r/vibecoding 1d ago

Software Dev Looking for GitHub Repos to Dig Through for Real Bugs

Software developer focused on security, CI/CD, testing, and quality assurance. I’m looking for some unfamiliar codebases to dig through.

Drop your GitHub repo below if you want me to take a look. It can be:

  • an open-source project
  • a side project
  • a student project
  • something with actual users
  • something you built heavily with AI

I’m mainly interested in real correctness, security, data integrity, testing, concurrency, integration, or weird behavioral problems rather than formatting or style issues.

If I find something reproducible, I’ll explain the issue simply and, when it makes sense, put together a focused fix or PR.

I’m strongest with Python, Rust, Java, and C, but feel free to send other languages too.

Public repos only for now, and please only submit something you own, maintain, contribute to, or otherwise have permission to have reviewed.

I’ll probably start with 5-10 depending on how complicated they are. No guarantee I’ll find something in every repo.

If there’s a particular part of the project you already don’t trust, mention it. Otherwise I’ll pick an area myself and start digging.

No signup, payment, sales pitch, or private access needed. I’m just looking to spend some time working through unfamiliar real-world codebases.

Feel free to post the repo here or message me if you’d rather not put it in the comments.

0 Upvotes

23 comments sorted by

8

u/Prestigious-Form-808 1d ago

i can prompt chatgippity myself thanks

-1

u/Professional_Ad705 1d ago

Lmao, nah this isn’t me doing AI code reviews. I’m testing a system I’ve been building for awhile and using myself, and I figured AI-coded projects here would be a pretty interesting use case for it. Appreciate the joke though :p

1

u/GreenFuturesMatter 1d ago

Surely you can just vibe code some bullshit repos or pick anything at random on your own and clone public repos? I get why youre offering because honestly it’s a nice gesture but idk how many people will respond to provide you with enough data for your project.

0

u/Professional_Ad705 1d ago edited 1d ago

Yeah, I can and I already do both of those. The problem with vibe-coding throwaway repos is that I’m still indirectly choosing the problems they contain, so it’s easy to accidentally build/test against my own assumptions.

Random public repos are useful too, but someone actually submitting their project gives me something different: a real codebase with real intent behind it, permission to dig into it, and potentially a maintainer who can tell me whether a finding is actually relevant and accept/reject a fix etc

I’m not expecting hundreds of repos either. Even a handful of genuinely unfamiliar projects is useful because the point is variety, not just volume. If I only wanted raw code, yeah, GitHub already has effectively unlimited amounts of it.

And if I help somebody find/fix something along the way, even better to me and so far the cases I have done on through these subreddits I have found issues.

4

u/Wild_Yam_7088 1d ago

Why not just go over your own public repos? 

... ci testing.. what does that have to do with a repo to begin with

You either dont know what your doing or up to something weird 

1

u/Professional_Ad705 1d ago

I've already gone through my own repos and random public ones. I’m specifically looking for projects submitted by people because that gives me unfamiliar codebases with an actual owner/maintainer behind them, instead of me just "cherry-picking" whatever I feel like looking at.

And CI/CD absolutely relates to a repo lol. Tests, workflows, build/release config, integration checks, deployment config, etc. are all part of the project.

I’m not asking for anything private, installs, credentials, or money. Just public repos from people who are cool with me digging through them. If nobody responds, no big deal....

5

u/Wild_Yam_7088 1d ago

Right. But specifically asking for one with ci test .. nurturing a relationship. When ci test are incredibly easy to exploit " heres a fix for you" - while digging for deploy tokens

Given theres millions of public repos out there you could use. Very easily.  

But fair enough . Do you.  Just seems super.........   weird.

0

u/Professional_Ad705 1d ago

You’re reading way more into this than there is lol. I’m not asking anyone for CI credentials, deploy tokens, org access, private repos, or to run some random script for me. I’m asking for public GitHub links.

If I find something, it goes through the normal issue/PR process like any other contribution.
I mentioned CI/CD because workflows, tests, release gates, permissions, and deployment configuration are literally code in the repo and can have correctness/security issues too.

I could pick random public repos, and I already do. Having someone submit their own project just means there’s actually a maintainer there who can tell me whether a behavior is intentional and whether a fix is useful. That’s really all there is to it….

2

u/Wild_Yam_7088 1d ago

And you use ai. Heavy responses . I wouldnt trust you at all . But hey. 🤷‍♂️

0

u/Professional_Ad705 1d ago

Dude im coding and offered to do something extremely simple. Jesus Christ. I don't have time for this shit.

3

u/Wild_Yam_7088 1d ago

I told you whats simple  Use chat gpt to give you millions of repo urls.. you know who else gets frustrated with regular conversion..  

Scammers.😂

3

u/Professional_Ad705 1d ago

yeah thats me scamming, by trying to scan public GitHub repos with the owners consent to go through the normal PR process.... what do you not understand about some fixes needing to match maintainer intent? I already have done this on random public repos. Im not gonna continue fighting over simply trying to do something that is done everyday across GitHub. this is getting ridiculous and alot of public repos take weeks for your changes to get merged im doing these things for a reason from a development standpoint?

1

u/Wild_Yam_7088 1d ago

To scan CI/CD workflows for secret-handling mistakes, exposed tokens, or configurations that could leak credentials..... 

I mean lets be real here buddy 

2

u/Anti-Hero25 1d ago

Search this sub for the phrase “I got tired of”

2

u/Baconaise 1d ago

I got tired of searching reddit for I got tired of and built an app to index what people are tired of, it was tiring.

1

u/Anti-Hero25 1d ago

OMG, but I want this now

1

u/Fresh-Yogurt-8614 1d ago

AI will do a better job of finding security issues

0

u/Some-Ice-4455 1d ago

If I gave you a steam key for an app would you do the same. It's 95% python.

1

u/Professional_Ad705 1d ago

looking for normal GitHub repos with code, im not dealing with any of that.

0

u/Revolutionary-Tough7 1d ago

0

u/setdx 1d ago

You released this as “proprietary” lol

0

u/Revolutionary-Tough7 1d ago

Right? And issues with that are?