Open Source as We Know It Is Dead

I made my GitHub account on June 17, 2011. About two minutes later, I opened my first issue: teleporting was broken in TShock, a Terraria server mod, and I wanted to know why. Not as early as some, but early enough to remember when getting a PR merged by a complete stranger felt like a small miracle. (I've been obsessed with game servers ever since - it's literally my job now.)

GitHub wasn't really the start, either. Before that, it was SVN checkouts that broke if you looked at them wrong, and tinkering with DarkRP on Garry's Mod servers, or writing SourcePawn plugins for old Counter-Strike: Source, or Zombie Master servers. GitHub just made it feel like everyone was finally in the same room.

Open source has been a part of my life for almost as long as I've been writing software. I'm self-taught, so it's not an exaggeration to say I wouldn't have a career without it. Most of what I know, I learned by reading someone else's code, or opening an issue that was probably a bit dumb, and having a maintainer patiently explain why.

This isn't easy to write and the title is a bit hyperbolic. But it's honestly how I've started to feel: open source, as I've known it, is dying. And I sadly think AI is what's killing it.

It was never just the code

When people talk about open source, they usually talk about code. Licenses, packages, download counts, stars. That was never the part that kept me coming back though.

It was the people. It was fixing a typo in a README and having someone say thanks. It was a stranger on the other side of the world finding a bug in my code and sending a fix before I'd even woken up. It was arguing (politely, mostly) in an issue thread about the right API, and ending up with something better than either of us would've built alone.

My first real GitHub PRs were in June 2014, three years to the day after I made that account. We were using PointDNS, and their little Node.js client crashed with SyntaxError: Unexpected end of input whenever you listed records on a big zone. It wasn't handling chunked responses, so I fixed it. Two hours later, feeling brave, I opened a second PR: a "global tidy up" that touched almost every line in the file. My description said, with all the confidence of someone who had never really maintained anything:

We're huge fans of your service, but this node.js module was rather counter-intuitive to use. Hopefully this pull request will help solve that issue for any future developers!

A maintainer merged both the next morning - no back and forth, no checklist, no bots. A stranger sent them 300 lines of unsolicited changes, and they took a chance on it. I can't fully explain what that did for me, except that it made me feel like I belonged.

A PR isn't just a diff - it's someone saying "I used your thing, I cared enough to make it better, and I'm trusting you with my work." Reviewing it is you saying "I see you, let's do this together." That exchange, repeated millions of times, is what built the Internet we all use every day.

Looking back at that second PR, I'm honestly a little embarrassed. An unsolicited rewrite from someone nobody had heard of, with a slightly cocky description? Miguel Grinberg, who maintains Flask-SocketIO, put it bluntly this year: "Today, an unsolicited PR is a red flag." If mine landed in a repo today, I'd assume an agent wrote it too, and I wouldn't blame anyone for closing it.

Andreas Kling said it best when Ladybird stopped accepting public PRs: "A substantial patch used to imply substantial effort, and that effort was a reasonable proxy for good faith. That assumption no longer holds." A real person wrote my PR, nervous, hoping it was good enough. The effort was the signal. That's what's gone.

It's not fun anymore

Something shifted over the last year or so, and it's been hard to put into words.

Open a PR on a popular repo today and observe what happens. Within seconds, a bot leaves an AI review summarizing your own change back to you. Another bot posts a preview deployment. Another posts a "walkthrough" with a sequence diagram nobody asked for. Sometimes a fourth shows up to respond to the third. By the time a human actually looks at it, the thread is a wall of generated text, and the real conversation (the human part) is buried somewhere in the middle.

That's the good case, where a human wrote the PR. The bad case is when nobody really did, like PRs that "fix" issues that don't exist, or PRs that rewrite half a file with confident, plausible, completely wrong code, or security reports that read like the real thing until you realize the vulnerability was hallucinated. And there are apparently accounts opening dozens of these a day across hundreds of repos, just farming green squares for a résumé.

I've started muting notifications from repos I used to love following since it's mostly just noise now, and that makes me sadder than I expected it to.

Even that first PointDNS PR, sitting quietly for over a decade, picked up a string of junk comments last November from an account I'd never seen. A #, a ###, a broken screenshot upload. I honestly don't know if it was a bot or a person. That's kind of the point.

I don't blame maintainers one bit

AI slop PRs are the worst kind of work. They look like contributions, so you feel obligated to read them. They take real time to review, and then more time to explain why they're wrong to someone (or something) that isn't listening. That's time not spent on the actual project, or with family, or sleeping.

And the doors are closing. Fast.

Not everywhere, and not all in the same way, but the direction of travel is hard to miss. curl ended its monetary bug bounty after the signal-to-noise ratio collapsed. Daniel Stenberg wrote that the share of real reports had fallen below 5%: “Not even one in twenty was real.”

tldraw started automatically closing external PRs. Ghostty tightened its AI policy, with Mitchell Hashimoto writing that low-effort AI contributions had increased the “bad” count “by 10x if not more.” Jazzband, home to dozens of Python projects, shut down entirely, blaming GitHub’s “slopocalypse” of generated PRs and issues.

OpenJDK banned LLM-generated contributions, naming reviewer burden as the first risk. Ladybird stopped accepting public pull requests. Godot now requires code to be human-authored and bans autonomous agents. COSMIC requires contributors to confirm that their PRs contain no LLM-generated code, comments, or descriptions. Codeberg members voted to ban mostly AI-generated projects from the platform.

Then on October 1, Sindre Sorhus disabled external pull requests across all of his repos:

Due to AI, I have disabled external pull requests on all my repos. Open source, as we have known it, was fun while it lasted. (It's been 15 years for me)

If you’ve written JavaScript in the last decade, you’ve almost certainly run his code.

The details vary, but the shape is the same: maintainers are no longer just deciding whether a contribution is good, they’re deciding whether they can afford to find out. I don’t think they’re wrong, and that's the really difficult part. Every maintainer closing the door is probably making the rational choice for their project, their time, and their sanity. But when enough people make that same rational choice, open source starts to become something else.

And then this week, Yusuke Wada disabled PRs from external contributors on Hono. That one hit hard. Hono is one of my favorite projects, and I've called it the gold standard for Workers development many times.

Sad news. We disabled PRs from external contributors on honojs/hono ... Hono has not stood here without PRs. I will never forget the PR @usualoma created for RegExpRouter. A damn fast HTTP router we have never seen! But PRs don't work in this era. Contribute in other ways. Thanks

That quote hurts because it contains the whole contradiction. Hono was shaped by an outsider’s PR, and that outsider is still contributing to it four years later. Now Hono has to close the door they walked through. I don’t read that as hypocrisy, I read it as grief.

Even the platforms are saying it out loud. In February, GitHub published "Welcome to the Eternal September of open source", which put it better than I can: "The cost to create has dropped but the cost to review has not." The next day, they shipped a setting to turn pull requests off entirely. Since then they've added caps on open PRs per user (AI agents count toward it), a way to restrict who can open issues, and a way to archive spammy PRs so nobody else can see them. The platform that made the pull request famous has spent the year building ways to turn it off.

Some projects aren't waiting around for GitHub to fix it. Zig moved to Codeberg last year, and more and more people are spinning up their own Forgejo or Gitea instances. I don't blame them either, since GitHub's reliability hasn't exactly been great lately. But every project that leaves takes its issues, its history, and its people somewhere new, with yet another account to make and another place to look. It fractures things even further, and makes the next stranger even less likely to wander in.

I'm part of this too

I use AI every single day, and that makes me feel slightly uncomfortable while writing this blog. I write code with it, review code with it, and I even had help organizing the rambling notes that became this post. It's an amazing tool and it's made me faster, and on good days, better at my job. I'm not here to tell anyone to stop using it.

But I think a lot of us (me included) have been treating the cost of it as zero. It isn't - the cost just moved. When generating a PR takes ten seconds and reviewing it properly takes thirty minutes, all you've done is shift the work from the person who wants something onto the person who has to say no - and the person saying no is almost always a volunteer who was already stretched thin.

AI made contributing cheap. It didn't make maintaining any cheaper - if anything, it made it a lot more expensive.

I don't know what the fix is

I wish I had a neat answer here, but I don't.

Banning AI PRs feels like the right call for a lot of projects, and I'll defend any maintainer who makes it - but it's also a blunt tool. It catches the person who used AI to help write one good test alongside the person who pointed an agent at a thousand repos. It relies on honesty, or on detection that doesn't really work, and it nudges us toward a world where repos are closed by default, where you need to be vouched for before you're allowed to help, and where the default answer to a stranger is no.

Perhaps that's just where we're heading - smaller, trusted circles, with source available, but contributions by invitation. Maybe that's even fine, and I'm being nostalgic for a version of the Internet that was never going to last.

But the early 2010s version of me, nervously sending a stranger 300 lines of "tidy up", wouldn't get through that door. I think we lose something real when people like that can't get in anymore.

I don't know what the fix is. I just know I miss how it used to feel.

You've successfully subscribed to James Ross
Great! Next, complete checkout for full access to James Ross
Welcome back! You've successfully signed in.
Success! Your account is fully activated, you now have access to all content.