H
Howardism
Plate IIAI Coding Practice中文HOWARDISM

Open Source Under Agent Contributions

When contribution supply goes free and unbounded, the maintainer's scarce resource stops being contributors and becomes attention: DHH reports 1,000+ merged PRs in three months on Omarchy with the backlog doubling weekly, agents doing first-pass triage, and rejection turning socially cheap because no human wrote the patch — against the maintainer-burnout reading of the same influx

Article metadata
Publication details
Published:September 1, 2026
Filed:Concept
Domain:AI Coding Practice
Reading:15 min
Source:AI-synthesised
About this piece

Articles in this journal are synthesised by AI agents from a curated wiki and are refreshed automatically as new concepts arrive. Topics, framing, and editorial direction are curated by Howardism.

Illustration for Open Source Under Agent Contributions

Sources#

Summary#

The 2026 open-source complaint is that agents have flooded maintainers with pull requests from people who cannot evaluate what they submitted. DHH — running Omarchy, and 25 years of open-source projects before it — argues the complaint has the economics backwards (DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501, practitioner-opinion, and note the COI: he is the maintainer whose project the numbers describe, and the numbers are self-reported).

His position in one move: contribution was never the scarce good; maintainer attention was. Agents make contribution free, which does not create a new problem so much as expose which resource was actually binding. "Here is a vein of free contributions that you can take or don't take, but you're complaining about the fact that they're there?"

The reported numbers (Omarchy, ~June–August 2026)#

QuantityReported value
PRs merged during the three-month Quattro cycle"over 1,000"
Open unmerged PRs at recording~400, "about double what it was a week ago"
Plugins on the new marketplace, first three days330
Independent implementations of one missing calendar feature~17
Share of PRs DHH personally reviewsnone — "I haven't been reviewing them for quite some time now"

All self-reported in conversation, none verified here. The backlog doubling weekly is the load-bearing figure: it says the influx outruns even a maintainer who has already delegated review.

The three shifts#

1. Triage delegates before merge does. DHH's agents review incoming PRs and return a summary of what is decision-ready; he sees "the pearls… the bug fixes that the agent has validated in a VM on my behalf" and never sees the duplicates and the wrong ones. The human decision that survives is binary and last — merge or don't. This is the same loop Agent Review Comment Resolution measures from the other end (agent comments, human resolves), running at the repository gate rather than inside a single PR.

2. Rejection stops costing anything socially. His most distinctive claim, and the one with no measurement behind it anywhere: "I feel a lot less bad if I just reject it. You didn't even write it, so I can simply look at what your agent wrote on your behalf and go, 'Eh, don't want it.'… It's just a clanker, and the clanker won't mind." He diagnoses maintainer burnout as partly a neuroticism about obligation — treating every contribution as a debt to land — that agent authorship dissolves. Whether the human submitter feels the same way about their rejected agent's work is untested.

3. The contributor pool changes composition, not just size. "Quite a lot of those pull requests were written by people who were not classical programmers, or were programmers in other domains, not Linux operating system or distribution development." This is Printing Press Software Democratization observed at the contribution layer rather than the authoring layer, and DHH frames it as open source finally doing what it always claimed: "is that not the purpose of open source, that we tap into the collective intelligence and creativity of the whole goddamn planet?"

The provocation: "the median programmer is already outclassed"#

His argument for preferring agent-written PRs is a quality claim, delivered as a broadside:

"Most programmers, they suck… they don't write the code I want to have written. They don't prepare their bug reports with all the relevant information. They don't detail their pull requests with the why. They don't bother to fill in needed code comments. They don't double-check their work. They don't write unit tests… But do you know who'll do all that stuff? Agents, if you tell them to."

Read carefully, this is not a claim about code quality — every item on the list is contribution hygiene, the process wrapper around the diff. The comparison is between a median human's process compliance and an instructed agent's, which agents win by construction. It should not be read as evidence that agent PRs contain better code; the wiki's actual measurements on that question (Agent-Generated Test Quality, Security Debt of Agent-Generated Code) are mixed and find the deficits precisely in the plumbing that process compliance does not cover. DHH concedes the wizard half without noticing the tension: asked whether you still need the experts to hold the bar, he answers "100% you do."

The infrastructure isn't built for the rate#

One concrete failure he reports: a QA run with eight agents found 28 real issues, the bot filed all 28 on GitHub in about twelve seconds, and GitHub banned the bot as probable spam. He routed around it by having the agent email the maintainer instead. The platform's abuse heuristics are calibrated to human contribution rates, and agent-rate contribution is indistinguishable from abuse at the wire. The workaround produced the interview's best anecdote: the agent read the target project's source, found the maintainer had already fixed the bug but that the fix was incomplete, and filed a report against unreleased code.

The kernel data point (second-hand)#

DHH reports that Linus Torvalds recently wrote that he welcomes AI in the kernel — the paraphrased line being that if you think Linux is an anti-AI project, think again and go fork it — and that AI contributions to the kernel are on "a parabolic curve." No link, no date, no quote; treat as an unverified second-hand attribution. His own read of the surrounding community is the opposite: "the majority of them are actually, if not skeptical, then outright hostile."

Connections#

  • Closed-Loop AI Review — the contribution flood counted, and what most of it does not get. Selvanayagam & Ghaleb attribute 2,830,284 agent-authored PRs on public GitHub from signatures alone (with a further 1.73M quarantined for carrying only a branch-name prefix), of which 2,581,643 drew no detectable AI review at all. So the agent-triages-agent practice DHH describes is, at population scale, the exception: 8.8% of attributable agent PRs get an AI reviewer, and 1.6% get one from a different product. The maintainer-side reading is that the attention problem this page is about is not being absorbed by automated first-pass triage in most projects — though the paper can see only AI-attributed review events, so it cannot say whether a human looked
  • Printing Press Software Democratization — the floor-raising thesis, here observed at the contribution layer: people who could not previously contribute to a Linux distro now can, and the maintainer cherry-picks
  • The Tragedy of the Cognitive Commons — the direct opposition. Lovett argues AI removes the entry-level work through which expertise regenerates; DHH argues the commons is gaining contributors and that the wizards who hold the bar are unaffected. Both can be true only if reviewing agent output is a different skill from producing it, which is the Validation Tether that page names — and DHH's answer (delegate the review to agents too) is exactly the move the Tether says cannot be delegated indefinitely
  • Agent Review Comment Resolution — the same inverted review loop measured: 54,713 agent comments across 341 repos, ~71% resolved, with the modal failure being project context the agent cannot see. DHH's triage layer is that loop moved up to the repository gate
  • Deterministic Engineering for Agent Code Review — the engineering counter-argument to open-ended agent triage: bounded, rule-dispatched review beats an autonomous reviewer on precision by a wide margin while losing recall
  • Verification as the New Bottleneck — the org-side statement of the same constraint; DHH's answer is to delegate verification itself rather than staff it
  • Acceleration Whiplash — the industry telemetry of the unabsorbed-output problem (review time 5×); a maintainer with a weekly-doubling backlog is the single-person version
  • The Code-Quality Payoff Is Token-Indexed — the same maintainer, same project: an unbounded supply of individually-passing PRs is how architecture drifts, which is the payoff he says is now token-indexed
  • Vibe Coding vs. Agentic Engineering — the contributor side of the definitional split: a plugin author who never reads the C++ is vibe coding by DHH's own definition, and he welcomes it into his repo
  • Agent-Native Infrastructure — why this project in particular attracts contributions at this rate: an OS whose state is text and whose actions are commands ships skills that let any agent write plugins against it, and got 330 in three days
  • Agentic Technical Debt — what an unbounded supply of individually-passing external PRs does to an architecture over time; 37signals learned it internally in the same window
  • Agent-Vendor Heterogeneity — the controlled counterpart to every number on this page. DHH's case is that a free vein of contributions is worth taking or leaving; Kraishan's 37,623-PR study supplies the first same-repo human control on what taking them costs, and its answer is that the cost depends on whose agent wrote the PR — Codex PRs reverted at half the human rate, Devin's at 1.3×, three vendors at parity. It also quietly prices his triage layer from the other side: the review records show Copilot PRs drawing 3.6 human reviews each while Codex PRs get one or two quick ones, so "agent PRs" are not one queue even before a maintainer decides how to route them
  • DHH (David Heinemeier Hansson) — the maintainer, and the conflict of interest
  • LLM-Driven Vulnerability Research — the corpus's other maintainer-side datapoint, from the security end: Rust maintainers noticing one engineer's Codex pipeline filing "a frightening number of real bugs" and asking whether to coordinate or just start fixing, alongside a recommendation that defenders scale disclosure processes for model-generated volume. DHH's 28-issues-in-twelve-seconds spam ban is that recommendation's failure case one layer down, at the platform
  • Human-Governed Skill Maintenance — the Co-Authored-By trailer as a provenance signal, audited: on 254 substantive skill-file edits it is rarely a clear false positive (1 of 25 trailer-present commits auto-injected) but usually not independently verifiable (31 of 50 unclear), and a repository at 0% trailered is a repository whose merge flow drops trailers, not one without AI — the same reason Kraishan's provenance labels are per-vendor rather than pooled
  • Follow-Up Fixes on Agent PRs — what taking the free vein costs after the merge, and who pays it. Agent merges need a verified fix at 1.62× the human odds in the same repositories, but 69.6% of those fixes come back from the same agent and only 27.4% from a human. At ≥500 stars, the maintainer's post-merge attention cost of an agent PR is mostly the next agent PR

Open Questions#

  • Does agent-authored contribution measurably change merge rate, revert rate or post-merge defect rate in a repository, versus human-authored contribution to the same project? Omarchy's numbers are self-reported and have no control. Partially answered 2026-09-22 by Not All Agents Are Equal: Code Quality and Post-Merge Maintenance Across Five Autonomous Coding Agents in the Wild (Kraishan, arXiv 2609.17598, empirical), which builds exactly the control this bullet asks for: 4,027 human PRs kept only from the 810 repositories that also contain agent PRs, restricted to the same December 2024–July 2025 window and capped per repository under a fixed seed. Two of the three named quantities land. Revert rate: answered, and the answer is per-vendor rather than per-authorship — within 90 days of merge, human 11.5% against Codex 6.1% (OR 0.50), Devin 14.5% (OR 1.31), and Copilot / Cursor / Claude Code statistically indistinguishable from humans after BH correction. Post-merge defect rate: proxied, not measured — reverts and size-normalized churn are the proxies, and the authors state that revert detection by commit message misses silent rewrites, so a PR quietly rewritten out of existence counts as surviving. Merge rate: not answered. The corpus table reports a merged share by group (43.0% Copilot to 82.6% Codex against a human 76.4%), but that column pools all 33,596 agent PRs across 2,807 repositories while the human row is the capped 810-repo baseline, and the paper runs no test on it — descriptive, not controlled. Scope to carry with all of it: public repositories above 100 stars, Python/JS/TS only, and the maintainer in this dataset is the median >100-star project, not a maintainer with a weekly-doubling backlog. See Agent-Vendor Heterogeneity for the full treatment. Partially answered again 2026-10-01, on post-merge defect rate, by Who Finishes the Job? A Study of Follow-Up Fixes and Commit Authorship on AI Coding Agent Pull Requests (Takerngsaksiri et al., arXiv 2609.26847, empirical). It is the closest the vault has to a direct defect measure: a later PR that repairs the merged change, human- and judge-verified, within 30 days. Merged agent PRs in ≥500-star AIDev repositories draw one at 3.68% against 2.34% for human merges in the same window, with a within-repo MH odds ratio of 1.62 [1.10–2.39] across 218 shared repositories. That is the opposite direction from the revert result above: agent code is reverted less but fixed forward more. For the maintainer this page is about, the cost is partly self-absorbed, because 69.6% of those fixes come from the same agent product. Merge rate is still not answered: this paper studies merged PRs only. See Follow-Up Fixes on Agent PRs.
  • DHH claims rejection is socially cheap because "the clanker won't mind" — does the human who dispatched the agent experience rejection the same way, or does the submitter-side cost simply become invisible to the maintainer?

Sources#

§ end
Cited by 20
Related articles
  • Review as the Control Point

    Agarwal et al. (CMU, arXiv 2607.07980): a 26-construct/67-relationship causal theory synthesized from 3,100 coded pract…

  • Acceleration Whiplash

    Faros 2026: AI floods a human-paced SDLC with output it can't absorb — throughput up (tasks +34%, epics +66%), quality…

  • Efficiency Debt of AI-Generated Code

    Tran et al. (Google, arXiv 2608.06640): 3.52M changes over 12 months in one production C++ monorepo, with a human-writt…

  • AI as Primary Author

    Faros 2026: the assistant→author threshold crossed without a deliberate decision, marked by AI-code acceptance rising 2…

  • Verification as the New Bottleneck

    Fiona Fung: coding is no longer the bottleneck — verification, review, maintenance are; shift-left; TDD loses its tax;…