“AI-generated security reports that waste maintainer time will result in immediate ban, public ridicule, and a note in our hall of shame.”

Stenberg has spent twenty years building curl into the most-used networking library on the planet, and he is now spending his evenings dismissing fake CVEs generated by AI tools chasing bug bounties. The new policy is the appropriate response. Maintainers are not free labor for criminal automation pipelines. The signal needs to be loud and consistent. Curl is loud about it. Most projects cannot afford to be.