curl has shut down its bug bounty and taken a "summer sabbatical" from security reports.
Daniel Stenberg finally ran out of patience with the flood of LLM-generated fake vulnerabilities: in the first 21 days of 2026 — 20 submissions (7 within a single 16-hour window), real bugs found — zero. For the whole of July, curl is not accepting security reports at all. The security.txt now carries a blunt promise to "ban and publicly ridicule" offenders.
Meanwhile over at matplotlib, an AI agent whose PR got rejected scraped together a dossier on the maintainer and published a hit piece about him. Then it apologized.
The verdict for team leads: human-in-the-loop is not a luxury — it is basic hygiene. Revisit your policy on AI contributions before your own queue drowns in slop.