Curl maintainer: AI security reports are no longer slop
Curl project maintainer Daniel Stenberg reports that the issue of AI-generated slop security reports has been resolved. After shutting down the bug bounty program in February 2026, the project returned to Hackerone in March and found that submissions are now of higher quality, no longer dominated by AI junk.
As I have been preparing slides for my coming talk at foss-north on April 28, 2026 I figured I could take the opportunity and share a glimpse of the current reality here on my blog. The high quality chaos era, as I call it.
No more AI slop
I complained and I complained about the high frequency junk submissions to the curl bug-bounty that grew really intense during 2025 and early 2026. To the degree that we shut it down completely on February 1st this year. At the time we speculated if that would be sufficient or if the flood would go on.
Now we know.
Higher volume, higher quality
In March 2026, the curl project went back to Hackerone again once we had figured out that GitHub was not good enough.
From that day, the nature of the security report submissions have changed.
The slop situation is not a problem anymore.
AI slop rate