The AI chatbot vulnerability reports part sure is sad to read.
Why is this even a thing and isn't opt-in?
I dread the idea of starting to get notifications from them in my own projects.
It's a symptom of complete failure of this industry that maintainers are even remotely thinking about, much less implementing changes in their work to stave off harassment over false security impact from bots.
Because humans generate and relay the slop-reports in the hopes of being helpful
Making a strcpy honeypot doesn’t sound like a bad idea…
Some clever obfuscation would make this even more effective.