<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reputation-Farming on krash.dev</title><link>https://krash.dev/tags/reputation-farming/</link><description>Recent content in Reputation-Farming on krash.dev</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 14 Aug 2026 08:29:09 +0530</lastBuildDate><atom:link href="https://krash.dev/tags/reputation-farming/rss.xml" rel="self" type="application/rss+xml"/><item><title>Reputation Farming in OSS: A Threat to Building Trust</title><link>https://krash.dev/posts/reputation-farming/</link><pubDate>Thu, 27 Jun 2024 00:00:00 +0000</pubDate><guid>https://krash.dev/posts/reputation-farming/</guid><description>&lt;p&gt;This issue complicates the open source and supply chain security space. For attacks like xz, such strategies can be used by attackers to build &amp;ldquo;fake&amp;rdquo; trust among fellow OSS community members.&lt;/p&gt;
&lt;p&gt;A few days ago, &lt;a href="https://openssf.slack.com/archives/C019M98JSHK/p1719225074824219" target="_blank" rel="noopener noreferrer"&gt;this discussion ignited in the OSSF Slack&lt;/a&gt;, which talked about the issue of credibility farming in several open source repositories.&lt;/p&gt;
&lt;img loading="lazy" decoding="async" src="../images/slack-message.png" alt="OSSF Slack Discussion"&gt;&lt;p&gt;So, the issue revolves around GitHub (or equivalent platforms) accounts approving or commenting on old pull requests and issues that were already resolved or closed, where these meaningless contributions show up prominently on the user&amp;rsquo;s profile and activity feed, making their involvement seem more significant than it actually is, without closer look.&lt;/p&gt;</description></item></channel></rss>