我们所熟悉的开源已经死了
Open Source as We Know It Is Dead

原始链接: https://jross.me/open-source-as-we-know-it-is-dead/

作者回顾了自己的开源历程:从 2011 年在 TShock 提交的一个 issue,到 2014 年在 GitHub 合并最初的几个 PR。其中,一次满怀热情、涉及 300 行代码的清理修改,被一位素不相识的人在一夜之间合并。这一经历体现了开源的核心:信任、共同努力与人与人的连接。 如今,AI 生成的 issue 和 PR 大量涌入各类仓库,其中既有看似合理却存在错误的成果,也有垃圾内容和未经请求的代码改写。创建贡献几乎只需片刻,但审查这些贡献的成本依然很高,对志愿维护者尤其如此。自动化审查淹没了人与人的讨论,而凭空生成、并不存在的问题报告,则浪费了宝贵的时间。 因此,一些项目和平台正在限制或关闭外部贡献,包括 Hono、curl、OpenJDK、Godot、Ladybird,甚至 GitHub 本身。作者每天都使用 AI,也不责怪维护者做出这些理性的选择;但他感到遗憾的是,贡献如今变成了一种负担,而不再是一份礼物。如果找不到简单的解决方案,开源可能会变得更小,并逐渐演变为仅限受邀者参与,从而恰恰排除那些曾为开源增添活力的热心外来者。

Hacker News 上关于“开源已如我们所知的那样消亡”的讨论,聚焦于 AI 生成的拉取请求和低质量贡献如何压垮开源项目的维护者。核心担忧是信任体系的崩塌:大量代码在没有真实社区参与的情况下涌入,维护者不仅要管理软件,还要应对一群陌生人的投稿。 评论者建议限制贡献数量、优先接纳值得信赖的贡献者,并通过邮件列表、论坛或 Discord reviving 较小规模的社区。也有人警告,过于严格的“善意证明”要求可能被 AI 代理钻空子,这符合古德哈特定律。还有人指出,开发者越来越多地维护由 AI 辅助的私有小型技术栈,因此不再那么依赖外部贡献,削弱了开源协作。 看法并不一致。部分参与者仍然乐观,认为开源比以往任何时候都更容易进入,能够产出更完善的软件,而且过去也曾成功适应重大的技术变革。真正的挑战或许不是开源本身的消亡,而是重新设计贡献机制,让自动化工具在不淹没人类讨论、不侵蚀信任的前提下帮助维护者。
相关文章

原文

I made my GitHub account on June 17, 2011. About two minutes later, I opened my first issue: teleporting was broken in TShock, a Terraria server mod, and I wanted to know why. Not as early as some, but early enough to remember when getting a PR merged by a complete stranger felt like a small miracle. (I've been obsessed with game servers ever since - it's literally my job now.)

GitHub wasn't really the start, either. Before that, it was SVN checkouts that broke if you looked at them wrong, and tinkering with DarkRP on Garry's Mod servers, or writing SourcePawn plugins for old Counter-Strike: Source, or Zombie Master servers. GitHub just made it feel like everyone was finally in the same room.

Open source has been a part of my life for almost as long as I've been writing software. I'm self-taught, so it's not an exaggeration to say I wouldn't have a career without it. Most of what I know, I learned by reading someone else's code, or opening an issue that was probably a bit dumb, and having a maintainer patiently explain why.

This isn't easy to write and the title is a bit hyperbolic. But it's honestly how I've started to feel: open source, as I've known it, is dying. And I sadly think AI is what's killing it.

It was never just the code

When people talk about open source, they usually talk about code. Licenses, packages, download counts, stars. That was never the part that kept me coming back though.

It was the people. It was fixing a typo in a README and having someone say thanks. It was a stranger on the other side of the world finding a bug in my code and sending a fix before I'd even woken up. It was arguing (politely, mostly) in an issue thread about the right API, and ending up with something better than either of us would've built alone.

My first real GitHub PRs were in June 2014, three years to the day after I made that account. We were using PointDNS, and their little Node.js client crashed with SyntaxError: Unexpected end of input whenever you listed records on a big zone. It wasn't handling chunked responses, so I fixed it. Two hours later, feeling brave, I opened a second PR: a "global tidy up" that touched almost every line in the file. My description said, with all the confidence of someone who had never really maintained anything:

We're huge fans of your service, but this node.js module was rather counter-intuitive to use. Hopefully this pull request will help solve that issue for any future developers!

A maintainer merged both the next morning - no back and forth, no checklist, no bots. A stranger sent them 300 lines of unsolicited changes, and they took a chance on it. I can't fully explain what that did for me, except that it made me feel like I belonged.

A PR isn't just a diff - it's someone saying "I used your thing, I cared enough to make it better, and I'm trusting you with my work." Reviewing it is you saying "I see you, let's do this together." That exchange, repeated millions of times, is what built the Internet we all use every day.

Looking back at that second PR, I'm honestly a little embarrassed. An unsolicited rewrite from someone nobody had heard of, with a slightly cocky description? Miguel Grinberg, who maintains Flask-SocketIO, put it bluntly this year: "Today, an unsolicited PR is a red flag." If mine landed in a repo today, I'd assume an agent wrote it too, and I wouldn't blame anyone for closing it.

Andreas Kling said it best when Ladybird stopped accepting public PRs: "A substantial patch used to imply substantial effort, and that effort was a reasonable proxy for good faith. That assumption no longer holds." A real person wrote my PR, nervous, hoping it was good enough. The effort was the signal. That's what's gone.

It's not fun anymore

Something shifted over the last year or so, and it's been hard to put into words.

Open a PR on a popular repo today and observe what happens. Within seconds, a bot leaves an AI review summarizing your own change back to you. Another bot posts a preview deployment. Another posts a "walkthrough" with a sequence diagram nobody asked for. Sometimes a fourth shows up to respond to the third. By the time a human actually looks at it, the thread is a wall of generated text, and the real conversation (the human part) is buried somewhere in the middle.

That's the good case, where a human wrote the PR. The bad case is when nobody really did, like PRs that "fix" issues that don't exist, or PRs that rewrite half a file with confident, plausible, completely wrong code, or security reports that read like the real thing until you realize the vulnerability was hallucinated. And there are apparently accounts opening dozens of these a day across hundreds of repos, just farming green squares for a résumé.

I've started muting notifications from repos I used to love following since it's mostly just noise now, and that makes me sadder than I expected it to.

Even that first PointDNS PR, sitting quietly for over a decade, picked up a string of junk comments last November from an account I'd never seen. A #, a ###, a broken screenshot upload. I honestly don't know if it was a bot or a person. That's kind of the point.

I don't blame maintainers one bit

AI slop PRs are the worst kind of work. They look like contributions, so you feel obligated to read them. They take real time to review, and then more time to explain why they're wrong to someone (or something) that isn't listening. That's time not spent on the actual project, or with family, or sleeping.

And the doors are closing. Fast.

Not everywhere, and not all in the same way, but the direction of travel is hard to miss. curl ended its monetary bug bounty after the signal-to-noise ratio collapsed. Daniel Stenberg wrote that the share of real reports had fallen below 5%: “Not even one in twenty was real.”

tldraw started automatically closing external PRs. Ghostty tightened its AI policy, with Mitchell Hashimoto writing that low-effort AI contributions had increased the “bad” count “by 10x if not more.” Jazzband, home to dozens of Python projects, shut down entirely, blaming GitHub’s “slopocalypse” of generated PRs and issues.

OpenJDK banned LLM-generated contributions, naming reviewer burden as the first risk. Ladybird stopped accepting public pull requests. Godot now requires code to be human-authored and bans autonomous agents. COSMIC requires contributors to confirm that their PRs contain no LLM-generated code, comments, or descriptions. Codeberg members voted to ban mostly AI-generated projects from the platform.

Then on October 1, Sindre Sorhus disabled external pull requests across all of his repos:

Due to AI, I have disabled external pull requests on all my repos. Open source, as we have known it, was fun while it lasted. (It's been 15 years for me)

If you’ve written JavaScript in the last decade, you’ve almost certainly run his code.

The details vary, but the shape is the same: maintainers are no longer just deciding whether a contribution is good, they’re deciding whether they can afford to find out. I don’t think they’re wrong, and that's the really difficult part. Every maintainer closing the door is probably making the rational choice for their project, their time, and their sanity. But when enough people make that same rational choice, open source starts to become something else.

And then this week, Yusuke Wada disabled PRs from external contributors on Hono. That one hit hard. Hono is one of my favorite projects, and I've called it the gold standard for Workers development many times.

Sad news. We disabled PRs from external contributors on honojs/hono ... Hono has not stood here without PRs. I will never forget the PR @usualoma created for RegExpRouter. A damn fast HTTP router we have never seen! But PRs don't work in this era. Contribute in other ways. Thanks

That quote hurts because it contains the whole contradiction. Hono was shaped by an outsider’s PR, and that outsider is still contributing to it four years later. Now Hono has to close the door they walked through. I don’t read that as hypocrisy, I read it as grief.

Even the platforms are saying it out loud. In February, GitHub published "Welcome to the Eternal September of open source", which put it better than I can: "The cost to create has dropped but the cost to review has not." The next day, they shipped a setting to turn pull requests off entirely. Since then they've added caps on open PRs per user (AI agents count toward it), a way to restrict who can open issues, and a way to archive spammy PRs so nobody else can see them. The platform that made the pull request famous has spent the year building ways to turn it off.

Some projects aren't waiting around for GitHub to fix it. Zig moved to Codeberg last year, and more and more people are spinning up their own Forgejo or Gitea instances. I don't blame them either, since GitHub's reliability hasn't exactly been great lately. But every project that leaves takes its issues, its history, and its people somewhere new, with yet another account to make and another place to look. It fractures things even further, and makes the next stranger even less likely to wander in.

I'm part of this too

I use AI every single day, and that makes me feel slightly uncomfortable while writing this blog. I write code with it, review code with it, and I even had help organizing the rambling notes that became this post. It's an amazing tool and it's made me faster, and on good days, better at my job. I'm not here to tell anyone to stop using it.

But I think a lot of us (me included) have been treating the cost of it as zero. It isn't - the cost just moved. When generating a PR takes ten seconds and reviewing it properly takes thirty minutes, all you've done is shift the work from the person who wants something onto the person who has to say no - and the person saying no is almost always a volunteer who was already stretched thin.

AI made contributing cheap. It didn't make maintaining any cheaper - if anything, it made it a lot more expensive.

I don't know what the fix is

I wish I had a neat answer here, but I don't.

Banning AI PRs feels like the right call for a lot of projects, and I'll defend any maintainer who makes it - but it's also a blunt tool. It catches the person who used AI to help write one good test alongside the person who pointed an agent at a thousand repos. It relies on honesty, or on detection that doesn't really work, and it nudges us toward a world where repos are closed by default, where you need to be vouched for before you're allowed to help, and where the default answer to a stranger is no.

Perhaps that's just where we're heading - smaller, trusted circles, with source available, but contributions by invitation. Maybe that's even fine, and I'm being nostalgic for a version of the Internet that was never going to last.

But the early 2010s version of me, nervously sending a stranger 300 lines of "tidy up", wouldn't get through that door. I think we lose something real when people like that can't get in anymore.

I don't know what the fix is. I just know I miss how it used to feel.

联系我们 contact @ memedata.com