Coffee With Developers • Jan 26, 2026

Don’t Insert Crazy! On cURL and AI Slop - Daniel Stenberg

Daniel Stenberg

Daniel Stenberg warns that AI-generated slop is destroying the open source ecosystem. Learn why the cURL creator finally killed his bug bounty program to stop the madness.

Pause
Mute Enter Fullscreen
#1 about 2 min

The ubiquity of the curl library in connected devices

Widespread reliance on foundational network libraries makes them a ubiquitous component in connected hardware.

#2 about 3 min

Shutting down the bug bounty program due to AI

Surges in automated chatbot submissions make evaluating generic security claims unsustainable for maintainers.

#3 about 5 min

Hallucinated vulnerabilities and automated bug hunting

Artificial intelligence tools frequently generate plausible but entirely fabricated vulnerability reports based on common language patterns.

#4 about 5 min

Moving vulnerability reporting to GitHub to deter bounty hunters

Shifting bug reports to platforms without direct payout incentives filters out low-effort automated submissions.

#5 about 3 min

Why standard pull requests face less AI spam

Automated continuous integration checks easily filter out non-functional code submissions before maintainer review.

#6 about 4 min

How AI code generation threatens open source feedback loops

Generating code without acknowledging external dependencies breaks the cycle of usage reporting and contributor recognition.

#7 about 6 min

Evaluating HackerOne metrics against fake vulnerability claims

Popular open source repositories face disproportionate amounts of fabricated security reports from users seeking monetary rewards or career advancement.

#8 about 4 min

Monetizing open source despite AI traffic interception

Alternative monetization strategies become necessary when generative AI tools intercept documentation traffic and reduce ad revenue.

#9 about 5 min

Commercial support contracts and maintainer succession planning

Providing long-term enterprise support requires established bus factor contingency plans for core maintainers.

#10 about 3 min

Code refactoring and the lifespan of software vulnerabilities

The latency between introducing a bug and its discovery complicates measuring the success of ongoing code refactoring efforts.

#11 about 2 min

Balancing library resilience with user responsibility for API inputs

Clear documentation must define the boundary between safe library usage and deliberate misuse by the caller.

#12 about 4 min

Supporting modern network protocols in foundational libraries

Foundational open source tools must continuously evolve to support modern web standards like HTTP/3.

#13 about 6 min

The necessity of human verification in security reporting

Submitting security claims requires independent logical reproduction rather than naive acceptance of automated tool outputs.

#14 about 2 min

Identifying AI-generated text patterns in issue tracking

Maintainers can identify generative AI submissions through distinct linguistic markers like excessive apologies and structured bullet points.

Matching moments

2:18 min

Handling the surge of AI-generated open-source code contributions

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

2:05 min

The disproportionate impact of AI vulnerabilities on open source

Adrian Mouat Adrian Mouat · World Congress 2026 Europe

1:59 min

Navigating the impact of AI on open source maintenance

Sinduri Guntupalli Sinduri Guntupalli · World Congress 2026 Europe

7:02 min

Managing AI generated code and slop in open source

Chris Heilmann Chris Heilmann +2 · LIVE

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann Chris Heilmann +2 · LIVE

1:34 min

Navigating security risks in AI-assisted open source contributions

Cédric Gégout Cédric Gégout +4 · World Congress 2026 Europe