Coffee With Developers Jan 26, 2026

Don’t Insert Crazy! On cURL and AI Slop - Daniel Stenberg

Daniel Stenberg

Daniel Stenberg warns that AI-generated slop is destroying the open source ecosystem. Learn why the cURL creator finally killed his bug bounty program to stop the madness.

Pause
Mute Enter Fullscreen
#1 about 2 min

The ubiquity of the curl library in connected devices

Widespread reliance on foundational network libraries makes them a ubiquitous component in connected hardware.

#2 about 3 min

Shutting down the bug bounty program due to AI

Surges in automated chatbot submissions make evaluating generic security claims unsustainable for maintainers.

#3 about 5 min

Hallucinated vulnerabilities and automated bug hunting

Artificial intelligence tools frequently generate plausible but entirely fabricated vulnerability reports based on common language patterns.

#4 about 5 min

Moving vulnerability reporting to GitHub to deter bounty hunters

Shifting bug reports to platforms without direct payout incentives filters out low-effort automated submissions.

#5 about 3 min

Why standard pull requests face less AI spam

Automated continuous integration checks easily filter out non-functional code submissions before maintainer review.

#6 about 4 min

How AI code generation threatens open source feedback loops

Generating code without acknowledging external dependencies breaks the cycle of usage reporting and contributor recognition.

#7 about 6 min

Evaluating HackerOne metrics against fake vulnerability claims

Popular open source repositories face disproportionate amounts of fabricated security reports from users seeking monetary rewards or career advancement.

#8 about 4 min

Monetizing open source despite AI traffic interception

Alternative monetization strategies become necessary when generative AI tools intercept documentation traffic and reduce ad revenue.

#9 about 5 min

Commercial support contracts and maintainer succession planning

Providing long-term enterprise support requires established bus factor contingency plans for core maintainers.

#10 about 3 min

Code refactoring and the lifespan of software vulnerabilities

The latency between introducing a bug and its discovery complicates measuring the success of ongoing code refactoring efforts.

#11 about 2 min

Balancing library resilience with user responsibility for API inputs

Clear documentation must define the boundary between safe library usage and deliberate misuse by the caller.

#12 about 4 min

Supporting modern network protocols in foundational libraries

Foundational open source tools must continuously evolve to support modern web standards like HTTP/3.

#13 about 6 min

The necessity of human verification in security reporting

Submitting security claims requires independent logical reproduction rather than naive acceptance of automated tool outputs.

#14 about 2 min

Identifying AI-generated text patterns in issue tracking

Maintainers can identify generative AI submissions through distinct linguistic markers like excessive apologies and structured bullet points.

Matching moments

2:18 min

Handling the surge of AI-generated open-source code contributions

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

2:05 min

The disproportionate impact of AI vulnerabilities on open source

Adrian Mouat Adrian Mouat · World Congress 2026 Europe

1:59 min

Navigating the impact of AI on open source maintenance

Sinduri Guntupalli Sinduri Guntupalli · World Congress 2026 Europe

7:02 min

Managing AI generated code and slop in open source

Chris Heilmann +2 · LIVE

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

1:34 min

Navigating security risks in AI-assisted open source contributions

Cédric Gégout Cédric Gégout +4 · World Congress 2026 Europe

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 15:30–16:00

Mainstage

Our Brains in the AI Era

Cassidy Williams

Senior Director of Developer Advocacy, GitHub

Cassidy Williams
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 24, 2026 · 16:10–16:40

Outdoor Stage

When Humans Stop Writing Code: Rethinking Languages, Compilers, and Responsibility

Simon Auer

Organizer of flutter vienna meetup and CEO of marqably

Simon Auer
Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer at Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Stage 4

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar