Have you ever found a GitHub project or anything that seemed nice and tempting to install until you dug a bit deeper?
What are some red flags that should detur anyone from installing and running something?
The project is requires really weird unconventional set up. Doesn’t package properly, configuration files in weird places, doesn’t follow convention but doesn’t gain anything from it
Runs on Windows CE
Requires weird IDE to build
I shifted 8 GB of files to an older machine just to be able to install Android Studio on barely-supported hardware, and now I’m cloning the repo and the
.gradledirectory alone is 1 GB?I bet they checked in the binary. Git is really poor with binaries since it can’t really diff them. And the worst part is gradle should never have the binary in the source tree
You don’t even need to check in .gradle to a repo, I always have that gitignored. And gradle projects should specify commands to build from CLI rather than having you download an IDE. Android Studio gives you a nice run button but it’s just invoking ./gradlew installDebug under the hood
I’m amused that you mentioned requiring an IDE and then gave gradle (a standalone build tool) and Android as an example… when I’m pretty sure that ios actually requires xcode (AND an apple account) to build apps
“This project has been archived on [10+ years ago]. It is now Read Only.”
or
Last commit 5+ years ago
Depends. Software can be done.
Shoutouts to pycocrypt!
When installing if I see a pre-checked check mark I will be more likely to read what the software is trying to install. What are you trying to install now?
Signing-in before being able to use a FREE software.
-glares at Canva after buying Affinity -
That’s why they bought it
Yeah, but it’s still irritating. The only function they added to the software that i use is Image Trace. Otherwise i still use the old Affinity Designer that i bought years ago.
Serif were always great, I’m a bit doom and gloom on it
😭
A rule of thumb I use is how desperate the software is to tell you the weather even when you never asked for it or even set it up to report it.
No stars (although easily manipulated)
No commit history
No issue history
No pr requests (soft no)
No contributions from people with a active history
Something I do is if a project has way too many stars, click on a few of the names randomly.
If those profiles have 0-1 projects, my yellow flag (not red flag) goes up. Because yeah, it’s really easy to buy GitHub stars now.
“Call us for pricing”
I can’t believe that marketing people are this fucking stupid.
Like, full-on knuckle-dragging morons.
They intentionally drive away more paying customers than they could ever “channelize” with this method.
Because most people realize that prices are only ever hidden for malicious, anti-consumer purposes.
Aaaaaand tab closed.
If the project maintainer has a policy of “no politics allowed.”
Rather than a policy more along the lines of “be respectful”
100%.
Then you look through their history and it’s them laugh emojiing something like doing a LGBT suicide or some ridiculous shit.
Something I ran into just now was AI generated Imagery in Docs or as an Icon.
I am not even that Anti AI as many on here I feel like. But this is a sure fire way to show how much you don’t give a shit about your project. Just use emojis or some shit which is ironically even less work but somehow makes it seem more deliberate.Had a conversation with someone recently about exactly this. Usage of AI generated assets gives me exactly the same feelings as a local business using a gmail or personal ISP email account on their advertising.
It doesn’t automatically mean it’s bad, but it’s an indication that whoever is running things just can’t be bothered to put in effort.
I tried to explain that to my manager but he didn’t believe me
Bun seems cool, but it’s icon looks too much like slop
I don’t think it is. IIRC they had that before AI Image Generation was widely available. You really can’t tell though with the simple cute art style which AI can very easily recreate.
GitHub repo that has “pm me on telegram” instead of code
join our discord
Venture capital funding. The plan is always to do a rug pull. Though if it properly freely licensed and the code is reasonable enough to be forked, it’s less worrying but still risky. It’s better to work with honest people.
This is why I avoid Bluesky
https://bsky.social/about/blog/03-19-2026-series-b
I didn’t know this about bluesky D:, but it makes sense. Thanks for the heads up. The atproto ecosystem seems to have cool features for user empowerment and it seems to work well on the few occasions I’ve visited atproto sites. I hope they can find an ethical way to persevere, but I can’t imagine that being easy.
🚩 - here’s one
This comment scares me
Web browsers are software, they can render a red flag
Only Linux install option is .deb
do we not like Debian packages here?
If there is no Flatpak or AppImage it is not a serious project. There are many distros that are not debian or rpm based. Linux projects should be portable.

I like them because I’m old, and tired of distro-specific packages like rpm and deb. I want a thing that works no matter my distro of choice this week. The linux ecosystem is much larger than Debian.
you sound like an Ubuntu user.
Arch btw.
Ubuntu is debian-based.
Ubuntu is debian-based.
I know, that’s why it was funny.
Arch btw.












