我的 Report ,把上面几位老哥的改了一下,去掉了关于名称碰瓷的不必要说明( GitHub 不管这个的),供参考:
1. 该仓库秘密滥用用户提供的 Token 。当用户使用该仓库提供的方式进行构建时,仓库会不禁同意地自动冒充他们的身份为作者的所有仓库点 star 、fork ,并 follow 作者。考虑到这一项目的流行度( 5k stars ),显然已经造成一定规模的破坏。
2. 该仓库滥用 GitHub issue 系统,在任意 build 都会冒充用户身份向仓库发送一条 issue ,每天都有数百条 spamming issues 被发送。
3. 该仓库作者声称自己已经加入显眼的 Token 使用说明,但实际上直到今天( 7 月 29 日)被发现后才加入,并且没有为英语等语言加入。
====以下 markdown 正文====
1. **This repository secretly abuses user-provided GitHub tokens**. When a user builds with the method provided by this repository, it automatically impersonates them to **star and fork all of the author's repositories and follow the author without consent**. Given the project's "popularity" (5k stars), it has clearly caused damage on a considerable scale. ([Proof 1](
https://github.com/Sjj1024/PakePlus/blob/49dd9484c2617bc85e0e510d38efd5b34b8d90b3/src/apis/github.ts#L30-L34), [Proof 2](
https://github.com/Sjj1024/PakePlus/blob/49dd9484c2617bc85e0e510d38efd5b34b8d90b3/src/utils/common.ts#L209-L218))
2. **This repository abuses the GitHub issue system** by impersonating the user to create an issue in the repository with _every_ build, resulting in hundreds of spam issues being sent daily. ([Proof](
https://github.com/Sjj1024/PakePlus/issues))
3. The author of this repository [claims](
https://github.com/Sjj1024/PakePlus/issues/9746#issuecomment-3132012208) to have added the token usage disclaimers in a prominent location. However, the statement was actually only added to the README _today_ (July 29th, [Proof](
https://github.com/Sjj1024/PakePlus/commit/49dd9484c2617bc85e0e510d38efd5b34b8d90b3)) after being discovered, and it has not been provided for other languages, such as English.