Empathy at scale: Techniques for user automation on one of the most active repos

DefinitelyTyped regularly appears in the Octoverse as one of the top 10 repos with most contributors. The repo provides community driven type definitions for many thousands of popular npm packages which are automatically picked up by JavaScript editors.

In 2020, the TypeScript team re-vamped the tooling on the repo providing getting to a point where more than half of the merged pull requests are handled entirely by the community.

How did we get there? What are the security ramifications, and how did we find ways to trust but verify on one of the fastest moving GitHub repos?