Skip to content

Conversation

Sajjon
Copy link
Contributor

@Sajjon Sajjon commented Sep 1, 2024

No description provided.

@vivoxfold3
Copy link

⚠️⚠️⚠️Caution⚠️⚠️⚠️

This user is attempting to execute the first step of a supply chain attack, attempting to break free from the 'first-time contributor' status. The user opened a similar PR in all other repositories on the same day. He also stole pictures of other users to make them look like real people.

There are still hundreds of submissions like this, and they can be fixed at once. They will be submitted in multiple batches, and this is one part of them

@Sajjon
Copy link
Contributor Author

Sajjon commented Sep 9, 2024

Context:

I informed lots of repos that Github user "vivoxfold3" had suspicous activity:

  1. has no sources (only forks)
  2. no profile photo
  3. no followers
  4. no bio
  5. forks ~10 crypto libs or repos used by crypto libs / wallets all within the same hour
  6. makes trivial contributions and tries to "counterfeit" a GPG signature by writing "Signed off by"
  7. ignores PR templates

When confronted he replied

hoprnet/hoprnet#6482 (comment)

"Unreasonable accusations from persecuted delusional patients"

Whatever that means? Obvious bad translation service.

==================

The difference between you vivoxfold3 and me is that I:

  1. Have many of SOURCE repos (not forks) with many stars
  2. My Github User is over 10 years old
  3. I have profile photo - and CyonAlexRDX is my work Github username.
  4. I have 100 followers
  5. I have a bio
  6. I have many verified email addresses
  7. I'm a Github PRO user
  8. I do in fact work in the crypto industry, unlike you doing trivial PRs intro 10 different crypto libs...
  9. My contributions fixing typos are non-trivial - often spent 1-3 hours per
  10. I actually sign commits since September 2024, I don't "forge" commits like you do by adding "Signed-Off-By" in commit message

@CyonAlexRDX
Copy link

( I am @Sajjon. )

@intitni
Copy link
Owner

intitni commented Sep 9, 2024

I think this pr is fine. But accepting typo fixes is so frightening, so I will do this after releasing 0.34.0.

@intitni intitni changed the base branch from main to develop September 13, 2024 06:23
@intitni
Copy link
Owner

intitni commented Sep 13, 2024

Some of the typos are from third parties and are removed.

@intitni intitni merged commit 5106228 into intitni:develop Sep 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants