"New era of slop security reports for open source" where @sethmlarson describes "an uptick in extremely low-quality, spammy, and LLM-hallucinated security reports to open source projects."
👉 https://sethmlarson.dev/slop-security-reports
Perhaps another argument for sending patches via a mailing list?