This is a real problem for maintainers.
AI “Security Researchers” making up scenarios out of literally any bug or even possible user mistake, as vulnerabilities.
We should not let it become normal.
Otherwise real vulnerabilities won’t be taken seriously!
Last night I received "5" potential vulnerabilities.
How many were actual vulnerabilities? 0.
How many were bugs? 5.
How many were from the same slop-bot? 5.
The worst part is that if you don't engage with the AI slop horde, they will escalate, and you get a CVE slapped on your project that you then need to dispute (and it will remain disputed).