Since Jan 1, I've received 200+ vulnerability reports and reviewed every one. Most looked AI-generated, and some days different people reported the exact same issue. I assigned just four CVEs. Over 98% were AI slop or unverified. This is the daily reality of OSS.