electron icon indicating copy to clipboard operation
electron copied to clipboard

chore: fix typos in 'patches/' folder.

Open Sajjon opened this issue 1 year ago • 2 comments

Fixes typos in the patches/ folder

@ckerr suggested I split what was originally a single PR with changes into 39 files into many.

Notes: none.

Sajjon avatar Aug 20 '24 17:08 Sajjon

Some of the changes here break the patches because the misspellings are from upstream code. For this PR, please only update the patch descriptions in order to not break the patches.

Patch descriptions are the text before the first line that starts with

diff --git ....

jkleinsc avatar Aug 20 '24 19:08 jkleinsc

@ckerr Thanks, I reverted the three you highlighted, I went from some of the other files and think you found them all, those three.

Sajjon avatar Aug 21 '24 06:08 Sajjon

⚠️⚠️⚠️Caution⚠️⚠️⚠️

This user is attempting to execute the first step of a supply chain attack, attempting to break free from the 'first-time contributor' status. The user opened a similar PR in all other repositories on the same day. He also stole pictures of other users to make them look like real people.

There are still hundreds of submissions like this, and they can be fixed at once. They will be submitted in multiple batches, and this is one part of them

  • https://github.com/babylonlabs-io/babylon/pull/34
  • https://github.com/intitni/CopilotForXcode/pull/570
  • https://github.com/ohmyzsh/ohmyzsh/pull/12647
  • https://github.com/Alamofire/Alamofire/pull/3891
  • https://github.com/rust-lang/rust/pull/129867
  • https://github.com/rust-lang/rust/pull/129875
  • https://github.com/rust-lang/rust/pull/129877
  • https://github.com/rust-lang/rust/pull/129878
  • https://github.com/babylonlabs-io/babylon/pull/30
  • https://github.com/Sajjon/babylon/pull/1
  • https://github.com/mattmassicotte/Empire/pull/3
  • https://github.com/electron/electron/pull/43375
  • https://github.com/electron/electron/pull/43374
  • https://github.com/electron/electron/pull/43373
  • https://github.com/Sajjon/TypeScript/pull/1
  • https://github.com/golang/go/pull/68964
  • https://github.com/rust-lang/rustc_codegen_gcc/pull/559
  • https://github.com/swiftlang/swift-evolution/pull/2547
  • https://github.com/Sajjon/swift-evolution/pull/2
  • https://github.com/Sajjon/swift-evolution/pull/1
  • https://github.com/swiftwasm/WasmKit/pull/117
  • https://github.com/swiftwasm/JavaScriptKit/pull/260
  • https://github.com/swiftwasm/carton/pull/493
  • https://github.com/pretzelhammer/rust-blog/pull/79
  • https://github.com/swiftlang/swift/pull/75034
  • https://github.com/swiftlang/swift/pull/75033
  • https://github.com/swiftlang/swift/pull/75032
  • https://github.com/swiftlang/swift/pull/75031
  • https://github.com/swiftlang/swift/pull/75030
  • https://github.com/swiftlang/swift/pull/75029
  • https://github.com/swiftlang/swift/pull/75028
  • https://github.com/swiftlang/swift/pull/75027
  • https://github.com/swiftlang/swift/pull/75026
  • https://github.com/swiftlang/swift/pull/75025
  • https://github.com/swiftlang/swift/pull/75024
  • https://github.com/swiftlang/swift/pull/75023
  • https://github.com/swiftlang/swift/pull/75021
  • https://github.com/swiftlang/swift/pull/75020
  • https://github.com/Sajjon/swift/pull/12
  • https://github.com/Sajjon/swift/pull/11
  • https://github.com/Sajjon/swift/pull/10

vivoxfold3 avatar Sep 09 '24 15:09 vivoxfold3

@ckerr Context:

I informed lots of repos that Github user "vivoxfold3" had suspicous activity:

  1. has no sources (only forks)
  2. no profile photo
  3. no followers
  4. no bio
  5. forks ~10 crypto libs or repos used by crypto libs / wallets all within the same hour
  6. makes trivial contributions and tries to "counterfeit" a GPG signature by writing "Signed off by"
  7. ignores PR templates

The exact same behaviour was done by GH use vivoxfold3 also last week, which responded using... hmm... interesting phrasing:

https://github.com/hoprnet/hoprnet/pull/6482#issuecomment-2333638612

"Unreasonable accusations from persecuted delusional patients"

Whatever that means? Obvious bad translation service.

==================

The difference between you vivoxfold3 and me is that I:

  1. Have many of SOURCE repos (not forks) with many stars
  2. My Github User is over 10 years old
  3. I have profile photo - and CyonAlexRDX is my work Github user, I have not stolen any picture, I control both Github accounts...
  4. I have 100 followers
  5. I have a bio
  6. I have many verified email addresses
  7. I'm a Github PRO user
  8. I do in fact work in the crypto industry, unlike you doing trivial PRs intro 10 different crypto libs...
  9. My contributions fixing typos are non-trivial - often spent 1-3 hours per
  10. I actually sign commits since September 2024, I don't "forge" commits like you do by adding "Signed-Off-By" in commit message

Sajjon avatar Sep 09 '24 15:09 Sajjon

I have profile photo - and CyonAlexRDX is my work Github user, I have not stolen any picture, I control both Github accounts...

That sounds reasonable. To verify that claim, could you please respond in this PR with a comment from that account?

ckerr avatar Sep 09 '24 16:09 ckerr

@ckerr sure, I am @Sajjon. My employer prefers me using a GitHub handler they have full control over.

CyonAlexRDX avatar Sep 09 '24 16:09 CyonAlexRDX

@vivoxfold3 I agree that the volume of PRs might look like a red flag. FWIW the PRs submitted to Electron seem helpful enough and uncontroversial. Also, @Sajjon was responsive when I asked how he found the spelling errors and we discussed ways that this might be automated in Electron's CI. Do you have any evidence that there's something malicious going on here?

ckerr avatar Sep 09 '24 16:09 ckerr

I agree that the volume of PRs might look like a red flag.

He got angry because I flagged him...

YES I'm an extremely active Github User - which I have 10 years of open source github activity to show for.

And since 6 months ago I've had the hobby of fixing typos in many repos. Work which I spend 30-120 min per PR on. Silly hobby, but quite pleasing and satisfactory. In contrast this new GH user spent 1 min on trivial PRs and try to counterfit commit signing by manually adding message "Signed-Off-By".

Have a great evening!

Sajjon avatar Sep 09 '24 16:09 Sajjon