Comment by 8organicbits
Comment by 8organicbits a year ago
Maybe GitHub had already deleted it as malicious, but the email was already delivered.
Comment by 8organicbits a year ago
Maybe GitHub had already deleted it as malicious, but the email was already delivered.
Same here, I get frequent spam on one specific (very popular) issue, and they always take care of it within an hour or two. I hide the spam myself to protect the users on the web (I can't do anything about the phishing emails though that gets sent [by default I think ?]), and their moderation wipe the spam account and sends a quick email to confirm.
Usually it's a new user who clones a few repositories to pass whatever mitigation they have.
Always get a "lots of reports, this may take a while" email first though. I don't think I ever not got that one.
I think there's something to be said about sending - by default - user generated content by email automatically if you've replied once to a thread. Lots of bad defaults here imho.
I got this on two org repo’s yesterday. About an hour after the email, I checked and it was gone. I wanted to report it, even though GitHub scam reports are so very unsatisfying (weeks go by, then random email about how they took some action).
One very simple measure I hope they implement is just not sending emails for unverified spam like this. I’d argue a majority of issues or comments do not need instant emails. Even one hour delay could help in combating abuse like this if they had any sort of reasonable moderation rules.