years after pull requests emerged, letting open-source repos disable PRs; the post frames this as a signal that AI coding workflows are changing collaboration. It gives a 2005-to-2026 timeline and cites agent stacks from OpenAI and Cloudflare as pressure toward prompt-driven contributions and sandboxed execution; the real question is whether Git-based workflows still fit agent collaboration.

Why it matters: This is not a primary GitHub announcement, but it turns one concrete change—open-source repos can disable PRs—into a sharp workflow question for agent coding. HKR-H/K/R all pass; the score stays mid-featured because the excerpt lacks scope, adoption data, and primary-source GitH​

Apr 15Wednesday

X · @dotey

pi maintainer Mario Zechner sets a new rule: unapproved issues and PRs will be auto-closed immediately

pi maintainer Mario Zechner says any issue or PR submitted without prior approval will be auto-closed, after he started receiving 30 to 50 issues per day and most were AI-agent spam. He will still review closed submissions daily; strong issues can earn an “lgtmi” tag, and strong issue-plus-fix PRs can earn “lgtm,” exempting future submissions from auto-close. The shift to watch is simple: open source projects are raising contribution gates to filter zero-cost AI-generated noise.

Why it matters: Featured on strong HKR-H/K/R: a maintainer-level policy change with concrete spam numbers and a review mechanism. Importance stays in the mid-70s because the blast radius is mainly the OSS agent/dev community, not a major model or platform release.

Mar 6Friday

Ruan YiFeng's Weblog

Technology Enthusiast Weekly Issue 387: You Are Ahead

Ruanyifeng says that, out of 8.1 billion people, only 1.38 billion have used AI, or 16%; just 15 to 25 million pay for AI services, or 0.3%. The post adds that only 2 to 5 million people have used AI to create their own coding projects, or 0.04%. The real signal is the adoption gap, not the idea that everyone already uses AI.

Why it matters: This is data-backed commentary, not a product launch or primary reporting. HKR-H/K/R all pass: the angle punctures the 'everyone uses AI' narrative and supplies 16% / 0.3% / 0.04% adoption estimates, but the source basis is unclear here, so it sits at the low end of featured.

Feb 4Wednesday

TheValley101 (硅谷101)

E224 | Why Clawdbot became the first breakout product of 2026 amid the Mac mini rush | Moltbot | MoltBook | OpenClaw

The podcast says Clawdbot passed 100k GitHub stars within days and reached 146k on Feb. 2, while being renamed to Moltbot and then OpenClaw within a week. It attributes the traction to a stack of Claude, long-term memory, IM-based messaging, and proactive heartbeat workflows; the title mentions a Mac mini rush, but the post does not disclose sales figures. The real signal is the interaction layer rather than a new model release: this is industry commentary and user anecdotes, not an official spec sheet.

Why it matters: This is a commentary-led breakdown of a hot agent phenomenon, not a primary launch. HKR-H/K/R all pass: the 146k-star surge and rename chain are novel, the post explains memory + IM + heartbeat mechanics, and it hits nerves on agent UX, dedicated hardware, and security bills; the

Sep 25, 2025Thursday

OpenAI News

More ways to work with your team and tools in ChatGPT

OpenAI rolled out shared projects for ChatGPT Business on September 25, 2025, and made them available for Enterprise and Edu plans. Shared projects support email or link invites, two access levels, and private project memory; Enterprise and Edu have them off by default under admin control. OpenAI also added Gmail, Google Calendar, Outlook, Teams, SharePoint, GitHub, Dropbox, and Box connectors, and said ChatGPT can now choose connectors automatically per prompt.

Why it matters: HKR-H/K/R all pass: shared projects, 8 connectors, and prompt-routed connector selection are concrete workflow changes with clear admin controls. I keep it below 85 because this is a collaboration-layer product update, not a model release or a broad capability jump.

Sep 15, 2025Monday

OpenAI News

Introducing upgrades to Codex

OpenAI released GPT-5-Codex and made it the default model for Codex cloud tasks and code review; in testing, it worked independently for more than 7 hours on complex tasks. OpenAI says it used 93.7% fewer tokens than GPT-5 on the lowest 10% of employee turns, while spending 2x longer reasoning, editing, and testing on the highest 10%. The key point is one model now spans interactive coding and long-running agentic execution; pricing and full availability details are not fully disclosed in the provided body.

Why it matters: This is a substantive OpenAI developer-tool update: GPT-5-Codex becomes the default for Codex cloud tasks and code review, with concrete numbers on 7-hour autonomy and token use. HKR-H/K/R all pass; pricing and full availability are not fully disclosed in the excerpt, so it stays

OpenAI News

Addendum to GPT-5 system card: GPT-5-Codex

OpenAI published a GPT-5-Codex system card addendum on September 15, 2025, stating the model is optimized for agentic coding in Codex and is available in terminal, IDE, web, GitHub, and the ChatGPT mobile app. The post says it uses reinforcement learning on real-world coding tasks, plus safety training for harmful tasks and prompt injection, with sandboxing and configurable network access. Benchmark scores, pricing, and context window are not disclosed.

Why it matters: HKR-H/K/R all pass: this is an OpenAI coding-agent model spanning terminal, IDE, GitHub, web, and mobile, with concrete training and safety details. I kept it below 85 because benchmarks, pricing, and context window are not disclosed in the body.

May 16, 2025Friday

OpenAI News

Addendum to OpenAI o3 and o4-mini system card: Codex

OpenAI published a May 16, 2025 addendum to the o3 and o4-mini system card, stating that Codex is a cloud coding agent powered by codex-1, an o3 variant tuned for software engineering. Each agent runs in an isolated cloud container preloaded with the user's code and environment, then loses internet access while it reads or edits files and runs tests, linters, and type checkers. The practical detail is the audit trail: Codex cites terminal logs and files, and its output can be exported as a GitHub PR or local diff.

Why it matters: This clears HKR-H/K/R because the addendum adds concrete execution details: isolated cloud containers, user-defined dev envs, internet disabled after setup, and test-running behavior. Strong featured score, but not p1: it is supporting safety documentation, not the primary launch

OpenAI News

Introducing Codex

OpenAI released the Codex research preview on May 16, 2025, a cloud software engineering agent powered by codex-1 that can handle multiple coding tasks in parallel. It runs each task in an isolated sandbox, can read and edit repos, execute tests and commands, and usually finishes in 1 to 30 minutes with terminal logs and test outputs as evidence. It launched for ChatGPT Pro, Business, and Enterprise users, then expanded to Plus on June 3; the post excerpt does not fully disclose pricing or complete limitations.

Why it matters: This is a same-day write: OpenAI moved from code assistance to a cloud software-engineering agent, with launch access for ChatGPT Pro, Business, and Enterprise. HKR-H/K/R all pass, with concrete mechanics and verifiable outputs; incomplete pricing and limits keep it at 88.

Aug 13, 2024Tuesday

OpenAI News

Introducing SWE-bench Verified

OpenAI released SWE-bench Verified, a human-validated subset built with the benchmark’s authors to assess real software issue resolution more reliably. The post names 3 failure modes in SWE-bench: overly narrow tests, underspecified issue statements, and unreliable environment setup; as of Aug. 5, 2024, top agents scored about 20% on SWE-bench and 43% on SWE-bench Lite. The key point is that the original benchmark can systematically underestimate coding-agent ability.

Why it matters: This is a strong benchmark release, not a routine post: OpenAI re-audited SWE-bench with the original authors, named 3 defect classes, and reported new score ceilings of 20% and 43%. HKR-H/K/R all pass because it changes how builders read code-agent leaderboards.