Coffee With Developers Jan 26, 2026

Don’t Insert Crazy! On cURL and AI Slop - Daniel Stenberg

Daniel Stenberg

Daniel Stenberg warns that AI-generated slop is destroying the open source ecosystem. Learn why the cURL creator finally killed his bug bounty program to stop the madness.

Pause
Mute Enter Fullscreen
#1 about 2 min

The ubiquity of the curl library in connected devices

Widespread reliance on foundational network libraries makes them a ubiquitous component in connected hardware.

#2 about 3 min

Shutting down the bug bounty program due to AI

Surges in automated chatbot submissions make evaluating generic security claims unsustainable for maintainers.

#3 about 5 min

Hallucinated vulnerabilities and automated bug hunting

Artificial intelligence tools frequently generate plausible but entirely fabricated vulnerability reports based on common language patterns.

#4 about 5 min

Moving vulnerability reporting to GitHub to deter bounty hunters

Shifting bug reports to platforms without direct payout incentives filters out low-effort automated submissions.

#5 about 3 min

Why standard pull requests face less AI spam

Automated continuous integration checks easily filter out non-functional code submissions before maintainer review.

#6 about 4 min

How AI code generation threatens open source feedback loops

Generating code without acknowledging external dependencies breaks the cycle of usage reporting and contributor recognition.

#7 about 6 min

Evaluating HackerOne metrics against fake vulnerability claims

Popular open source repositories face disproportionate amounts of fabricated security reports from users seeking monetary rewards or career advancement.

#8 about 4 min

Monetizing open source despite AI traffic interception

Alternative monetization strategies become necessary when generative AI tools intercept documentation traffic and reduce ad revenue.

#9 about 5 min

Commercial support contracts and maintainer succession planning

Providing long-term enterprise support requires established bus factor contingency plans for core maintainers.

#10 about 3 min

Code refactoring and the lifespan of software vulnerabilities

The latency between introducing a bug and its discovery complicates measuring the success of ongoing code refactoring efforts.

#11 about 2 min

Balancing library resilience with user responsibility for API inputs

Clear documentation must define the boundary between safe library usage and deliberate misuse by the caller.

#12 about 4 min

Supporting modern network protocols in foundational libraries

Foundational open source tools must continuously evolve to support modern web standards like HTTP/3.

#13 about 6 min

The necessity of human verification in security reporting

Submitting security claims requires independent logical reproduction rather than naive acceptance of automated tool outputs.

#14 about 2 min

Identifying AI-generated text patterns in issue tracking

Maintainers can identify generative AI submissions through distinct linguistic markers like excessive apologies and structured bullet points.

Matching moments

2:18 min

Handling the surge of AI-generated open-source code contributions

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

2:05 min

The disproportionate impact of AI vulnerabilities on open source

Adrian Mouat Adrian Mouat · WWC Europe 2026

1:59 min

Navigating the impact of AI on open source maintenance

Sinduri Guntupalli Sinduri Guntupalli · WWC Europe 2026

7:02 min

Managing AI generated code and slop in open source

Chris Heilmann +2 · LIVE

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

1:34 min

Navigating security risks in AI-assisted open source contributions

Cédric Gégout Cédric Gégout +4 · WWC Europe 2026

Upcoming sessions on this topic

Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

When Humans Stop Writing Code: Rethinking Languages, Compilers, and Responsibility

Simon Auer

Organizer of flutter vienna meetup and CEO of marqably

Simon Auer
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

The spectrum of agentic coding: From vibe coding to high-quality software engineering

YK Sugi

Developer Experience Manager at Eventual

YK Sugi
Open session

World Congress 2026 North America

The Broken Rung: How AI is Rebuilding Software Development from the Ground Up

Tomislav Tipurić

Chief Technology Officer, Nephos

Tomislav Tipurić